Blog-Online Payment Fraud Detection: A UK Business Guide (2026)1469
Payment

How to Detect and Prevent Online Payment Fraud: A UK Business Guide

James Carter
Business Finance Writer

Protect your UK business from payment fraud. Covers common fraud types, detection methods, prevention strategies, and the tools British businesses use to stay secure.

2026.06.25 06:57:37 · 5minute(s)
Payment fraud cost UK businesses and consumers £1.28 billion in 2025, according to UK Finance's 2026 Annual Fraud Report. Authorised Push Payment (APP) fraud — where criminals trick victims into sending money to accounts they control — accounted for the largest share. For a UK business taking payments online, the threat is not theoretical: it lives in every card-not-present transaction, every invoice payment, and every new customer account. This guide covers the fraud types most relevant to British businesses, how detection works in practice, and the steps you can take to reduce your exposure without creating so much friction that genuine customers walk away.

Common Types of Payment Fraud Affecting UK Businesses

Fraud does not look the same for every business. A Manchester e-commerce shop faces different risks than a London-based B2B service company. But several fraud patterns recur across sectors:

Card-not-present (CNP) fraud

When a stolen card number is used to make an online purchase without the physical card present. CNP fraud accounted for over £400 million in UK losses in 2024. Criminals buy card details in bulk from data breaches, then test them on online checkouts — often starting with small-value purchases to verify the card is live before escalating.

Authorised Push Payment (APP) fraud

A criminal convinces someone in your business to authorise a bank transfer to an account they control. Common scenarios include: fake supplier invoices (the "CEO fraud" where an email appears to come from a director), impersonation of HMRC demanding urgent payment, and investment scams targeting company treasurers. What makes APP fraud particularly damaging is that the victim authorises the payment — standard fraud detection systems may not flag it because it looks like a legitimate transfer.

Chargeback fraud (friendly fraud)

A customer makes a legitimate purchase, receives the goods or service, then disputes the charge with their bank claiming they never authorised it or never received it. The card scheme rules heavily favour the cardholder, so the business loses both the product and the payment. For digital goods and services with no shipping proof, chargeback fraud is especially hard to fight.

Account takeover

A fraudster gains access to a customer's account on your platform — through stolen credentials, phishing, or credential-stuffing attacks — then makes purchases, changes payment details, or drains stored value. Account takeovers are harder to detect than first-time fraud because the transaction history on the account may look genuine.

Synthetic identity fraud

A fraudster combines real and fabricated personal information to create a new identity, opens an account with your business, builds a transaction history over months, then executes a large fraudulent transaction or applies for credit and disappears. This is more common in financial services and BNPL (buy-now-pay-later) than in retail, but any UK business that extends credit or offers account-based services is exposed.

How Payment Fraud Detection Works

Modern fraud detection is not about a single check at the point of transaction. It is a layered system that evaluates risk at multiple stages:

1. Rules-based screening

The simplest layer: predefined rules that flag or block transactions matching known fraud patterns. Examples: orders from a high-risk IP address, shipping addresses in countries you do not serve, multiple orders from the same device in a short window (velocity checking), mismatched billing and shipping postcodes. Rules are fast and transparent but brittle — fraudsters learn to work around static rules quickly.

2. Machine learning and behavioural analytics

Instead of fixed rules, ML models learn from your historical transaction data to identify patterns that correlate with fraud. They evaluate hundreds of signals simultaneously — device fingerprint, browsing behaviour before checkout, typing cadence, geolocation, transaction amount relative to the customer's history, time of day, and dozens more. A model might flag a £200 transaction that would pass a simple rules check because the customer's mouse movements and page navigation pattern differ from the norm for that account.

3. Device fingerprinting

Each device that visits your site has a unique combination of attributes — operating system, browser version, installed fonts, screen resolution, timezone, language settings. Device fingerprinting creates a persistent identifier that does not rely on cookies. If the same device has been linked to fraudulent transactions on other sites, or if a single device is cycling through multiple customer accounts, the system flags it.

4. 3D Secure 2 (3DS2)

Mandated in the UK under Strong Customer Authentication (SCA) rules since March 2022, 3DS2 shifts liability for fraud from the merchant to the issuing bank — but only if the challenge is applied and completed. The FCA requires two of three authentication factors: something the customer knows (password), something they have (phone), and something they are (biometric). 3DS2 is not optional for UK card-not-present transactions, and the friction it adds is the trade-off for the liability shift.

5. Consortium data and shared intelligence

Fraudsters rarely target a single business. Networks like Cifas (the UK's fraud prevention membership organisation) and card scheme fraud databases allow businesses to check whether an identity, device, or payment method has been associated with fraud elsewhere. A new customer whose email domain appears in multiple recent fraud reports is a higher-risk sign-up.

6. Manual review

When an automated system scores a transaction as borderline — not clearly fraudulent, but not clearly safe — it enters a queue for human review. A fraud analyst checks the order details, may contact the customer for verification, and makes a judgment call. Manual review is expensive and does not scale, so the goal of automated detection is to push as few transactions as possible into this stage while maintaining a low false-positive rate (declining legitimate customers).

Best Practices for UK Businesses

Preventing fraud is not about eliminating risk entirely — that would mean declining every transaction. It is about managing the trade-off between security and customer experience. Here are the practices that move the needle for UK businesses:
  • Implement 3DS2 properly, not as an afterthought. Many UK businesses treat 3DS2 as a compliance checkbox. But well-implemented 3DS2 — with risk-based authentication that only challenges high-risk transactions (frictionless flow for low-risk ones) — reduces fraud without hurting conversion.
  • Tune your velocity rules to your transaction patterns. A blanket rule blocking more than three transactions per hour from the same IP may stop fraud in a luxury goods shop but kill sales for a ticket-selling platform where customers routinely buy four or five seats at once. Velocity thresholds must reflect your actual customer behaviour.
  • Use AVS (Address Verification) and CVV checks together. Neither alone is sufficient — a stolen card number often comes with the billing postcode and CVV. But combined, they filter out the lowest-hanging fraud attempts with near-zero customer friction.
  • Monitor for post-transaction signals. A completed transaction that looks clean at purchase may trigger alerts later: the customer immediately requests a shipping address change, or the issuing bank sends a chargeback notification. Integration with chargeback alert services (like Verifi or Ethoca) lets you refund a disputed transaction before it becomes a chargeback, avoiding the chargeback fee and protecting your chargeback ratio.
  • Educate your finance team on APP fraud red flags. The strongest technical defences cannot stop an employee from authorising a payment to a fraudster. Train your team to verify payment instruction changes by phone (using a known number, not one in the email), to question urgent or unusual payment requests, and to flag invoices with slightly altered bank details or domain names.
  • Keep a close eye on chargeback ratios. Visa and Mastercard monitor merchant chargeback ratios. Exceeding 0.9% of total transactions can place you in a monitoring programme with higher fees; exceeding 1.5% can lead to your merchant account being terminated. Chargeback prevention is not just about recovering lost payments — it is about maintaining your ability to accept cards at all.

Tools and Technologies Worth Considering

The UK market has no shortage of fraud prevention tools, ranging from entry-level to enterprise:
  • Stripe Radar — built into Stripe's payment processing; uses machine learning trained on Stripe's global transaction data. Good for smaller UK businesses already on Stripe.
  • Ravelin — UK-based fraud detection platform specialising in online marketplaces and delivery businesses. Its models are trained per-client, so they learn your specific fraud patterns.
  • Sift — enterprise-grade fraud detection with a strong UK presence. Covers payment fraud, account takeover, and content abuse.
  • Signifyd — offers a chargeback guarantee model: they approve or decline transactions on your behalf and reimburse you for any chargebacks on transactions they approved.
  • Cifas — not a software tool but a UK fraud prevention membership. Provides access to the National Fraud Database for cross-referencing identities and payment methods against known fraud cases.
PhotonPay contributes to fraud prevention at the infrastructure level through:
  • Stablecoin-native transaction transparency. Stablecoin-based settlement creates an immutable record of each transaction's path, making it harder for fraudsters to obscure the flow of funds compared to traditional correspondent banking chains where each intermediary bank is a visibility gap.
  • Real-time settlement monitoring. Because stablecoin transactions settle on-chain, anomalies can be detected and flagged at the point of settlement rather than days later through batch reconciliation.
  • Multi-layer verification for cross-border payouts. High-value international transfers go through tiered approval workflows that add friction selectively — a £500 supplier payment processes differently from a £50,000 transfer to a new payee.
  • UK-based compliance infrastructure. Operating under FCA authorisation, PhotonPay's compliance framework includes customer due diligence, transaction monitoring, and suspicious activity reporting aligned with UK regulatory expectations.

FAQ

What is the most common type of payment fraud for UK online businesses?

Card-not-present (CNP) fraud is the most frequent in volume terms, while authorised push payment (APP) fraud causes the highest per-incident losses. For a typical UK e-commerce business, CNP fraud — stolen card details used online — is the daily concern. For a B2B service company or importer that makes large bank transfers to suppliers, APP fraud (invoice redirection, CEO fraud) is the greater financial risk.

How much fraud is too much? What is an acceptable fraud rate?

Card schemes monitor chargeback ratios, not fraud rates directly. Visa and Mastercard typically require merchants to stay below 0.9% chargeback ratio (chargebacks ÷ total transactions). Above 1.5%, you risk account termination. Most healthy UK businesses operate at 0.1–0.3%. If your chargeback ratio is climbing, focus on prevention (3DS2, AVS, velocity checks) before it triggers scheme monitoring.

Does 3D Secure 2 stop all card fraud?

No. 3DS2 shifts liability for fraud from the merchant to the issuing bank when the challenge is completed, but it does not prevent the fraud itself. A determined fraudster with a victim's card details and access to their phone can pass a 3DS2 challenge. What 3DS2 does is protect you financially if the fraud succeeds — and the friction of the challenge deters casual fraudsters. For maximum protection, use 3DS2 alongside behavioural analytics and device fingerprinting, not instead of them.

Can small UK businesses afford fraud detection tools?

Yes. Stripe Radar, for example, is included in Stripe's standard processing fee (with a small additional cost for the advanced version). For businesses not on Stripe, entry-level tools start at roughly £50–£100/month. The cost of fraud itself — a single chargeback can cost £15–£50 in fees plus the lost goods and payment — often exceeds the cost of basic prevention tools. If you process more than £10K/month in card payments, fraud detection is almost certainly cheaper than the fraud it prevents.

Final Thoughts

Payment fraud is a cost of doing business online, but it is a cost you can control. The UK businesses that manage it best do three things: they implement the technical defences that regulators and card schemes already require (3DS2, AVS, CVV), they add a behavioural detection layer that learns from their actual transaction data rather than generic rules, and they train their people to recognise social engineering — because no software stops a finance team member from paying a fake invoice. Security that creates too much friction loses customers, and a hands-off approach loses money. The right balance is specific to your transaction profile, and worth recalibrating as your business grows.

Power Your Global Growth with PhotonPay