Fraud Matters to Online Shoppers – Make Sure It Matters to You Too
First published in 2014, rewritten in 2026 so the advice holds today.
Online shoppers have always weighed up trust before they enter card details. Back in 2014, a study by Kaspersky Lab and B2B International found that more than half of consumers buying online were worried about fraud, and 42% said they would spend more, and more often, if they were confident their details were safe. Well over half admitted to abandoning a transaction because they suspected their data wasn't secure. Around 60% put the responsibility on themselves and their bank rather than the retailer.
Those figures are over a decade old, but the underlying behaviour hasn't gone away. Shoppers still drop out of checkouts when something feels off, and a security scare still does lasting damage to a brand's reputation, even when the money is refunded quickly.
What's changed since 2014
A lot of what was advice at the time is now simply the baseline. Some of it needs updating:
- HTTPS is now compulsory in practice. Since 2018, Chrome and other browsers mark any page without HTTPS as "not secure". A site without a valid SSL certificate will lose trust and sales before a customer even reaches the checkout.
- Card payments are protected by law, not just goodwill. Strong Customer Authentication, introduced under PSD2 and fully enforced in the UK from March 2022, means most online card payments now require two-factor verification (typically a one-time code or biometric check via your bank's app). This has made card-not-present fraud harder to commit than it was in 2014.
- Hosting is no longer the whole security story. The original advice to choose your hosting provider carefully still stands, but most stores now also rely on a payment gateway (Stripe, PayPal, Adyen, and similar) to handle the actual card transaction, which takes a large chunk of PCI DSS compliance off your plate. If you're on Shopify, BigCommerce or a similar hosted platform, much of this is managed for you as standard.
Where responsibility actually sits now
The 2014 study found most shoppers saw fraud prevention as a job for banks and customers, not retailers. That's still broadly true legally, banks carry most of the liability for fraudulent card transactions, and SCA has shifted more of the verification burden onto the customer's bank at the point of payment.
But shopper perception hasn't moved much. If someone's card details are compromised after shopping with you, or your checkout looks dated or untrustworthy, they will associate the problem with your brand regardless of where the fault technically lies. Reputational risk still sits with the retailer even when financial liability doesn't.
What to actually do about it in 2026
- Never store card data yourself. Use a reputable payment gateway with a hosted or tokenised checkout so you're not holding sensitive data you don't need.
- Use built-in fraud screening. Most modern payment providers (Stripe Radar and equivalents) include fraud detection as standard. Make sure it's switched on and the risk thresholds are actually reviewed, not left on default settings indefinitely.
- Keep visible trust signals up to date. A current SSL certificate, recognisable payment logos, and a clear, honest returns and contact policy still do the job the original article was pointing at: reassuring a nervous shopper in the seconds before they click "pay".
- Don't let SCA friction cost you sales. Two-factor checks reduce fraud but can also cause drop-off if a customer isn't expecting them. Make sure your checkout messaging explains what's happening rather than leaving people to abandon the basket out of confusion.
- Monitor abandoned checkouts for patterns. A spike in abandonment at the payment step, rather than earlier in the funnel, is often a signal worth investigating rather than ignoring.
The takeaway
The specific numbers from 2014 will have moved, but the behaviour behind them hasn't: shoppers who feel uneasy about security will abandon their basket, and they'll remember it. The tools have improved (HTTPS as standard, SCA, gateway-level fraud screening) but they only help if they're actually switched on, kept current, and explained clearly at checkout. Trust is still built in the seconds before someone clicks "pay", and that hasn't changed at all.