PaymentsJournal
No Result
View All Result
SIGN UP
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
PaymentsJournal
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
No Result
View All Result
PaymentsJournal
No Result
View All Result

The Evolution of 3D Secure Puts it at the Center of Fraud Prevention

By Wesley Grant
September 18, 2026
in Featured Content, Fraud & Security, Merchant
0
0
SHARES
0
VIEWS
Share on LinkedIn
bots fraud, bank security in data sharing, J.P. Morgan fraud protection TSYS

Golden padlock with integrated electronic circuits, password security technology for fraud prevention and confidential data network

Today, consumers can buy almost anything with a few taps on a phone. But there was a time when entering a card number online felt like a leap of faith.

As e-commerce took off, security concerns threatened to slow its growth. One of the earliest attempts to address them was 3D Secure, a technology designed to verify that the person making an online purchase was actually the cardholder. Its approach was pretty straightforward: connect shoppers with their institution to verify their identity before completing the purchase.

The technology solved one problem, but created another. While 3D Secure helped shift liability for fraud away from merchants, its early authentication processes introduced enough friction to frustrate customers and complicate the checkout experience.

Still, as Don Apgar, Director of Merchant Payments at Javelin Strategy & Research, explored in the 3D Secure’s Next Act: From Checkout Friction to Trust Orchestration report, the platform did not disappear from the e-commerce equation. Instead, it evolved to play a critical role in fraud prevention—at a time when organizations face more challenges than ever.

An Unprofitable Trade-Off

In its early form, 3D Secure was often encountered via platforms like Verified by Visa and Mastercard SecureCode. To verify that the individual making an online card-not-present payment was the legitimate cardholder, 3D Secure prompted users to complete authentication through redirects, passwords, and pop-up authentication boxes.

The platform’s objective was to shift liability for e-commerce fraud from the merchant to the issuer, a benefit that incentivized many merchants to adopt 3D Secure. However, many soon found that the platform created significant friction for customers and was poorly suited to mobile transactions.

Ultimately, the reduction in fraud losses did not compensate for the increased customer friction. In the competitive e-commerce market, these drawbacks made the original 3D Secure approach a bridge too far for many merchants.

“Back in the early 90s, there was a proposal to make PINs required for every credit card purchase,” Apgar said. “The issuers fought against it, even though they were the ones that were taking the heat with the point-of-sale fraud. Because if you have a Chase card and a Citibank card in your wallet and the Citibank requires a PIN and the Chase doesn’t, you’re likely to use your Chase card.”

“It’s the same with 3D Secure. If Citibank wants you to validate a pop-up box and put in your password and Chase doesn’t, you’re most likely going to use the Chase card because it’s easier,” he said.

Evolving to the Moment

As merchants shifted away from the original platform, 3D Secure evolved. 3D Secure 2.0 (3DS2) is a security protocol for online card payments designed to reduce fraud while making the checkout process more efficient than the original version.

One of the most game changing features of 3DS2 is its ability to support more accurate authentication. It analyzes over 100 data points, including factors such as device ID and location, to assess the risk associated with a transaction.

Consider a customer visiting an e-commerce store for the first time and attempting to purchase a $1,000 laptop. Under older authentication models, the transaction might have raised a red flag simply because it was unusual.

“Now, the merchant can say: ‘He shopped here before, not with this card, but he logged into his account at the merchant with the password,’” Apgar said. “’He has made purchases from this IP address. I recognize the MAC address of the machine he’s using. I’m confident that this guy is who he is.’  The merchant can send all that data in the background to the card issuer.”

If doubts linger about a high-risk transaction, 3DS2 can require customers to verify their identity through biometric authentication, such as facial recognition or fingerprint scans, or through a one-time passcode. Conversely, low-risk transactions can be authenticated in the background without requiring additional customer input or introducing unnecessary friction.

Another key feature is that when additional customer input is required, 3DS2 does not rely on redirects. Authentication can occur directly within the merchant’s mobile app or website, rather than sending the customer to an external page.

Along with all these benefits comes the hallmark feature of 3D Secure: merchants can shift liability for certain fraud-related chargebacks to the issuer.

Moving Beyond Binary Authentication

The evolution to 3DS2 has made 3D Secure an essential component of the broader suite of fraud tools on which merchants rely. Perhaps most importantly, the platform no longer depends on binary verification, such as whether a password matches or not.

Instead, it provides an array of signals that both issuers and merchants can leverage to make more informed decisions.

“Going back to the laptop example, say that authorization comes in from the e-commerce merchant that you want to buy a $1,000 laptop and the issuer says, ‘Wait a minute, five minutes ago, I got an authorization request at a gas pump at whatever the local gas station is. How does that track?’” Apgar said. “‘He’s pumping gas and five minutes later he’s buying a laptop on his home computer?’”

“Everybody is starting to get a little smarter about tracking some of these behavioral things, where nothing by itself definitively says, ‘Yes or no, this is a fraud transaction,’” he said.

Building on the Technology

The shift toward a more sophisticated authentication is especially important because fraud has evolved, too. The sophistication and scale of fraud have made conventional fraud strategies—which heavily rely on one-time checks and defenses—an increasingly outdated approach. At the same time, consumers have more tools to spend and make purchases with remarkable efficiency.

For merchants, this creates a difficult balancing act. Security measures need to be strong enough to stop fraudulent transactions, but not so intrusive that legimiate customers abandon their purchases.

That has driven the need for fraud prevention mechanism that can sift through vast amounts of behavioral and transactional data and make timely, accurate decisions—without interfering with the customer experience.

This is a role 3D Secure was designed to play. What began as a relatively cumbersome authentication step has evolved into a more dynamic layer of fraud prevention, one that can use transaction data and risk signals to determine when authentication is necessary—and when it’s better left in the background.  

“They’re building on what they started 20 years ago and following what the technology allows us to do, and that is to enable that exchange of data for the benefit of the cardholder without inconveniencing the cardholder,” Apgar said.

0
SHARES
0
VIEWS
Share on LinkedIn
Tags: 3D Secure3DS2Behavioral AnalyticsFraudMerchant

    Get the Latest News and Insights Delivered Daily

    Subscribe to the PaymentsJournal Newsletter for exclusive insight and data from Javelin Strategy & Research analysts and industry professionals.

    Must Reads

    bots fraud, bank security in data sharing, J.P. Morgan fraud protection TSYS

    The Evolution of 3D Secure Puts it at the Center of Fraud Prevention

    September 18, 2026
    fraud detection signals

    Why Fraudsters Look Trustworthy and Good Customers Look Suspicious

    September 17, 2026
    Fraud Monitoring, Nacha ACH Rules, Same Day ACH

    10 Years Running, Same Day ACH Continues to Break New Ground

    September 16, 2026
    stablecoin infrastructure

    To Unlock Stablecoins’ Potential, Infrastructure Gaps Must Be Resolved

    September 15, 2026
    Latin America payment orchestration

    Navigating Latin America’s Complex Payment Ecosystem

    September 14, 2026
    upi biometric

    Beyond Authentication: Rethinking Digital Identity Security

    September 11, 2026
    Fraud Monitoring, Nacha ACH Rules, Same Day ACH

    Nacha’s Upcoming Rules Refresh Is All About Improving Clarity

    September 10, 2026
    instant payments for financial institutions

    Why Haven’t More Financial Institutions Adopted Instant Payments?

    September 9, 2026

    Linkedin-in X-twitter
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter

    ©2026 PaymentsJournal.com |  Terms of Use | Privacy Policy

    • Commercial Payments
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    No Result
    View All Result