Payments Fraud in Spain 2026: Cards, Transfers and a Changing Risk Landscape
Cards still generate most reported fraud events in Spain. Transfers generate far fewer incidents, but a successful transfer fraud is much more expensive. Meanwhile, the market itself is fragmenting: cash remains important in person, cards dominate online, and instant payments are becoming mainstream.
Spain’s Payment Market: Cash, Cards, Transfers and Online Payments
Physical retail remains cash-heavy, online commerce remains card-led, and person-to-person payments are moving quickly toward instant account-to-account transfers.
Banco de España's analysis of the 2024 SPACE survey shows how sharply behavior changes by context. Cash accounted for 57% of physical point-of-sale transactions by number, cards 32% and mobile-device payments 7%. Online, cards still led at 51%, while electronic payment solutions represented 26% and instant payments 6%.
Person-to-person payments are further along in the account-to-account shift: instant payments represented 35% of transactions by number in 2024. Bizum illustrates the scale of that change. The company reported 30.6 million users and 1.237 billion operations in 2025. Direct debit remains important for recurring bills and subscriptions, while a mobile wallet may simply be a new interface over an existing card rail.
Payment Fraud in Spain: Cards Drive Volume, Transfers Drive Loss Severity
The latest harmonized cross-rail country comparison is full-year 2024. It shows why transaction count alone is a poor proxy for economic severity.
The EBA/ECB 2024 country data recorded about 2.58 million fraudulent transactions on Spanish-issued cards, compared with 86,382 fraudulent credit transfers. Yet reported fraud value was €141 million for cards and €153 million for transfers.
That produces two different operational problems. Card fraud is frequent and usually small, which rewards scalable screening and authentication. Transfer fraud is much less frequent, but the economics of a successful event are far harsher. Average values derived from the same data were about €55 for card fraud and €1,772 for transfer fraud.
How Payment Fraud Is Changing in Spain
Recent Banco de España data point to two changes: authenticated card transactions continue to show lower observed fraud rates, while transfer fraud is increasingly driven by manipulation of the genuine payer.
Card Fraud in Spain: SCA Versus Non-SCA Transactions
Transfer Fraud in Spain: Payer Manipulation
The two trends point in opposite directions because they address different problems. SCA makes stolen or reused credentials less useful. It does not stop a legitimate customer from being persuaded to authorize a transfer voluntarily.
That distinction is becoming more important as instant payments and Bizum-style account-to-account interactions become more common. Authentication can answer “is this the real customer?” while manipulation controls must also ask “does the customer understand what they are authorizing?”
The Main Payment Fraud Mechanisms Affecting Spanish Merchants
The important distinction is whether the attacker tries to impersonate the payer or instead manipulates the genuine payer's understanding of the transaction.
Card Credential Theft and Unauthorized Payment Fraud
Spanish card fraud remains dominated by stolen card details and fraudster-issued transactions, with lost or stolen cards a distant second. The attacker is trying to use a payment credential without the genuine customer's intent.
Authorized Transfer Scams and Payer Manipulation
The legitimate customer can be persuaded to send money after a fake bank call, impersonated contact or misleading payment request. Banco de España's Bizum guidance warns that a supposed incoming payment may actually be a request for money.
Business Email Compromise and Beneficiary Substitution
Business Email Compromise can leave the invoice, supplier and amount looking legitimate while changing only the destination account. A Spanish National Police case involving more than €4 million documented this pattern.
Who Is Most Affected by Payment Fraud in Spain?
Spain's 2024 cybercrime records show two different demographic patterns at once. The largest number of recorded adult victimizations sits between ages 26 and 65. But within each age band, computer fraud becomes a progressively larger share of the cybercrime mix as age rises.
The Ministry of the Interior recorded 89,878 cybercrime victimizations among ages 26–40 and another 88,652 among ages 51–65. Those are raw recorded victimizations, not population-adjusted rates, so they should be read as volume rather than probability.
The composition is more revealing. Computer fraud represented 81.3% of recorded cybercrime victimizations among ages 18–25, then 84.8% among 26–40, 87.7% among 41–50 and 90.6% among 51–65. Among people over 65, it reached 95.1%.
That means older Spaniards appear less often in the raw victim count, but when cybercrime does reach them it is overwhelmingly fraud. Working-age adults create the largest transaction volume; later-life cybercrime is more concentrated in financially motivated deception.
Computer Fraud by Age Group in Spain
Share of recordedcybercrime victimizations
Source: Spanish Ministry of the Interior, Informe sobre la Cibercriminalidad en España 2024, Illustration 15. Figures are recorded victimizations, not per-capita victimization rates.
Payment Fraud Prevention in Spain: Beyond Strong Customer Authentication
Spain's current response attacks several points in the chain: identity, communications, beneficiary information, transaction behavior and the receiving account.
SCA and 3-D Secure remain central for card and account authentication. Order TDF/149/2025 added telecom blocking rules from March 2025, while the CNMC's Alias Registry adds controls for branded messaging. Since 9 October 2025, Verification of Payee has added a beneficiary-name check for ordinary and instant euro transfers.
The controls solve different problems. Authentication can make stolen credentials less useful; telecom controls can reduce spoofed identities; VoP can expose a beneficiary-name mismatch; transaction monitoring can flag unusual behavior; receiving-bank controls can identify mule activity. None substitutes for the others.
Recorded spoofing incidents rose from 196 in 2021 to 3,135 in 2024. By August 2026, the Ministry for Digital Transformation said telecom measures had blocked more than 300 million calls and 26.6 million messages. Those are filtering totals, not confirmed prevented scams.
Fraud Controls for Cards, Transfers and Merchant Payments in Spain
The practical question is not whether a payment method is simply “safe” or “unsafe.” It is where the most important failure point sits and which operational control can interrupt it.
Preventing Unauthorized Card and Account Use
Operational response: use 3DS, risk-based screening, device and order signals, and fulfillment checks.
Stopping Fake Payment Confirmations and Misleading Requests
Operational response: verify the transaction inside the actual banking or payment environment before fulfillment or refund.
Preventing Wrong-Beneficiary and Manipulated-Payer Fraud
Operational response: use beneficiary verification and escalation for unusual or high-value payments.
Preventing BEC and Beneficiary Substitution
Operational response: independently verify account changes and use dual approval for exceptions.
Payment Processing in Spain: Build Controls Around Your Actual Risk
Merchants selling into Spain or operating across borders need payment acceptance, fraud controls and underwriting that reflect where the business is established, where customers are located, the currencies they use, and the risk profile of the transactions—not a generic international setup.