Payment security for South African e-commerce merchants
Card fraud losses in South Africa grew 26.2% in 2024 to R1.466 billion, according to SABRIC. This article covers the main security threats facing e-commerce merchants, what South African consumers expect from a secure checkout, and practical defences, from dynamic 3DS to tokenisation, that protect revenue without adding friction.

For e-commerce merchants, fraud rates aren't a distant industry statistic. They're a direct hit on revenue, customer trust and, in the worst cases, merchant account standing. Card-related fraud losses in South Africa climbed 26.2% in 2024 to R1.466 billion, according to SABRIC's Annual Crime Statistics report, with card-not-present (CNP) fraud, where stolen card details are used to complete an online purchase, driving most of that increase.
The real challenge isn't picking between security and conversion. Stitch's 2026 Consumer Payments Report found that consumers actively want security signals at checkout, but they abandon the process when that security becomes burdensome. Merchants need both, and the two aren't as opposed as they seem.
The main threats facing South African e-commerce merchants
Card-not-present fraud is the most prevalent form of e-commerce fraud in the country. A fraudster uses stolen card details to complete a purchase on a merchant's site, the cardholder disputes the transaction once they spot it, and the merchant loses both the goods and the payment if the transaction wasn't verified through 3D Secure. The resulting chargeback carries its own processing fee on top of the loss.
Chargeback abuse is a related but distinct problem. Here the transaction is legitimate, but the customer disputes it anyway, often because they don't recognise a generic reference on their bank statement. Unclear bank references are a significant contributor to this in South Africa, and it's one of the more preventable causes of chargebacks a merchant will face.
Account takeover happens when fraudsters gain access to a customer's account using compromised credentials, then use whatever payment details are saved there. For platforms that store card data, a single compromised account can open the door to a wave of fraudulent transactions before anyone notices.
Promotion and refund abuse tends to show up on high-volume platforms, where customers systematically exploit promotional offers, referral codes or refund policies. Individually, these look like minor edge cases. At scale, across thousands of accounts, they become a meaningful drain on revenue.
What consumers expect from a secure checkout
South African consumers actively look for security signals when they pay online, rather than treating security as invisible background infrastructure. Stitch's 2026 Consumer Payments Report found that 45% of consumers wouldn't feel safe paying online if they didn't recognise the payment provider, and 57% cite unexpected pop-ups or redirects as the clearest sign that something is wrong with a checkout.
Biometric authentication is a particular point of trust. Stitch's 2025 Consumer Payments Report found that over 90% of consumers would prefer to authorise a payment using biometrics or a passkey over a password or OTP, given the choice, with only 7.2% unsure and just 2.7% saying they'd never use them at all.
How to protect your platform without harming conversion
3D Secure (3DS) is one of the strongest defences against CNP fraud, but applying it to every transaction adds friction that pushes legitimate customers to abandon checkout. Dynamic 3DS is more selective. It triggers the authentication step only where risk indicators warrant it, such as an unusual transaction amount, a new device, a high-risk geography or behaviour that doesn't match a customer's usual pattern. Merchants get the fraud protection without slowing down the majority of transactions that are perfectly legitimate.
Bank statement clarity matters more than most merchants expect. When customers see a recognisable merchant name on their statement rather than a generic reference, they're far less likely to dispute a transaction they actually made. Stitch supports dynamic bank references that include the merchant name and transaction context, which cuts down on exactly this kind of avoidable chargeback.
Stitch Shield, our embedded fraud solution, monitors transactions across three layers: platform-wide, product-specific and client-specific. It's trained on transaction data across industries and dispute data from every major South African bank, and it flags suspicious activity using both predefined rules and machine learning. Rules can be set to block a transaction automatically the moment they're triggered, and once a fraudster is identified, they're blocked across every Stitch merchant, not just the one they targeted first.
Payment method mix affects chargeback exposure too. Pay by bank and Capitec Pay don't carry chargeback risk the way card payments do, so as their share of checkout transactions grows, a merchant's overall chargeback exposure shrinks with it. This is a structural benefit of a multi-method checkout that goes beyond the usual conversion argument for offering more ways to pay.
For merchants storing card details to support recurring billing or one-click checkout, tokenisation takes the raw card number out of your systems entirely. Network tokens also let merchants charge post-purchase adjustments, like a delivery fee added after the fact, without asking the customer to re-enter their card. Stitch Vault provides PCI DSS Level 1 certified tokenisation that stays portable across PSPs, so merchants aren't locked into a single provider's token format.
The cost of getting it wrong
The financial loss from fraud is only part of the cost. Stitch's 2025 Consumer Payments Report found that a single fraud-related incident, even one a customer only heard about second-hand, can turn them off a platform for good. In a market where switching to a competitor's site takes seconds, the reputational cost of a fraud incident often outweighs the direct financial loss.
FAQs
What is the biggest payment fraud risk for South African e-commerce merchants?
Card-not-present (CNP) fraud, where stolen card details are used to complete an online purchase, is the most prevalent threat and the main driver behind the 26.2% rise in South African card fraud losses in 2024.
How can I reduce chargebacks on my South African e-commerce store?
Descriptive, dynamic bank references reduce disputes from customers who don't recognise a generic merchant name on their statement. Offering pay by bank and Capitec Pay lowers overall chargeback exposure, since these methods don't carry chargeback risk the way card transactions do. Dynamic 3DS also protects against fraudulent chargebacks while keeping friction low for legitimate customers.
What is 3DS and should I use it for every transaction?
3D Secure (3DS) is an authentication protocol that adds a verification step to card transactions. Dynamic 3DS applies it selectively, only to transactions carrying elevated risk indicators, rather than universally. This protects against fraud without adding friction that would increase abandonment among legitimate customers.
What does Stitch Shield do?
Stitch Shield is Stitch's embedded fraud detection solution. It monitors transactions across multiple layers using predefined rules and machine learning, flags suspicious transactions, can automatically block high-risk activity, and shares fraud signals across all Stitch merchants to stop known fraudsters moving between platforms.
What is card tokenisation and how does Stitch Vault protect stored card data?
Tokenisation replaces a customer's real card number with a randomly generated token, so the actual card data never sits on a merchant's systems. Stitch Vault provides PCI DSS Level 1 certified tokenisation that's portable across payment service providers, so merchants can store card details securely for recurring or one-click payments without being locked into one provider's token format.
Elevate your security infrastructure with Stitch




