Key Takeaways
- 36% of breaches in the 2024 Verizon DBIR involved web application attacks (common vector for card theft via skimming or form compromise)
- 33% of card fraud attempts are attributed to card testing/credential stuffing patterns in 2023 across online channels (industry threat intel summary)
- 28% of consumers said they had experienced at least one type of fraud in the past year in the 2024 LexisNexis “Risk of Fraud” consumer survey
- 8.0% of consumers reported credit card theft/fraud as the type of fraud they experienced most frequently in the 2023/2024 UK Chartered Trading Standards Institute (CTSI) consumer report (ATM/card-related theft category)
- 31% of fraud cases involved fraudsters using stolen identity or false credentials (ACFE Report to the Nations 2024)
- 24% of organizations reported increased customer churn after a data breach (affects payment brand and customer trust)
- $1.2 million average annual cost of chargebacks for merchants with $10–50 million in revenue (chargeback management industry estimate)
- €1.7 billion total chargeback-related losses in Europe (payments industry estimate reported in trade publications referencing card networks)
- $23.0 billion estimated losses worldwide from online card fraud in 2023 (Nilson Report estimate as cited by multiple trade sources)
- $5.2 billion global fraud detection and prevention market size in 2023 (industry market research estimate, payment fraud applications)
- $7.7 billion global payment security market size in 2023 (industry market research estimate for card payment security controls)
- 2FA reduces account takeover success rates by 50% to 99% (NIST Special Publication 800-63B referenced by NIST guidance)
- 39% of organizations reported using API security controls to reduce fraud and account compromise exposure
- 23% of organizations in a 2023 survey reported using tokenization for payment data to reduce card theft impact
- 32% of consumers reported that they were tricked by phishing or social engineering attempts (common precursor to online card theft)
Online card theft is driven by phishing and credentials, causing billions in losses, churn, and chargeback disputes.
Related reading
01 · Category
Attacker Methods2 stats
Attacker Methods Interpretation
02 · Category
Fraud Prevalence3 stats
Fraud Prevalence Interpretation
03 · Category
Impact & Cost3 stats
Impact & Cost Interpretation
04 · Category
Market Size6 stats
Market Size Interpretation
More related reading
05 · Category
Detection & Prevention3 stats
Detection & Prevention Interpretation
06 · Category
Customer & Behavior6 stats
Customer & Behavior Interpretation
07 · Category
Threat Techniques1 stats
Threat Techniques Interpretation
08 · Category
Controls & Mitigation2 stats
Controls & Mitigation Interpretation
Where online card theft starts: common attack and fraud patterns
Most online payment fraud is driven by credential compromise and testing (web app attacks, phishing/social engineering, and card testing/credential stuffing), which then leads to unauthorized transactions and chargeback disputes.
Cite This Report
This report is designed to be cited. We maintain stable URLs and versioned verification dates. Copy the format appropriate for your publication below.
Daniel Varga. (2026, February 13). Online Credit Card Theft Statistics. Gitnux. https://gitnux.org/online-credit-card-theft-statistics
Daniel Varga. "Online Credit Card Theft Statistics." Gitnux, 13 Feb 2026, https://gitnux.org/online-credit-card-theft-statistics.
Daniel Varga. 2026. "Online Credit Card Theft Statistics." Gitnux. https://gitnux.org/online-credit-card-theft-statistics.
Sources & references
26 datasets cited across this report · attribution is report-level
+3 additional datasets cited (not shown individually)

