Compliance
Where UK payment fraud actually happens, and what it means for merchants
UK payment fraud losses reached £1.28 billion in 2025, a four per cent increase. That headline gets quoted widely and tells a merchant almost nothing useful, because most of that money was never at risk in a shop, a restaurant or a school office. The figure covers two very different problems, and only one of them involves a merchant taking a payment. Understanding which part of the number applies to your business is what turns a statistic into something you can act on.
The two halves of the number
UK Finance splits payment fraud into two categories that behave completely differently.
Unauthorised fraud is a criminal using someone else's card or account without permission. Losses fell five per cent to £703.4 million in 2025, while the number of cases rose eleven per cent to 3.81 million. Losses down, cases up: criminals are stealing smaller amounts from more people.
Authorised push payment fraud is a victim being manipulated into sending money themselves. Losses rose nineteen per cent to £576.4 million across 248,070 cases, a seven per cent increase in case numbers.
The industry prevented a further £1.68 billion in unauthorised fraud from being stolen.
APP fraud is the growing problem, but it is largely a bank transfer problem rather than a card acceptance problem. Investment fraud accounted for the highest proportion of APP losses at £221.5 million, up forty per cent, and purchase scams accounted for seventy-one per cent of all cases with losses rising twenty per cent to £118.1 million. A legitimate business taking card payments for goods it actually supplies is not where that money goes.
The half that matters to merchants is the unauthorised half, and specifically the card categories within it.
The card breakdown
- Remote purchase, where card details are used online: £423.5 million in losses, up three per cent, across 3.2 million cases, up thirteen per cent.
- Lost and stolen: £109.8 million in losses, down two per cent, across 449,189 cases, up two per cent.
- Contactless: £46.8 million in losses, up eight per cent. Case numbers not stated.
- Remote banking: £104.4 million in losses, down twenty-seven per cent, across 37,646 cases, up eleven per cent.
Source: UK Finance, Annual Fraud Report 2026.
Two things stand out.
Remote purchase fraud dominates. At £423.5 million it is roughly four times lost and stolen and nine times contactless. This is fraud where a criminal has obtained card details and uses them where the physical card is not required: online, over the phone, through a booking form.
Case volumes are rising faster than losses in nearly every category. Remote purchase cases rose thirteen per cent while losses rose three per cent. That is a shift towards higher volumes of lower value attacks, which changes what detection looks like. A business watching for one large suspicious transaction may miss a pattern of small ones.
Which of this can actually reach a merchant
A merchant is exposed to fraud losses in a narrower set of circumstances than the headline figure implies.
Card-present transactions carry the least risk. Where a chip and PIN or contactless transaction is properly authenticated at the terminal, liability for fraudulent use generally sits with the card issuer rather than the merchant. This is the whole point of the authentication.
Card-not-present transactions carry the most. Online, telephone and booking-form payments are where remote purchase fraud lands. A merchant who ships goods or provides a service against a stolen card can face a chargeback for the transaction and lose the goods as well.
Refund and credit abuse is a separate category that does not appear in the fraud figures at all, because it is a dispute rather than a crime against the cardholder.
So the practical exposure for most businesses in education, hospitality, retail, catering and sport concentrates in one place: transactions taken without the card physically present.
What the contactless figure does and does not mean
Contactless fraud rose eight per cent to £46.8 million. It is the smallest card category by some distance, and it is worth reading alongside a regulatory change.
In December 2025 the FCA announced greater flexibility for firms in setting contactless limits, with rule changes taking effect in March 2026. This was widely reported as the contactless cap being removed. What was actually removed was the regulatory requirement for a fixed limit, and the FCA said at the time that it expected most providers to keep their existing limits for the foreseeable future. Firms that do change limits have to communicate clearly with customers under the Consumer Duty.
For a merchant, this changes very little in the short term. Contactless liability rules have not changed, and the cap is a matter for card issuers rather than for the businesses accepting the payments.
Where a merchant's effort is best spent
Not on the headline number. On the specific exposure.
For card-present businesses, the risk is low and the priority is making sure transactions are properly authenticated rather than keyed in manually. A manually entered card number in a face-to-face setting removes the authentication that protects the merchant.
For businesses taking card-not-present payments, the exposure is real and the defences are practical: use the authentication available on your checkout, check that the delivery address matches the billing address, be cautious about unusual orders that arrive shortly before a deadline, and keep the records that answer a chargeback if one arrives.
For everyone, the descriptor on the customer's statement matters. A recognisable trading name prevents the not-recognised disputes that look like fraud in the statistics and are simply confusion.
And for the business itself, the more common risk is not card fraud but invoice and mandate fraud: someone impersonating a supplier and changing bank details. That sits in the APP category, it is a finance process problem rather than a payments problem, and it is worth separating from the card conversation entirely.
Frequently asked questions
Am I liable if someone uses a stolen card in my business? For a properly authenticated card-present transaction, liability generally sits with the issuer. For card-not-present transactions, the merchant is more exposed and can face a chargeback. The specifics depend on the transaction type and the card scheme rules.
Is contactless fraud a growing risk for merchants? Contactless losses rose eight per cent in 2025 to £46.8 million, which is the smallest of the card categories. The rules on contactless liability did not change with the FCA's 2026 flexibility announcement.
Why are fraud cases rising while losses fall? Because the average value per case is falling. Criminals are targeting more people for smaller amounts, particularly in remote purchase fraud where cases rose thirteen per cent against a three per cent rise in losses.
Does APP fraud affect my business? Not usually as a card acceptor. It can affect your business as a payer, through invoice and mandate fraud where someone impersonates a supplier to change bank details. That is a finance control question rather than a card payments one.
What single thing reduces card fraud exposure most? For card-present businesses, ensuring transactions are properly authenticated at the terminal rather than keyed in. For card-not-present businesses, using the authentication available at the checkout and keeping the records that answer a dispute.
UK Finance publishes the full breakdown of cases and losses across every fraud category in its Annual Fraud Report 2026.
Your software provider is the best first point of contact for questions about your own setup and what authentication is available to you. VestaOne is the payments engine behind the platform.
VestaOne is a trading brand of Vesta Merchant Services Limited, registered in England and Wales, company number 07108015. Vesta Merchant Services Limited is authorised by the Financial Conduct Authority as a payment institution, firm reference number 784165. Part of Vesta Software Group.
This article is provided for general information only. It is not financial, legal or regulatory advice, and it does not take account of any particular business's circumstances.
More from Payments101
- ComplianceSeptember 2026
Safeguarding: what happens to merchant money if a payment firm fails
New FCA safeguarding rules came into force on 7 May 2026. Here is what safeguarding is, what went wrong before, and what it means for merchant money.
Read article - Payments explainedAugust 2026
Embedded payments in 2026: what the evidence actually says
Embedded payments have stopped being an add-on. Here is the UK and EU evidence for what that means for software businesses and for merchants, including the obligations most write-ups leave out.
Read article - Payments explainedSeptember 2026
How money moves from a card payment to your bank account
A card payment is authorised in seconds but settles over days. Here is what happens in between, and why the bank total rarely matches the till.
Read article