What changed
The ECB and EBA released a joint assessment of payment fraud drawing on supervisory reporting across the European Economic Area. The findings are notable less for novelty than for confirmation at scale: after several years of mandatory strong customer authentication, the data now supports what practitioners suspected — SCA materially reduces card fraud where it is applied.
The second finding is the operationally significant one. Card-payment fraud was reported as 17 times higher when the payee was outside the EEA. That is not a marginal difference in risk weighting; it is a structural difference in exposure driven by where authentication requirements and liability frameworks stop applying.
The regulators also observed that strong authentication was less conclusive for some non-card instruments, particularly credit transfers — consistent with the pattern that authentication protects against impersonation of the customer, not manipulation of the customer.
Why it matters
Fraud does not respond to a control by disappearing. It responds by relocating. When authentication raises the cost of one attack path, criminal activity migrates toward transactions, channels, geographies and payment instruments where authentication coverage is thinner and liability protection is weaker.
For merchants, this reframes 3DS strategy. The relevant question is not whether authentication is enabled but where the exempted, out-of-scope and cross-border portions of the portfolio sit — because that is where the residual risk concentrates. An enterprise with 92 percent SCA coverage may hold the overwhelming majority of its fraud exposure inside the remaining 8 percent.
For issuers and acquirers, the cross-border figure has direct portfolio-management implications. It also carries an important caveat: a merchant or portfolio with heavy non-EEA acquiring will show a higher fraud rate for reasons of mix, not necessarily of control quality. Comparing fraud rates across portfolios without normalizing for geography, channel and merchant category produces conclusions that are confidently wrong.
Successful authentication changes the economics of fraud. It does not remove the adversary.
Who is affected
- Cross-border merchants. Businesses acquiring or selling outside the EEA carry structurally higher card-fraud exposure and should expect closer acquirer scrutiny.
- Payment and fraud leaders in the EEA. Authentication coverage, exemption strategy and fraud outcomes now need to be reported together rather than by separate teams.
- Issuers. Cross-border authorization decisioning requires segmentation that reflects the measured risk differential without indiscriminately declining legitimate travel and international commerce.
- Compliance functions. PSD2 compliance and effective fraud control are related but not equivalent. Regulatory conformance does not certify a risk posture.
MerchantGo analysis
The most common strategic error following data like this is to treat the cross-border figure as a targeting instruction. It is not. Declining non-EEA transactions as a class would suppress fraud and revenue in roughly equal measure, and would do so in the segments many businesses are actively trying to grow.
The productive response is segmentation. Fraud rate by corridor, by merchant category, by channel, by authentication status and by exemption type — measured together — reveals whether elevated cross-border fraud reflects genuine control weakness or simply portfolio composition. Most organizations cannot currently produce that view without a manual exercise, which is itself the finding.
Exemption strategy deserves specific scrutiny. Transaction-risk-analysis and low-value exemptions are commercially valuable and operationally sensible, but they create a measurable, deliberate gap in authentication coverage. That gap should be monitored as a named risk with its own fraud rate, not absorbed into a portfolio average where it is invisible.
There is also an authorization-performance dimension that fraud teams frequently miss. Authentication data improves issuer confidence and can lift approval rates on legitimate cross-border traffic. Treating SCA purely as a fraud control undervalues it; treating it as a data-quality investment in the authorization message frames it correctly.
Finally, the credit-transfer finding is the quiet warning. Where authentication is less conclusive, the attack is usually not credential theft — it is the customer being persuaded. Card-centric fraud strategies do not transfer cleanly to those rails.
What leaders should do now
- 01Map authentication coverage against fraud outcomes. Produce a single view of what percentage of volume is SCA-verified, exempted or out of scope — and the fraud rate of each. Manage the gaps explicitly.
- 02Segment before you compare. Normalize fraud rates by geography, merchant category, channel and authentication status. Portfolio mix explains more variance than control quality in most comparisons.
- 03Treat cross-border as a managed corridor, not a risk class. Apply differentiated decisioning by corridor and category rather than blanket restriction on non-EEA activity.
- 04Review exemption strategy quarterly. Each exemption type should carry its own monitored fraud rate and an agreed threshold at which it is narrowed.
- 05Measure authentication's authorization benefit. Track approval-rate impact alongside fraud impact so that authentication investment is evaluated on total economics.
- 06Separate compliance reporting from risk reporting. Regulatory conformance and effective control are different questions. Executive reporting should answer both, distinctly.

