Fraud in online retail is not a fringe issue but a line in the profit and loss account. Reported payment fraud in the European Economic Area added up to EUR 4.2 billion in 2024 (ECB/EBA), after EUR 3.5 billion the year before. European merchants lose an average of 2.8% of their revenue to fraud (Sift), and among incidents with a determinable intrusion vector, around 60% start with phishing (ENISA). This article sorts the patterns that hit an online shop, shows the picture for Germany and describes which protective measures can be evidenced legally and technically.
Threat Landscape 2026: Payment Fraud in Numbers
The most solid figures for Europe come from the reporting data of payment service providers. The European Central Bank and the European Banking Authority evaluate them jointly: reported payment fraud in the European Economic Area stood at EUR 4.2 billion in 2024, compared with EUR 3.5 billion in 2023 (ECB/EBA). Around EUR 1.3 billion of that fell on cards issued in the EU or the EEA, an increase of 29% on the previous year (ECB/EBA). These values describe reported losses across all payment types, not the share of a single shop.
For a merchant, a different figure matters more: the share of their own revenue. European merchants lose an average of 2.8% of revenue to fraud (Sift). How strongly the rate depends on the payment route is shown by the same reporting base: outside the EEA, where strong customer authentication is not required, the fraud rate for card payments was seventeen times higher than inside (ECB/EBA). Anyone selling through their own channels and through marketplaces at the same time sees this difference in their own numbers.
Losses from data theft, industrial espionage and sabotage most recently ranged from EUR 211 billion to EUR 270.8 billion (Bitkom). Cyber attacks account for 76% of that, and 58% of companies suffered damage from cyber attacks in the past twelve months (Bitkom). The basis is a representative survey of companies with ten or more employees, not an evaluation of shop data.
The attack surface is not limited to large organisations. Around 80% of reported attacks were directed at small and medium-sized enterprises (BSI). For a shop with few employees this means: the threat does not scale with company size, so the defence has to work without a security team of its own.
Five Fraud Patterns That Hit Online Shops
Fraud in online retail is not a single phenomenon. Five patterns appear regularly in shop data, and they differ clearly in who is behind them, how visible they are and what stops them: payment fraud using third-party card or account data, the takeover of existing customer accounts, misuse by the customer themselves, misuse of the right of return and misuse of coupons and promotions. Anyone trying to catch all five with the same rule ends up mainly blocking honest orders.
Payment Fraud: Third-Party Card and Account Data
In payment fraud, third-party card or account data is used at checkout. The data rarely comes from the shop itself but from payment forms skimmed on other sites: in 2025, more than 10,500 active skimming infections compromised over 23 million online transactions (Recorded Future). How such code gets into a checkout and how it can be spotted is described in the article on checkout skimming.
Account Takeover: Outside Access to Customer Accounts
In an account takeover, the attacker signs in with genuine credentials, usually with username and password pairs captured in a breach of another service. OWASP calls this trying-out credential stuffing and lists it as automated threat OAT-008. Among respondents affected by cybercrime within twelve months, 14% reported outside access to an online account (Cybersicherheitsmonitor), after 8% the year before. The most effective lever is a second factor; how to solve this without a password at all is shown in the article on passkeys.
First-Party Misuse: The Customer as the Offender
In first-party misuse, the actual cardholder disputes an order they placed themselves, or reports goods as not delivered. There are no solid rates for the German market: the cases end up in chargebacks and are not separated there from genuine card fraud. The pattern only becomes visible through customer history – repeated chargebacks alongside otherwise unremarkable orders are the signal, not the single order.
Return Misuse: The Refund as a Scheme
In return misuse, the return becomes the tool: worn goods, swapped items, empty parcels. The volume behind it is considerable – US retail returns of USD 890 billion were expected for 2024, and 93% of the retailers surveyed described return fraud and similar behaviour as a significant problem (NRF). The year before, returns stood at USD 743 billion, the rate across all channels at 14.5% and online at 17.6% or USD 247 billion (NRF). These values are not transferable to Germany; how to lower your own rate is covered in the article on returns management.
Coupon and Promotion Abuse
Coupon and promotion abuse is the quietest of the five cases: multiple accounts redeem new-customer discounts repeatedly, codes from closed groups are shared publicly, scripts try out code patterns. Individually the losses are small; together they shift the margin of an entire campaign. This case too is catalogued by OWASP as an automated threat, and the countermeasures resemble those against credential stuffing: rate limiting, device recognition and account binding rather than plain code checking.
The five patterns rarely appear on their own. In triangulation fraud, an offender orders in your shop using third-party card data and resells the goods through a fake storefront – the buyer there pays the offender, the chargeback hits you. How large this shadow market is can be seen in a single network with more than 4,800 fake storefronts imitating known brands (Sansec). The same source adds an average of 30 new skimmer signatures per day to its scanner – so the tooling side changes faster than a hand-maintained rule list can follow.
| Pattern | What is evidenced | Visibility in the shop | Strongest lever |
|---|---|---|---|
| Payment fraud | EUR 1.3 billion card fraud in the EEA in 2024 (ECB/EBA) | medium, usually only after the chargeback | strong customer authentication |
| Account takeover | 14% of those affected report outside access (Cybersicherheitsmonitor) | high, through sign-in attempts and device changes | second factor, rate limiting |
| First-party misuse | no solid rate for Germany | low, only through customer history | proof of delivery, customer profile |
| Return misuse | USD 890 billion in returns in US retail in 2024 (NRF) | medium, through the return rate per account | return inspection, account binding |
| Coupon abuse | no solid rate | high, through redemption patterns per account | account binding, rate limiting |
Germany in Detail: BKA, BSI and a Consumer Survey
For Germany, the Federal Criminal Police Office provides the official count. The police crime statistics report 333,922 cybercrime cases for 2025 taken together, an increase of 0.2% on the previous year (BKA). Attacks with encryption trojans were reported 1,041 times, 10% more than the year before (BKA). Both series count reports, not incidents – the unreported figure sits below them, and a shop that handles an incident internally appears in neither number.
What an incident costs when it occurs is measured by the annual evaluation of data breaches: the global average cost of a data breach was most recently USD 4.99 million (IBM). What matters is who discovers the incident – if the own team finds it, its course is shortened markedly (IBM). Both are averages across companies of all sizes; for a small shop the lesson is not the sum but the link between your own monitoring and the duration of the damage.
The consumer view completes the picture. A good one in four, 27%, has already been affected by cybercrime (Cybersicherheitsmonitor). Of those affected in the past twelve months, 35% turned to the operator of the service and 32% filed a report with the police (Cybersicherheitsmonitor). For a shop the first number matters most: the operator is the first point of contact, and how quickly someone answers there decides whether the incident is documented at all.
Intrusion Vectors: Where Attackers Actually Get In
Anyone wanting to prioritise defence needs to know where attackers get in. Among the cases where the intrusion vector could be determined, around 60% fell to phishing including vishing, malspam and malvertising (ENISA). Exploiting vulnerabilities follows with 21.3%, botnets with 9.9%, malicious applications with 8% and unauthorised access by insiders with 0.8% (ENISA). The distribution applies within the cases with a known vector, not across all evaluated incidents – so it says where to start, not how frequent an incident is.
For retail in the narrower sense, the evaluation of reported data breaches shows a similar picture in a different order: in retail, 42% of known intrusion routes run through an exploited vulnerability, 14% through misused credentials and 9% through phishing (Verizon). For a shop this means: patch level and account security come before any fraud rule at checkout – anyone getting in through an open vulnerability does not need to place an order at all.
Every fraud rule has two error types: it lets fraud through, or it declines honest orders. The second type appears in no loss statistic, because the rejected customer does not complain but stays away. Measuring detection only by fraud that got through therefore optimises in the wrong direction. Measure both sides: decline rate and chargeback rate belong in the same report.
Pattern Recognition Instead of Rigid Rules
Rigid rules – order value above a limit, deviating delivery address, a particular country – are quick to build and age quickly. They describe yesterday’s fraud, and every new exception makes the rule set more contradictory. Model-based detection reverses the order: instead of setting thresholds, the method learns from your own order data which combinations of features coincide with chargebacks, and returns a risk value per order. How such methods fit into existing shop processes is described on our page on AI automation.
Payment features
Check digit, difference between billing and delivery address, a change of payment method shortly before completion.
Device features
Browser and system details, time zone, language setting – differences between order and account stand out.
Timing behaviour
Time to the confirmation page, typing speed in the address field, time of day measured against the account history so far.
Account history
Age of the account, number of completed orders, returns and chargebacks to date.
Address patterns
Delivery addresses reused across different accounts, pick-up stations, unusual country combinations.
Velocity
Number of orders, sign-in attempts and code redemptions per time window and per account.
What Can Be Measured About Detection
Detection that nobody measures is a claim. Four figures are enough to start with, and all four can be drawn from your own systems: the chargeback rate per payment method, the share of manually reviewed orders, the decline rate and the average time from order to decision. Only these four together show whether a tightening works or merely costs revenue.
With detection rates from others, caution is advised. A hit rate above ninety per cent depends entirely on how the base was chosen: is it measured against all orders or only against those already flagged? Does a withdrawn order count as detected? Without these details a rate is not a metric but an advertising claim. The same applies to your own shop: a number without a denominator says nothing.
Seven Protective Measures for Online Shops
Two measures work regardless of the detection method. The first is multi-factor sign-in: it blocks the vast majority of attacks on accounts, measured across the accounts of a large cloud provider it was 99.9% (Microsoft). The second is how reused passwords are handled: in an evaluation of leaked data sets, 38% of the people examined used the same password with several services, and another 20% merely modified an existing password (Virginia Tech). It is precisely this reuse that makes credential stuffing worthwhile in the first place.
- Apply strong customer authentication consistently. It requires at least two elements from the categories knowledge, possession and inherence, plus the generation of an authentication code (Delegated Regulation (EU) 2018/389, Article 4). Where it is absent, the fraud rate rises noticeably: outside the EEA it was seventeen times higher (ECB/EBA).
- Risk scoring per order instead of fixed thresholds. A risk value built from payment, device and account features separates three routes: pass, review, decline. Only the middle route costs working time, and its share is the adjustment screw.
- Device recognition at checkout. Recurring devices on ever-new accounts and changing devices on one account are the two signals that make credential stuffing visible (OWASP).
- Rate limiting on sign-in, ordering and code redemption. For sign-in attempts NIST sets a hard upper limit: at most 100 consecutive failed attempts per account and authenticator, after which the authenticator is to be disabled (NIST SP 800-63B-4).
- Raise account security. Passwords serving as the only factor need at least 15 characters under the same requirement, and when they are created or changed a comparison against a blocklist of known and compromised passwords is mandatory (NIST SP 800-63B-4).
- Process chargebacks systematically. Every chargeback belongs on record with reason, payment method and account reference – without this assignment any detection method lacks its target variable.
- Prepare monitoring and reporting routes. Entities subject to reporting must submit an early initial report of a significant security incident within 24 hours (Section 32 paragraph 1 BSIG); a data breach must be reported to the supervisory authority within 72 hours (Art. 33 GDPR). Anyone clarifying only in an emergency who reports will miss the deadline.
Legal Framework: Strong Customer Authentication
Strong customer authentication is not a recommendation but applicable law. Article 4 of Delegated Regulation (EU) 2018/389 requires at least two elements from the categories knowledge, possession and inherence and the generation of an authentication code. How far implementation reaches is shown by the reporting data: electronically initiated card payments were strongly authenticated in 40% of cases in 2024, e-money transactions in 38% (ECB/EBA); outside the EEA, where the obligation does not apply, the fraud rate was seventeen times higher (ECB/EBA). For account access through an account information service provider, Delegated Regulation (EU) 2022/2360 sets a deadline: if the last access was more than 180 days ago, strong authentication is required again.
Fraud detection processes personal data and therefore falls under the GDPR. Every processing operation needs a legal basis (Art. 6 GDPR); purpose limitation and data minimisation follow from the principles (Art. 5 GDPR); data protection is to be planned into the architecture rather than added afterwards (Art. 25 GDPR); and transmission and storage need technical measures appropriate to the risk (Art. 32 GDPR). If a data breach occurs, a deadline of 72 hours applies for reporting to the supervisory authority (Art. 33 GDPR). For entities subject to reporting, the BSIG is added: solutions for multi-factor authentication or continuous authentication are mandatory (Section 30 paragraph 2 number 10 BSIG), and the early initial report of a significant incident is due within 24 hours (Section 32 paragraph 1 BSIG). Who is affected is explained in the article on the NIS2 Directive. Regulation (EU) 2024/2847 on products with digital elements applies from 11 December 2027; the reporting obligations for manufacturers under Article 14 have applied since 11 September 2026.
Zero Trust in the Ordering and Account Process
In the ordering process, zero trust does not mean distrusting every customer but trusting no detail blindly just because it was confirmed once. A successful sign-in is not a free pass for the coming weeks; a confirmed delivery address stays confirmed only as long as it does not change. In practice this means: trust has a shelf life, and security-relevant changes reset it. How the principle transfers to the whole shop is described in the article on zero trust for online shops.
Three transitions deserve a check of their own in the shop: the change of delivery address after the order, the change of the stored payment method and the change of email address or password in the account. All three are harmless when the genuine customer triggers them, and all three are the last step before the loss when an attacker triggers them. A confirmation through a second channel costs little at this point and works exactly where account takeover collects its profit.
Technically this is not a rebuild of the whole shop but a question of order. The check belongs before the order is released, not behind the shipping instruction, and the features it needs belong in a separate, sparsely filled data model. Data protection by design (Art. 25 GDPR) here means storing only the features that actually influence a decision and protecting them appropriately to the risk (Art. 32 GDPR). How such checks can be wired between shop, ERP and payment provider is shown in the article on middleware integration.
- Sign-in, password change and payment method change each trigger a check of their own.
- A second factor is available for customer accounts and mandatory for account changes.
- Orders with differing delivery and billing addresses run into a separate assessment.
- Sign-in attempts, orders and code redemptions are limited per account and per time window.
- Every chargeback is recorded with reason and account reference and feeds back into the assessment.
- Decline rate and chargeback rate appear in a joint report and are read regularly.
Economics: What Fraud Really Costs
The calculation for fraud protection rarely works out on direct losses alone. Surveys in retail put the total cost per unit of direct fraud loss at more than five times that amount (LexisNexis) – counted in are handling, chargeback fees, lost goods and shipping. Added to this is the link shown by the evaluations of data breaches: those who discover an incident themselves shorten its course markedly (IBM). Both shift the comparison away from the question of what a protection system costs towards the question of what an unnoticed incident costs.
A simple order helps with prioritisation: first the measures that work without a model – patch level, second factor, rate limiting -, then the assessment per order, and last the fine-tuning of thresholds. Anyone reworking the shop technically anyway should bundle this sensibly: the articles on IT security in e-commerce and on shop monitoring describe the foundations that fraud detection builds on.
We look at your ordering and account processes, sort the conspicuous patterns and build the checks in at the points where they take effect – without honest orders suffering for it. Request an analysis
Frequently Asked Questions on Fraud Detection
Reported payment fraud in the European Economic Area stood at EUR 4.2 billion in 2024, after EUR 3.5 billion the year before (ECB/EBA). For an individual merchant the share of their own revenue is more meaningful: European merchants lose an average of 2.8% of revenue to fraud (Sift).
US retail returns of USD 890 billion were expected for 2024, and 93% of the retailers surveyed described return fraud and similar behaviour as a significant problem (NRF). There is no comparable survey for Germany; what is meaningful here is your own return rate per customer account.
Three signals in quick succession are typical: a sign-in from a device never seen on this account, a change of email address or payment method shortly afterwards, and an order to a new delivery address. Individually each signal is harmless; one after the other it is the usual pattern of an account takeover.
False declines are rejected orders from honest customers. They appear in no loss statistic, because no loss is booked – the revenue simply does not happen, and some of those customers do not come back. That is why the decline rate belongs in the same report as the chargeback rate: a tightening that improves both values at once is progress, any other is a shift.
For electronic payments in the European Economic Area, yes: Article 4 of Delegated Regulation (EU) 2018/389 requires at least two elements from the categories knowledge, possession and inherence. In practice, electronically initiated card payments were strongly authenticated in 40% of cases in 2024 and e-money transactions in 38% (ECB/EBA); outside the EEA, where the obligation does not apply, the fraud rate was seventeen times higher (ECB/EBA).
Multi-factor sign-in for customer accounts: it blocks the vast majority of attacks on accounts, measured across the accounts of a large cloud provider 99.9% (Microsoft). In addition, passwords used as the only factor require a minimum length of 15 characters and a mandatory comparison against a blocklist of known and compromised passwords (NIST SP 800-63B-4).
Recommended Action
Fraud protection is not a product you switch on but a sequence of decisions. The order of magnitude is known: EUR 4.2 billion in reported payment fraud in the EEA in 2024 (ECB/EBA), an average of 2.8% of revenue at European merchants (Sift), around 60% of incidents with a determinable vector starting with phishing (ENISA). Anyone deriving three measures from this and measuring them gets further than anyone waiting for a complete solution: strong authentication where payment happens, a second factor where accounts are changed, and a report that shows declines and chargebacks side by side.
European Central Bank and European Banking Authority (Report on Payment Fraud), ENISA (Threat Landscape 2025), Federal Criminal Police Office (Bundeslagebild Cybercrime 2025), BSI (The State of IT Security in Germany 2025), Federal Office for Information Security and the German police crime prevention programme (Cybersicherheitsmonitor), Bitkom (Wirtschaftsschutz), National Retail Federation (Consumer Returns in the Retail Industry), Verizon (Data Breach Investigations Report), IBM (Cost of a Data Breach Report), Microsoft, NIST (SP 800-63B-4), OWASP (Automated Threats to Web Applications), Sansec, Recorded Future, LexisNexis Risk Solutions, Sift and the work of Wang, Jan, Hu and Wang (Virginia Tech). Every value is backed by a deep link and a verbatim quote.