Payments Fraud in Belgium 2026: Card-Led Checkout, Transfer-Led Fraud Losses
Belgium is one of the euro area’s most card-oriented physical payment markets, anchored by Bancontact and rapidly growing mobile use. Yet the expensive fraud is concentrated elsewhere: credit transfers account for a minority of fraudulent events but nearly four-fifths of reported fraud value.
Belgium’s Payment Market: Cards, Bancontact and Mobile Payments
The Belgian payment market is unusually easy to recognise: Bancontact is deeply embedded, contactless card use is mainstream, cash is still relevant, and smartphone payments are growing rapidly online and in person.
The National Bank of Belgium’s summary of the ECB SPACE 2024 survey shows cards accounting for 53% of physical purchases, cash for 39%, and payment apps for 3%. Belgium was one of only three euro-area countries where cards exceeded half of POS transactions.
The local layer matters just as much as the generic card category. Bancontact Company reported 2.5 billion electronic payments in 2025, including 526.2 million mobile payments. In December 2025, 72% of in-store Bancontact card payments were contactless, while 86% of online Bancontact payments were mobile.
For merchants, this means Belgium is not simply “Visa and Mastercard plus cash.” Bancontact, QR/mobile flows, SEPA transfers and increasingly instant transfers all sit alongside international card acceptance. The fraud controls need to understand which rail actually settles the payment.
How Belgians Pay at Physical Checkout
Belgium · 2024Belgium is one of the euro area’s most card-heavy POS markets.
Still material, but down from roughly 45% in 2022.
Small in the ECB diary definition, despite much wider mobile use within Bancontact.
Sources: National Bank of Belgium / ECB SPACE 2024; Bancontact Company 2025.
Payment Fraud in Belgium: Cards Drive Volume, Transfers Drive Value
Belgium’s 2024 EBA/ECB data show a particularly sharp split between how often fraud occurs and how expensive the successful event becomes.
Across credit transfers, direct debits, cards and cash withdrawals, Belgium recorded about 554,800 fraudulent transactions worth €272.35 million in 2024. Cards accounted for 461,738 of those events, or about 83%.
Credit transfers produced only 87,235 fraudulent events—about 15.7% of the total—but €216.0 million in fraud value. That is roughly 79.3% of all fraud value measured across those instruments.
The derived average makes the operational difference obvious: about €115 per fraudulent card transaction versus €2,477 per fraudulent transfer. These are transaction values, not necessarily final consumer losses, but they show why one bad transfer can matter far more than many low-value card events.
Fraud by Payment Rail in Belgium
EBA/ECB · 2024Source: EBA/ECB 2025 Report on Payment Fraud, Belgium 2024 country tables. Shares and averages calculated from reported values.
Card figures are reported from the issuer perspective: they cover payments made with cards issued in Belgium, including transactions acquired outside Belgium. They are not a measure of all card transactions acquired by Belgian merchants.
How Faster Transfers and Phishing Are Changing Belgian Fraud
Belgium is simultaneously accelerating account-to-account payments and strengthening the controls around them. That matters because phishing increasingly ends with a transfer the customer has genuinely authorized.
Reported amount stolen through phishing.
Broadly stable versus 2022.
Higher despite extensive bank detection and recovery.
Up 54% from 2024; just over 31% of all Belgian transfers.
Febelfin says roughly €49 million was stolen through phishing in 2024, up from around €40 million in 2023. Banks still detected, blocked or recovered about 75% of fraudulent transfers resulting from phishing.
The speed of the underlying rail is changing too. Belgium processed 197.8 million instant transfers in 2024 and 305.2 million in 2025. Once a manipulated payment is sent instantly, the recovery window becomes extremely short.
That is why beneficiary identity became part of the security perimeter. From 9 October 2025, Belgian banks must verify the beneficiary name against the IBAN for euro transfers within the euro area and warn the payer when they do not match.
Belgium’s Transfer Fraud Controls Are Becoming More Contextual
Belgium · 2025Instant payments became mainstream in 2025.
Verification of the beneficiary became mandatory for euro transfers.
More than 200 Belgian reports in 2024 helped motivate stronger beneficiary checking.
Source: Febelfin / Instant Payments Regulation.
Fraud Demographics in Belgium: Phishing Victimization Was 13% in Both Age Groups
Belgium’s representative 2025 phishing survey gives a much cleaner age comparison than awareness or banking-use proxies: reported phishing victimization was the same in ages 16–30 and 31–79.
A Febelfin / IndiVille representative survey of 2,149 Belgians aged 16–79 found that 13% had personally been victims of phishing. The result was exactly the same in the two reported age bands: 13% among ages 16–30 and 13% among ages 31–79.
The age difference appears more in what happens around the fraud than in the victimization rate itself. Seventeen percent of 16–30-year-olds said someone in their immediate environment had been a phishing victim, compared with 16% among ages 31–79. Among successful-phishing situations, 39% of young respondents said they did not know what to do afterward, versus 27% of the older group.
Younger Belgians also play a distinct role in the fraud infrastructure. In the same 2025 research program, 7% of ages 16–30 had been directly approached to become a money mule, and more than 60% of those actually approached accepted the offer. That is not victimization in the same sense as phishing, so it is treated here as a separate criminal-role measure rather than combined into the age chart.
The direct age conclusion is unusually clear: Belgium’s survey does not show a higher phishing victimization rate for either broad age group. Younger adults differ more in post-fraud response and money-mule recruitment than in the measured phishing-victim rate.
Ever Victim of Phishing · Representative Survey 2025
Bars use a 0–20% comparison scale. Survey: n=2,149, ages 16–79, 20 January–9 February 2025; maximum margin of error 2.1%.
Source: Febelfin / IndiVille, “If it smells phishy, it probably is!”, 2025.
The Main Payment Fraud Mechanisms Affecting Belgium
The technology is often not broken. The customer is moved from a fake message or call into a payment action that appears legitimate to the bank.
Phishing and Credential Theft
Fake bank, parcel, government or commercial messages direct the user to a fraudulent site or persuade them to share banking details.
Bank Impersonation and Social Engineering
In February 2026 Febelfin warned that telephone fraud was rising, with criminals impersonating banks, Card Stop, telecom firms or police.
Safe-Account Transfer Scams
The transfer is genuinely authorized, but the destination is controlled by criminals—often through a money mule.
Money Mules and Fraud-Proceeds Movement
Young people are recruited through social media and promises of easy money to lend their account, card and PIN to criminals.
Invoice Fraud and IBAN Substitution
Belgian authorities recorded more than 200 reports and €3.3 million of reported damage in 2024.
Payment Fraud Prevention in Belgium: Identity, Beneficiary and Transaction Context
Strong authentication remains effective against classic card and account takeover. The newer challenge is preventing a real user from authenticating the wrong economic decision.
Strong Customer Authentication
Protects card and online-banking access, especially against stolen credentials.
Beneficiary Verification
Since October 2025, euro transfers check the beneficiary name against the IBAN before release.
Transaction Monitoring
Belgian banks say roughly 75% of phishing-related fraudulent transfers are detected, blocked or recovered.
Cross-Sector + Victim Response
Belgium’s July 2026 banking-sector action plan adds stronger bank-to-bank data sharing and coordinated response; Fraudstop launched in June as a central contact for suspected online fraud.
Fraud Controls for Bancontact, Cards and Transfers in Belgium
A local Bancontact checkout, a foreign card-not-present order and a supplier transfer can all occur inside the same business while exposing it to completely different fraud mechanisms.
| Exposure | Main failure mode | Control priority |
|---|---|---|
| Bancontact / local cards | Card misuse, phishing and account-linked credential theft. | Use official Bancontact flows, strong authentication and clear separation between checkout and support communication. |
| Ecommerce cards | Remote card credential theft and cross-border card fraud. | 3DS, tokenization, device intelligence and velocity controls. |
| Instant transfers | Manipulated payer sends money with almost no recovery window. | Verification of Payee, behavioral scoring and strong warnings for unusual beneficiaries. |
| Supplier payments | Invoice redirection or changed bank details. | Dual approval and mandatory call-back to a previously verified supplier contact. |
| Customer support | Criminal impersonation of the merchant or bank after a phishing event. | Publish clear support channels and never ask customers for PINs, response codes or card handover. |
| Cross-border commerce | Foreign issuers, weaker SCA outside the EEA and more complex dispute handling. | Geographic rules, 3DS and disciplined chargeback management. |
Merchant context: Durango Merchant Services — Belgium payment processing.
Payment Processing in Belgium: Protect Local Checkout and High-Value Transfers
Merchants operating in Belgium need to support Bancontact, cards, contactless, wallets, SEPA transfers and international customers without treating every payment as the same fraud problem.