Compliant but Compromised: Why PCI Compliance Isn’t Stopping Australian Card Fraud
Australia's card fraud hit A$762m even as 90% of large merchants pass PCI DSS. A QSA explains the card-not-present gap and why compliance and fraud detection have drifted apart.

Here are two facts that should not be true at the same time. In Australia, more than 90% of large merchants report full PCI DSS compliance. And card fraud losses reached A$762 million in 2023, up 32% in a single year, with card-not-present fraud now accounting for roughly 85% of all losses.
If compliance worked the way most boards assume it does, those numbers would move in opposite directions. Instead they are climbing together. As a firm that assesses organisations against PCI DSS for a living, we do not find this contradictory. We find it predictable. The fraud has simply moved to where the compliance checkbox does not reach.
This analysis draws on our open-access study of Australian card fraud from 2020 to 2024, published in full with a DOI on our research page.
Where the fraud actually went
A decade ago, card fraud was largely a physical problem: skimmers on terminals, cloned magnetic stripes, stolen cards used in stores. PCI DSS, chip-and-PIN and tokenisation were effective against exactly that threat, and card-present fraud fell accordingly. In our analysis, card-present fraud now represents only about 15% of losses.
The other 85% is card-not-present: e-commerce, phone and recurring payments where no physical card is involved. This is not a failure of the controls that were built. It is a migration. Attackers went where the money still flows and the defences are thinner. The fraud rate has reached 70.2 cents per A$1,000 spent, the highest in five years, and over two million Australians were affected in 2024.
Why a passing audit does not catch it
The uncomfortable truth is that a merchant can be genuinely, honestly PCI DSS compliant and still be a productive host for card-not-present fraud. Three reasons stand out.
Compliance is a point-in-time floor, not a continuous ceiling. A Report on Compliance or a self-assessment questionnaire confirms that controls existed and functioned during the assessment. It does not guarantee they hold every day for the following twelve months, and attackers work in that gap.
The newest attack surface is the customer’s own browser. Card-not-present fraud increasingly relies on client-side attacks, where malicious JavaScript is injected into a checkout page to skim card details before they are ever encrypted or tokenised. PCI DSS v4.0.1 addresses this directly with Requirements 6.4.3 and 11.6.1, which mandate payment-page script management and tamper detection. These became mandatory only in March 2025, and many organisations are still treating them as a documentation exercise rather than an operational control.
The compliance burden thins out where volume concentrates. Large merchants have the budgets and teams to sustain compliance. Smaller merchants, who collectively process an enormous share of transactions, often validate through simplified questionnaires and lack the resources to maintain controls between assessments. Fraud follows the path of least resistance, and that path runs through the long tail.
Compliance and detection are not the same discipline
The deeper issue our research surfaced is structural. In most organisations, PCI DSS compliance and fraud detection are run by different teams, measured by different metrics, and rarely coordinated. Compliance asks “do we meet the standard?” Detection asks “is fraud happening right now?” Both are necessary. Neither is sufficient alone.
We found advanced machine-learning fraud-detection systems achieving over 90% accuracy in controlled conditions, yet struggling in production against data-quality problems and adversarial adaptation. Meanwhile, compliance programmes generate audit evidence that fraud teams never see. The organisations that fare best close this gap: they treat compliance controls and detection capability as a single system, feeding each other, rather than as two cost centres reporting up separate chains.
What this means in practice
For merchants and service providers, three shifts matter more than another audit.
Treat the payment page as live infrastructure, not static code. Implement genuine script inventory, integrity checking and tamper detection under 6.4.3 and 11.6.1, and monitor them continuously. This is where card-not-present fraud is being manufactured.
Close the loop between compliance and fraud teams. If your assessors and your fraud analysts have never compared notes, that is a finding in itself. Compliance evidence should inform detection tuning, and detection data should inform where compliance is thinnest.
Do not confuse validation with security. A clean assessment is the beginning of a defensible position, not the end of one. The question a board should ask is not “are we compliant?” but “would we detect it if a compliant control quietly failed?”
Australia’s rising fraud figures are not evidence that PCI DSS has failed. They are evidence that compliance and fraud prevention have drifted apart, and that the threat has moved faster than the checkbox. The organisations that reconnect the two are the ones that will bend the curve.
Frequently asked questions
How much did card fraud cost Australia?
Card fraud losses in Australia reached A$762 million in 2023, a 32% increase year on year, with over two million Australians affected in 2024. Card-not-present fraud now accounts for around 85% of losses.
If we are PCI DSS compliant, why are we still exposed to fraud?
PCI DSS compliance is a point-in-time floor, not a guarantee of continuous security. Most card fraud is now card-not-present and relies on client-side attacks on the checkout page, an area only recently addressed by Requirements 6.4.3 and 11.6.1. Compliance and fraud detection are also usually run by separate teams, leaving gaps between them.
What is the single most important control against card-not-present fraud today?
Payment-page security. Treat the checkout page as live infrastructure: inventory and integrity-check every script, deploy tamper detection, and monitor continuously under PCI DSS Requirements 6.4.3 and 11.6.1. This is where most card-not-present fraud is now manufactured.
Does a QSA assessment cover fraud detection?
A QSA assessment validates PCI DSS controls, not your fraud-detection performance directly. The two disciplines are complementary. The organisations that perform best treat compliance evidence and fraud detection as a single, connected system rather than separate functions.
Work with an independent QSA
Cianaa is an independent PCI QSA and certification body serving New Zealand and Australia. We help merchants and service providers move beyond point-in-time compliance to defensible, continuously monitored payment security. Talk to our assessors or read our open-access research.
Talk to Cianaa Technologies
Talk to our QSA team about scoping, gap remediation, and Report on Compliance under PCI DSS 4.0.1.
Book a discovery callGet the next one in your inbox
One email when we publish. Written by named auditors, never by a marketing robot. Unsubscribe anytime with one click.



