DMS MARKET EXPANSION RESEARCH · 2026
U.S. vs. UK Payments & Fraud: What Changes When You Cross the Atlantic
If you are expanding from the U.S. to the UK—or from the UK to the U.S.—you are not just changing currencies. You are entering a market where customers pay differently, banks approve transactions differently, security checks work differently, and fraud losses can land on different parties.
If you simply copy the payment setup that works at home, you can leave yourself more exposed to fraud or make checkout harder than it needs to be. This report walks you through eight practical questions so you can decide what should stay the same, what should change, and what to watch after launch.
$11.01 / $10k
About $11.01 of card fraud for every $10,000 processed in the U.S. in 2023.
£5.70 / £10k
About £5.70 of card fraud for every £10,000 processed in the UK in 2025.
£576.4M
UK bank-transfer scam losses in 2025—almost as large as all UK card-fraud losses.
Executive snapshot
The U.S. and UK use many of the same payment tools—but you should not use them the same way.
The U.S. and UK are both mature card markets, but fraud shows up differently. In the U.S., total card-fraud losses climbed as card spending grew, while fraud per $10,000 processed improved only a little. In the UK, card fraud per £10,000 fell more meaningfully, but criminals shifted toward online card fraud, scams and bank transfers that victims were tricked into sending themselves.
What this means for you: entering a new country should trigger a fresh payment and fraud plan—not a simple country setting. The goal has three parts: protect your customers from avoidable harm, protect your business from fraud and disputes, and approve as many legitimate sales as possible. A payment setup that looks good only because fraud is low can still be failing if it blocks good customers—or if the fraud that gets through falls directly on customers who may have a harder time getting their money back.
79%
U.S. noncash payments made by card
Federal Reserve Payments Study, 2024
64%
UK payments made by card
UK Finance, 2025
- ~59%
Growth in total U.S. card-fraud losses
2016→2023; fraud per $10,000 changed much less
- ~31%
Drop in UK card fraud per £10,000
2016→2025
| What to compare | United States | United Kingdom | What this means for you |
|---|---|---|---|
| How people use cards | Credit and debit both matter, and credit-card use has grown. | Debit is especially important, and cards make up most payments overall. | Expect different customer habits and different approval patterns from customers’ banks. |
| Contactless and mobile wallets | Growing quickly, but not as central to everyday payments as in the UK. | Contactless made up 39% of all payments in 2025, and mobile wallets are mainstream. | If you enter the UK, contactless and wallet payments should feel like standard checkout options. |
| Online checkout security | There is no general rule requiring stronger customer verification on every online card payment. You, your processor and the customer’s bank have more flexibility. | Stronger customer verification is generally required, although many low-risk payments can qualify for exemptions or smoother flows. | Do not copy the same 3-D Secure settings from one market to the other. |
| Card fraud for every 10,000 processed | Recent industry data has stayed around $10–$12 of fraud loss for every $10,000 processed. | Fraud loss for every £10,000 processed has fallen meaningfully over the decade. | The U.S. is a larger market, but its fraud rate is also higher in the broad industry series. |
| Scams involving bank transfers | Reported losses are large and growing, but the U.S. does not publish one clean nationwide total that matches the UK data. | The UK closely tracks scams where a customer is tricked into sending money, and many qualifying victims must be reimbursed. | If you accept UK bank payments, fraud prevention cannot stop at card screening. |
| How fraud prevention is organized | More of the responsibility is spread across card networks, customers’ banks, processors and merchants. | More security requirements and reimbursement incentives are built into the payment system itself. | The same fraud tool can affect approvals, losses and responsibility differently in each country. |
Planning to take payments in the U.S. or UK?
Your merchant account and processor need to fit your business model, expected volume and the market you are entering. DMS can review your processing needs before launch.
Question 1 · Payment habits
How do your customers prefer to pay—and what should you change at checkout?
Start with the way real customers pay. A market built heavily around debit cards and contactless payments creates a different checkout and fraud picture than one where credit cards are nearly as common as debit.
If you are expanding, do not assume customers in the new country will behave like customers at home. In the U.S., the latest Federal Reserve consumer diary shows about 16 credit-card payments, 15 debit-card payments and six cash payments per consumer each month. In the UK, cards made up 64% of all payments in 2025, debit alone accounted for more than half of payments, and contactless accounted for 39%.
Why this matters to you: the payment methods your customers prefer affect which banks approve their transactions, which types of fraud you are likely to see, how disputes happen and which security steps feel normal at checkout.
United States · how consumers paid in 2025
Average number of payments made by one consumer each month. These are payment counts, not percentages of total spending.
No Data Found
United Kingdom · how people paid in 2025
Selected shares of all UK payments. Contactless is a way of making a card payment, so it overlaps with the card total and should not be added to it.
No Data Found
Why these charts are separate: the U.S. and UK studies measure different things. The U.S. chart shows average payments made by a consumer each month. The UK chart shows the share of all payments made in different ways. They are useful side by side, but they should not be combined into one 100% chart.
Entering the U.S.
If you are coming from the UK, expect credit cards to matter more than you may be used to. Track credit and debit separately, because customers’ banks can approve them differently and the cost and pattern of disputes can differ.
Entering the UK
If you are coming from the U.S., make debit cards, contactless payments and mobile wallets feel like normal parts of checkout from day one. In the UK, these are everyday payment habits—not optional extras.
Question 2 · Fraud per 10,000
Is card fraud really higher in the U.S.—or does the U.S. just process more card payments?
Raw fraud totals can be misleading because the U.S. card market is much larger. A fairer question for you is: how much fraud loss occurs for every $10,000 or £10,000 processed?
That separates the size of the market from the amount of fraud inside it. When you are planning an expansion, you need to know whether you are entering a bigger market, a riskier market, or both.
For every 10,000 processed, U.S. card fraud stayed high while the UK moved lower.
A value of 11.01 means about $11.01 of fraud loss for every $10,000 processed in the U.S.; 5.8 means about £5.80 for every £10,000 processed in the UK. The two sources are not perfectly identical, so focus on the size and direction of the gap rather than treating it as an exact transaction-by-transaction comparison.
No Data Found
$11.81 → $11.01
U.S. fraud per $10k, 2016→2023
$11.81 → $11.01 · only about 7% lower
£8.3 → £5.8
UK fraud per £10k, 2016→2023
£8.30 → £5.80 · about 30% lower
$9B → $14.32B
Total U.S. card-fraud losses, 2016→2023
$9B → $14.32B · total losses rose much faster than the fraud rate
£618M → £551M
Total UK card-fraud losses, 2016→2023
£618M → £551M · total losses stayed in a relatively similar range
Total card-fraud losses are on very different scales in the U.S. and UK.
This chart shows total fraud dollars, not fraud risk per transaction. UK losses are converted to U.S. dollars so the overall size can be viewed on one scale. Some U.S. values are calculated from Nilson’s published global totals and U.S. shares. Use the chart above when you want to compare fraud relative to payment volume.
No Data Found
If you are entering the U.S.: you are not only entering a larger card market. The broad industry data also shows more card fraud for every 10,000 processed than in the UK.
If you are entering the UK: the lower card-fraud rate does not mean you can relax. Fraud has shifted into online purchases, stolen accounts, social engineering and bank-transfer scams.
Question 3 · Fraud migration
When one kind of fraud gets harder, where do criminals go next?
Fraudsters change tactics when a payment method becomes harder to attack. Chip cards made it much harder to create and use counterfeit cards, but that did not remove the incentive to steal. More fraud moved toward online purchases, stolen accounts and scams that manipulate the customer directly.
For you, the lesson is simple: do not judge a fraud program only by the type of fraud it stopped. Watch for where the losses move next.
UK counterfeit-card fraud collapsed, but online card fraud stayed dominant.
UK Finance losses in millions of pounds. “Face-to-face” tells you where the card was used; online/card-not-present and counterfeit describe types of fraud. Because those categories overlap in different ways, do not add the lines together.
No Data Found
What changed: UK counterfeit-card losses fell about 87%, from £36.9 million in 2016 to £4.7 million in 2025. But online and other card-not-present fraud still made up about 71% of card-fraud losses in 2025.
What this means for you: once cloned cards became less profitable, criminals leaned more heavily on stolen cards, stolen login accounts, mobile-wallet enrollment fraud, one-time-code scams and social engineering. Your fraud controls need to protect the customer account and the customer journey—not just the card number.
| UK fraud type | 2016 | 2025 | What it tells you |
|---|---|---|---|
| Online / remote card fraud | £432.3M | £423.5M | Still the largest category. Losses fell for several years, then began rising again as criminals adapted. |
| Counterfeit | £36.9M | £4.7M | About 87% lower. Chip security made traditional counterfeit-card fraud far less profitable. |
| Lost & stolen | £96.3M | £109.8M | Fraud with a physical card still matters, especially when cards or devices are stolen. |
| Card identity theft | £40.0M | £54.0M | Stolen identities and compromised customer accounts became more important. |
Question 4 · Checkout security
How often will your customers be asked for an extra security check?
Both countries use chip cards, 3-D Secure (3DS), fraud scoring, digital tokens and device information. The big difference is how the rules start.
In the UK, Strong Customer Authentication (SCA) generally requires stronger customer verification for many electronic payments, with exemptions that can keep low-risk transactions smooth. In the U.S., there is no equivalent nationwide rule for ordinary card purchases, so you, your processor and the customer’s bank have more freedom to decide when an extra check is worthwhile.
For you: in the UK, security checks need to be part of checkout design from the beginning. In the U.S., 3-D Secure is more often a tool you use selectively when the fraud, responsibility or approval benefit is worth the extra step.
Typical U.S. online checkout
Customer checks out
You send the card details and basic transaction information.
Your fraud screening
Your fraud tools decide whether the order looks normal or risky.
Extra bank verification?
Use 3-D Secure when the added security or change in responsibility is worth the extra step.
Customer’s bank
The bank approves or declines the payment and may verify the shopper.
Typical UK online checkout
Customer checks out
Strong Customer Authentication generally applies unless the payment qualifies for an exemption.
Can checkout stay smooth?
Low-risk and other eligible payments may qualify for an exemption that avoids an extra customer step.
Security check if needed
Use 3-D Secure / SCA in the background when possible; ask the customer for an extra step when required.
Customer’s bank
The bank makes the final approval decision after the required security checks.
If you are entering the U.S.
Do not assume that sending every U.S. transaction through the same 3-D Secure policy you use in Europe will improve results. Use extra verification where it meaningfully reduces fraud or moves responsibility without creating unnecessary customer friction or hurting approvals.
If you are entering the UK
Build Strong Customer Authentication and its exemptions into checkout before launch. The goal is not to challenge every customer. It is to let as many legitimate low-risk payments as possible move through smoothly while keeping your normal fraud checks around the transaction.
Question 5 · Who pays
When fraud gets through, who usually ends up paying for it?
A fraud loss is not just about whether a transaction was fraudulent. You also need to know who loses access to the money, how quickly it happens, and how likely that person is to get it back.
An unauthorized credit-card charge, money stolen from a checking account, and a bank transfer that a customer was tricked into sending can all be called “fraud,” but they can feel very different to the person affected. Some losses are normally refunded quickly. Others can temporarily remove money the customer needs for rent, payroll or everyday expenses. And when a customer personally authorizes a scam transfer, recovery can be much harder—especially in the U.S.
That makes customer protection part of your fraud strategy, not a separate issue. You still need to understand who ultimately absorbs the financial loss, but you should also ask what the customer experiences before the reimbursement or dispute process is finished.
The same $1,000 of fraud can feel very different to the customer.
A credit-card fraud claim often starts as a charge on a line of credit. Debit-card fraud or an unauthorized electronic transfer can take money directly from a deposit account while the bank investigates. A scam transfer can be harder still: the customer may have personally pressed “send” after being deceived, which can change the protections that apply.
The chart below does not show which payment method has the highest fraud rate. It shows the dollar losses consumers reported to the Federal Trade Commission in 2024 when they identified how they paid. That distinction matters.
U.S. consumers reported much larger scam losses through bank transfers than card payments.
FTC Consumer Sentinel 2024 reported consumer losses by payment method, sorted by dollars lost. These are consumer reports—not a market-wide fraud rate—and only 18% of 2.6 million fraud reports named a payment method.
No Data Found
What this means: In FTC reports that named a payment method, bank-transfer/payment scams produced $2.089 billion of reported consumer losses in 2024, compared with $275 million for credit cards and $180 million for debit cards. This does not prove bank transfers have a higher fraud rate because the underlying payment volumes and reporting rates are different. It does show why the way money leaves the customer matters: scammers favor payment methods that can be difficult to reverse.
Reimbursement can return the money. It cannot erase the experience.
The UK now offers stronger protection for many bank-transfer scam victims. From 7 October 2024 through 31 March 2026, the Payment Systems Regulator reports that 88% of the money in qualifying APP scam claims was reimbursed, totaling £316 million.
But PSR victim research shows why prevention still matters. Fraud can change how people shop, whom they trust and whether they feel safe using newer payment methods.
88%
of money in qualifying UK APP scam claims reimbursed
7 Oct 2024–31 Mar 2026 · PSR
21%
of APP scam victims said the experience left them anxious or depressed
PSR APP Fraud Survey 2024
48%
said they felt less confident using unfamiliar retailers after APP fraud
PSR APP Fraud Survey 2024
What protection looks like when fraud reaches the customer
The rules below are simplified for comparison. They are not legal advice, and exceptions can apply. The important merchant lesson is that unauthorized fraud and a payment the customer was tricked into authorizing are not treated the same way.
| Payment situation | What the customer may experience | What protection/recovery looks like | What you should think about |
|---|---|---|---|
| U.S. unauthorized credit-card use | A fraudulent charge appears on the customer’s credit line; money is not directly removed from their checking account. | Federal law generally caps required cardholder liability at $50. If only the account number was stolen, the customer generally has no liability. Many issuers provide even stronger protection. | Stop the fraud before the dispute when you can: secure stored accounts, watch for unusual devices or behavior, and use 3-D Secure when the added protection is worth the checkout step. |
| U.S. unauthorized debit / electronic transfer | Money can leave a checking or savings account and reduce what the customer can use while the problem is being investigated. | Regulation E protections depend heavily on how quickly the customer reports the problem. Liability can increase with delayed reporting. Banks may have to provide temporary credit if an investigation takes longer than 10 business days, subject to the rule’s conditions. | Treat debit and account-takeover controls as customer-cash protection, not only as a chargeback problem. |
| U.S. customer-authorized scam transfer | The customer is tricked into sending real money from their own account. | U.S. protections are generally weaker than for unauthorized credit-card use. The FTC warns that a person scammed into moving money out of an account may not be protected and may not get the money back. | Use clear scam warnings, careful recipient/account-change checks and extra confirmation when a bank-payment pattern looks unusual. |
| UK unauthorized payment | Money leaves the customer’s account without their permission. | The FCA says the refund should generally be back in the account by the end of the next business day, with limited exceptions. Up to £35 may apply in some lost/stolen-card situations. | Strong authentication and account protection can prevent the customer from ever needing the refund process. |
| UK qualifying APP scam | The customer authorizes the payment because a criminal has convinced them the recipient or reason is legitimate. | For eligible Faster Payments and CHAPS claims from 7 October 2024, reimbursement can be up to £85,000 and is usually due within five working days. The provider may apply up to a £100 excess in some cases. | If you accept bank payments, use scam warnings, Confirmation of Payee where relevant, recipient risk and controls for suspicious account changes—not only card-fraud screening. |
Then ask who ultimately absorbs the financial loss.
Protecting the customer and assigning the final loss are related, but they are not the same question. A customer may be made whole while the merchant, customer’s bank, processor or another payment provider ultimately carries the cost.
| Scenario | United States | United Kingdom | What this means for you |
|---|---|---|---|
| Stolen / unauthorized credit-card use | U.S. law generally limits what the cardholder can be required to pay, and card-network policies often protect the cardholder even further. | Unauthorized payments are generally refunded quickly, subject to specific exceptions and limited customer responsibility in some lost/stolen cases. | A refunded customer does not tell you who ultimately pays the transaction loss. You still need to understand the card-network and processor rules. |
| Debit / electronic bank payments | How much a U.S. consumer may owe can depend on how quickly the problem is reported. | UK payment-services rules govern how unauthorized debit and electronic payments are handled. | Do not assume debit and credit have the same rules or financial outcome. |
| Chip cards / 3-D Secure | Card-network rules can move certain fraud losses toward the party that did not use the stronger available security step. | 3-D Secure and Strong Customer Authentication can change the evidence available and, in some cases, who is responsible for the loss. | Security settings can change your actual costs—not just the fraud rate shown in a report. |
| Customer tricked into sending a bank payment | The U.S. does not have one nationwide reimbursement system that directly matches the UK approach across payment types. | Many eligible UK Faster Payments scam claims must be reimbursed up to £85,000, with the sending and receiving payment providers generally sharing the cost. | If you accept UK bank payments, you also need to think about scam warnings and whether the receiving account looks suspicious. |
What fraud can really cost you
Think beyond the face value of the fraudulent payment. Your real cost can include the product or service you already delivered, shipping or fulfillment, chargeback fees, staff time, good customers who were wrongly declined, and customers who gave up during checkout.
There is also a customer cost that will not appear neatly in your processor statement: time spent replacing cards, waiting for money to be restored, dealing with a scam, and deciding whether they still trust the business or payment method involved.
Why UK bank-transfer scams change the picture
Under the UK reimbursement system, the payment company that sends the money and the one that receives it generally split the reimbursement cost 50/50 for qualifying claims. That gives the receiving side a financial reason to spot suspicious “mule” accounts used to collect scam proceeds.
If you sell high-ticket products, run a marketplace, provide financial services or accept bank payments in the UK, your fraud plan needs to ask two questions: Was the customer tricked? and Does the receiving account look trustworthy?
Question 6 · How fraud is fought
Why do the U.S. and UK fight fraud differently?
The two countries use many of the same security technologies, but responsibility is organized differently.
In the U.S., more of the day-to-day decision is spread across card networks, customers’ banks, processors and merchants. In the UK, more security requirements and reimbursement incentives are built into the payment system itself.
The results are visible in the long-term data: total U.S. card-fraud dollars rose sharply as card spending grew, while fraud per $10,000 improved only modestly. The UK reduced card fraud per £10,000 more substantially, even though criminals shifted toward other types of attacks.
Since 2016, total U.S. card-fraud losses grew much faster than UK card-fraud losses.
Both countries are set to 100 in 2016, so the chart compares how quickly fraud losses grew rather than comparing dollars with pounds. It removes exchange-rate noise. Pair it with the fraud-per-10,000 chart to see whether losses changed mainly because payment volume grew or because fraud became more common relative to card activity.
No Data Found
What this means in the U.S.
You generally have more freedom to decide how aggressively to screen and verify each transaction. That flexibility makes it especially important to watch how customers’ banks respond, because a fraud rule that looks safer on paper can also reduce approvals.
What this means in the UK
More security is built into the system through chip-and-PIN, Strong Customer Authentication, 3-D Secure exemptions, Confirmation of Payee for bank transfers and reimbursement rules for many bank-transfer scams. Your job is to work within that structure without adding unnecessary friction on top of it.
The data cannot prove that regulation alone created the difference; payment habits, bank behavior and the types of fraud being committed also matter.
The practical lesson for you: judge your fraud program by the whole business result. A control is only helping if it lowers total losses without simply pushing fraud somewhere else—or blocking so many good customers that you lose more revenue than you save.
Question 7 · What to change
What should you actually change before entering the other market?
You do not need to rebuild your fraud program from scratch. You can keep the same core tools—device information, customer identity, order history, transaction speed and frequency, tokenized card data, and signals from banks and card networks.
What should change is how heavily you rely on each signal and when you create extra friction. The best controls do more than protect your chargeback rate: they stop criminals before a customer has to discover a stolen payment, recover money, replace a card or argue over a scam transfer. Use the least disruptive control that meaningfully protects both the customer and your business.
| Situation | If you are entering the U.S. | If you are entering the UK | What to watch after launch |
|---|---|---|---|
| Lower-risk online orders | Screen quietly in the background first. Use 3-D Secure selectively when the added protection is worth the extra step. | Build Strong Customer Authentication into checkout from the start, while using valid exemptions so low-risk customers can move through smoothly. | Card approval rate · smooth security checks · fraud per 10k |
| Higher-risk online orders | Combine device, customer identity, order history and unusual activity; add 3-D Secure when the risk justifies it. | Use 3-D Secure / SCA together with device, customer and behavior checks. Do not rely on the security challenge alone. | Security-check completion · fraud loss · good orders declined |
| Stolen customer accounts | Block repeated login attacks, recognize trusted devices and watch for sudden changes in customer behavior. | Use the same account protections, plus controls for one-time-code scams and fraudulent mobile-wallet enrollment. | Suspicious logins · stolen accounts · unusual wallet enrollments |
| In-store payments | Use chip/contactless payments and closely monitor fallbacks, manually keyed cards and unusual terminal behavior. | Chip and contactless are standard. Focus on stolen cards, stolen devices and unusual use. | Fallback/keyed-entry rate · lost/stolen-card disputes |
| Mobile wallets | Use tokenized wallet credentials and device verification as strong trust signals. | Treat wallets as mainstream, but watch for fraudulent wallet enrollment and stolen one-time codes. | Wallet share · suspicious wallet enrollments |
| Bank payments | Verify account details, watch where money is going, and flag unusual payment patterns. | Use Confirmation of Payee and scam/recipient checks where they apply. | Name/account mismatches · scam warnings · reimbursement claims |
| Subscriptions / recurring billing | Use tokenized stored cards, clear billing descriptions, easy refunds and good dispute prevention. | Use the same basics, while handling UK security requirements correctly when the card is first saved and for later recurring charges. | Renewal approval rate · disputes · customers lost to failed payments |
| Chargebacks and disputes | Keep strong proof of the sale, use clear billing descriptions, resolve complaints early and challenge invalid disputes when appropriate. | Still important, but UK security checks and local rules can change who is responsible for certain losses. | Dispute win rate · cost per dispute · total loss |
If you are entering the UK, 3-D Secure should not be an emergency switch you add after launch. It needs to fit naturally into checkout and the local Strong Customer Authentication rules.
If you are entering the U.S., the opposite mistake is possible: copying a European authentication policy exactly can add friction that U.S. customers and banks do not expect.
Keep the tools. Change the settings. Rebuild your benchmarks around local customer behavior, bank approvals, payment methods and fraud patterns. Then judge each control by three questions: Does it protect the customer? Does it reduce meaningful business loss? Does it still let good customers pay without unnecessary trouble?
Need a merchant account that fits the way you actually sell?
Durango Merchant Services works with domestic and international businesses to find processing options that fit their industry, transaction profile and risk—not just a generic rate sheet.
Question 8 · Fraud vs. sales
How do you protect customers without turning away too many good sales?
Your fraud strategy has three jobs: protect customers, protect your business, and keep checkout easy for legitimate buyers.
You can reduce fraud by declining more orders or adding more security checks, but some of the customers you lose will be legitimate. At the other extreme, an easy checkout with weak protection can leave customers dealing with stolen card use, money missing from a bank account or a scam payment they may struggle to recover.
The commercial goal is still to keep as much good business as possible after fraud losses, chargebacks, processing fees and lost sales—but customer harm is a boundary on that optimization, not simply another cost to price into the equation.
Too little fraud control
Sales approvals may look good at first, but weak controls can expose customers to avoidable fraud while losses and chargebacks climb until they threaten your margins or merchant account.
A balanced approach
Most good customers pass through quietly, while higher-risk activity gets extra review or verification. You protect customers from avoidable fraud without forcing every legitimate buyer through the same level of friction.
Too much fraud control
Too many good customers are declined or asked to complete extra steps. Fraud may fall, but legitimate sales suffer and customers can lose trust in checkout that feels unnecessarily difficult.
See how a fraud-control change can affect the money you keep
A fraud rule can save money by stopping bad transactions, but it can also cost money if it blocks good customers or makes checkout difficult enough that they leave. Enter your current monthly numbers below, then change one assumption and compare the result.
One thing this calculator cannot measure: the personal cost when fraud reaches a real customer. It cannot put a dollar value on someone losing access to money in a checking account, being tricked out of savings or becoming afraid to use an unfamiliar business after a scam. Use the calculator to understand your business economics—but treat customer protection as a requirement, not a number to optimize away.
How much are fraud controls helping—or hurting—your sales?
Enter a few numbers from your payment reports. The calculator estimates what you keep after payment fees, fraud and chargebacks, then lets you see what happens if one part of your checkout improves or gets worse. Use the same currency for every money field.
What the numbers suggest
How this estimate works: We estimate the gross profit from sales that get approved, then subtract fraud losses, chargeback losses and payment-processing fees.
Why declined and abandoned good customers are shown separately: If a good customer is declined or leaves during a security check, that sale never becomes an approved sale. It is already missing from the monthly result, so we do not subtract it a second time. We show the missed gross profit separately so you can see how much potential business may be getting lost before approval.
This is a planning estimate, not a full profit-and-loss statement. It assumes an average chargeback is about the same size as your average order and that customers recovered from a decline or security step behave like your other customers. It does not include taxes, refunds, shipping or fulfillment costs, recovered fraud losses, processor reserves or fixed dispute fees.
Eight numbers worth watching after you enter a new market
1
Card approval rate
What percentage of payments are customers’ banks approving?
2
Security checks completed in the background
How often can 3-D Secure / SCA verify a customer without interrupting checkout?
3
Customers completing extra security checks
When customers are challenged, how many successfully finish?
4
Fraud loss per 10,000
How much fraud are you losing for every 10,000 in approved sales?
5
Chargeback rate
How many approved sales later become disputes?
6
Good orders declined
How often are legitimate customers being blocked?
7
Customers leaving during checkout
Are security steps causing people to give up before paying?
8
Net approved revenue
After fraud, disputes and lost good sales, how much valuable business are you actually keeping?
Visa says authenticated Visa Secure e-commerce transactions show lower fraud than non-authenticated transactions in its network data. Stripe has also published a small U.S. sample showing that some merchant-requested 3-D Secure transactions were approved at a lower rate than the merchants’ normal baseline.
Both can be true. Extra verification can reduce fraud and still hurt some legitimate approvals. That is why you should test the result in your own business instead of assuming that more security is always better.
The question to keep asking: How many good sales are you approving, how much fraud are you accepting, how many good customers are you losing, and what do you keep after all of those effects?
Want help turning these numbers into a processing plan?
If the calculator shows that approvals, fraud or checkout friction are costing you meaningful revenue, DMS can review your business and help you evaluate merchant-account options built around how you take payments.
One UK fraud problem you should not overlook
UK bank-transfer scam losses are now almost as large as all UK card-fraud losses.
UK card fraud totaled £594.9 million in 2025. Authorized Push Payment (APP) fraud—where a person or business is tricked into sending money to a fraudster—totaled £576.4 million. Of that APP loss, £500.8 million was personal loss and £75.6 million was business loss.
That changes the way you should think about the problem. Making stolen-card fraud harder does not remove the criminal incentive; sometimes it moves the attack toward the customer. Instead of stealing a card number, the fraudster convinces a real person to send real money.
UK bank-transfer scam losses have grown to nearly the size of card-fraud losses.
Millions of pounds. The two lines show different kinds of fraud: unauthorized card fraud and Authorized Push Payment (APP) scams, where the victim is tricked into sending the bank payment. The comparison shows that APP fraud is a large, persistent problem—not a one-year spike.
No Data Found
If you are entering the UK: do not assume the card number is always the main target. Sometimes the easier target is the customer. If you run a marketplace, sell high-ticket products, offer financial products or accept bank payments, add scam warnings, recipient checks and controls for suspicious account changes alongside ordinary card-fraud screening.
UK reimbursement rules now return much of the money lost in qualifying APP scams, but reimbursement is not the same as preventing the experience. Payment Systems Regulator research found that fraud can leave people anxious, less trusting and less willing to use unfamiliar retailers. Protecting the customer before the money leaves is better than relying on reimbursement afterward.
Before your first transaction
Build your local payment setup before you start tightening fraud rules.
If you are expanding into another country, treat it as a fresh payment setup—not a new country switch inside your existing fraud rules. Customer payment habits, security requirements, how banks approve transactions, who pays for fraud and what customers expect at checkout can all change.
Before launch, set a new baseline for the market you are entering. Your gateway affects the information sent with each payment. Extra security can change approvals and who is responsible for some fraud. Your processor and acquiring bank can affect approval performance. Tokenization changes how card information is exposed. Your dispute process determines how much of a bad transaction becomes a real loss.
Geography matters, but it should not be your whole strategy.
| Question to answer before launch | What you should decide |
|---|---|
| 1 · How will customers in this market pay you? | Estimate debit, credit, mobile-wallet, in-store, online, recurring and bank-payment sales separately. |
| 2 · When will customers see an extra security check? | Decide when 3-D Secure / Strong Customer Authentication should run in the background, when customers should be challenged, and how that changes responsibility for fraud. |
| 3 · Which fraud checks actually work in the new country? | Confirm that address checks, device data, identity checks, customer-bank data and your fraud tools work well in the new market. |
| 4 · What approval rate should good customers get? | Measure normal approval performance before stricter fraud rules make the numbers look safer by simply declining more customers. |
| 5 · Who pays when fraud gets through? | Understand when the customer’s bank, card network, processor/acquiring bank or your business is likely to absorb the loss. |
| 6 · What will you change if the new rules hurt sales? | Set clear limits for approvals, fraud, chargebacks and checkout drop-off so you can loosen rules quickly if good sales start falling. |
Sources & methodology
The data comes from regulators, central banks and established payment-industry sources.
This report combines government and regulatory data with established payment-industry reporting. U.S. sources include the Federal Reserve, Federal Reserve Bank of Kansas City, Consumer Financial Protection Bureau (CFPB), Federal Trade Commission (FTC) and The Nilson Report. UK sources include UK Finance, the Financial Conduct Authority, the Payment Systems Regulator and UK government payments policy.
Why the U.S. and UK card-fraud lines are not perfectly apples-to-apples: Nilson and UK Finance cover broadly similar card-loss questions but do not use perfectly identical denominators. We use them to compare direction and scale rather than claim false precision.
Why the FTC consumer-loss chart is different: Consumer Sentinel is based on unverified consumer reports, not a census of every fraud event. In 2024, only 18% of 2.6 million fraud reports identified a payment method. The chart is therefore used to show the reported loss pattern by payment method—not to calculate a fraud rate or directly compare FTC card losses with Nilson’s industry-wide card-loss totals.
Payment terms used in this report
| Term | Plain-English meaning |
|---|---|
| APP | Authorized Push Payment — a bank payment that a person or business is tricked into sending to a fraudster. |
| SCA | Strong Customer Authentication — UK rules that generally require stronger customer verification for many electronic payments unless an exemption applies. |
| 3DS | 3-D Secure — an online card security process that lets the customer’s bank verify the shopper and can affect who is responsible for some fraud. |
| CNP | Card-not-present — a transaction where the physical card is not presented, such as most e-commerce and mail/telephone orders. |
| PSP | Payment service provider — a company that helps a business accept, route or process payments. |
| TRA | Transaction Risk Analysis — a UK pathway that can allow some low-risk payments to avoid an extra customer security step when required fraud thresholds are met. |
| EMV | EMV chip-card standard — the global technical standard for chip and contactless card payments; the acronym originated with Europay, Mastercard and Visa. |
| ATO | Account takeover — when a criminal gets into a real customer’s account using stolen login information, a stolen session or a compromised device. |
| OTP | One-time passcode — a temporary security code, commonly delivered by text message, app or another channel. |
| AVS | Address Verification Service — a fraud check that compares the billing address a customer enters with the address held by the customer’s bank. |
| MIT | Merchant-initiated transaction — a later charge made under a customer’s existing agreement, such as many subscription renewals. |
| PIN | Personal identification number — the numeric security code used to verify some in-person card payments. |
| Source family | What it contributes |
|---|---|
| Federal Reserve / Federal Reserve Financial Services | U.S. payment volumes, how consumers pay, debit/card fraud and how fraud shifted after chip cards became widespread. |
| Federal Reserve Bank of Kansas City | Research comparing in-store and online/remote card fraud in the U.S. and other markets. |
| The Nilson Report | Long-term U.S. card-fraud losses and fraud per $10,000 processed. |
| UK Finance | UK payment habits, card fraud by type and location, and Authorized Push Payment bank-transfer scams. |
| Financial Conduct Authority (FCA) / Payment Systems Regulator (PSR) | UK checkout-security rules, unauthorized-payment protections and reimbursement rules for many bank-transfer scams. |
| Federal Trade Commission (FTC) | U.S. consumer-reported scam losses grouped by how the money was paid. |
| Visa / Stripe | Real-world industry data about checkout security and approvals; we treat it as company-provided evidence rather than neutral government data. |
Primary links:
Federal Reserve Payments Study ·
2026 Diary of Consumer Payment Choice ·
Federal Reserve payment fraud study ·
Kansas City Fed card-present/card-not-present analysis ·
Nilson 2023 card fraud ·
UK Finance Fraud Report 2026 ·
UK Payment Markets 2025 ·
Financial Conduct Authority Strong Customer Authentication ·
Payment Systems Regulator authorized push-payment reimbursement · FTC Consumer Sentinel Network Data Book 2024 · CFPB unauthorized credit-card protections · CFPB Regulation E unauthorized-transfer liability · FCA fraudulent-payment refunds and APP protections · PSR APP reimbursement dashboard · PSR APP Fraud Survey 2024.
Durango Merchant Services
Build a payment setup that protects good customers as carefully as it protects your business.
Your processor, gateway, fraud tools, checkout security, chargeback strategy and underwriting all affect whether good transactions get approved, whether customers are protected when criminals attack, and whether the account stays stable as you grow.
Durango Merchant Services works with U.S. and international merchants, including businesses with more complex or higher-risk payment needs. If you are planning to sell into the U.S. or UK, DMS can review how you accept payments, where customer harm is most likely to occur, and which merchant-account and fraud-control options fit the way you actually sell.