top of page

Fraud has always followed payments. What’s changed is how we deal with it.

Morten Hofstad
6 hours ago
4 min read

If you look at the history of payments over any meaningful period of time, you can see a pattern; every time the way we pay evolved, it has almost immediately been followed by a change in how fraud shows up. These shifts in fraud are in direct response to the way the system is designed.


Payments have never been just about moving money; they are about trust. About whether the person initiating a transaction is genuinely the one who should be. And every time that question becomes harder to answer, fraud finds a way to evolve.


Certainty in the physical world

Cash is remembered as simple and certain. You could see it, hold it, exchange it. The transaction felt complete in a way that required no interpretation. But that certainty sat in the physical world, and eventually fraud followed with counterfeiting, theft, and loss. So, the response was to make the asset itself harder to replicate, to build trust into the notes and coins through various means within the production process.


Then, cards were introduced and changed the dynamic in a more fundamental way. They allowed payments to happen conveniently and at scale, without the delays and friction that came with earlier systems like cheques. Instead of exchanging value directly, the transaction became an instruction to move money.


That shift meant that the person making the payment was no longer tied to the transaction in the same immediate, physical way as cash. Early systems bridged that gap with simple checks, such as a signature, a visual comparison, and a basic assumption that the person presenting the card was the rightful owner. It worked for a time, but it didn’t take long for those assumptions to be taken advantage of by fraudsters.


What followed with chip and PIN was not just a technical upgrade, but a shift in how trust was established. The cardholder was brought back into the transaction in a way that could be confirmed. The physical card and the PIN created a moment of certainty that was difficult to replicate fraudulently. The impact was an instant reduction in fraud because the digital certificate in the chips cannot be cloned, and the PIN cannot be stolen. It is these two factors that have made chip and PIN the most enduring and safest way to pay, ever.


But then ecommerce took that certainty away again. It removed the physical interaction - the presence of the cardholder - and replaced it with sets of data that attempt to guess legitimacy. Devices, behaviour, historical patterns, location. Over time, the tools used to detect fraud have become more sophisticated, layered with machine learning and increasingly complex models. And the industry has become very capable at identifying what looks risky. However, what it has never been able to do is confirm, with any real certainty, who is really behind the transaction.


That truth is what sits at the centre of how fraud operates today.


Living with probability

Decisions around cardholder legitimacy in ecommerce transactions are made on probability. Sometimes that probability is high enough to allow a transaction through, sometimes low enough to block it. Nevertheless, it remains a judgement call. Even when the models perform well, the underlying uncertainty does not go away. It is managed, contained, and optimised, but still there.


This is why fraud is never resolved. We have seen it evolve and becomes more efficient and sophisticated via the very same types of technology used to detect it. But at the same time, legitimate transactions are caught in the same system, declined not because they are fraudulent, but because they cannot be proven otherwise with enough confidence. The cost of that uncertainty is becoming more visible in ways other than just in fraud losses; such as customer experience, lost revenue, and the operational effort required to keep everything moving.


What reduces fraud

Looking back across the different phases of payments, the moments where fraud has reduced most meaningfully have never come from better prediction. They’ve come from changing the structure of the transaction so that the identity of person making the payment can be confirmed. Cash did it through physical exchange. Chip and PIN did it through authentication. In both cases, the system was designed to answer the question directly.


ecommerce, in its current form, does not answer that question. It works around it. That is why we constantly see the limits of fraud detection technology. Adding more data, more signals, and more intelligence refines the model, but it doesn’t change the nature of what the system is doing. It’s still interpreting, still inferring, still operating at a distance from the cardholder.


Closing the gap

The next shift in payments won’t come from pushing the current model further. The only option is to introduce certainty in digital payments in a way that fits how people transact today. By bringing the most proven and effective principles of payments forward – card and PIN.


That is the space where approaches like Card Present over Internet (CPoI®) sit. Rather than adding another layer of assessment, it changes the transaction itself by bringing the identity of the cardholder into the moment of payment. It allows the issuer to see something they have always trusted in the physical world, now applied to an online context. When that happens, the conversation changes from whether a transaction looks legitimate, to whether it has been authorised.


Fraud has always followed the gaps in how payments are designed. CPoI® provides the opportunity to close one of the most persistent gaps that has been left open.

 
 
 

Comments


bottom of page