OSMP — France’s payment fraud figures and how to use them
France publishes payment-fraud rates by instrument and by channel, and those published rates are the benchmark your own numbers get measured against. The Observatoire de la sécurité des moyens de paiement was created by Law 2016-1691 of 9 December 2016 and is chaired by the First Deputy Governor of the Banque de France. Among its statutory missions is to establish aggregated fraud statistics — which is what turns it from a policy forum into a public measuring instrument. Its tenth annual report was presented on 7 September 2026 and covers 2025. This piece explains what the Observatory publishes, what the current figures say, and how to use them as a benchmark rather than as a headline.
1. What it is, and who sits on it
The Observatory exists to organise exchange and consultation between everyone concerned with the smooth functioning of payment means and with the fight against fraud — consumers, retailers and companies, public authorities and administrations, and banks and managers of payment means.
Its composition reflects that: two parliamentarians, representatives of public administrations, payment-market participants, users — merchants, businesses and consumers — and qualified individuals, under the chairmanship of the First Deputy Governor of the Banque de France.
| Mission | What it means for a reporting firm |
|---|---|
| Follow the security measures adopted by market actors and their clients | Qualitative information on controls, not only numbers |
| Establish aggregated fraud statistics | The data collection itself |
| Maintain a technology watch | Collects information capable of reinforcing payment security and makes it available to members |
2. The instruments it covers
The scope is broader than cards, and two entries in the list are the reason this matters to an e-money or remittance business:
- credit transfers;
- direct debits;
- payment cards;
- cheques;
- commercial paper;
- electronic money; and
- the transmission of funds.
That breadth is also what makes the published output usable as a benchmark across a mixed product set. A firm issuing cards, holding e-money balances and executing transfers can find a market rate for each of the three, expressed on the same denominator, in the same document.
3. What it publishes, and on what cadence
Two outputs, at two speeds. The annual report is drawn up each year, sent to the minister responsible for the economy and submitted to Parliament; the 2025 edition was presented on 7 September 2026. Between annual reports the Observatory publishes half-yearly key-figures notes on fraud statistics — the note covering the first half of 2025, for instance, was published in January 2026.
The cadence has a governance use that is easy to overlook. A fraud committee reviewing internal numbers monthly and market numbers annually is comparing a moving series against a stale one. Aligning the benchmark review to the half-yearly note gives the comparison a fixed cadence and a public reference point, which is a materially stronger position in a supervisory conversation than an internal trend with no external anchor.
Because the outputs are public and parliamentary, the definitions behind them are stable and citable. That is the property that makes them usable as a standing internal benchmark rather than as a one-off comparison that has to be re-argued each year.
4. The current figures, and how they are expressed
The Observatory expresses fraud as a rate per €100,000 of payments, not as a count. That choice matters: it normalises for volume, so a firm growing quickly does not look safer simply because its denominator grew.
| Measure | 2025 | 2024 |
|---|---|---|
| Total fraud, all cashless instruments | Up 3.8% year on year | Just below €1.2 billion, stable since 2022 |
| Number of fraudulent transactions | Down 7.6% | — |
| Card fraud rate | €47 per €100,000 — a historic low | €53 per €100,000 |
| Card — mobile payment in store | €9 per €100,000 | — |
| Card — internet payments | €124 per €100,000 | — |
| Cheque fraud | Down 16%; detection stopped 41% of attempts; stolen cheques are 90% of cheque fraud | €69 per €100,000 |
| Credit transfers | — | €1 per €100,000 overall; €43 online banking; €46 instant |
| Fraud by manipulation | €516 million, up 34% — 41.6% of all payment fraud | €382 million — 32% of the total |
Read the first two rows together: amounts rose while the number of fraudulent transactions fell. Fewer, larger cases is a different operational problem from many small ones — it moves the answer away from transaction-level scoring and toward intervention on high-value payments.
The third and fourth rows are the ones most often misused. A single “card fraud rate” comparison is close to meaningless if the two sides have different channel mixes: in-store mobile and internet card payments sit roughly fourteen times apart on the same measure. A card programme that is entirely e-commerce should not expect to sit at €47.
Alongside the figures the Observatory issued four recommendations for 2026: closer cooperation with the telecommunications sector, a cooperation plan with digital actors including social media and search engines, promotion of advanced fraud-prevention tools by banks, and wider user-awareness campaigns. Three of the four are about the channel through which the victim is approached rather than the payment itself, which is the clearest possible statement of where the Observatory thinks the problem now sits.
5. Worked example — benchmarking a card rate honestly
Facts: an e-money institution issuing cards to French customers measures its 2025 card fraud rate at €96 per €100,000. The market rate is €47. The head of risk asks whether the firm is twice as bad as the market.
Which figures apply: not the headline. The comparable figures are the channel-level ones — €9 per €100,000 for in-store mobile payments against €124 for internet payments. The market aggregate of €47 is a blend of the two, weighted by the whole French market’s channel mix.
What the practitioner does: re-expresses the firm’s own number by channel, then builds a mix-adjusted benchmark: apply the published channel rates to the firm’s own channel weights and compare that synthetic figure with the actual rate. A card book that is 80% e-commerce has an expected blended rate far above €47, and the honest question is whether the firm beats the internet rate of €124 — not whether it beats the national blend.
Outcome: in this case the firm’s e-commerce rate came out at €108 against a market €124, and its in-store rate at €11 against €9. The correct conclusion is the opposite of the one the headline suggested: the card programme is at or slightly better than market on its dominant channel, and the gap to €47 is a business-mix fact, not a control failure. That distinction is exactly what a supervisor will expect the firm to have made before being asked.
6. Worked example — the fraud that authenticates correctly
Facts: a payment institution reviews a rise in disputed outgoing transfers. In each case strong customer authentication succeeded, the device was the customer’s own, and the customer confirms they approved the payment after a telephone call from someone presenting as their bank.
Which figures apply: this is fraud by manipulation, and it is now the largest and fastest-growing component of French payment fraud — €516 million in 2025, up 34%, and 41.6% of the total. Transfers are where it lands: €376 million of that total was taken by transfer, most commonly through impersonation of a bank adviser.
What the practitioner does: stops treating authentication success as evidence that no fraud occurred. Three changes follow. The fraud case record gets a manipulation attribute independent of the authentication outcome, so these cases can be counted at all. Detection moves to behavioural signals that survive a correct authentication — a first payment to a new beneficiary, an unusual amount relative to the account’s history, a session preceded by a change of contact details. And the intervention changes shape: a friction step that names the scam pattern explicitly in the payment flow works where a generic warning does not, because the customer has been coached to expect generic warnings.
Outcome: the firm can now report a number for a category that previously disappeared into “customer-authorised”. That matters twice over — it is the category the Observatory is tracking most closely, and it is the category where a firm reporting zero is telling a supervisor that it cannot see rather than that it is clean.
7. Worked example — instant transfers and the rate that moves
Facts: a firm enables instant credit transfers for French customers and models expected fraud losses using the overall transfer fraud rate of €1 per €100,000.
Which figures apply: the overall transfer rate is dominated by bulk low-risk flows such as salary and supplier payments. The published channel breakdown puts online banking transfers at €43 per €100,000 and instant transfers at €46 — roughly forty-five times the overall figure.
What the practitioner does: rebuilds the loss model on the channel rate rather than the instrument rate, and carries the difference into product decisions: per-transaction and daily limits at launch, a cooling period for first payments to new beneficiaries, and a recall procedure that is staffed at the speed the instrument settles at. The relevant control fact about an instant transfer is not that it is fast but that it is irrevocable before a human review can begin.
Outcome: the loss line in the product business case moves by an order of magnitude, which is usually enough to change what launches and with what limits. A firm that priced instant transfers off the €1 figure has priced the wrong instrument.
8. How this sits alongside the EU regime and the French return
The Observatory’s statistics are an output; they are not the obligation. A payment service provider operating in France remains subject to the EU-level fraud reporting framework built on the EBA guidelines under Article 96(6) of PSD2, whose taxonomy divides reportable fraud into unauthorised transactions and manipulation of the payer, and to the ECB payment statistics regulation. The French collection through which firms actually file their fraud data — proven fraud only, declared at the nominal payment amount — is covered separately in OSCAMPS Fraude.
The data-model point that makes all three work from one source is small and structural: capture the instrument and the fraud type as separate attributes at case creation, rather than deriving either from a payment-scheme reason code afterwards. A dataset built around card chargeback codes can populate the card lines and nothing else — it has no natural place for an e-money or transfer case, and no place at all for manipulation, where the payer authenticated correctly. One dataset with two independent attributes serves the EU statistical return, the EU fraud guidelines and the French collection without three parallel reconciliations.
A last caution on interpretation. Published market aggregates reflect the whole population of reporting participants, including business models very different from a specialist e-money or remittance firm. The right use is directional — is our rate on the same order, and moving in the same direction — rather than an expectation of convergence on the market average.
FAQ
What is the legal basis for the Observatory?
It was created by Law 2016-1691 of 9 December 2016 and is chaired by the First Deputy Governor of the Banque de France. Establishing aggregated fraud statistics is one of its statutory missions.
Does it cover e-money and money remittance?
Yes — electronic money and the transmission of funds are both named among the instruments within its scope, alongside transfers, direct debits, cards, cheques and commercial paper.
How often does it publish?
An annual report sent to the minister responsible for the economy and submitted to Parliament, plus half-yearly key-figures notes on fraud statistics.
What was the card fraud rate in 2025?
€47 per €100,000 of payments, a historic low, against €53 in 2024. Within that, in-store mobile payments were €9 per €100,000 and internet payments €124.
Why did total fraud rise while the number of cases fell?
Amounts rose 3.8% in 2025 while the number of fraudulent transactions fell 7.6% — fewer but larger cases, driven by manipulation fraud, which reached €516 million and 41.6% of the total.
Is this the same thing as filing the French fraud return?
No. The Observatory publishes aggregated statistics; the return through which firms submit their own fraud data is a separate obligation with its own counting rules and filing channel.
What to do, today
- Re-express your fraud rate per €100,000 of payments, by instrument and by channel, so it is on the same footing as the published figures. A rate expressed per transaction cannot be compared with anything the Observatory prints.
- Build the mix-adjusted benchmark rather than comparing against the national blend. Apply the published channel rates to your own channel weights and compare the synthetic figure with your actual one.
- Add a manipulation attribute to the fraud case record, independent of the authentication outcome. If you cannot count these cases, you cannot report the category that is now over 40% of French payment fraud.
- Reprice instant transfers off the instant-transfer rate, not the overall transfer rate — the two differ by a factor of roughly forty-five.
- Put the half-yearly note in the fraud committee calendar so the external benchmark refreshes twice a year rather than once.
- Separate the instrument and the fraud type at case creation, so one dataset serves the EU statistical return, the EU fraud guidelines and the French collection.
Related: OSCAMPS Fraude — the French fraud return · PSD2 fraud reporting · The supervisory fraud taxonomy · The French reporting calendar · ERMES TRACFIN — the déclaration de soupçon platform


