stripecard fraud3d secureinvoluntary churn

Card Fraud in Latin America Runs 160% Higher Than Europe's. Mandated 3D Secure Is Most of the Reason Why.

Stripe's 2026 data: Asia-Pacific now beats Europe on card fraud. Latin America runs 160% higher — mandated 3DS explains most of the gap.

XY
28 September 2026 · 8 min read

Most SaaS billing stacks run one fraud policy worldwide. One Radar risk tolerance, one 3D Secure setting, applied identically whether the card was issued in Ohio, Osaka, or São Paulo. Stripe published regional fraud data in September 2026 that makes the case for why that's a mistake, and the gap between regions isn't a rounding error — it's the difference between a market where card fraud has been falling for four straight years and one where it just became the highest of any region Stripe tracks.

Key stat
+160%
How much higher Latin America's 2025 card fraud rate ran versus Europe, the Middle East, and Africa
Source: Stripe, regional card fraud analysis (September 2026)

The study behind that number analyzed billions of Stripe transactions from January 2022 through March 2026, broken out by region and country. It wasn't built for SaaS specifically — it's a payments-industry fraud report — but the mechanism it documents lands squarely on subscription businesses, because the moment that decides how exposed a renewal is to fraud isn't the renewal itself. It's the one card-capture event months or years earlier, and whether 3D Secure ran on it at all.

What actually changed, region by region

Asia-Pacific posted the most consistent fraud decline of any region in the study, and by Q1 2026 it had a lower card fraud rate than Europe, the Middle East, and Africa for the first time since Stripe started tracking it. Stripe credits mandated 3DS rollouts across the region. Malaysia's fraud rate fell 74% from 2022 to 2025, the sharpest drop of any Asia-Pacific market. Japan is the clearest before-and-after case: it implemented a 3DS mandate under its Credit Card Security Guidelines in April 2025, and dispute rates in 2025 ran 30% below 2024 levels.

Europe kept improving too, just less dramatically and less evenly. Card fraud across the region fell 21% from 2022 to 2025, with France down 40% and Great Britain down 27% over the same stretch. But "Europe" isn't one curve — Iberia (Spain and Portugal) saw fraud rates rise every single year from 2022 to 2025, inside a region that's supposedly covered by the same PSD2 mandate as the rest of the EEA. A regulatory floor doesn't guarantee a uniform outcome; it guarantees a mechanism is available, and adoption still varies.

Latin America is the outlier in the other direction. The region posted 2025 fraud rates 160% higher than EMEA, 151% higher than Asia-Pacific, and 65% higher than North America — the highest of any region in the study. Some individual markets bucked the trend, with Ecuador, Panama, and Brazil each posting decreases from 2022 to 2025. But the region as a whole is still working against a cash-heavy payments culture and dispute frameworks that tilt toward the cardholder by default, and — unlike Japan, India, or Australia — nothing requires a Latin American issuer to challenge a risky card-not-present transaction with 3DS.

How much higher Latin America's 2025 card fraud rate ran, by comparison region
vs. Europe, Middle East & Africa+160%
vs. Asia-Pacific+151%
vs. North America+65%

Source: Stripe, regional card fraud analysis (September 2026)

RegionCard fraud rate, 2022–20253DS status
Asia-PacificDown sharply — Malaysia -74%; now below EMEAMandated in Japan, India, Australia
Europe (EEA/UK)Down 21% overall — France -40%, GB -27%; Iberia risingMandated under PSD2, adoption uneven
North AmericaLower than Latin America, no region-wide mandate citedOptional, merchant-configured
Latin AmericaHighest of any region in 2025; some countries improvingOptional, merchant-configured

Why this locks in at signup, not at renewal

We've written before about how SCA exemptions let EEA and UK renewals skip authentication entirely once a customer completes one properly-authenticated charge. That mechanic isn't unique to Europe — it's how 3D Secure works everywhere. Stripe's own documentation is direct about it: off-session payments generally don't support 3DS at all, because there's no customer present to complete a challenge. The authentication almost always happens once, at the original card capture, and every renewal after that inherits whatever happened — or didn't happen — at that first charge.

That's what makes the regional gap a subscription problem specifically, not just a one-off checkout problem. In Japan, India, Australia, the EEA, and the UK, a regulatory mandate means a meaningful share of initial card captures run through 3DS automatically, whether the merchant configured anything or not. The authenticated mandate gets recorded, and Stripe's exemption logic can lean on it for every renewal that follows. In the US, Canada, and most of Latin America, nothing forces that first authentication to happen. If a SaaS business never explicitly requests it, the initial charge clears with no challenge, no mandate gets recorded beyond a basic one, and every renewal on that subscription carries the same unauthenticated risk profile for as long as the customer stays subscribed.

Fraud that gets through an unauthenticated signup doesn't necessarily show up as a failed renewal. It shows up as a dispute weeks or months later, on a subscription that had been billing successfully the whole time — the exact blind spot most dunning logic is built to catch the opposite of: a decline your retry schedule can act on, not a chargeback on a charge that already succeeded.

The trap on both sides of a blanket policy

Copying one region's fraud posture onto every market doesn't just under-protect the high-fraud regions — it actively costs you in the low-fraud ones. Stripe's own testing found that AI-driven, adaptive 3DS optimization delivered a 1.20% conversion uplift while cutting fraud on all transactions by 7.67%, in markets already subject to SCA. That's evidence that even inside a mandated region, a blunt "challenge everything" setting underperforms a tuned one — the same failure mode we've covered with Stripe's dynamic risk threshold, where a fraud rule left too tight quietly blocks legitimate renewals long after the attack that justified it has passed.

Run that same blunt setting the other direction — leaving 3DS off everywhere it isn't legally required, including a Latin American subscriber base running fraud rates 160% above EMEA's — and the business absorbs the fraud liability itself instead of shifting it to the issuer. Stripe's documentation flags a further consequence worth knowing about: an account that lets chargebacks run high enough can be enrolled in a card network's fraud or dispute monitoring program, which can strip away liability-shift protection even on payments that were properly authenticated. A blanket "3DS off, it's optional here" policy isn't a neutral default. It's a decision to carry every unit of that regional gap yourself.

Segmenting authentication instead of guessing at one global setting

You don't need to run a different Radar configuration by hand for every country. Two mechanisms handle this without turning fraud settings into a full-time job:

  • Radar Plus custom rules. Accounts on Radar Plus can write rules that request 3DS conditionally — scoped to card country, BIN range, or any other signal Radar exposes — instead of one account-wide toggle. This is the direct tool for treating a Brazilian card differently from a US one without touching how EEA or Japanese traffic gets handled.
  • Manual request_three_d_secure. Without Radar Plus, you can set payment_method_options[card][request_three_d_secure] to any (prefer a frictionless outcome, minimal added friction) or challenge (force active authentication) when creating or confirming a PaymentIntent, SetupIntent, or Checkout Session. Applied at the initial card-capture step for subscribers in high-fraud, non-mandated markets, this gets you the same benefit the EEA gets automatically — an authenticated mandate on file before the first renewal ever fires.

The same advice we've given for EEA subscribers applies here, just deliberately instead of by regulation: set usage: 'off_session' on the initial SetupIntent or PaymentIntent so 3DS runs — and a real mandate gets recorded — before you need one. Skipping that step and treating every region's first charge the same way is how a fraud gap that shows up clearly in Stripe's aggregate data stays invisible in any single company's dashboard, buried inside a blended chargeback rate that never gets split out by where the card was issued.

Segmenting your reporting the same way matters just as much as segmenting the setting. Pull chargeback rate and dispute-to-charge ratio by card issuing country, the same way currency mismatch shows up as a distinct failure mode once you stop looking at a single blended international decline rate. A US-heavy SaaS business and a Latin America-heavy one can post identical topline fraud numbers while one of them is one bad quarter away from a network monitoring program and the other isn't close.

Where this fits against the rest of involuntary churn

A subscriber who churns from an unauthenticated fraud dispute never sees a cancel button, and neither does one who never got the fraud dispute because the merchant ate the cost of a chargeback quietly instead. Both outcomes sit entirely upstream of any save offer CancelFlow could ever show — there's no cancellation decision happening, just a fraud-liability question that got answered by default months earlier, at signup, by a 3DS setting nobody thought to check by region. If your subscriber base spans multiple markets, that's worth pricing out directly: model what even a fraction of a point of recovered involuntary churn is worth using our churn calculator, with your highest-risk region isolated as its own segment rather than folded into a global average that hides exactly where the exposure lives.

Frequently asked questions

Does Stripe require 3D Secure for subscriptions outside Europe?+

Not by default. Strong Customer Authentication-style rules apply automatically in the EEA and UK under PSD2, and Stripe's own documentation names similar regulatory requirements in India, Japan, and Australia. Outside those markets — including the US, Canada, and most of Latin America — 3D Secure is optional. Stripe will only request it there if your Radar rules ask for it or you set the request_three_d_secure parameter yourself.

Why did Asia-Pacific's card fraud rate drop below Europe's in 2026?+

Stripe's regional analysis, published in September 2026, credits mandated 3D Secure rollouts across Asia-Pacific markets. Malaysia's card fraud rate fell 74% from 2022 to 2025, the largest drop in the region. Japan implemented a 3DS mandate under its Credit Card Security Guidelines in April 2025, and dispute rates there ran 30% lower in 2025 than in 2024. Stripe reported Asia-Pacific had a lower card fraud rate than Europe, the Middle East, and Africa for the first time in Q1 2026.

Does a successful 3D Secure authentication guarantee I won't get hit with a chargeback?+

No, and Stripe is explicit about this in its own documentation: successful 3DS authentication does not guarantee liability shift for any specific payment or dispute. You can generally expect liability to shift to the issuer on an authenticated payment that's later disputed as fraud, but card network rules decide the actual outcome, and accounts enrolled in a card network's fraud or dispute monitoring program can lose that protection even on authenticated charges.

Can I require 3D Secure only for certain countries or card types instead of my whole account?+

Yes. Stripe Radar can trigger 3DS dynamically based on risk, and Radar Plus accounts can write custom rules scoped to specific conditions, including card country. Without Radar Plus, you can manually set payment_method_options[card][request_three_d_secure] to any (prefer a frictionless outcome) or challenge (force active authentication) when creating or confirming a PaymentIntent, SetupIntent, or Checkout Session — which lets you target the regions where 3DS isn't mandatory but your own fraud data says it should be.

Try CancelFlow

Stop losing subscribers today

One script tag. One function call. A live cancellation flow in under 10 minutes.

Start free trial →
← All postsHome