
How 3D Secure Cuts Card Fraud in Rentals
August 11, 2026 · 11 min read
How 3D Secure Cuts Card Fraud in Rentals
If you run self-service rentals, 3D Secure can cut card fraud before pickup. It adds a bank check at payment, stops many stolen-card bookings, and can move fraud chargeback costs to the card issuer after a passed 3DS check.
Here’s the short version:
- Card-not-present fraud is much higher than in-person card fraud
- Rentals face more risk because the scam can lead to a lost trailer, vehicle, scooter, or tool
- 3DS2 checks the payer with the bank before access is given
- Low-risk bookings can pass in the background, while riskier ones get a code, app prompt, or biometric check
- Visa data in the article shows 11 basis points of fraud for authenticated payments vs. 20 for non-authenticated payments - about 45% less
- A passed 3DS check can often shift fraud chargeback liability away from the rental business
- 3DS works best when you use it on high-risk bookings, not every order
- It should sit inside a larger flow with ID checks, booking review, and access control
A few booking types need more attention:
- High-value rentals
- First-time customers
- Last-minute reservations
- Late-night or weekend pickups
- High-risk pickup locations
One point matters most: payment approval alone should not trigger pickup access. I’d treat 3DS as one payment check, then pair it with ID verification and only release keys, lock codes, or digital access after both steps pass.
| Checkpoint | What it does | Why it matters in rentals |
|---|---|---|
| 3DS2 frictionless | Bank reviews the payment in the background | Keeps low-risk bookings moving |
| 3DS2 challenge | Customer confirms identity with a code, app, or biometric step | Stops many stolen-card attempts |
| ID verification | Confirms the renter matches the booking | Helps stop pickup by the wrong person |
| Access control | Releases keys or codes only after checks pass | Helps protect the asset before handoff |
So if I had to sum it up in one line: 3D Secure helps cut fraud at checkout, but the best rental setup links payment checks, ID checks, and access release in one flow.
3D Secure explained
sbb-itb-eb44693
How 3D Secure works and why it reduces stolen card use
3D Secure adds one more security check between card entry and payment approval. The goal is simple: confirm that the person using the card is the actual cardholder. To do that, the rental platform sends booking details to the issuer, which scores the transaction in milliseconds.[13][16] Based on that score, the payment either goes through quietly or moves to a challenge.
Frictionless checks for low-risk bookings
In a frictionless flow, the issuer decides the booking looks legitimate and approves it without showing the customer any extra screen.[3][4][8][10] The payment goes through with no added step.
That matters because less friction can still mean less fraud. Visa data shows authenticated payments carry 11 basis points of fraud, compared with 20 basis points for non-authenticated payments, or about 45% less.[2]
For contactless rentals, Lockii and Stripe can send pickup and booking details into 3DS2 before digital access is granted. That helps more low-risk bookings stay frictionless.[4][6]
Challenge flows for higher-risk rentals
If a booking looks riskier, the issuer triggers a challenge. The customer then has to verify their identity before the payment can move forward.[4][7][11] In most cases, that means a one-time code, a banking app prompt, or biometric approval.[14][15]
Some bookings are more likely to trigger that extra step:
That extra check is where stolen cards often fall apart. A fraudster may have the card number, but they usually do not have the cardholder's phone or banking app. So the payment gets stopped before pickup. This is a critical step when starting a contactless trailer rental business to prevent asset loss.
Liability shift and what it means for rental operators
One of the biggest upsides of 3DS2 is liability shift. When authentication succeeds, fraud chargeback liability usually moves from the rental operator to the card issuer.[4][5][10] If the cardholder later claims the charge was unauthorized, the issuer takes the loss instead of the business.
Without 3DS, the operator eats the damage: the lost asset, the chargeback, and the fee. Here's how the three paths stack up:
| Flow | Fraud exposure | Liability on fraud chargebacks | Typical rental use case |
|---|---|---|---|
| No 3DS | Highest - stolen cards can pass with just CVV and AVS | Merchant is liable | Legacy or manual checkouts |
| 3DS2 frictionless | Lower - risk is scored silently using device and transaction data | Liability shifts to the card issuer | Routine |
| 3DS2 challenge | Lowest - risky transactions are stepped up for verification | Liability shifts to the card issuer on completed challenge | High-risk |
In practice, the best setup is selective routing, not blanket authentication. Low-risk bookings can stay frictionless, while higher-risk ones get stepped up when needed.[4][5][9][10]
How 3D Secure reduces fraud without hurting conversion

Once 3DS is in place, the next question is simple: does it slow down checkout? For rental operators, that’s the big worry. Checkout friction can kill bookings fast, making it essential to automate rental business operations efficiently. And that fear didn’t come out of nowhere. Legacy 3DS did create friction. 3DS2 usually doesn’t.
Why legacy 3DS hurt checkout and 3DS2 performs better
Legacy 3DS1 pushed customers out of checkout and onto a bank page with a separate login. In many cases, that meant entering a static password the cardholder hadn’t used in ages. On mobile, it got even messier. Pop-ups failed, pages loaded badly, and people dropped off before finishing the payment. Studies found 10–25% abandonment on transactions that triggered a 3DS1 challenge, with overall conversion dropping 3–15% when it was used across most transactions.[19][20]
3DS2 was built to fix that mess. It works inside your checkout page or mobile app instead of bouncing users somewhere else. Most approvals happen in the background, so the customer doesn’t have to do anything at all. And when a challenge is needed, it usually relies on a one-time code or a banking app approval, which tends to be much faster on a phone.
| Aspect | 3DS1 (Legacy) | 3DS2 (Modern) |
|---|---|---|
| Checkout friction | Bank redirects and static password prompts that broke checkout flow. | Frictionless for 80–90% of transactions, with targeted challenges based on risk.[18][19][21] |
| Mobile experience | External pages and pop-ups often break or render poorly on smartphones. | Built for mobile and in-app flows, with authentication inside the rental app or responsive page.[14][22] |
| Conversion impact | 3–15% overall conversion drops when used across most transactions, plus 10–25% abandonment on challenged transactions.[19][20] | With good implementation, the effect can be neutral or slightly positive; some merchants report about a 1.20% conversion uplift while reducing fraud by about 7–8%.[12][20] |
That last point matters. 3DS2 is not just “less bad” than 3DS1. In some setups, it can help performance while cutting fraud. The catch is pretty obvious: don’t throw it at every payment without thinking.
The best results tend to come when 3DS is used where risk is highest.
Using risk-based rules instead of applying 3DS to every payment
In the U.S., 3D Secure is not a legal requirement for card-not-present transactions. It’s a fraud control tool.[23][24][25] So you’re not stuck applying it to every booking. You choose when it makes sense.
For rentals, that usually means sending 3DS to the bookings that carry more risk, such as:
- High-value reservations
- First-time bookings
- Last-minute bookings before access is released , a common scenario in 24/7 contactless rentals
At the same time, repeat customers with a clean payment history can move through checkout with little to no added friction.[17][21]
That approach keeps 3DS aimed at the bookings most likely to fail or turn out to be fraud. In other words, it works best as a targeted control, not a standard step for everyone.
How to add 3D Secure into a rental fraud workflow
Once you've decided when 3DS should challenge a booking, the next step is to slot that decision into your rental flow.
Here’s the simple way to think about it: 3DS is a payment checkpoint, not a full fraud system. It helps confirm the cardholder at the time of payment. But it doesn't handle everything. Identity checks, access release, and audit logs still need to happen around it.
A solid flow looks like this: score the booking, authenticate the cardholder, verify the renter’s identity, and release access only after both checks pass.
Where 3D Secure fits from booking to pickup
3DS belongs in the payment step, after you collect booking details and before you release access. Before that point, you’re checking for risk signals. After that point, you’re confirming identity and deciding whether pickup should go ahead.
| Stage | Goal | Security Controls |
|---|---|---|
| Online Booking | Spot unusual patterns early | Booking data review, velocity checks, device fingerprinting |
| Payment & 3DS | Confirm cardholder and reduce stolen-card use | 3DS2 via Stripe, AVS, CVV, Stripe Radar rules |
| Identity Verification | Confirm the person matches the booking | Government ID scan, facial match, document verification |
| Access Release | Prevent unauthorized pickup | Time-bound lock codes, digital locks, schedule-based rules |
The main rule is simple: don’t release pickup access until both payment authentication and identity verification are done. A paid booking is not the same thing as proof that the right person is there to collect the asset.
This setup works best when payment checks, identity checks, and access control all sit inside one connected flow.
Using Lockii with Stripe to strengthen payment checks
For unattended trailer and equipment rentals, this layered setup matters even more. There’s no staff member at pickup to spot red flags or step in if something looks off.
Lockii is built for contactless self-hire, and its Stripe integration makes it easier to connect payment checks straight into the pickup flow.
When a customer books through Lockii, Stripe checks transaction risk and either processes the payment frictionlessly or triggers a 3DS challenge. After payment clears, Lockii moves to identity verification by capturing a government ID and running a facial match before any lock code is issued. The digital lock releases access only after both checks pass. Lockii also logs the payment, ID check, and access release in one audit trail.
For operators with multiple locations, this can make a big difference. Lockii supports different risk settings by location, so a high-theft area can require stricter 3DS and ID checks, while lower-risk sites can stay frictionless.
Rule examples for rental risk routing
You don’t need a maze of rules here. In most cases, simple routing rules are enough to send higher-risk bookings into a 3DS challenge and keep lower-risk bookings moving.
| Condition | 3DS Action | Additional Step |
|---|---|---|
| Repeat customer, low-value booking, familiar device | Frictionless | Standard audit trail |
| New customer, high-value booking | Challenge required | Full ID + facial match |
| High-value asset | Challenge required | Mandatory ID verification |
| Weekend or late-night booking, high-value asset | Challenge or manual review | ID check + manual review |
| High-risk pickup location | Challenge required | ID check + manual review |
| Mismatched identity or booking data | Manual review | Hold access until resolved |
Keep the routing logic simple at first. Start with new customers and high-value bookings, then adjust thresholds based on Stripe disputes and your booking logs. The goal is straightforward: use 3DS on the bookings most likely to involve stolen-card fraud, and keep low-risk repeat customers on the fastest path.
Conclusion: 3D Secure as a payment control for self-service rentals
In self-service rentals, 3D Secure puts a payment checkpoint in place before access is released.
The goal isn't just lower fraud. It's safer approval with less friction at checkout. 3DS2 checks the payer with the cardholder's bank, which makes stolen-card bookings much harder to push through. Visa reports about a 45% drop in fraud for authenticated transactions compared with non-authenticated e-commerce payments[2]. And when a transaction is authenticated, fraud-chargeback liability can shift from the merchant to the issuer[26].
That said, 3DS checks the payment, not the person showing up for pickup. That's where the strongest setups go a step further and pair 3DS with identity verification and booking audit logs. Operators using automated identity verification have seen fraud rates fall to 0.03%, compared with 0.5% for manual checks[1].
In day-to-day use, this means connecting payment checks to the same flow that controls pickup. With Lockii integrated with Stripe, payment authentication can move straight into access control, so lock codes are released only after payment and identity checks pass.
Use 3DS as a targeted payment control, not a default step for every checkout. When used selectively, it helps protect high-risk bookings without slowing down routine ones.