Fraud without fear-mongering

Global E-Commerce CNP Fraud Rate: Data Without Panic

An objective view of e-commerce card-not-present fraud: the calculated global rate, what the data can and cannot prove, and what merchants should do next.

Goal of This Page

The goal is to give merchants and fintech teams an objective picture of e-commerce fraud: no vendor panic, no complacency, and no metric mixing. We preserve the original 2020-2025 card-not-present (CNP) fraud-rate calculation, mark the estimate years clearly, check what later public data can and cannot confirm, and turn the result into merchant actions.

Read it as a planning lens: correct numerator, correct denominator, explicit limits, and a path from the market benchmark to your own fraud and dispute data.

Payment Bros first published this calculation in a 2024 Medium article about Ethoca's chargeback forecast. This page is the maintained reference.

What This Calculates

The calculation turns absolute CNP fraud-loss dollars into a market rate:

CNP fraud rate = CNP fraud losses / retail e-commerce sales

It is not a regulatory metric, card-network monitoring ratio, or merchant-specific KPI. It is a global benchmark that puts fraud losses beside the sales volume they relate to.

Absolute losses show the dollars at risk. Fraud rate shows exposure relative to sales volume. For investment decisions, rate and segment mix matter more than the headline loss number.

The Fear-Mongering Pattern

Many fraud reports are useful, but the industry often architects fear. The common pattern is simple: lead with a large absolute loss number, extend it with a multi-year forecast, avoid the matching transaction or sales denominator, then place a vendor solution next to the anxiety.

That is not the same as lying. Fraud losses are real. Chargebacks are expensive. First-party misuse can hurt a merchant badly. The problem is context removal: a USD 25B loss pool sounds catastrophic until the reader sees the sales base, metric definition, geography, period, and comparison set.

A sober fraud read should always ask: what is the numerator, what is the denominator, is this value or count, is this fraud or disputes, is this observed history or forecast, and who benefits if the reader panics?

Source Inputs

The input source is the 2023 Chargeback Trends and Outlook report, published by Ethoca/Mastercard. The rate table uses two parts of that report: regional CNP fraud-loss charts and the worldwide retail e-commerce sales chart.

The chargeback-volume forecast is useful context, but it is not the numerator in the fraud-rate calculation.

USD 25.40Bestimated total CNP fraud losses for 2025 after summing the regional fraud-loss charts.
USD 7,385Bestimated worldwide retail e-commerce sales for 2025 in the report's sales chart.
0.344%2025e global CNP fraud rate derived from those two inputs.
337Mseparate chargeback-volume forecast for 2026, kept out of the fraud-rate numerator.

Can We Use a More Trusted Source?

We looked for a stronger public source to replace the industry-report numerator. The answer is: not for this exact global calculation. The public official sources are better governed, but they are regional or instrument-specific. The global sources are broader, but they either sit behind paywalls or report total card fraud rather than global e-commerce CNP fraud losses.

SourceWhy it is strongerWhy it cannot replace the numerator
EBA/ECB 2025 payment fraud reportOfficial EEA payment-fraud reporting under PSD2 and ECB payment-statistics rules. It reports 2024 card fraud of EUR 1.3B and a 0.033% card-payment fraud rate by value.EEA-issued cards and all card payments are not the same as global e-commerce CNP fraud losses.
Federal Reserve 2023 debit-card fraud data and Kansas City Fed analysisOfficial U.S. debit-card data and transparent CNP fraud-rate methodology through 2023.U.S. debit-card scope only; not global, not all cards, and not a retail e-commerce denominator.
Nilson public referencesUseful global card-fraud direction and widely cited payment-card loss figures.Public references are total payment-card fraud, not a public global e-commerce CNP loss series.

So the maintained position is conservative: keep the original Ethoca/Mastercard-derived table as an industry-source calculation, label the 2023-2025 rows as estimates, and use official EEA and U.S. sources as reality checks rather than forced replacements.

Global CNP Fraud Rate Table

Using the 2023 report's retail e-commerce sales chart and its regional CNP fraud-loss charts, we summed CNP fraud across Europe, Asia-Pacific, rest of world, and the U.S. Then we divided by worldwide retail e-commerce sales. The report gave 2026 fraud but not a matching 2026 sales denominator, so the original table stopped at 2025.

YearRetail e-commerce salesTotal CNP fraud lossesDerived CNP fraud rate
2020USD 4,213BUSD 13.55B0.322%
2021USD 4,921BUSD 15.44B0.314%
2022USD 5,545BUSD 17.57B0.317%
2023eUSD 6,169BUSD 20.02B0.325%
2024eUSD 6,773BUSD 22.80B0.337%
2025eUSD 7,385BUSD 25.40B0.344%

The rate stays near one third of one percent. It rises in the estimate years, but the main read is scale: CNP fraud losses are material in dollars while still sitting well below one percent of global retail e-commerce sales in this calculation.

2026 Check on Estimate Years

The 2023e, 2024e, and 2025e rows were estimates. We can now check the e-commerce denominator against later EMARKETER data and compare some adjacent chargeback and merchant-risk signals. We still cannot validate the exact global CNP fraud-loss numerator from later public reports, because the public Mastercard/Ethoca metric changed.

Original estimateLater public dataPayment Bros read
E-commerce denominator: 2023e USD 6.169T, 2024e USD 6.773T, 2025e USD 7.385T.Later EMARKETER/Shopify figures put 2023 at USD 5.580T, 2024 at USD 6.007T, and 2025 at USD 6.419T.The denominator came in lower than the original chart. If the old fraud-loss numerator were unchanged, the implied rates would be higher. That is a sensitivity check, not an actual fraud-rate update.
CNP fraud-loss numerator: 2023e USD 20.02B, 2024e USD 22.80B, 2025e USD 25.40B, with Ethoca's 2026 headline at USD 28.1B.No directly comparable public global CNP fraud-loss series was found. Nilson's public references show total payment-card fraud losses of USD 33.83B in 2023 and USD 33.41B in 2024, but total card fraud is not CNP fraud.Do not substitute chargeback value, survey loss rates, or total card-fraud losses for the original CNP fraud-loss numerator.
Chargeback volume forecast: 337M global chargebacks by 2026.The later Mastercard/Ethoca chargeback report forecasts 261M chargebacks in 2025 and 324M in 2028.The old chargeback-volume path looks aggressive. Keep that separate from the derived CNP fraud-rate calculation.
Merchant reality: global market averages should not drive a tooling decision by themselves.MRC's 2026 survey reports 3.2% of annual e-commerce revenue lost to payment fraud globally and says 62% of merchants report more first-party misuse disputes. Kansas City Fed analysis says U.S. debit CNP fraud rates climbed through 2023.Merchant-level reality can diverge sharply from a market-wide average. The practical answer is still to calculate your own fraud and dispute rates.

Denominator sensitivity

This table asks one narrow question: what happens if we keep the original CNP fraud-loss numerator but replace the old retail e-commerce denominator with later EMARKETER/Shopify figures? It is a sensitivity check, not an actual fraud-rate update.

YearOriginal denominatorLater denominatorIf original CNP numerator is unchanged
2023eUSD 6,169BUSD 5,580B0.359%
2024eUSD 6,773BUSD 6,007B0.380%
2025eUSD 7,385BUSD 6,419B0.396%

The honest conclusion is narrow. The rate table remains the anchor. The 2023-2025 rows were estimates. Later e-commerce sales data makes the denominator lower, but later public sources do not give a matching actual global CNP fraud-loss numerator. The chargeback-volume forecast looks aggressive, but chargeback volume is not the fraud-rate metric.

Recommendations for Merchants

Use the global rate as a planning benchmark, not as a pass/fail threshold. Set controls from your own fraud value, fraud count, dispute value, dispute count, sales value, transaction count, segment mix, issuer-country mix, and product mix.

Card-network monitoring programs are a separate calibration point because they define when the ecosystem starts treating a merchant's fraud or dispute level as a compliance problem.

Stripe's monitoring-program guide summarizes the basic operating reality: networks track disputes and fraud against thresholds, and merchants can face remediation, fees, or processing risk if they stay above program limits.

Accessible payment service provider (PSP) documentation gives examples. PayPal Braintree's Visa Secure Excessive Fraud Program page lists an early-warning level at USD 50,000 and 0.65%, with the standard level at USD 75,000 and 0.90%. Its Mastercard Excessive Fraud Merchant page describes a global threshold that includes 1,000 prior-month sales transactions, USD/EUR 50,000 fraud chargeback amount, and a 0.50% fraud-chargeback-to-sales-count ratio, plus 3DS volume criteria.

These examples are only calibration points. Programs change, exact calculations differ, and acquirers may impose stricter controls. They do show that market-wide calculations are planning references, not automatic emergency thresholds.

Concrete Next Steps

  1. Ask your PSP or acquirer for monthly fraud and dispute reporting by value and count.
  2. Calculate rates against the correct denominator: sales value for value-based fraud rates and transaction count for count-based program ratios.
  3. Segment by region, issuer country, product, traffic source, card product, authentication flow, and merchant ID.
  4. Separate true third-party fraud from first-party misuse, unclear descriptors, refund friction, delivery issues, subscription confusion, and customer-service gaps.
  5. Review 3DS and Strong Customer Authentication (SCA) strategy, authorization rules, refund policies, descriptor clarity, post-purchase notifications, and dispute-alert coverage before building custom tooling.
  6. Treat high-risk verticals differently. Financial services, gambling, crypto, and other risk-heavy categories need stronger controls than a low-risk subscription or retail merchant.

The right response may be PSP configuration, chargeback alerts, 3DS policy tuning, descriptor cleanup, support-process fixes, vendor tooling, or an internal risk platform. Choose based on your loss pattern, not on a vendor screenshot.

Takeaways

  1. Fraud is real, but absolute fraud-loss charts need a denominator.
  2. The calculated global CNP fraud rate sits near one third of one percent in the 2020-2025 series.
  3. The 2023e, 2024e, and 2025e rows were estimates, not final observed history.
  4. Later e-commerce data lowers the denominator; the matching actual global CNP fraud-loss numerator is not public.
  5. Chargeback volume, chargeback value, survey loss rates, total card fraud, and CNP fraud losses are different metrics.
  6. Invest in fraud tooling when your own rates, segments, and root causes show the need.

Where Payment Bros Helps

We help merchants and fintech teams turn fraud and dispute noise into a working control plan: KPI definitions, PSP reporting review, root-cause analysis, 3DS and SCA policy, build-versus-buy decisions, and risk-tooling architecture.

If a report, vendor pitch, or acquirer warning has created pressure inside your team, we can help translate it into a rate-based read of your own data and a concrete action plan.

Talk to Payment Bros

Sources

Inline links carry the evidence trail. This list keeps the public references easy to scan.