Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM What do merchants get wrong about relying on…
Identity Beyond IAM

What do merchants get wrong about relying on 3DS as their main fraud control?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 19, 2026 Domain: Identity Beyond IAM

Merchants often treat 3DS as a complete fraud solution when it is only one control in a broader payment-risk strategy. Fraudsters adapt by using phishing, code interception, email takeovers, and social engineering to bypass authentication. 3DS also does not address friendly fraud, policy abuse, or merchant errors, so it cannot be the only line of defence.

Why 3DS Is a Control, Not a Fraud Strategy

3DS is useful when it adds authentication or liability shift, but merchants often overstate what that means in practice. It reduces some card-not-present fraud, yet it does not replace transaction monitoring, order review, policy controls, dispute handling, or account-level protections. A sound payment stack treats 3DS as one signal, not the whole decisioning layer.

That matters because fraud is not one problem. Authentication failures, misuse of stored credentials, suspicious customer behaviour, delivery abuse, and post-purchase disputes all sit in different parts of the lifecycle. If the merchant only optimises for the 3DS step, the rest of the payment journey stays exposed.

Merchants also underestimate how often a strong authentication step still leaves room for bad outcomes. A legitimate authentication can precede an illegitimate purchase, and a failed or bypassed challenge does not prove the transaction is safe. The control helps narrow risk, but it does not convert every approved payment into a trustworthy one.

Where 3DS Breaks Down in Real Merchant Operations

Attackers and abusers tend to route around the step that is most visible to the merchant. They can use phishing, code interception, email account takeover, and social engineering to defeat the authentication flow, especially when the merchant relies on 3DS to carry the entire burden of fraud prevention. That is why the surrounding controls matter as much as the challenge itself.

Failure mechanism: The merchant assumes the authentication event is the same thing as transaction trust, then misses abuse that happens before, during, or after checkout. Fraudsters exploit gaps in device signals, customer verification, fulfilment checks, and refund handling to create losses even when 3DS is present.

Impact: Losses shift into categories that 3DS does not address, including friendly fraud, policy abuse, first-party misuse, account compromise, and operational errors. The merchant may also get a false sense of security and underinvest in controls that actually reduce net fraud and dispute volume.

That is why a stronger model is layered: use 3DS where it meaningfully improves approval quality or liability posture, then back it with risk scoring, behavioural signals, shipping and refund controls, and chargeback management. For merchants that handle higher-value or repeat abuse patterns, the real decision is not whether to use 3DS, but how much trust to assign to it in the overall stack.

What Practitioners Should Measure Instead of Assuming 3DS Is Enough

The practical mistake is measuring only challenge completion or friction reduction. Those metrics tell you whether the authentication step worked, not whether fraud dropped, disputes fell, or net margin improved. A merchant should separate authentication performance from fraud outcomes and review both at the portfolio level.

What to verify: Check whether 3DS approval rates, fraud rates, chargeback rates, refund abuse, and manual review outcomes move together or diverge. If fraud is flat while 3DS adoption rises, the control is probably being used as a gate rather than as part of a broader decision engine.

What to prioritise: Focus first on the transaction types where 3DS adds the most value, then tune controls for the cases it cannot solve, such as post-transaction abuse, account takeover, and merchant process weakness. The goal is to reduce net loss, not to maximise authentication coverage for its own sake.

Practitioner takeaway: Treat 3DS as a risk-reduction layer with a specific job, and judge it by downstream loss, dispute quality, and abuse containment rather than by whether the challenge itself succeeded.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-1 — Identities and Credentials Managed3DS is one access and authentication control within a broader payment-risk posture.
DE.CM-1 — Monitoring for Anomalies and EventsMerchants need ongoing monitoring because 3DS alone does not detect fraud patterns.
Recommendation — Manage authentication and access controls as one layer, not the full fraud strategy. Monitor transaction behaviour and dispute trends to spot fraud beyond authentication.
CIS Controls v86 — Access Control ManagementThe topic hinges on limiting misuse and managing trust around authenticated transactions.
Recommendation — Apply access control discipline alongside 3DS to reduce misuse and abuse.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 19, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org