Skip to main content
Guides & Advice

3D Secure, Card Stop, phishing: the 10 words of card security

3D Secure, SCA, tokenisation, chargeback, Card Stop: the 10 security terms on a Belgian credit card, defined and priced from official sources.

By Sophie L.9 septembre 20268 min

A 28 euro online payment can go through without anyone asking you for a code. Nothing is broken there: Article 16 of Commission Delegated Regulation (EU) 2018/389 expressly allows it, and the Belgian banking sector asked in July 2026 that the door be closed. The ten words below all read from that point.

3D Secure proves your phone said yes

The protocol looks at neither the merchant, nor the product, nor the price. It checks a single thing: that the declared cardholder can confirm, at that moment, on a channel they control. The whole Belgian security structure rests on that, holes included.

3D Secure

3D Secure is the protocol by which a card issuer has a remote payment confirmed by the cardholder, on a second channel, before authorising the transaction.

Each network sells it under its own name, Visa Secure, Mastercard Identity Check, American Express SafeKey, but the mechanics are shared. Its second version, 3DS2, passes the issuer a set of context data, the device, the delivery address, the merchant history, which sometimes let it authorise without asking you anything. That silent path explains why a 200 euro order with a merchant you have used for three years goes through faster than a 40 euro purchase from a stranger. In Belgium the second channel is most often the banking app, itsme or a card reader, and the phone dominates: of the 382 million online payments recorded in 2024, 90 % were confirmed from a smartphone, according to the Bancontact Payconiq Company release of 12 February 2025. Our guide to online purchases with a credit card covers the journey, and our guide to credit card fraud covers the case where the confirmation was extracted by deception.

Strong customer authentication (SCA)

Strong customer authentication is the legal obligation to combine at least two independent factors among something you know, something you hold and something you are.

Article 4 of Commission Delegated Regulation (EU) 2018/389 requires those factors to be genuinely independent: the breach of one must not compromise the others. A code sent by SMS to the phone that already serves as the possession factor ticks that box badly, which is why Belgian banks moved to the app and to itsme. The same regulation then organises its own exceptions. Article 16 lets a remote payment through up to 30 euros, as long as the cumulative amount since the last authentication stays below 100 euros or below five consecutive transactions. Article 11 does the equivalent in store for contactless, at 50 euros per transaction and 150 euros cumulative, thresholds our guide to contactless payment takes one by one.

The 30 euro threshold strikes me as the worst placed point in the whole scheme. It was calibrated on shopping convenience, not on what a fraudster can take out in five transactions in a row before the sixth finally asks for a code.

PSD2

PSD2 is the European payment services directive that made strong authentication compulsory and set out who bears the loss on an unauthorised payment transaction.

It is Directive (EU) 2015/2366, transposed into Belgian law in Book VII of the Code of Economic Law, where the articles deciding who bears the loss when a transaction is not yours are found; our guide to credit card security covers them. A dispute with a merchant falls outside that regime and follows the route described in our guide to the chargeback.

The Febelfin action plan dated 9 July 2026, which I read in Dutch for want of a French version, writes what the sector never puts on its consumer pages: the exemptions from strong authentication provided for by PSD2, for known beneficiaries as much as for small amounts deemed low risk, are exactly the ones fraudsters exploit, generally on modest sums. Belgian banks announce there that they want to make authentication compulsory on certain card-not-present transactions, through a mechanism called soft decline: the payment request without authentication is refused, then the merchant resubmits it with authentication. The document cites the French measure as its model. A security scheme whose regulator built in the exits, and whose industry asks eight years later that they be closed, deserves to be presented to the reader for what it is.

Does a disposable number protect better than a tokenised card?

Both answer the same worry, not leaving a sixteen-digit number lying around at a merchant. They act at two different points in the chain.

Tokenisation

Tokenisation replaces your card number with a token specific to one device and one merchant, worthless anywhere else.

The token travels instead of the number, so a data leak at the merchant hands over nothing reusable. Every in-store payment from a phone rests on one, and the Belgian volume is far from marginal: 65 million in-store smartphone payments in 2024, up 58 % year on year, against 1.9 billion in-store Bancontact payments of which 1.35 billion were contactless. The protection stops dead on one point: an unlocked phone in someone else's hand pays just as well as yours. The number, the BIN and the security code that the token replaces are defined in our first instalment, the glossary of basics.

Virtual card

A virtual card is a card number generated on demand, attached to the same account as the physical card but distinct from it.

The disposable version regenerates its numbers after every payment: the Revolut Belgium help page, read on 9 September 2026, states that once the payment has gone through, the numbers no longer work. A subscription you struggle to cancel stops on its own. The downside fits on one line of travel: no car rental desk, no hotel demanding a card imprint at check-in will accept a number without a physical medium. Our guides to the virtual credit card and the disposable virtual card compare the offers, and the comparison tool flags which Belgian cards include one.

Belgian skimming fell from 1,425 cases to 9 in two years

In early 2011, the country's banks blocked non-European withdrawals by default on ordinary debit cards.

Skimming

Skimming is the copying of a card's magnetic stripe, at an ATM or at a tampered terminal, in order to manufacture a duplicate.

The block emptied the fraud of its outlet: the magnetic stripe no longer worked outside Europe, and inside it the chip takes over. Nine cases were recorded across the whole of 2012, against 1,425 two years earlier, according to Atos Worldline figures reported by Belga on 14 January 2013. That geographic zone setting still exists and it has become the leading cause of a card blocked abroad; our page on the Belgian card abroad explains how to open it before you leave.

That figure is thirteen years old, and it is the most recent I could find. Febelfin no longer publishes a skimming series, which makes sense for a dead fraud, but leaves me unable to say what remains of it in 2026. So I write the mechanics without pretending to put a number on the current year.

Who do you call, and in what order?

48 % of phishing victims surveyed by Indiville for Febelfin, between 20 January and 9 February 2025, telephoned Card Stop. On a transfer they had approved themselves, that call recovers nothing.

Phishing

Phishing is the manoeuvre by which a fraudster poses as a trusted third party in order to obtain your codes or your approval.

The Belgian haul nearly doubled in a year: 49 million euros in 2024, 93 million in 2025, even as the banking sector detects, blocks or recovers 75 % of fraudulent transfers. Both amounts come from Febelfin, the first from its phishing dossier published in 2025, the second from its action plan of 9 July 2026. The reporting point is the Centre for Cybersecurity Belgium: any doubtful message is forwarded to suspicious@safeonweb.be, which was receiving close to 26,000 reports a day in July 2025. You will only get an automatic acknowledgment. The service checks the links and has them blocked, which mostly protects the next reader. In the same Indiville survey, 6 % of victims had taken no step at all.

Card Stop

Card Stop is the Belgian interbank service that blocks, around the clock, payment instruments issued by institutions in the country.

One number, 078 170 170, a standard call with no surcharge, in French, Dutch or English. At the end of the call you are given a case number: it is the proof that the call took place, and you will be asked for it again if you dispute transactions. I reread the cardstop.be FAQ on 9 September 2026: it answers fourteen questions, and not one of them is about reimbursement. The division of roles is worth knowing before you need it.

  • blocking is not compensation, the two files stay separate;
  • a card you find again can only be unblocked by the issuing bank;
  • your identity card falls under Doc Stop, on 00800 2123 2123, not Card Stop;
  • a transfer you approved yourself is not stopped by blocking the card;
  • filing a police report remains advisable after a theft or a fraud.

The full procedure after a loss is in our guide to the lost or stolen credit card.

Chargeback

A chargeback is the procedure by which the card network takes back from the merchant a sum already collected, at your issuer's request.

These are network rules, written by Visa and by Mastercard, not Belgian law. The admissible grounds all turn on performance: goods never delivered, service not as described, a subscription debited after cancellation, a double charge on one purchase. The entry point changes with the instrument, and it is rarely explained: for a Visa or Mastercard credit card, the dispute form is filled in on macarte.be, whereas for a debit card the request goes through your bank. The Card Stop FAQ says so in one line, read on 9 September 2026. A cardholder who writes to their bank about a credit card transaction does not lose the right, they lose days.

Rétrofacturation

Rétrofacturation is the French name for a chargeback, and it is not to be confused with the refund of an unauthorised payment transaction.

Two separate doors. A chargeback handles a dispute with the merchant: the transaction really came from you, it is the other side of the bargain that failed. An unauthorised transaction covers the opposite case, a transaction you never started, and falls under Articles VII.38 to VII.45 of the Code of Economic Law, so under the law rather than under network rules. Picking the wrong door costs weeks, because the deadlines and the contacts are not the same. The pricing vocabulary that goes with these procedures, from the APR to the currency exchange fee, is covered in our second instalment, the glossary of fees.

The full record, source by source:

TermFigure recordedSource and date
3D Secure382 million online payments in 2024, 90 % confirmed by smartphoneBancontact Payconiq Company, release of 12 February 2025
Strong authenticationno authentication required below EUR 30, up to EUR 100 cumulative or 5 transactionsDelegated Regulation (EU) 2018/389, art. 16
Contactless in storeEUR 50 per transaction, EUR 150 cumulative or 5 transactionsDelegated Regulation (EU) 2018/389, art. 11
PSD2exemptions to be closed by soft decline on certain remote transactionsFebelfin action plan, 9 July 2026
Tokenisation65 million in-store smartphone payments in 2024, up 58 %Bancontact Payconiq Company, 12 February 2025
Virtual cardnumbers regenerated after each payment on the disposable versionRevolut Belgium help page, read 9 September 2026
Skimming9 cases across 2012, against 1,425 two years earlierAtos Worldline figures, Belga dispatch of 14 January 2013
PhishingEUR 93 million taken in 2025, EUR 49 million in 2024, 75 % of transfers recoveredFebelfin, action plan of 9 July 2026 and 2025 phishing dossier
Safeonweb reportsclose to 26,000 suspicious messages a daySafeonweb, July 2025, cited by Febelfin
Card Stop078 170 170, no surcharge, 24 hours a day in three languagescardstop.be, FAQ read 9 September 2026

Last check of these amounts, numbers and articles: 9 September 2026. The oldest of them is thirteen years old, and it is the industry itself that stopped updating it.

Contactless payment with a credit card in a café

Comparator Guides & Advice

Compare side by side.

Compare now →

Frequently asked questions

Because European law provides for exemptions. Article 16 of Commission Delegated Regulation (EU) 2018/389 lets a remote payment through up to 30 euros, as long as the cumulative amount since your last authentication stays below 100 euros or below five consecutive transactions. Other exemptions exist, notably for beneficiaries you have registered as trusted and for subscriptions whose amount does not change. Your issuer remains free to require authentication even where the law does not impose it.

Yes, and which route you take depends on what happened. If the transaction really came from you but the merchant delivered nothing, it is a chargeback request, based on Visa or Mastercard network rules. If the transaction is not yours, even where a code was obtained by deception, it is an unauthorised payment transaction under Articles VII.38 to VII.45 of the Code of Economic Law, and the liability regime applies. A successful authentication therefore closes neither door on its own.

Calling costs nothing and makes sense if your card details may have circulated. Blocking stops future transactions on that instrument, it recalls no amount already gone, and it does not stop a transfer you approved yourself in your banking app. Keep the case number given at the end of the call, you will be asked for it when you dispute. Then tell your bank, which remains your contact for the rest of the file.

Ask yourself a single question, which is who started the transaction. You started it and the goods or service never arrived: that is a chargeback, handled under the card network's rules. You did not start it: that is an unauthorised payment transaction, handled by Belgian law, with its own dispute deadlines. The entry point also differs by instrument, an online form for a Visa or Mastercard credit card, your issuing bank for a debit card.

Sophie L. worked eight years in a Belgian bank branch, first as a credit adviser and then in customer relations, before going independent in 2021 and settling in Louvain-la-Neuve. Her work starts with the issuers' official fee schedules, from the high-street banks (ING, BNP Paribas Fortis, KBC, Belfius) to the neobanks (Revolut, N26, Wise), reduced to five comparable lines: annual fee, currency conversion charge, borrowing rate, spending limits and bundled insurance. Every price on this site carries the date it was checked: the annual-fee grid was gone through line by line on 12 August 2026, after Belfius moved its Beats Star package to 5.90 € a month in February. If an issuer does not publish a figure, she writes that down instead of estimating it. For readers who moved to Belgium, she spells out what a Belgian issuer expects from an applicant with no local credit history.