High-priced products
(Home appliances / branded goods / jewelry, etc.)
This is an area where fraud for impersonation and resale purposes are often targeted.
Our Commitment
Identity authentication to prevent payment of impersonation
EMV 3-D Secure (3D Secure 2.0) is a personal authentication service that determines whether a transaction during an online payment is made by the genuine cardholder or by 'spoofing' using stolen credit card numbers.
Currently, as a measure against credit card fraud, it is essential to implement it for all non-face-to-face e-commerce site operators in principle.
PG Multi-Payment Service 's EMV 3-D Secure (3D Secure 2.0) contributes to reducing input load for end users through risk-based authentication and lowering chargeback risks for operators.
PG Multi-Payment Service
Contact Information for EMV 3-D Secure
Based on device, behavior, and attribute information, risk-based authentication is used to determine whether the card issuer is conducting a transaction with the person themselves or is being 'spoofed' through credit card number theft. Businesses can establish a highly secure transaction environment and more easily suppress fraud occurrence.
If fraud occurs in an EMV 3-D Secure (3D Secure 2.0) authentication transaction, in principle, the business operator's chargeback is exempt. This helps reduce unexpected costs and stabilizes revenue.
With EMV 3-D Secure (3D Secure 2.0), if a risk-based authentication determines a transaction is low-risk, no additional authentication is required (frictionless). By reducing the input load on end users, we help suppress payment process abandonment and improve the purchase completion rate (CVR).
The "Credit Card Security Guidelines," which serve as practical guidelines under the Installment Sales Act, require all EC merchants to implement EMV 3-D Secure (3D Secure 2.0) in principle. Taking the measures outlined in the guidelines is recognized as meeting the standards for the security measures specified under the Installment Sales Act.
This is an area where fraud for impersonation and resale purposes are often targeted.
Because they are delivered immediately, spoofing transactions tend to become more apparent.
This area is crucial for identity verification when registering your card number.
These products are expensive and highly convertible, making them easy targets for fraud through impersonation.
The Credit Card Security Guidelines outline three operational patterns centered on EMV 3-D Secure (3D Secure 2.0). In all operations, the introduction of EMV 3-D Secure (3D Secure 2.0) is required. You can consider the most suitable operation according to the products you handle and your risk situation.
| Operation Patterns | Authentication when registering the card number | payment Individual Authentication | fraud Measures Required Outside EMV 3-D Secure |
|---|---|---|---|
| (1) Based on the merchant's risk assessment 3D Secure Operations for Authentication |
Authentication only when necessary | Authentication only when necessary |
|
| (2) When registering the card number 3D Secure Operations for Authentication |
Must | Authentication only when necessary *Required for guest purchases |
|
| (3) Each payment 3D Secure Operations for Authentication |
Recommendation | Must |
|
payment Comprehensive fraud measures before, payment, and payment after have deterrent effects equal to or greater than EMV 3-D Secure (3D Secure 2.0), and the operator decides on the implementation of certification. Establishing specialized departments, analyzing attributes and behaviors, and establishing appropriate organizational structures and countermeasures are required. Separate approval from the acquirer is required to carry out this operation.
Authentication is always performed when registering, changing, re-registering, or adding credit card numbers, and authentication is performed when necessary for payment time based on fraud risk assessment. Operations are combined with fraud measures such as unauthorized logins and attribute behavior analysis. Also, when accepting guest purchases, authentication at payment time is mandatory.
payment Each time, EMV 3-D Secure (3D Secure 2.0) authentication is performed. It is also recommended to perform authentication when registering your credit card number.
*Created based on Credit Card Security Guidelines version 6.1.
Identity authentication is a mechanism to prevent fraud by implementing the identity verification process, such as entering a PIN at a Credit card payment at a physical store, even on non-Card Present Transactions sites such as e-commerce sites. In EMV 3-D Secure (3D Secure 2.0), the authentication process is divided into three patterns by "risk-based authentication" that determines the degree of risk based on device information, behavioral information, and attribute information used in online shopping.

For transactions implemented with EMV 3-D Secure (3D Secure 2.0), if (1) authentication is successful (2) in transactions where the card company or member does not participate * fraud occurs, the card company generally bears the cost.
* The EC business operator has conducted a transaction via EMV 3-D Secure (3D Secure 2.0), but authentication is not performed depending on the status of the card company or the cardholder's settings.
|
status |
Risk Burden |
|
|---|---|---|
|
1 |
EMV 3-D Secure Authentication Successful |
Merchants are exempt from liability *1 |
|
2 |
Member's card issuer or member has not joined EMV 3-D Secure |
|
|
3 |
EMV 3-D Secure Authentication Out of Trade |
Merchants are not exempt from liability *2 |
Credit card fraud damage amounts have been increasing year by year, exceeding 50 billion yen in 2023. Since April 2025, when the introduction of EMV 3-D Secure (3D Secure 2.0) became mandatory, the amount of damage from number theft where identity authentication is valid has started to decrease.
The introduction of EMV 3-D Secure (3D Secure 2.0) is effective in suppressing fraud caused by number theft and underscores the importance of identity authentication services that detect impersonation.
| Supported Brands | Visa/Mastercard/JCB/American Express/Diners Club |
|---|---|
Connection method?What is the connection method?
This is how to connect your business site, system, and PG Multi-Payment Service. Depending on your site layout and operation method, you can choose from OpenAPI type, Link Type, Plus, and more. |
OpenAPI Type / Link Type Plus / Protocol Type *Planned Closure / Module Type *Planned Closure |
| cost | Monthly Usage Fee |
In principle, it is mandatory. It is regulated by the 'Credit Card Security Guidelines [Version 6.0]' set by the Japan Credit Association.
VISA, Mastercard, JCB, American Express *, and Diners brands are supported. For other credit card brands, normal transactions are conducted without identity verification.
* If you use merchant acquiring service, you must have a contract with JCB Co., Ltd. to be a condition of use.
If you are contract directly with your card company, you must have a contract with American Express International, Inc., Inc. as a condition of use.
If you change the amount of payment using EMV 3-D Secure (3D Secure 2.0), you will be payment without using 3D Secure.
Therefore, if you receive a chargeback from the credit card company at a later date by fraud, etc., you may have no choice but to accept it.
Introduction and operation costs are quoted individually. For more details, please contact us.
Whether or not it can be introduced depends on the development environment such as EC cart. Please check with the development company.
Even transactions that have passed EMV 3-D Secure (3D Secure 2.0) certification may still be fraud, but in such cases, the chargeback burden is generally considered an issuer.
PG Multi-Payment Service
Contact Information for EMV 3-D Secure
If you have any questions or consultations about our services, please contact us.
Please feel free to contact us from the following.