SecurityUnited States

Mastercard SAFE Data Visibility and Scam Merchant Monitoring Impact on Merchants

The article details Mastercard's SAFE (now Fraud and Loss Database), a system where issuers file records for fraudulent claims that merchants typically cannot access directly.

Mastercard SAFE Data Visibility and Scam Merchant Monitoring Impact on Merchants Payment RadarOriginal source: Chargebacks911 · linked publisher media; native reuse rights require confirmation

The article details Mastercard's SAFE (now Fraud and Loss Database), a system where issuers file records for fraudulent claims that merchants typically cannot access directly. This data influences acquirer risk assessments, potentially leading to rolling reserves or termination, and is now central to the Scam Merchant Monitoring Program enforceable since July 2026, which mandates 72-hour investigations for merchants flagged by two or more issuers. While SAFE data does not directly feed into the Mastercard EFM program, it impacts issuer authorization decisions and approval rates. Merchants can sometimes access this data through their payment platforms (e.g., Stripe's Early Fraud Warnings) or by requesting it from their acquirer, though reports are delayed due to batch processing.

What changed

Mastercard's Scam Merchant Monitoring Program became enforceable in July 2026, mandating that acquirers investigate merchants within 72 hours if two or more issuers report their transactions as scams via the Fraud and Loss Database (FLD). Additionally, the article clarifies that while SAFE data is not used for the EFM program, it directly influences acquirer risk assessments and issuer authorization decisions, often without merchant visibility.

Why a business should care

Merchants are effectively blind to a significant portion of their fraud data, which is used by acquirers and issuers to make critical decisions about their business viability, including funding holds, repricing, and termination. The new Scam Merchant Monitoring Program introduces a rapid-response mechanism that can disrupt operations without giving merchants time to correct course.

Who it affects

All merchants processing Mastercard transactions, particularly those with high fraud exposure or new merchants (under six months) who face lower trigger thresholds in the Scam Merchant Monitoring Program.

What to consider doing

Merchants should request fraud notification records from their acquirer, specifically asking for fraud type codes delivered on a recurring schedule. They should also check if their payment platform (e.g., Stripe, Adyen) already provides access to this data under different names like Early Fraud Warnings. Merchants should avoid blanket-refunding flagged transactions, as this does not remove the fraud record and harms revenue. Instead, they should use the data for pattern detection to optimize fraud prevention.

Important consequence

The enforcement of the Scam Merchant Monitoring Program in July 2026 creates a new, rapid-response risk trigger for merchants based on invisible fraud data, potentially leading to immediate investigations and operational disruption without prior warning or direct data access.

Uncertainty and risks

Merchants may face immediate investigations and potential termination due to the Scam Merchant Monitoring Program based on data they cannot see. The lack of direct access to SAFE data makes it difficult to proactively manage fraud profiles or dispute inaccuracies. Refunding transactions to mitigate risk is ineffective and financially damaging as it does not remove the fraud record.

Was this useful?

Comments

← Back to Payment Radar