MerchantGo Intelligence Platform

White Papers

Evidence-led analysis for leaders making consequential decisions across fraud, payments, disputes and digital identity.

Long-form executive analysis that connects network rules, external evidence and operating economics—without vendor agendas.

Papers
3 Papers
Updated
August 2026
Format
On-page, no gating
Audience
Executives, Legal, Regulatory

White Paper 01 · Updated August 2026

The New Economics of Card-Not-Present Risk

Why fraud, disputes, false declines and customer friction must be managed as one economic system.

What the evidence says

The Federal Trade Commission reported that consumers filed 2.6 million fraud reports in 2024 and reported losing more than $12.5 billion — 25% more than in 2023. Just as telling: the share of people who reported losing money rose from 27% in 2023 to 38% in 2024. Report volume held broadly steady while conversion into loss climbed. These are consumer-reported losses, not merchant losses, but they describe the pressure landing on consumer-facing commerce.

On the dispute side, Visa has stated that approximately $11 billion of charges were disputed with U.S. issuers in the cited year, against $7.2 billion in 2019. Mastercard, separately, cites a forecast that global merchant chargeback costs may reach $42 billion by 2028, with nearly half reported as fraudulent. That $42 billion is a forecast, not an observed result, and should be treated as directional planning input only.

FTC-reported consumer fraud losses, 2024

Consumers reported more than $12.5B lost to fraud in 2024 — 25% more than 2023. FTC did not publish the comparison year as a charted value here, so only the 2024 total and the stated year-over-year change are shown.

  • 2024 reported consumer fraud losses$12.5B+

    2.6 million fraud reports filed in 2024.

  • Year-over-year change vs 2023+25%

    Stated by the FTC as a percentage increase, not a charted dollar comparison.

View data as a table
FTC-reported consumer fraud losses, 2024
MeasureReported figure
2024 reported consumer fraud losses$12.5B+
Year-over-year change vs 2023+25%

Share of fraud reports involving a monetary loss

The proportion of people reporting fraud who said they lost money rose year over year.

  • 202327%
  • 202438%
View data as a table
Share of fraud reports involving a monetary loss
YearShare reporting a loss
202327%
202438%

Executive implications: the loss waterfall

Most fraud programmes are still reported as a single ratio. That ratio is one line in a waterfall of eight costs, and every control moves more than one line at a time. A tightened rule that removes approved fraud almost always adds false declines, review labour and support contacts. The programme looks better; the business is worse.

Card-not-present loss waterfall — the eight lines that must be priced together
LineWhat it measuresTypical direction when fraud rules tighten
Approved fraudConfirmed fraud losses on approved transactionsDown
False declinesGood demand rejected by policy, model or issuer responseUp — usually the largest hidden line
Authentication abandonmentCustomers lost during 3DS challenge or step-upUp
Manual-review expenseAnalyst hours, tooling, queue latencyUp
Dispute handlingRepresentment labour, evidence assembly, win-rate outcomesMixed
Network exposureMonitoring-programme ratio risk and remediation effortMixed — depends on dispute mix, not fraud alone
Support costContacts generated by declines, holds and disputesUp
Lifetime-value damageCohort retention loss from wrongly blocked customersUp, and rarely measured

The discipline is not complexity for its own sake. It is that no single owner currently holds all eight lines, so improvements are declared in one function while the cost lands in another. Optimising fraud rate alone can and does worsen total economics.

White Paper 02 · Updated August 2026

VAMP Changes the Operating Model

Network monitoring is no longer a back-office ratio; it is a cross-functional control system.

What the evidence says

Visa’s 2025 fact sheet defines VAMP as a count-based ratio that combines fraud and disputes: [TC40 fraud + TC15 disputes] divided by TC05 settled card-not-present transactions. The change from earlier, separately monitored fraud and dispute programmes is structural — a merchant can hold an acceptable fraud rate and still breach on non-fraud dispute volume.

Pre-dispute resolutions and qualifying CE3.0 fraud can be excluded from the numerator, but those exclusions are contingent on timing. Evidence submitted or resolutions filed outside the qualifying window do not remove the count. That single detail moves dispute operations from a recovery function to a ratio-management function.

Visa VAMP thresholds as published in the 2025 fact sheet — confirm current applicability
MeasureRegionsThresholdEffective
Excessive merchant ratioAP, Canada, EU, U.S.220 bps with at least 1,500 monthly fraud-plus-dispute countAs shown in the 2025 fact sheet
Excessive merchant ratio (reduced)AP, Canada, EU, U.S.150 bps1 April 2026
EnumerationAs publishedRatio of at least 2,000 bps and count of at least 300,000 transactionsAs shown in the 2025 fact sheet

Executive implications: an operating cadence

A monthly ratio cannot be managed monthly. By the time a breach is confirmed, the transactions that caused it are 30 to 60 days old and the remediation window is largely spent. The workable cadence separates signal, cause and reconciliation.

VAMP operating cadence
CadencePurposeOwnerOutput
Daily signalTrack fraud and dispute counts against the denominator trend; flag anomalies within 24 hoursFraud / Payments operationsException list with named follow-up
Weekly root causeClassify the week's counts by driver — fraud, service, fulfilment, subscription, first-party claimRisk, CX/Support, ProductRanked driver list and one owned action each
Monthly network reconciliationRebuild numerator and denominator, verify exclusions applied within their timing windows, reconcile to acquirer reportingPayments + Finance with acquirerSigned-off ratio and variance explanation

White Paper 03 · Updated August 2026

Account Takeover Is a Payments Problem Too

The compromised login is one event inside a larger sequence of identity, session and value movement.

What the evidence says

Verizon’s 2025 DBIR research reports that compromised credentials were an initial access vector in 22% of reviewed breaches. In the analysed SSO-provider data, the median daily credential-stuffing share was 19% of authentication attempts — 25% for enterprise-sized organisations and 12% for small businesses. And in the median infostealer case, only 49% of a user’s passwords were distinct.

Median daily credential-stuffing share of authentication attempts

Verizon 2025 DBIR research, analysed SSO-provider data. Cohorts are organisation size bands, not industries or merchant categories.

  • Small businesses12%
  • All analysed organisations (median)19%
  • Enterprise-sized organisations25%
View data as a table
Median daily credential-stuffing share of authentication attempts
CohortMedian daily share of authentication attempts
Small businesses12%
All analysed organisations (median)19%
Enterprise-sized organisations25%

Executive implications

If roughly a fifth of login traffic is adversarial on a median day, authentication is not a gate that occasionally fails — it is a continuously contested surface. Password reuse at the level the infostealer data describes means a credential compromised anywhere is a credential that works here. The security team can reduce the volume of attempts. Only the payments and product teams can decide what a successfully authenticated session is permitted to do next.

Where the control sits after authentication succeeds
StageWhat changesWho holds the control
Session behaviourNavigation, velocity and device consistency after loginFraud / Product
Profile changeEmail, phone, address, MFA method and payout detailsProduct / Identity
Payment instrumentCard add, stored-value top-up, saved-instrument reusePayments / Fraud
Fulfilment or withdrawalShipping change, digital delivery, cash-out or transferOperations / Payments
RecoveryReversal, reimbursement decision and evidence retentionSupport / Risk / Finance

Sources & methodology

Where these figures come from.

Every figure on this page is quoted directly from the primary source listed alongside it. MerchantGo does not extrapolate, blend or restate third-party data, and no client results are implied anywhere in these papers.

Figures are labelled by their nature. Consumer-reported losses come from the FTC Consumer Sentinel Network and reflect what consumers reported, not merchant losses. The $42B chargeback number is a Mastercard-cited forecast for 2028, not observed loss. Visa VAMP thresholds are network programme rules published in Visa’s 2025 fact sheet and are subject to change. Verizon DBIR figures are cybersecurity and authentication measurements, not payment-fraud rates.

Programme thresholds and effective dates should always be confirmed with your acquirer, processor or Visa representative before operational decisions are made.

Work through these decisions with the MerchantGo team.