Payments Fraud in Germany 2026: Cash, Cards, Transfers and Multiple Fraud Economies
Germany did not replace cash with one dominant electronic rail. It accumulated girocard, international cards, ELV, direct debit, invoice purchasing, PayPal and faster bank transfers. Fraud follows those distinctions.
Germany’s Payment Market: Less Cash-Heavy, Still Far From Card-Only
The important feature is accumulation. Physical retail, ecommerce and the banking layer each have their own dominant methods—and therefore their own fraud logic.
Germany crossed a symbolic line in 2025. According to the Deutsche Bundesbank, cashless methods accounted for 55% of recorded everyday purchases for the first time. Cash still remained the single most frequently used method at 45%, while debit cards represented 26%, mobile payments 10% and e-payment methods 6%. For merchants selling into this mix, a German merchant account needs to support local debit expectations rather than assuming a card-only checkout model.
Retail turnover tells a more specifically German story. The EHI Retail Institute estimates that girocard accounted for 40.5% of stationary retail turnover in 2025, ahead of international debit cards at 9.4% and credit cards at 8.2%. SEPA direct debit still contributed 6.4%. The plastic may look familiar; the underlying contract is not always the same.
Online, the hierarchy changes again. PayPal represented 28.7% of ecommerce turnover, invoice purchasing 26.1%, direct debit 14.4%, and international credit and debit cards 13.7%. That means a large share of German online fraud exposure sits in identity, account, fulfillment and non-payment risk before a conventional card-fraud rule is even relevant. That is why cross-border merchant accounts serving Germany need controls that cover cards, bank-based payments and post-payment risk.
Payment Fraud in Germany: Cards Drive Incidents, Transfers Drive Losses
Germany's 2024 country data show why a single national fraud rate is a poor guide to merchant risk. Frequency and severity point to different payment rails.
Shares use the four published instruments shown above. *Direct-debit reporting is unusually sensitive to methodology because refunded transactions may not always be investigated and reported as fraud.
The EBA/ECB 2025 fraud report records about 1.36 million fraudulent card transactions on cards issued by German payment service providers in 2024. Credit-transfer fraud produced only 153,909 events. Judged by incident count alone, cards appear to be the German fraud problem.
Value reverses the ranking. Those fraudulent transfers were worth €474.2 million, compared with €124.5 million in card fraud. Across the four instruments shown here, cards generated about 85% of reported fraud events, while transfers generated almost 68% of reported fraud value.
The direct-debit figure needs more caution than the clean-looking number suggests. Germany reported €72.2 million of fraud but only 1,520 fraudulent direct-debit transactions. The EBA/ECB notes that refunded direct debits may go unreported if PSPs do not investigate and classify them as fraud. Treat the figure as reported exposure, not a clean measure of underlying fraud incidence. The card series is also an issuer-side measure: it covers cards issued by German PSPs, including transactions acquired outside Germany, so it should not be read as the fraud rate for all card payments acquired by German merchants.
Instant Transfers Became Mainstream Before Germany’s Fraud Data Caught Up
The transfer rail became much faster in 2025, but Germany's latest harmonized annual country-fraud comparison still covers 2024. Faster payments enlarge the high-speed transfer surface; they do not, by themselves, prove that fraud rose at the same rate.
SEPA Instant Payments Are Accelerating in Germany
2024 is approximately 337 million, derived from the Bundesbank's reported 102% increase to around 680 million in 2025.
The Main Payment Fraud Mechanisms Affecting Germany
The payment mix exposes merchants to three different classes of failure: unauthorized payment use, manipulated bank transfers, and identity or fulfillment fraud that may never look like payment fraud in the regulatory data.
Remote Credential Theft and Account Fraud
German-issued cards generated about 1.36 million fraudulent transactions in 2024, worth €124.5 million; fraudulent value was about 0.022% of card-payment value in the issuer-side country data. Across the EEA, SCA-authenticated card transactions continue to show lower fraud rates than non-SCA transactions. For merchants, that makes card-processing controls most useful when they are applied risk-selectively rather than as blanket checkout friction.
Manipulated Payers and Beneficiary Fraud
Credit transfers produced Germany's largest reported fraud value in 2024. The important failure is often not stolen credentials but a legitimate user or employee authorizing a payment to the wrong beneficiary after phishing, impersonation, invoice substitution or other social engineering.
Identity Fraud, Non-Payment and Account Takeover
A September 2026 CRIF/bevh survey of 76 German online merchants found 93% had encountered fraud or attempted fraud. Identity fraud was cited by 75%. The survey is a merchant-experience sample, not a national incidence estimate, but it is useful evidence that German ecommerce risk extends well beyond stolen card credentials. Merchants with elevated fraud, fulfillment or dispute exposure may also need a high-risk merchant account structured around those operating realities.
Fraud Demographics in Germany: Age Changes the Channel More Than It Produces One Risk Ranking
Germany's best age evidence does not support one universal “most vulnerable” group. Ages 25–44 are the most embedded in online banking, while organized call-center fraud explicitly targets older people—and adults over 50 report much less confidence identifying AI-generated content.
In 2025, Destatis found that online-banking use was highest among 25–44-year-olds at 83%. It was 71% among ages 16–24, 68% among ages 45–64 and 50% among ages 65–74. Those figures measure participation in the digital banking surface, not fraud victimization.
Older adults face a different risk channel. The Bundeskriminalamt says organized call-center groups use shock calls, grandchild stories and false-police or false-authority impersonation against victims who are mostly seniors. The mechanism is deliberate selection and social pressure rather than simply greater use of digital banking.
The Cybersicherheitsmonitor 2026, a representative survey of 3,060 internet users aged 16+, adds a newer age signal: only 33% of people over 50 said they were confident they could identify AI-generated images or video, compared with 47% overall. Among cybercrime-affected respondents, 33% reported financial loss. These measures describe recognition and consequences—not an age-specific payment-fraud rate.
Online Banking Participation by Age
Share of age group2025
This is a digital-exposure measure, not a victimization rate.
Why Older-Adult Impersonation Fraud Can Bypass Authentication
The fraudster may not need to compromise an account. Authority, urgency and secrecy can cause a legitimate victim to hand over cash or valuables or to authorize the transfer themselves.
Sources: Destatis, 2025 internet activities by age; BKA, organized call-center fraud targeting; ProPK/BSI, Cybersicherheitsmonitor 2026.
Payment Fraud Prevention in Germany Must Match the Payment Rail
Germany's payment diversity makes generic “fraud prevention” too vague. girocard, ELV, cards, invoice commerce and bank transfers fail in different ways and need different intervention points.
At the physical checkout, girocard and ELV may begin with the same debit card but create different merchant exposures. girocard routes through the domestic debit scheme with issuer-backed payment assurance; ELV creates a direct-debit claim and shifts more attention toward stolen-card blocking, mandate integrity, returns and default.
For remote card payments, strong customer authentication remains the core regulatory control. The EBA/ECB evidence continues to show that SCA is effective against the fraud types it was designed to stop, especially unauthorized card use. Merchant-side fraud and chargeback controls still need to cover identity, fulfillment and dispute risk outside the authentication event.
The transfer layer changed materially in October 2025. Verification of Payee now checks the beneficiary name against the IBAN before both standard and instant SEPA transfers are authorized. It reduces account-substitution errors and some invoice fraud, but it cannot prove that the underlying request itself is genuine.
Fraud Controls for Germany’s Cards, Transfers and Local Debit Methods
For German merchants, offering the payment methods customers expect changes more than conversion. It changes when the merchant takes risk, who authenticates the payment, whether funds are guaranteed and how easily the transaction can be reversed.
Identify the Underlying German Debit Rail
Use: scheme-appropriate authentication, stolen-card blocking, mandate controls and return monitoring. The same physical card can create a materially different merchant exposure.
Move Fraud Decisions Earlier in the Payment Flow
Use: identity, account, address and fulfillment signals before shipment. Invoice purchasing adds credit and intent risk that a card-fraud engine was not built to solve.
Use Strong Card-Fraud Controls Where They Fit
Use: 3DS, SCA, tokenization, device analysis, velocity controls and disciplined exemption handling, with extra scrutiny for unusual cross-border orders.
Protect the Beneficiary Decision
Use: Verification of Payee, dual approval, callbacks for changed account details, transaction limits and escalation rules for new or unusual beneficiaries.
Payment Processing in Germany: Match Fraud Controls to How Germans Actually Pay
Merchants selling into Germany may need domestic and international card acceptance, SEPA workflows, local checkout methods and fraud controls that change with the rail. Underwriting should reflect that real transaction mix—not a generic country average.