PDPedram Dadgar“Mr. Pay” · Payments · Sales · Frankfurt
DEEN
NewsOnline payments

93 per cent of online shops have already seen fraud — the payment method decides who pays for it

On 22 September 2026 bevh and CRIF published a joint survey of 76 German online shops: 93 per cent have already been confronted with fraud or attempted fraud, 48 per cent see cases rising. The most common patterns — denied receipt of goods and ordering without intent to pay — hit exactly those payment methods where the merchant carries the risk alone.

What happened

The German e-commerce association bevh (Bundesverband E-Commerce und Versandhandel) and the information services provider CRIF published the results of a joint merchant survey on 22 September 2026. They questioned 76 online shops in Germany between 1 June and 14 August 2026. 93 per cent say they have already been confronted with fraud or attempted fraud; 48 per cent see the risk as having grown over the past twelve months, 37 per cent as unchanged and 15 per cent as falling. Identity fraud is named most often at 75 per cent, including manipulated name and address data (67 per cent) and entirely invented identities (55 per cent). Next come denied receipt of goods at 60 per cent, ordering without any intention to pay at 57 per cent, account takeover at 56 per cent, return fraud at 47 per cent and stolen payment credentials at 40 per cent. On losses, 25 per cent name less than 5,000 euros a year, 45 per cent between 10,001 and 100,000 euros and 15 per cent more than 100,000 euros; for 32 per cent the largest single loss exceeds 2,500 euros. 75 per cent already use fraud detection, 9 per cent plan to. CRIF sells fraud prevention itself — the survey is therefore vendor-adjacent, and a sample of 76 shops is small. The direction is unambiguous all the same.

Who is affected

Online shops of every size, especially those offering purchase on account, instalments or direct debit in the checkout — and every marketplace seller with an open guest ordering process.

Assessment

The headline says 93 per cent; the actual information sits in the list underneath. Denied receipt of goods, ordering without intent to pay, stolen payment credentials: these are not three versions of one problem, they are three different liability positions. With card payments under strong customer authentication the risk generally does not sit with the merchant; anyone applying 3-D Secure properly pushes fraudulent third-party access to where it belongs. With purchase on account, with direct debit and with any form of instalment payment there is no such shift. There the loss is an ordinary bad debt, and the shop carries it.

That is precisely why the payment-method mix is the most effective lever a merchant has — and the one least often pulled. According to the EHI study Online-Payment 2026, purchase on account accounts for 26.1 per cent of online turnover and instalment purchase for 4.7 per cent. So almost a third of the checkout runs through routes with no liability shift. Whoever checks nothing there ends up paying for the survey. And there is a date attached: from 20 November 2026 the new consumer credit law applies, covering instalment payments and small loans for the first time, with it still disputed how far classic purchase on account falls within it. Anyone who has to touch their risk controls anyway should do both in one go.

What to do now

  1. Break down the fraud losses of the last twelve months by payment method, not by type of fraud. Only that table shows which method is eating the margin.
  2. Check whether 3-D Secure really takes effect in your checkout, or whether exemptions are set in a way that leaves the liability with you.
  3. Clarify in writing with your provider for purchase on account and instalments who takes on which checking duty from 20 November 2026 — and what a default will then cost you.

Sources

WhatsApp @pedramdadgar LinkedIn