Blog post

Your Card Terminal Is a Security Risk. Most Merchants Don't Know It.

Blog hero image
May 25, 2026
TappiPay

Your Card Terminal Is a Security Risk. Most Merchants Don't Know It.

When card fraud makes the news, the story is almost always about the consumer. Their card details, their bank reversal, their inconvenience.

That framing leaves out half the picture.

Merchants absorb significant fraud risk too. It's just quieter. Less visible. And most of the people carrying it don't fully understand what they're holding.

The Chargeback Loop Merchants Can't Easily Win

When a customer disputes a card transaction, their bank reverses the payment. The funds leave the merchant's account. The goods or services have already been delivered.

Now the merchant needs to prove the transaction was legitimate. That means producing documentation in the form of receipts, delivery records, signed confirmation in the way the  bank requires. For most small businesses, that documentation is incomplete or doesn't exist in the required form.

Merchants frequently lose these disputes even when the transaction was entirely genuine. The reversal sticks. And a dispute processing fee, ranging from R200 to over R900 per incident, gets added on top of the lost revenue.

South Africa is not insulated from the trend. Chargebacks in the Middle East and Africa region are projected to grow by 59% in the coming years. Nearly half of all chargebacks involve some form of fraud, not from stolen cards, but from customers disputing genuine purchases anyway.

The Terminal Vulnerability Nobody Discusses at Onboarding

Card terminals process payment data. In many cases, they log it. This creates a vulnerability that most merchants haven't considered.

South Africa saw a 23% year-on-year increase in card-skimming fraud in a recent reporting period, rising from R366 million to R453 million recorded by the Hawks. Criminals attach hardware to POS devices, sometimes internally, that captures card details silently, transaction by transaction.

A customer swipes. A payment processes normally. Nothing looks unusual. Meanwhile, card data is being harvested for use elsewhere.

For restaurants and service businesses, there's a related risk: perpetrators supply handheld skimming devices to staff, who use them during legitimate transactions. It's extremely difficult to detect until the fraud has already happened and when it does, the question of merchant liability depends on factors that most business owners don't know until a dispute is already in progress.

How Liability Gets Assigned

The card networks have detailed liability rules that govern who bears the cost when something goes wrong.

The short version: the side with less advanced technology typically absorbs the liability. If your terminal is older, or if a chip card gets processed via magnetic stripe, the liability can shift to you. Most merchants don't know these rules exist until they're in the middle of a chargeback process.

What Changes With QR Payments

QR payments restructure where the risk sits.

When a customer pays through TappiPay, their card credentials never enter the merchant's system. Authentication happens on the customer's own device, using their own biometrics or PIN. No card data changes hands at the merchant level. And due to the payment being confirmed by the customer's own phone, the dispute pathway that exists in card payments doesn't apply in the same way.

This isn't a policy decision or a contractual protection. It's a result of how the architecture works. Less complexity in the chain means less surface area for fraud exposure on the merchant side.

The Conversation That Should Have Happened Earlier

Card fraud is framed as a consumer issue because consumers are the visible victims.

But merchants absorb costs quietly through chargebacks, dispute fees, terminal liability, and fraud they didn't cause. Understanding that exposure is the first step to managing it and choosing infrastructure that reduces it is increasingly a straightforward business decision.

T

TappiPay Assistant

Online · Typically replies instantly