Skip to content

The home for fintech intelligence and news, for the people who build it, fund it and regulate it.

RECENT ROUNDS
AIRWALLEXSeries H$320M@ $11BNORM AISeries C$120M@ $1.2BEDX MARKETSSeries C$76MINTERCHECKSSeries C$50MTANGOSInvestment Round$20MKREDOSAISeries A$7MKORDSeries A$8.6M
MEMBER VOICES

The Card That Fights Back

Mikko Kähkönen, Global Head of Card Products at Giesecke+Devrient (G+D), argues that as card fraud keeps rising, the physical payment card itself needs to become a more active layer of defence, from minimalist, numberless designs to dynamic CVVs and cards that double as authentication devices.

By Mikko Kähkönen, Global Head of Card Products, Giesecke+Devrient (G+D)

Mikko Kähkönen

GLOBAL HEAD OF CARD PRODUCTS, GIESECKE+DEVRIENT

23 SEP 2026

The Card That Fights Back

Mikko Kähkönen, Global Head of Card Products at Giesecke+Devrient (G+D), argues that as card fraud keeps rising, the physical payment card itself needs to become a more active layer of defence, from minimalist, numberless designs to dynamic CVVs and cards that double as authentication devices.

Card security measures can’t afford to stand still while fraud tactics continue to evolve at speed. From card-not-present (CNP) fraud and large-scale data breaches, to criminals using AI to launch widespread attacks, fraud losses are rising globally.

The proof is in the data. The European Banking Authority (EBA) and the European Central Bank (ECB) released a joint report in 2025, revealing that fraud escalated to $4.2 billion in 2024, continuing its rapid upward trajectory from the last few years. In my view, to keep pace with evolving fraud tactics, banks and issuers need to consider how the payment card itself can become a more active layer of defence.

Minimalist card designs 

I believe that the physical payment card no longer needs to function as a static payment tool alone. It can now play a far more active role in preventing fraud. Before they arrive at more complex technology, issuers can take the simple first step of removing sensitive information such as the account number from the card surface. This reduces the risk of unauthorised use if a card is lost or stolen.

In 2025, Mastercard introduced cards in Australia that remove the 16-digit number from the physical card surface, reflecting a wider shift towards more minimalist and security-focused card designs. Instead, sensitive information is securely stored within a banking app, reducing the risk of exposed card details being used fraudulently if a card is lost or stolen.

The move comes as Australia continues to face significant card fraud challenges, with losses nearing $1 billion in 2024. I see reducing visible card data as an important first step, with newer technologies pushing card security even further.

Fighting fraud with a changing code

One area where I’m witnessing growing attention is dynamic CVV technology, designed to tackle the rise of card-not-present (CNP) fraud. This type of fraud involves stolen card details being used for online or phone transactions and now accounts for around 70% of card fraud losses in the UK, with cases continuing to rise year-on-year. Traditional static three-digit security codes offer limited protection once card details have been compromised. Dynamic CVVs change regularly, making stolen credentials significantly harder to re-use.

With a dynamic CVV code, a new one-time verification code can be deployed with every transaction via an ultra-low-power e-ink display, rendering any stolen code useless within seconds. The code can also be refreshed via a user’s mobile banking app, providing real-time protection for both contactless payments and those made online.

Crucially, I think one of the strongest aspects of dynamic CVV technology is that it can strengthen security without compromising the user experience, because it requires no additional hardware and maintains the same functionality as a standard EMV payment card. This should be particularly appealing to issuers who understandably don’t want end users to be negatively impacted by any security changes.

Cards as authenticators

Ever-changing CVV codes are just one example of how cards can evolve to battle fraud and evolving cyber threats. Something that I think is very beneficial is the ability for payment cards to act as FIDO authenticators. FIDO is the global standard for multifactor authentication (MFA) to protect against SMS OTP attacks and other attack techniques. This essentially enables a card to handle secure login, secure payment confirmation, oversee access control and even handle activation of the card itself.

With cards essentially doubling as authentication devices, payment transactions and online banking access can be protected with strong multi-factor authentication (MFA), alongside optional user-chosen PINs. Issuers should also be looking at other authentication methods such as biometrics embedded in the card. The user places their thumb to the card to approve a transaction, making it incredibly difficult to replicate for fraudsters if they intend to use a stolen card.

Balancing security and customer convenience

While I’m excited by the significant potential in these evolving protection techniques, security should never come at the expense of the customer experience. For example, low-value everyday payments ideally shouldn’t go through a three-step authentication check, which risks frustrating users.

This is where I believe innovations such as biometrics offer extra value to consumers. Because fingerprints can’t be lost or forgotten, they will always have a smooth payment experience. However extra checks should still be in place for suspicious-looking transactions, with flexibility across the board to ensure that security adjusts to the context of an individual transaction.

Card security needs to move at the pace of fraud

Fraud is moving quickly, and I want to stress the importance of card security needing to move with it. As criminals adopt new techniques to steal card details, banks and issuers need to rethink the role of the physical payment card as an active layer of defence. Numberless designs reduce the risk of exposed data, while dynamic CVVs can disrupt CNP fraud by making stolen details useless. Cards can also act as authenticators, using strong MFA and biometrics to secure online banking and e-commerce.

I’m of the opinion that the role of the payment card is changing rapidly. No longer just a payment tool, it is becoming an active participant in fraud prevention, helping issuers respond more dynamically to emerging threats.

Disclaimer: Giesecke+Devrient (G+D) is a manufacturer of the card security technologies discussed in this piece.

 

By Mikko Kähkönen, Global Head of Card Products, Giesecke+Devrient (G+D)

ABOUT THE AUTHOR

Mikko Kähkönen

PROFILE