Losses from manipulation fraud in France, meaning payments that victims authorize themselves after being deceived, reached €516 million in 2025, up 34% from a year earlier. The Observatory for the Security of Payment Means (OSMP), a body housed at the Banque de France, the French central bank, reported the figure in its tenth annual report, published September 9, 2026. Manipulation fraud now accounts for more than 40% of all payment fraud losses, and it drove the rise in the overall total.
Fraud on cashless payment instruments in France cost €1.241 billion in 2025, up 3.8% year over year. The number of fraudulent transactions fell over the same period, by 7.6% from 2024 to 7.2 million.
Scams have doubled their share of losses in four years
Social engineering is taking over from technical attacks. The share of manipulation fraud in total losses has doubled in four years, after a cumulative 43% rise between 2021 and 2024. The schemes include:
- Bank impersonation scams, in which a fake bank advisor talks the victim into approving a fraudulent transaction themselves
- Fake fraud department scams, which hijack the very procedure meant to protect the customer
- CEO fraud, in which the fraudster poses as an executive to get a company to send a transfer
- IBAN substitution, which swaps a legitimate creditor’s bank details for the fraudster’s
Card fraud falls to a record low
Card fraud fell in both value and rate, a sign that the strong customer authentication rolled out on remote payments over the past several years is working. Checks, by contrast, carry the highest fraud rate of any instrument the Observatory tracks, even as their use keeps declining. The report singles out checkbook delivery as a persistent weak point. It recommends that banks offer secure, tracked delivery, or free pickup at a branch, by December 2026.
Passing authentication does not end a bank’s duty to refund
Under Article L. 133-18 of France’s Monetary and Financial Code, the bank that holds the account must immediately refund a customer hit by an unauthorized transaction, unless it can show gross negligence by the customer. A transaction that passed strong authentication does not, on its own, prove that negligence. When a scammer leads the victim to approve the payment on their own device, the authentication works exactly as designed. The dispute then turns on how the customer behaved, not on how secure the system was.
Fraud prevention shifts from identity checks to payment behavior
The tenth report confirms a reversal that has been building for several years. Payment fraud is moving away from technical attacks, which have become costly to scale against mature defenses, and toward manipulating the payer, which gets around those defenses without having to break them. Detection based on payment behavior, rather than on verifying the payer’s identity alone, is becoming the main tool banks have left against fraud that strong authentication, by design, cannot stop.