+1 (866) 415-2636

Talk To An Agent Today

Payment Fraud in Germany: a 2026 Brief

Durango Merchant Services · Payments intelligence

Payments Fraud in Germany 2026: Cash, Cards, Transfers and Multiple Fraud Economies

Germany did not replace cash with one dominant electronic rail. It accumulated girocard, international cards, ELV, direct debit, invoice purchasing, PayPal and faster bank transfers. Fraud follows those distinctions.

45%Share of recorded everyday payments made in cash in 2025.
40.5%girocard share of stationary retail turnover in 2025.
28.7%PayPal share of German ecommerce turnover in 2025.
€474.2mReported fraudulent credit-transfer value in Germany in 2024.
01
The payment market

Germany’s Payment Market: Less Cash-Heavy, Still Far From Card-Only

The important feature is accumulation. Physical retail, ecommerce and the banking layer each have their own dominant methods—and therefore their own fraud logic.

Germany crossed a symbolic line in 2025. According to the Deutsche Bundesbank, cashless methods accounted for 55% of recorded everyday purchases for the first time. Cash still remained the single most frequently used method at 45%, while debit cards represented 26%, mobile payments 10% and e-payment methods 6%. For merchants selling into this mix, a German merchant account needs to support local debit expectations rather than assuming a card-only checkout model.

Retail turnover tells a more specifically German story. The EHI Retail Institute estimates that girocard accounted for 40.5% of stationary retail turnover in 2025, ahead of international debit cards at 9.4% and credit cards at 8.2%. SEPA direct debit still contributed 6.4%. The plastic may look familiar; the underlying contract is not always the same.

Online, the hierarchy changes again. PayPal represented 28.7% of ecommerce turnover, invoice purchasing 26.1%, direct debit 14.4%, and international credit and debit cards 13.7%. That means a large share of German online fraud exposure sits in identity, account, fulfillment and non-payment risk before a conventional card-fraud rule is even relevant. That is why cross-border merchant accounts serving Germany need controls that cover cards, bank-based payments and post-payment risk.

02
The fraud shape

Payment Fraud in Germany: Cards Drive Incidents, Transfers Drive Losses

Germany's 2024 country data show why a single national fraud rate is a poor guide to merchant risk. Frequency and severity point to different payment rails.

Payment type
Fraud
Share of reported total
Credit transfersSEPA and other credit transfers
153.9k€474.2m
Count
Value
CardsGerman-issued card payments
1.36m€124.5m
Count
Value
Direct debitsReported series; important caveat
1.5k*€72.2m*
Count
Value
ATM withdrawalsCash-withdrawal fraud
82.3k€27.1m
Count
Value

Shares use the four published instruments shown above. *Direct-debit reporting is unusually sensitive to methodology because refunded transactions may not always be investigated and reported as fraud.

Source: EBA/ECB 2025 Report on Payment Fraud · Germany 2024

The EBA/ECB 2025 fraud report records about 1.36 million fraudulent card transactions on cards issued by German payment service providers in 2024. Credit-transfer fraud produced only 153,909 events. Judged by incident count alone, cards appear to be the German fraud problem.

Value reverses the ranking. Those fraudulent transfers were worth €474.2 million, compared with €124.5 million in card fraud. Across the four instruments shown here, cards generated about 85% of reported fraud events, while transfers generated almost 68% of reported fraud value.

The direct-debit figure needs more caution than the clean-looking number suggests. Germany reported €72.2 million of fraud but only 1,520 fraudulent direct-debit transactions. The EBA/ECB notes that refunded direct debits may go unreported if PSPs do not investigate and classify them as fraud. Treat the figure as reported exposure, not a clean measure of underlying fraud incidence. The card series is also an issuer-side measure: it covers cards issued by German PSPs, including transactions acquired outside Germany, so it should not be read as the fraud rate for all card payments acquired by German merchants.

The fraud model changes with the denominator.Cards are the high-frequency channel. Transfers are the high-severity channel. Direct debit is the channel where reporting mechanics themselves become part of the interpretation.
03
What changed

Instant Transfers Became Mainstream Before Germany’s Fraud Data Caught Up

The transfer rail became much faster in 2025, but Germany's latest harmonized annual country-fraud comparison still covers 2024. Faster payments enlarge the high-speed transfer surface; they do not, by themselves, prove that fraud rose at the same rate.

SEPA Instant Payments Are Accelerating in Germany

German PSPs · millions of transfers

2024 is approximately 337 million, derived from the Bundesbank's reported 102% increase to around 680 million in 2025.

Source: Deutsche Bundesbank
Instant-transfer volume +102%The number of SEPA instant transfers rose to around 680 million in 2025.
Instant-transfer value +141%Value climbed to roughly €610 billion. Speed is becoming a mainstream feature of the transfer rail, not an edge case.
girocard kept growinggirocard recorded 8.3 billion transactions in 2025, up 4.8%, with 88.5% contactless by December.
2026 consumer evidence adds a separate fraud lensThe Cybersicherheitsmonitor 2026 found online-shopping and online-banking fraud among the most common cybercrime experiences; one-third of affected respondents reported financial loss. This is a representative consumer survey, not PSP payment-fraud reporting, so it should not be merged into the EBA/ECB series.
Fraud measurement lags the market changeThe most recent harmonized annual Germany fraud comparison in the joint EBA/ECB report is still 2024. It would be misleading to present the 2025 payments expansion as proof that German transfer fraud increased by the same amount.
04
Prominent fraud

The Main Payment Fraud Mechanisms Affecting Germany

The payment mix exposes merchants to three different classes of failure: unauthorized payment use, manipulated bank transfers, and identity or fulfillment fraud that may never look like payment fraud in the regulatory data.

Cards

Remote Credential Theft and Account Fraud

German-issued cards generated about 1.36 million fraudulent transactions in 2024, worth €124.5 million; fraudulent value was about 0.022% of card-payment value in the issuer-side country data. Across the EEA, SCA-authenticated card transactions continue to show lower fraud rates than non-SCA transactions. For merchants, that makes card-processing controls most useful when they are applied risk-selectively rather than as blanket checkout friction.

Main defenses3-D Secure, SCA, tokenization, device signals, velocity controls, order-risk scoring and stricter treatment of unusual cross-border transactions.
Transfers

Manipulated Payers and Beneficiary Fraud

Credit transfers produced Germany's largest reported fraud value in 2024. The important failure is often not stolen credentials but a legitimate user or employee authorizing a payment to the wrong beneficiary after phishing, impersonation, invoice substitution or other social engineering.

Main defensesVerification of Payee, independent callbacks for changed bank details, dual approval, transaction monitoring, sensible limits and escalation for unusual beneficiaries.
Ecommerce

Identity Fraud, Non-Payment and Account Takeover

A September 2026 CRIF/bevh survey of 76 German online merchants found 93% had encountered fraud or attempted fraud. Identity fraud was cited by 75%. The survey is a merchant-experience sample, not a national incidence estimate, but it is useful evidence that German ecommerce risk extends well beyond stolen card credentials. Merchants with elevated fraud, fulfillment or dispute exposure may also need a high-risk merchant account structured around those operating realities.

Main defensesIdentity and address consistency, account-tenure and device checks, credit assessment for invoice purchasing, fulfillment evidence, delivery controls and account-security monitoring.
ELV / stolen-card control150,314Cards added to Germany's KUNO blocking system for electronic direct-debit use in 2025. EHI / KUNO.
Card fraud rate · 20240.022%Fraudulent value as a share of issuer-side German card-payment value in the EBA/ECB country data.
05
Who fraud reaches

Fraud Demographics in Germany: Age Changes the Channel More Than It Produces One Risk Ranking

Germany's best age evidence does not support one universal “most vulnerable” group. Ages 25–44 are the most embedded in online banking, while organized call-center fraud explicitly targets older people—and adults over 50 report much less confidence identifying AI-generated content.

In 2025, Destatis found that online-banking use was highest among 25–44-year-olds at 83%. It was 71% among ages 16–24, 68% among ages 45–64 and 50% among ages 65–74. Those figures measure participation in the digital banking surface, not fraud victimization.

Older adults face a different risk channel. The Bundeskriminalamt says organized call-center groups use shock calls, grandchild stories and false-police or false-authority impersonation against victims who are mostly seniors. The mechanism is deliberate selection and social pressure rather than simply greater use of digital banking.

The Cybersicherheitsmonitor 2026, a representative survey of 3,060 internet users aged 16+, adds a newer age signal: only 33% of people over 50 said they were confident they could identify AI-generated images or video, compared with 47% overall. Among cybercrime-affected respondents, 33% reported financial loss. These measures describe recognition and consequences—not an age-specific payment-fraud rate.

Online Banking Participation by Age

Share of age group
2025
16–24
71%
25–44
83%
45–64
68%
65–74
50%
050%100%

This is a digital-exposure measure, not a victimization rate.

Highest banking participation83%Ages 25–44 used online banking in the prior three months, Destatis 2025.
Older digital participation50%Ages 65–74 used online banking in the prior three months, Destatis 2025.
AI-content confidence33%People over 50 who said they could confidently identify AI-generated images or video, CyMon 2026.
Age-specific mechanism

Why Older-Adult Impersonation Fraud Can Bypass Authentication

The fraudster may not need to compromise an account. Authority, urgency and secrecy can cause a legitimate victim to hand over cash or valuables or to authorize the transfer themselves.

01 · SelectOlder targetBKA describes shock-call victims as mostly senior citizens and false-authority victims as mostly older people.
02 · ImpersonateFamily, police, authoritySpoofed numbers and credible social roles are used to manufacture legitimacy.
03 · PressureEmergency + secrecyUrgency reduces the chance of independent verification with a bank or family member.
04 · ExtractCash, valuables, transferThe victim completes a real handoff or payment, so credential security alone may not stop the loss.
The useful age conclusion is channel-specific: middle-aged adults have the greatest measured online-banking participation, while older adults are deliberately selected for authority-based call-center scams and report lower confidence identifying AI-generated content. Controls should follow the mechanism rather than treating age itself as a fraud score.

Sources: Destatis, 2025 internet activities by age; BKA, organized call-center fraud targeting; ProPK/BSI, Cybersicherheitsmonitor 2026.

06
The German response

Payment Fraud Prevention in Germany Must Match the Payment Rail

Germany's payment diversity makes generic “fraud prevention” too vague. girocard, ELV, cards, invoice commerce and bank transfers fail in different ways and need different intervention points.

At the physical checkout, girocard and ELV may begin with the same debit card but create different merchant exposures. girocard routes through the domestic debit scheme with issuer-backed payment assurance; ELV creates a direct-debit claim and shifts more attention toward stolen-card blocking, mandate integrity, returns and default.

For remote card payments, strong customer authentication remains the core regulatory control. The EBA/ECB evidence continues to show that SCA is effective against the fraud types it was designed to stop, especially unauthorized card use. Merchant-side fraud and chargeback controls still need to cover identity, fulfillment and dispute risk outside the authentication event.

The transfer layer changed materially in October 2025. Verification of Payee now checks the beneficiary name against the IBAN before both standard and instant SEPA transfers are authorized. It reduces account-substitution errors and some invoice fraud, but it cannot prove that the underlying request itself is genuine.

07
Merchant takeaways

Fraud Controls for Germany’s Cards, Transfers and Local Debit Methods

For German merchants, offering the payment methods customers expect changes more than conversion. It changes when the merchant takes risk, who authenticates the payment, whether funds are guaranteed and how easily the transaction can be reversed.

girocard / ELV

Identify the Underlying German Debit Rail

Use: scheme-appropriate authentication, stolen-card blocking, mandate controls and return monitoring. The same physical card can create a materially different merchant exposure.

PayPal / invoice

Move Fraud Decisions Earlier in the Payment Flow

Use: identity, account, address and fulfillment signals before shipment. Invoice purchasing adds credit and intent risk that a card-fraud engine was not built to solve.

International cards

Use Strong Card-Fraud Controls Where They Fit

Use: 3DS, SCA, tokenization, device analysis, velocity controls and disciplined exemption handling, with extra scrutiny for unusual cross-border orders.

Bank transfers

Protect the Beneficiary Decision

Use: Verification of Payee, dual approval, callbacks for changed account details, transaction limits and escalation rules for new or unusual beneficiaries.

Germany is not a market where one fraud-control stack can simply be localized into German. The payment mix itself is part of the risk model.
Durango Merchant Services

Payment Processing in Germany: Match Fraud Controls to How Germans Actually Pay

Merchants selling into Germany may need domestic and international card acceptance, SEPA workflows, local checkout methods and fraud controls that change with the rail. Underwriting should reflect that real transaction mix—not a generic country average.

Data note. Payment-market figures primarily use 2025 Bundesbank and EHI data, with girocard's 2025 scheme statistics where noted. Harmonized Germany fraud figures use the EBA/ECB 2025 Report on Payment Fraud covering calendar 2024; its card data are issuer-side, not a measure of all transactions acquired by German merchants. Fraud values are reported fraudulent transaction values, not necessarily final net losses after recovery or reimbursement. The direct-debit series has a specific reporting caveat noted by EBA/ECB. The September 2026 CRIF/bevh ecommerce findings come from 76 German online merchants and should be read as merchant experience, not population incidence. Demographic evidence combines digital-use, representative cyber-safety survey and BKA targeting evidence; those datasets answer different questions and are not combined into one age-risk score.
Scroll to Top