Credit Card Fraud Protection in UAE: Zero Liability, OTP, 3D Secure & What to Do If Your Card Is Compromised
A credit card does not have to leave your wallet for fraud to happen.
A fake delivery message, a copied toll-payment page or a phishing website can be enough for someone to obtain your card details. Sometimes, the first transaction is only a few dirhams. You may think it is a normal verification charge, only to discover later that a much larger transaction has gone through.
That is when the questions start. Was the payment actually authorized? Does entering an OTP mean the bank will treat it as a genuine transaction? Will the money be refunded? And what should you do if the bank says the transaction was authorized?
Credit card fraud protection in the UAE involves several layers, including transaction monitoring, OTP and 3D Secure authentication, card-blocking facilities and rules issued by the Central Bank of the UAE (CBUAE) for unauthorized transactions.
The important thing is to act quickly when something looks wrong.
What the CBUAE Rules Mean for Credit Card Fraud
The CBUAE Consumer Protection Standards contain specific requirements for unauthorized transactions.
Consumers must have at least 30 business days to report an unauthorized transaction after being informed about it. This does not mean you should wait. If an unfamiliar transaction appears on your card today, it is better to contact the bank immediately.
For unauthorized payments covered by the relevant reimbursement provisions, the financial institution must reimburse the consumer after completing its investigation or within 30 calendar days from the report or identification of the unauthorized transaction, whichever comes first.
There is an important exception. The reimbursement provision does not apply where there is evidence that the consumer acted fraudulently or with gross negligence.
This is why the circumstances surrounding the transaction matter. A customer who was tricked by a phishing message is not automatically in the same position as someone who knowingly participated in fraudulent activity.
Zero Liability Does Not Mean Every Disputed Payment Is Automatically Refunded
The term "zero liability" can sound straightforward, but credit card fraud cases are not always that simple.
A customer may see a transaction they do not recognize and assume that the bank must immediately reverse it. The bank, however, still needs to examine what happened.
It may look at the transaction details, authentication records, merchant information and the customer's account activity. The information supplied by the customer can also become important, particularly where the customer believes they were tricked into approving something different from what they intended.
So, when discussing zero liability in the UAE, it is better to think of it as protection against covered unauthorized transactions subject to the applicable rules, rather than an unconditional guarantee.
Fraud Is Not the Same as a Merchant Dispute
Not every unwanted credit card charge is fraud.
Suppose you subscribed to a streaming service and forgot to cancel it. The company charges your card for another month. You may not want the payment, but that does not automatically make it an unauthorized transaction.
Now consider a different situation. Someone obtains your card details and uses them to make an online purchase that you never made.
That is an unauthorized transaction.
| Unauthorized Card Transaction | Merchant Dispute | |
| Payment | Customer says they did not authorize it | Customer made the payment |
| Typical example | Stolen card details or unknown online purchase | Product not delivered or incorrect charge |
| Evidence | Transaction details, alerts and fraud-related information | Receipts, order records and merchant communication |
| Card | Bank may block or replace the card | Card can generally remain active |
What to Do When an Unauthorized Transaction Appears
The first priority is to stop the situation from getting worse.
If your bank allows you to freeze the card through its mobile app, do that while contacting the bank. Then use the bank's official telephone number, website, app or branch to report the transaction.
It is important to tell the bank clearly that you did not authorize the payment.
Do not rely only on a telephone conversation. Ask for the transaction to be formally disputed and keep the complaint or case reference.
The details of the transaction should also be recorded. Note the amount, merchant name, currency, date, time and transaction reference if one is available.
If the payment followed a suspicious SMS, email or website, keep that information as well.
A fake courier message or toll-payment link may disappear later, so take screenshots while the information is still available.
The OTP Problem
One of the most confusing parts of card fraud is the OTP.
A customer may say, "I never authorized this payment," while the bank's records show that an OTP was successfully entered.
That does not necessarily explain the entire situation.
Consider a common phishing scenario.
You receive a message saying that a parcel is waiting for delivery. The message asks you to pay AED 5. You open the link, enter your card details and receive an OTP.
You enter the OTP because you believe you are approving the AED 5 payment.
Later, you discover that a much larger transaction was processed.
The bank can examine the authentication record, but it can also look at the transaction itself and the information supplied by the customer.
What amount was displayed? Which merchant processed the payment? When did the OTP arrive? What amount was eventually charged? What did the original message say?
These details can form part of the investigation.
So, an OTP in the transaction record should not simply be treated as the whole story.
At the same time, customers should never assume that saying "I was tricked" automatically guarantees reimbursement. The CBUAE standards specifically recognise situations involving consumer fraud or gross negligence.
How Does 3D Secure Protect Credit Card Payments?
3D Secure adds another authentication step to certain online card payments.
Depending on the bank and the transaction, the customer may be asked to enter an OTP, approve the payment through a banking application or use another authentication method.
The purpose is to make it harder for someone with only the card number and expiry date to complete an online purchase.
But 3D Secure does not make a customer completely immune to fraud.
A fraudster can still use social engineering to persuade someone to approve a transaction. This is why an unexpected OTP should always be treated carefully.
If an OTP arrives when you are not making a payment, do not share it and do not approve the transaction.
If you are making a payment, check the merchant and amount before approving it.
What Happens After You Report the Fraud?
Once the bank receives the complaint, it investigates the transaction.
The investigation may involve transaction records, authentication information, merchant details and other account activity.
This is where the evidence collected by the customer can become useful.
For example, several overseas transactions appearing within a few minutes on a card that is normally used in the UAE may provide useful context. A suspicious message received immediately before the transaction may also help explain how the card details were obtained.
The customer should keep a simple record of what happened:
The customer should keep a simple record of what happened:
Message received → link opened → card details entered → OTP received → transaction appeared → card blocked → bank contacted → complaint registered.
The bank has its own records, but having the customer's timeline makes it easier to explain the sequence of events.
What If the Bank Says the Transaction Was Authorized?
A bank may conclude that a transaction was authorized after reviewing its records.
If that happens, ask for the decision and explanation in writing.
You can also ask what information led the bank to reach that conclusion, particularly if authentication such as an OTP or 3D Secure was involved.
Keep the original complaint, transaction details, screenshots, messages and correspondence with the bank.
The CBUAE framework includes complaint-handling requirements for financial institutions. If the matter remains unresolved, there is also a further complaint-resolution route through Sanadak, subject to its eligibility requirements.
When Can You Take a Complaint to Sanadak?
Sanadak is the UAE's financial and insurance dispute-resolution body.
The bank should normally be approached first.
According to Sanadak's current guidance, a consumer can generally submit an eligible complaint after first complaining to the financial institution and waiting 15 calendar days for a response, provided the other eligibility requirements are met.
This is why keeping the bank's complaint reference and written response is important.
If the case is escalated, the customer may need to provide the original complaint, the bank's response and supporting documents such as transaction records and correspondence.
Should You Report Credit Card Fraud to the Police?
A bank complaint deals with the disputed payment. A police or cybercrime report deals with the suspected criminal activity.
If the transaction resulted from phishing, impersonation, a fake website or another scam, reporting the incident to the relevant authority may be appropriate.
In Dubai, Dubai Police provides 901 for non-emergency enquiries and also has cybercrime reporting services. Residents of other emirates should use the appropriate police or government reporting channel.
Keep the original fraudulent message or website information where possible. It may help explain how the scam took place.
How to Reduce the Risk of Credit Card Fraud
Most people do not expect to become victims of card fraud. That makes simple habits particularly useful.
Do not enter card details through an unexpected payment link. If a message says that a parcel, toll payment or account needs immediate attention, open the organisation's official website or app yourself instead of using the link in the message.
Be particularly careful with messages that create urgency.
A familiar company logo does not prove that a message is genuine. Fraudsters can copy logos, colours and website designs surprisingly well.
The domain name is often more useful.
Never share an OTP with someone who calls or messages you claiming to be from your bank.
It is also worth turning on transaction alerts if your bank provides them. A notification can help you notice a suspicious payment before several more transactions appear.
If your bank provides virtual cards or other controls for online purchases, these can also be useful for limiting exposure of your main card details.
And check your statements regularly.
An unfamiliar small payment may be the first sign that your card details have been compromised.
For more information about card security, you can also read our guide on what a CVV number is.
What Should You Do in the First Hour After Your Card Is Compromised?
If you believe your card has been compromised, the first hour is mainly about containment.
- Freeze or block the card.
- Contact your bank through an official channel.
- Report any unauthorized transaction.
- Ask for a complaint or dispute reference.
Save the messages, screenshots and transaction information.
If you believe your online-banking credentials may also have been exposed, follow your bank's instructions to secure the account.
If the incident involves a scam or suspected criminal activity, report it to the relevant authority.
Most importantly, keep a record of everything you do.
Takeaway
Credit card fraud in the UAE is no longer just about losing a physical card.
A five-dirham delivery payment, a fake toll message or a convincing verification page can be enough to expose card details.
The safest response is to act quickly.
Block the card, contact the bank through an official channel, report the transaction formally and keep the evidence. Do not assume that an OTP automatically proves that you knowingly authorized a payment, but do understand that the circumstances of the transaction and your own actions can affect the outcome of a fraud investigation.
Credit card security is ultimately about more than one feature such as OTP or 3D Secure. It is the combination of secure authentication, careful online behaviour, transaction alerts and quick action when something looks wrong.
And when money does disappear, a clear record of what happened can be just as important as the first phone call to the bank.
Disclaimer
This article is for general informational purposes and should not be treated as legal or financial advice. CBUAE regulations, bank procedures, security features and dispute-resolution requirements may change. Always check the latest information with your bank and the relevant UAE authorities.
FAQs
Q. What should I do if someone uses my credit card without permission?
A.Contact your bank immediately through an official channel, freeze or block the card if possible and report the transaction as unauthorized. Keep the complaint reference and all supporting evidence.
Q. Does an OTP mean I cannot report credit card fraud?
A.No. An OTP is part of the authentication process, but the circumstances surrounding the transaction can also be considered. The customer should explain exactly what happened and provide any supporting evidence.
Q. How long do I have to report an unauthorized credit card transaction in the UAE?
A.The CBUAE Consumer Protection Standards provide consumers with at least 30 business days to report an unauthorized transaction after being informed about it. It is still advisable to report it as soon as it is discovered.
Q. Will the bank refund money stolen from my credit card?
A.Covered unauthorized transactions are subject to the CBUAE's reimbursement provisions, but exceptions apply, including situations where consumer fraud or gross negligence is established.
Q. What is 3D Secure?
A.3D Secure is an additional authentication layer for certain online card payments. It can involve an OTP, banking-app approval, biometric authentication or another security method, depending on the bank and transaction.
Q. Can I report credit card fraud to the police in the UAE?
A.Yes. If you believe the transaction resulted from a scam, phishing attack, impersonation or another criminal activity, you can report it through the appropriate police or cybercrime channel.
Q. What if the bank rejects my fraud complaint?
A.Ask for the bank's decision and explanation in writing. Keep your complaint reference and evidence. If the matter remains unresolved, you may be able to escalate it to Sanadak if you meet its eligibility requirements.
Q. Is a merchant dispute the same as credit card fraud?
A.No. A merchant dispute generally concerns a transaction you made but have a problem with, such as a missing delivery or incorrect charge. Credit card fraud involves a transaction you say you did not authorize.