Published by Capital Insight Ltd · Nicosia Herausgegeben von Capital Insight Ltd · Nikosia
The Banking Dossier
Authentication

Strong authentication worked. The fraud moved.

Die starke Authentifizierung hat gewirkt. Der Betrug ist umgezogen.

Strong customer authentication was supposed to end remote card fraud. It reduced it substantially. It also moved it, and the part that moved is the part now growing fastest.

What the rule does

Under the EU’s second Payment Services Directive, electronic payments generally require two independent factors: something the customer knows, has, or is. In card commerce this is implemented through 3-D Secure, the protocol behind the verification step that appears at checkout.

It worked. Fraud on authenticated transactions fell sharply, and liability for authenticated fraud shifted from the merchant to the issuer — which is the mechanism that made merchants adopt it rather than a regulatory penalty.

Where the fraud went

Authentication verifies that the person approving a payment holds the credentials. It does not verify that they understand what they are approving. So fraud migrated from stolen credentials to authorised push patterns: the customer is persuaded to authenticate a payment they will later regret.

This is not a loophole. It is the boundary of what the control was designed to do. A system built to answer “is this the right person” cannot answer “is this person being deceived”, and the criminals who lost the first question simply started asking the second.

The consequence for liability is uncomfortable. An authenticated transaction carries a strong presumption that the cardholder consented. A victim of a well-run scam has authenticated, and finds that the protocol designed to protect them is the evidence used against their claim.

The exemptions nobody discusses

SCA is not applied to every transaction. The rules permit exemptions — low value, recurring payments, merchant-initiated transactions, and transaction risk analysis, under which a payment can skip authentication if the acquirer’s measured fraud rate stays below defined thresholds.

Transaction risk analysis is the interesting one, because it turns authentication into a commercial variable. Every exemption improves conversion. Merchants want them, PSPs sell them as a feature, and the constraint is a fraud rate measured at portfolio level.

That constraint is real, but it means the actual level of authentication in the market is set by an optimisation, not by a policy. The rule says authenticate; the implementation says authenticate unless the numbers allow otherwise.

What we would want to see

Published exemption rates by acquirer would tell you more about the state of European payment security than any compliance statement. How many transactions actually carry authentication? How many ride an exemption? What happens to fraud rates at the portfolio boundary?

None of this is secret in principle — acquirers report fraud data to supervisors. Almost none of it is public. That gap is where we intend to look.

The honest assessment

SCA was a genuine success at what it targeted, and anyone claiming otherwise is arguing against the data. But a control that succeeds tends to be treated as the problem solved, and the fraud that replaced it now sits in a category where the customer authenticated, the merchant was paid, and the loss falls on whoever has the weakest claim.

Second-generation problems from first-generation successes are the normal condition of security. Recognising them as such, rather than as evidence the first fix failed, is how the next one gets built.


Sources: Directive (EU) 2015/2366 (PSD2) and Commission Delegated Regulation (EU) 2018/389 on regulatory technical standards for strong customer authentication; EMVCo 3-D Secure specifications; published EBA opinions on SCA exemptions.

Die starke Kundenauthentifizierung sollte den Fernabsatzbetrug mit Karten beenden. Sie hat ihn deutlich verringert. Sie hat ihn auch verschoben — und der verschobene Teil wächst heute am schnellsten.

Was die Regel bewirkt

Nach der zweiten EU-Zahlungsdiensterichtlinie brauchen elektronische Zahlungen grundsätzlich zwei unabhängige Faktoren: etwas, das der Kunde weiß, besitzt oder ist. Im Kartengeschäft wird das über 3-D Secure umgesetzt, das Protokoll hinter dem Bestätigungsschritt im Checkout.

Es hat funktioniert. Der Betrug bei authentifizierten Transaktionen ist stark gefallen, und die Haftung dafür wanderte vom Händler zur kartenausgebenden Bank — dieser Mechanismus, nicht eine Strafandrohung, hat die Händler zur Einführung gebracht.

Wohin der Betrug gewandert ist

Authentifizierung prüft, ob die freigebende Person die Zugangsdaten besitzt. Sie prüft nicht, ob diese Person versteht, was sie freigibt. Also wanderte der Betrug von gestohlenen Zugangsdaten zu veranlassten Zahlungen: Der Kunde wird überredet, eine Zahlung zu bestätigen, die er später bereut.

Das ist keine Lücke, sondern die Grenze dessen, wofür die Kontrolle gebaut wurde. Ein System, das „ist das die richtige Person” beantwortet, kann „wird diese Person getäuscht” nicht beantworten — und die Täter, die an der ersten Frage scheiterten, stellen seither die zweite.

Für die Haftung ist das unangenehm. Eine authentifizierte Transaktion begründet eine starke Vermutung der Zustimmung. Wer einem gut gemachten Betrug aufsitzt, hat authentifiziert und stellt fest, dass das Protokoll zu seinem Schutz nun als Beweis gegen seinen Anspruch dient.

Die Ausnahmen, über die niemand spricht

Nicht jede Transaktion wird authentifiziert. Die Regeln erlauben Ausnahmen — Kleinbeträge, wiederkehrende Zahlungen, händlerveranlasste Transaktionen und die Transaktionsrisikoanalyse, unter der eine Zahlung die Authentifizierung überspringen darf, solange die gemessene Betrugsquote des Acquirers unter definierten Schwellen bleibt.

Die Risikoanalyse ist der interessante Fall, weil sie Authentifizierung zu einer betriebswirtschaftlichen Größe macht. Jede Ausnahme verbessert die Abschlussquote. Händler wollen sie, Zahlungsdienstleister verkaufen sie als Funktion, und die Schranke ist eine auf Portfolioebene gemessene Betrugsquote.

Diese Schranke ist real. Sie bedeutet aber, dass das tatsächliche Authentifizierungsniveau im Markt von einer Optimierung bestimmt wird und nicht von einer Vorgabe. Die Regel sagt: authentifizieren. Die Umsetzung sagt: authentifizieren, sofern die Zahlen nichts anderes zulassen.

Was wir sehen wollen würden

Veröffentlichte Ausnahmequoten je Acquirer würden mehr über den Stand der europäischen Zahlungssicherheit aussagen als jede Konformitätserklärung. Wie viele Transaktionen tragen tatsächlich eine Authentifizierung? Wie viele laufen über eine Ausnahme? Was passiert mit den Betrugsquoten an der Portfoliogrenze?

Geheim ist davon im Grunde nichts — Acquirer melden Betrugsdaten an die Aufsicht. Öffentlich ist davon fast nichts. In dieser Lücke wollen wir nachsehen.

Die ehrliche Bilanz

Die SCA war bei dem, was sie adressierte, ein echter Erfolg, und wer das bestreitet, argumentiert gegen die Daten. Nur wird eine erfolgreiche Kontrolle gern als erledigtes Problem behandelt — und der Betrug, der an ihre Stelle trat, sitzt heute in einer Kategorie, in der der Kunde authentifiziert hat, der Händler bezahlt wurde und der Schaden bei demjenigen landet, der den schwächsten Anspruch hat.

Probleme zweiter Ordnung aus Erfolgen erster Ordnung sind der Normalzustand der Sicherheit. Sie als solche zu erkennen, statt als Beleg für das Scheitern der ersten Lösung, ist der Weg zur nächsten.


Quellen: Richtlinie (EU) 2015/2366 (PSD2) und Delegierte Verordnung (EU) 2018/389 zu den technischen Regulierungsstandards für die starke Kundenauthentifizierung; EMVCo-Spezifikationen zu 3-D Secure; veröffentlichte EBA-Stellungnahmen zu den SCA-Ausnahmen.