The Central Bank of Ireland published its annual payment fraud statistics for 2025 on 4 September 2026. Payment service providers resident in Ireland reported €179.04 million of fraudulent payments, against €140.80 million a year earlier, a rise of 27.2 per cent. A second figure, far less quoted, says more about the shape of the problem. Of the €165.36 million of fraud recorded on electronic payments, 67.4 per cent, or €111.53 million, involved transactions authenticated with strong customer authentication.
What the release covers
The figures are reported under the European regulation on payment statistics, which took effect in 2022 and harmonised the collection of fraud data. The Irish reporting population covers banks, credit unions, payment institutions, e-money institutions and payment service operators resident in Ireland. Volume barely moved, up 0.3 per cent to 510,840 fraudulent transactions, while value grew by more than a quarter. Measured against all payments processed, the fraud rate stands at 0.001 per cent by value and 0.01 per cent by volume, roughly one transaction in every 10,000.
| Instrument | 2025 value | Year-on-year change | Average amount |
|---|---|---|---|
| Credit transfer | €83.34m | +23.3% | €2,412 |
| Card | €51.01m | +18.6% | €119 |
| E-money | €40.42m | +57.7% | €1,427 |
| Direct debit | €12.21m | +28.0% | €126 |
| Cheque | €0.08m | -56.4% | €9,741 |
The scope of strong customer authentication
Strong customer authentication, required by the second Payment Services Directive, checks the identity of the payer through at least two independent elements drawn from knowledge, possession and inherence. The requirement works within the perimeter it was given. Payments authenticated with SCA show a fraud rate of 0.005 per cent by volume, against 0.01 per cent for payments that are not.
The check covers who issues the order, and says nothing about where the money goes or why. A payer talked by phone or by message into moving funds to an account controlled by a third party completes the authentication personally, with their own factors. The order is genuine under the directive and fraudulent in its outcome. The €111.53 million of fraud value sitting inside the authenticated perimeter follows from that gap between the identity verified and the destination of the funds.
The shift towards manipulation of the payer
The Central Bank of Ireland sorts fraud into four scenario types. Manipulation of the payer covers cases where the account holder issues the order themselves after being deceived, the category the industry calls authorised push payment fraud. It reached €74.86 million in 2025 and 45.0 per cent of total fraud value, up from 35.2 per cent a year earlier. On credit transfers alone it moved from 45.6 per cent to 67.2 per cent of fraud value.
The largest of them, issuance of a payment order by the fraudster, still leads by value at €91.32 million and 54.9 per cent of the total. The remaining two, modification of a payment order by the fraudster and unauthorised payment transactions, count for little, and unauthorised transactions are concentrated in direct debits. Banking and Payments Federation Ireland, the industry body, issued a consumer warning the same day built on a narrower perimeter, manipulated credit transfers alone, which it puts at close to €53 million.
Where the money goes
Most fraud reported in Ireland leaves the country. Cross-border transactions carry 69.8 per cent of fraud value, €124.89 million, up 6.3 percentage points on the year, while domestic fraud comes to €54.14 million and 30.2 per cent of the total. The split sets €59.01 million routed inside the European Economic Area, up 26.1 per cent, against €65.88 million sent to accounts outside it, up 54.8 per cent. The faster of the two flows is also the one beyond the cooperation mechanisms set by EU law, which shifts the burden onto the recovery of the funds.
What the rules move
Regulation (EU) 2024/886 on instant credit transfers in euro added a check that looks at the payee. The Article 5c it inserts into Regulation (EU) No 260/2012 requires providers to match the payee name entered by the payer against the actual holder of the account behind the IBAN, and to warn the payer when the two diverge. Providers in a Member State whose currency is the euro have been bound since 9 October 2025. The 2025 Irish figures therefore describe a year that ran almost entirely before that control applied. The Payment Services Regulation, still in the adoption process, extends the same check beyond the transfers already covered.
Colm Kincaid, Deputy Governor for Consumer and Investor Protection at the Central Bank of Ireland, tied the release to a reminder about reporting. Victims who tell their provider are more likely to recover their money. The supervisor notes that 38 per cent of financial fraud victims never report at all. Average fraud amounts differ sharply by instrument, from €119 on cards to €2,412 on credit transfers, while e-money rose from €692 to €1,427 in a year.