What instant payments do to fraud, and who ends up with the bill. Since 9 October 2025 every euro credit transfer has to arrive within ten seconds and cannot be pulled back afterwards; in 2024 users bore roughly 85% of the losses on fraudulent credit transfers in the European Economic Area, while the United Kingdom put the bill with the banks and saw the losses concerned fall by roughly 21%.
Frequently asked questions
What do the mandatory instant euro payments change since October 2025?+
Since 9 October 2025 every euro transfer must arrive within ten seconds, day and night — and it can no longer be recalled afterwards. Irreversibility and speed together change the fraud question fundamentally: there is no longer a window to reverse a mistaken or fraudulent payment.
Why does strong authentication not fully solve fraud?+
Strong authentication has worked for the fraud it was designed against. But the fraud that remains travels the one route authentication cannot close: the payer themselves, tricked into approving the payment. Against a correctly authenticated but deceived user, a stronger login does not help.
Who bears the cost of fraudulent transfers in Europe today?+
Largely the user. In 2024 users bore roughly 85% of the losses on fraudulent transfers in the European Economic Area, not the bank — according to the joint EBA and ECB report of 15 December 2025.
What is the difference between the European and the UK approach to payment fraud?+
Europe answered with a warning screen you can ignore. The United Kingdom pulled a different lever and put the bill on the banks, after which the losses involved fell by about 21%. Where liability sits appears to steer the fraud.
What does the shift from fraud as a cost to fraud as a liability mean for fintechs?+
Once a loss is no longer a cost but a liability, the blueprint changes. Fraud prevention, detection and the allocation of responsibility between payer, bank and platform stop being an afterthought and become a core design choice of every payment product.