Why Are More Customer Payments Being Declined on Your Website in 2026?

Your website traffic is increasing. More customers are attempting to pay. Your payment dashboard shows transactions going up.

But approved revenue is going down.

For many business owners, the explanation ends with one frustrating word:

Declined.

The problem is that “issuer decline” is not one diagnosis. It is a broad category that can include insufficient credit, fraud controls, account restrictions, card limits, outdated credentials, incorrect transaction data, network decisions and merchant-specific risk signals.

Unless a business has a sophisticated payments or analytics team, separating those causes can be extremely difficult.

Capital One’s migration of debit cards to the Discover network has created a visible source of payment disruption in 2026. But it is only one part of a much larger story involving consumer-credit pressure, merchant category codes, evolving fraud models, stored credentials and new card-network monitoring rules.

Quick answer: Issuer declines may be increasing for certain merchants because financially constrained customers have less available credit, issuers are receiving more merchant-level fraud intelligence, MCC and transaction data can influence authorization decisions, and card migrations are creating credential failures. Merchants should measure the change by issuer, BIN, network, response code and transaction type instead of relying on a single dashboard decline rate.

What Is an Issuer Decline?

An issuer decline occurs when the bank or financial institution that issued the customer’s card rejects an authorization request.

The payment begins at the merchant’s checkout. It then travels through the payment gateway, processor, acquiring bank and card network before reaching the issuing bank.

The issuer may consider:

  • Available funds or credit

  • Account status

  • Cardholder spending history

  • Transaction amount

  • Merchant category code

  • Merchant location

  • Fraud and device signals

  • Card-present or card-not-present status

  • Authentication data

  • Transaction velocity

  • Whether the payment is an initial or recurring charge

An issuer decline is different from a merchant fraud filter blocking the purchase before authorization. It is also different from a gateway error, unsupported card type, processor restriction, routing failure or system timeout.

That distinction matters because a payment dashboard may group several unrelated failures under labels such as “bank decline,” “failed payment” or “do not honor.”

Align Ecommerce’s Payment Processing Glossary explains issuers, acquirers, gateways, authorizations, MCCs and other payment terms merchants encounter while investigating declines.

Are Card Issuer Declines Actually Rising in 2026?

There is no public national database showing real-time authorization rates for every U.S. issuer, merchant category and transaction type.

That makes it difficult to prove that every bank is broadly declining more purchases.

A merchant can still experience a real and financially significant increase even if the overall card market appears stable. The deterioration may be concentrated within:

  • One issuer or group of BINs

  • Debit rather than credit cards

  • A particular MCC

  • Recurring payments rather than first-time purchases

  • Stored cards rather than network tokens

  • Card-not-present transactions

  • Nonprime customer segments

  • Cross-border cardholders

  • Transactions missing AVS, CVV or authentication data

  • Automated retries following an initial decline

The more useful question is not, “Are all banks declining more?”

It is:

Which issuers are declining more of this merchant’s transactions, and what changed in the customers, credentials, transaction data or risk signals being submitted?

That is the question most basic payment dashboards cannot answer.

Consumer Credit Stress Is Real—but It Does Not Explain Everything

The strongest consumer-credit evidence shows growing financial pressure among vulnerable borrowers rather than a universal collapse across every cardholder segment.

The Federal Reserve’s May 2026 household report found that average credit-card balances among respondents who said they were “finding it difficult to get by” increased from $6,735 in 2023 to $9,265 in 2025—a 37% increase.

Consumers who were “finding it difficult” or “just getting by” accounted for 65% of the observed balance growth. Average balances among respondents “living comfortably” increased by only $59. Federal Reserve household credit report

The New York Fed reported that credit-card balances reached $1.263 trillion during Q2 2026. New credit-card delinquencies remained elevated, although credit-card delinquency transitions were largely steady during the quarter. New York Fed Q2 2026 household debt report

For merchants serving consumers under financial pressure, this can plausibly produce more declines involving:

  • Insufficient available credit

  • Credit limits being reached

  • Daily or transaction limits

  • Pending authorization holds

  • Missed payments or account restrictions

  • High utilization combined with unusual purchase behavior

However, the newest Federal Reserve bank data provides important counterevidence to the idea that all cardholders suddenly became riskier.

During Q2 2026, the commercial-bank credit-card delinquency rate declined to 2.85%, compared with 2.91% in Q1 and 3.04% one year earlier. The annualized credit-card charge-off rate remained at 3.82% and was lower than the 4.19% reported in Q2 2025. Federal Reserve delinquency data and Federal Reserve charge-off data

Banks nevertheless remain selective about extending credit.

In the Federal Reserve’s July lending survey, a modest net share of banks reported tightening standards for new credit-card loans during Q2. Banks also characterized subprime credit-card standards as being near the tighter end of their historical ranges. Federal Reserve July 2026 lending survey

This survey concerns the approval and terms of credit accounts—not individual purchase authorizations. It cannot prove that banks are issuing more codes 05, 51, 61 or 65 at checkout.

The evidence supports a narrower conclusion:

Merchants serving financially constrained or nonprime customers may experience more insufficient-credit declines even though aggregate bank-card delinquency and loss rates are not broadly worsening.

Fraud Models Are Becoming More Merchant-Aware

A legitimate customer can have available credit and still be declined.

One reason is that issuers are gaining access to more information about the merchant receiving the payment.

In May 2026, Mastercard announced Merchant Scam & Risk Indicator, or MSRI. The service provides merchant-level risk signals to issuers during authorization.

In a pilot with a leading issuer, Mastercard said MSRI detected approximately 80% of the issuer’s identified risky merchants. Many were flagged as early as 90 days before the issuer’s initial escalation. Mastercard Merchant Trust Services

This creates a direct mechanism through which a merchant’s identity and risk profile can influence the issuer’s decision.

Two transactions from the same cardholder may receive different results because the issuers see different combinations of:

  • Merchant-risk indicators

  • Historical fraud or dispute patterns

  • Customer-recognition signals

  • Device and behavioral data

  • MCC and merchant location

  • Purchase amount and velocity

  • Authentication results

  • Card-testing activity

  • Cross-border risk

  • Merchant identity consistency

This does not mean the issuer has officially classified every declined merchant as fraudulent. It means authorization models can consider more than the cardholder’s account balance.

The broader fraud environment gives issuers a reason to use these signals.

The 2026 Merchant Risk Council survey found that 62% of responding merchants reported increased first-party-misuse disputes, while 57% reported increased refund or policy abuse. The report estimated that payment fraud represented 3.2% of annual ecommerce revenue globally. Its survey included 1,278 payment and fraud professionals across 37 countries. 2026 MRC Global Payments and Fraud Report

Mastercard also reported identifying more than five million card-testing transactions across 192 issuing countries. Card-testing intelligence can be used to decline suspicious tests, replace compromised cards or increase monitoring. Mastercard card-testing research

The result is a more complicated authorization environment in which legitimate merchants can be affected by risk signals that are invisible inside a basic gateway report.

Can a Merchant Category Code Cause a Decline?

A merchant category code, or MCC, identifies the merchant’s primary business activity.

It is transmitted with the authorization request and can influence fraud models, cardholder controls, rewards, transaction eligibility and underwriting.

But “banks block high-risk MCCs” is too simplistic.

An MCC can contribute to a decline in several ways.

The MCC can change how the transaction looks

A large cryptocurrency, gambling, supplement or gift-card transaction may look materially different from an ordinary grocery purchase.

The MCC may not decide the authorization by itself, but it provides important context when combined with transaction amount, customer history, merchant location and fraud signals.

Some cards have explicit category restrictions

Corporate, fleet, purchasing, virtual, prepaid and controlled-spend cards may restrict where the credential can be used.

A legitimate transaction can therefore be declined because the cardholder’s employer, benefit program or card product does not permit purchases within the merchant’s category.

An inaccurate MCC can create inconsistencies

Problems can also arise when the MCC does not accurately describe what the merchant sells.

The transaction data may appear inconsistent with the merchant’s products, website, average ticket, customer geography or billing behavior. Those inconsistencies can attract attention from the issuer, network, processor or acquiring bank.

Mastercard’s current rules instruct acquirers to monitor warning signals including products unrelated to the merchant’s registered MCC, low authorization rates, weak CVC match rates, missing 3D Secure and issuer-country activity inconsistent with the merchant’s target market. Mastercard Security Rules and Procedures

MCC 5968 is a particularly important 2026 example.

It applies to certain non-face-to-face negative-option physical-product businesses. It should not automatically be assigned to every SaaS company, coaching program, digital membership or subscription business.

Align’s MCC 5968 reclassification guide explains which subscription models may be affected and why accurate classification matters.

Why Capital One Debit Transactions May Be Declining

Capital One is migrating its debit-card portfolio from Mastercard to the Discover network.

That transition requires new debit cards with new 16-digit card numbers, security codes and expiration dates. Capital One instructs customers to activate the replacement card and update recurring payments and subscriptions. It also warns that stored payments using the older card may eventually stop working. Capital One debit-card transition guide

Stripe has separately warned merchants that authorization rates may be lower for Capital One debit cards when customers have not activated their reissued cards. Stripe says an existing card may continue working for approximately 130 days after the replacement is issued. Stripe’s Capital One and Discover notice

For merchants, the transition can create:

  • Unactivated replacement cards

  • Stored credentials tied to the old card

  • New expiration dates and CVVs

  • Recurring-payment interruptions

  • Network-routing differences

  • Digital-wallet or account-updater gaps

  • Confusion when comparing issuer performance with network performance

Discover credit accounts are also moving onto Capital One’s servicing platform.

Capital One says primary Discover cardholders generally retain their existing cards and account numbers. Authorized users and joint account holders, however, receive cards with their own unique 16-digit numbers. Capital One Discover migration FAQ

Those credential changes can disrupt card-on-file billing.

This is a documented reason some Capital One and Discover-related payments may be failing in 2026. It is not proof that Capital One is broadly rejecting more credit-card purchases or that the Discover network has a universal acceptance problem.

Merchants should separate:

  • Capital One debit from Capital One credit

  • Mastercard-routed transactions from Discover-routed transactions

  • Activated cards from outdated stored credentials

  • First-time payments from recurring charges

  • Issuer declines from routing and acceptance errors

Without that separation, several unrelated problems can appear to be one Capital One decline spike.

What Do Decline Codes 05, 51, 61, 65 and 83 Mean?

The response code is often the first clue that a merchant’s overall decline rate contains several different problems.

Code 05: Do Not Honor

Code 05 is a generic issuer decline.

It tells the merchant that the issuer rejected the transaction but does not explain the exact reason.

Stripe notes that code 05 can reflect insufficient funds, suspicious activity, daily limits, incorrect information and other issuer restrictions. Stripe’s code 05 explanation

A rise in code 05 should be analyzed by issuer, BIN, MCC and transaction type. It should not automatically be classified as fraud or insufficient credit.

Code 51: Insufficient Funds

Code 51 generally indicates that the account lacks enough available funds or credit to complete the purchase.

This is the response most directly associated with consumer-credit pressure, although gateways and processors may translate raw network responses differently.

Code 61: Exceeds Approval Amount Limit

Code 61 indicates that the transaction exceeds an issuer-defined amount limit.

It may appear when the customer exceeds a daily limit, transaction limit or other account control.

Code 65: Exceeds Withdrawal Frequency Limit

Code 65 generally indicates that the account has exceeded an activity or frequency limit.

Repeated submissions can contribute to this problem, especially when an automated retry system continues attempting the same card within a short period.

Visa’s current response-code rules identify code 61 as “Exceeds approval amount limit” and code 65 as “Exceeds withdrawal frequency limit.” Visa Core Rules

Code 83: Visa Fraud/Security

Effective July 25, 2026, Visa introduced code 83 for transactions declined through Visa’s stand-in processing because of high-risk or fraudulent conditions.

This distinction is important.

Code 83 may represent a decision made through Visa’s stand-in processing rather than directly by the customer’s issuing bank. Visa’s 2026 rule changes

A payment report that labels every code 83 as an issuer decline may overstate how often the cardholder’s bank made the decision.

Stored Credentials Create a Separate Decline Problem

Subscription merchants should separate first-time customer-initiated transactions from later merchant-initiated recurring charges.

A recurring transaction can fail even when the customer’s physical card still works.

Common causes include:

  • Reissued or expired cards

  • Outdated PANs or expiration dates

  • Incorrect recurring indicators

  • Missing linkage to the customer’s original authorization

  • Cardholder cancellation instructions

  • Issuer restrictions on merchant-initiated transactions

  • Immediate retries following a decline

  • Account-updater exclusions

  • Differences between network tokens and stored card numbers

Visa Account Updater also allows an issuer to place a merchant-specific Stop Advice.

A Stop Advice can prevent one merchant from receiving an updated card number after a reissue—such as following reported fraud—while allowing other merchants to continue receiving updates. Visa Account Updater FAQ

That means a customer’s card can continue working elsewhere while recurring charges fail at one particular merchant.

The customer may insist that the card is valid. The merchant may assume the bank is randomly declining the payment. Both can be correct from their limited view of the transaction.

Better Payment Data Can Improve Approval Rates

Issuers can make better decisions when authorization requests contain complete and consistent information.

Effective July 25, 2026, Visa began requiring accurate information rather than placeholder or dummy values for Account Name Inquiry, Address Verification Service and Account Verification requests.

Visa also requires merchant information—including the merchant location and MCC—to remain consistent across verification requests. Visa verification-product requirements

Incomplete or inconsistent data can make a legitimate purchase more difficult to distinguish from fraud.

A Visa and Adyen case study involving an enterprise travel merchant demonstrates how meaningful the difference can be. Sharing richer transaction and authentication data with issuers produced a 190-basis-point increase in U.S. domestic authorization rates. Cross-border, stored-PAN and network-token transactions also improved while fraud remained stable. Visa and Adyen authorization case study

Better data does not guarantee approval. It gives the issuer more context with which to evaluate the payment.

How Issuer Declines Can Trigger Mastercard SMMP Attention

Mastercard’s Scam Merchant Monitoring Program makes authorization performance more than a conversion metric.

It can also become a merchant-risk signal.

Under Mastercard’s current rules, an acquirer or payment facilitator must begin investigating a card-not-present merchant within 72 hours when the merchant conducts at least 25 purchase transactions over a period of at least 72 hours and either:

  • Its average approval rate falls by at least 50 percentage points compared with its preceding seven-day-or-longer baseline; or

  • Its approval rate falls below 30%

Mastercard excludes defined BIN attacks and system issues at the acquirer or its service provider from this particular approval-rate trigger. Mastercard Security Rules and Procedures

An investigation trigger does not prove that the merchant is a scam.

It means the acquirer or payment facilitator must investigate the activity and determine what happened.

Align’s Mastercard SMMP guide explains the 72-hour rule and the difference between a monitoring signal, an investigation and a confirmed scam finding.

Discover-network transactions should not directly enter a Mastercard authorization-rate calculation. Capital One cards still routed through Mastercard can.

Merchants should ask how their processor counts:

  • Purchase transactions

  • Original attempts

  • Automated retries

  • Reversals

  • Technical failures

  • BIN attacks

  • Issuer declines

  • Network declines

  • Acquirer or gateway errors

The merchant’s dashboard may not calculate approval rates the same way its acquirer or Mastercard does.

QMAP Also Considers Issuer Declines

Issuer declines can also matter under Mastercard’s Questionable Merchant Audit Program, or QMAP.

One QMAP condition is that at least 20% of the merchant’s submitted transactions were declined by issuers or received response code 01, “Refer to issuer.”

Another considers whether fraudulent transactions, authorization declines and issuer referrals collectively exceeded approved transactions.

However, a 20% decline rate alone does not automatically make a business a Questionable Merchant.

Mastercard’s public rule includes minimum transaction activity requirements and additional conditions. A merchant generally must meet at least three of four specified indicators unless a separate bust-out-account condition applies. Mastercard QMAP rules

The practical lesson is not that every merchant approaching a 20% decline rate will enter QMAP.

It is that issuer declines can become part of a broader network-risk profile when combined with extreme fraud, issuer-referral or merchant-history signals.

False Declines and Insufficient-Credit Declines Need Different Solutions

Not every rejected customer is a false decline.

A false decline occurs when a legitimate customer with a valid payment method is incorrectly rejected because the transaction appears risky.

An insufficient-credit decline is different. The customer may be legitimate, but the account does not have enough available funds or credit.

For suspected false declines, merchants can investigate:

  • AVS and CVV results

  • 3D Secure or other authentication

  • Network-token use

  • Device and behavioral signals

  • Merchant and issuer countries

  • Merchant identity and descriptor consistency

  • Issuer-specific approval performance

  • Gateway or routing configuration

For insufficient funds or credit, the practical response may be:

  • Asking for another payment method

  • Allowing the customer to update the stored card

  • Retrying later when appropriate and authorized

  • Offering a lower-cost option or legitimate payment plan

  • Avoiding repeated immediate attempts

Treating every decline as recoverable can make the problem worse. Repeated retries may trigger additional velocity controls while artificially inflating the merchant’s total decline count.

How Merchants Should Investigate Rising Declines

A basic dashboard showing transactions increasing and revenue falling identifies the symptom. It rarely identifies the cause.

Merchants should begin with the following steps.

1. Request raw response data

Ask for the raw network response code, issuer or BIN detail, network, card type and transaction timestamp.

Confirm whether the decline originated with the issuer, network, processor, gateway or merchant fraud system.

2. Measure first attempts separately

One customer whose card is submitted five times can produce one failed purchase but five decline events.

Measure unique first attempts before adding retries to the analysis.

3. Separate credit and debit cards

Capital One’s documented transition is especially relevant to reissued debit cards. Combining debit and credit performance can hide the pattern.

4. Split initial and recurring payments

Customer-initiated purchases and merchant-initiated recurring charges follow different authorization rules and can fail for different reasons.

5. Review MCC and transaction indicators

Confirm that the MCC, stored-credential fields, recurring indicators and customer- versus merchant-initiated designations match the actual business and billing relationship.

6. Audit account-updater and token coverage

Determine whether updated card numbers are reaching the billing platform and whether the merchant is relying on network tokens, gateway tokens or stored PANs.

7. Compare issuers and BINs

A change concentrated within Capital One requires a different response from a decline increase across every issuer.

Compare the affected issuer with a control group over the same dates.

8. Review decline codes over time

A rise in code 51 suggests a different problem from an increase in code 05, code 65, code 83 or invalid-credential responses.

9. Document technical incidents

Mastercard’s SMMP approval-rate trigger excludes specified BIN attacks and acquirer or service-provider system issues. Preserve support tickets, timestamps and affected transaction records.

10. Escalate unexplained changes

A processor or acquiring bank may have issuer- and network-level visibility that is not available through the merchant’s dashboard.

Ask for a formal authorization analysis before the decline pattern becomes a prolonged revenue problem.

The Bottom Line

Issuer declines in 2026 cannot be explained by one headline.

Capital One’s debit-card migration is creating documented activation and stored-credential issues. Financial stress is leaving certain consumer groups with less available credit. Mastercard is providing issuers with more merchant-risk intelligence during authorization. MCCs and controlled-spend programs can affect transaction eligibility. Visa has introduced a network-level fraud response code and stricter verification-data requirements.

At the same time, aggregate bank data does not show that every cardholder or issuer portfolio is deteriorating. Commercial-bank credit-card delinquency and charge-off rates were lower in Q2 2026 than one year earlier.

The strongest evidence supports this conclusion:

Financial stress is making some customer groups more likely to exceed available credit, while merchant-risk signals, MCC controls, credential migrations and payment-data requirements are simultaneously changing how issuers and networks evaluate transactions.

For merchants, the answer is not to guess why “the banks” are declining more.

It is to isolate the issuer, BIN, network, MCC, credential, transaction type and response code responsible for the change.

Align Ecommerce helps ecommerce, subscription and complex merchants evaluate authorization performance, merchant-account structure, payment technology, fraud controls and processor risk exposure.

If your transaction attempts are rising while approved revenue is falling, request a Free Payment Risk Review before the pattern becomes a larger revenue or merchant-account problem.

FAQ

Website Payment Declines: Frequently Asked Questions

Plain-language answers for business owners investigating failed online payments, issuer declines, Capital One card changes, MCCs, and Mastercard monitoring.

Why are more customer payments being declined on my website?

Online payments can be declined because of insufficient funds, issuer fraud controls, card limits, outdated credentials, incorrect billing information, merchant fraud filters, network decisions, or gateway and routing problems.

Start by separating first attempts from retries and reviewing the raw response code, issuer or BIN, card network, credit versus debit, and initial versus recurring payment type. A general “declined” message rarely identifies the actual cause.

Does decline code 05 mean the customer has insufficient funds?

Not necessarily. Code 05, commonly described as “Do Not Honor,” is a generic issuer response. It can reflect insufficient funds, suspected fraud, account restrictions, spending limits, activation problems, or another issuer decision that is not disclosed to the merchant.

Merchants should not classify every code 05 as fraud or repeatedly retry the payment without understanding the issuer response.

Why are some Capital One debit-card payments being declined?

Capital One is moving debit cards from Mastercard to the Discover network. Customers are receiving replacement cards with new card numbers, expiration dates, and security codes.

Payments may fail when a replacement card has not been activated or a merchant is still billing credentials associated with the older card. This is a documented migration issue, but it does not prove that every Capital One or Discover decline has the same cause.

Can a merchant category code cause an online payment decline?

An MCC can influence authorization because it tells the issuer what type of business is accepting the payment. Issuers may consider the MCC alongside the transaction amount, cardholder history, merchant location, fraud signals, and authentication data.

Some corporate, prepaid, virtual, benefit, and controlled-spend cards also have explicit category restrictions. An inaccurate MCC can create additional problems when the category does not match the merchant’s products or billing activity.

Can a low approval rate trigger Mastercard SMMP attention?

Yes. Under Mastercard’s 2026 rules, an acquirer or payment facilitator must begin investigating a card-not-present merchant within 72 hours when the merchant conducts at least 25 purchase transactions over at least 72 hours and its approval rate either falls below 30% or drops by at least 50 percentage points from its preceding seven-day-or-longer baseline.

Defined BIN attacks and certain acquirer or service-provider system issues are excluded from this particular signal. Triggering an investigation does not, by itself, prove that the merchant is a scam.

Previous
Previous

Can Bad Credit Make Your Business High Risk? How Credit Affects Merchant Account Approval

Next
Next

Merchant Debanking in 2026: Why I Believe VAMP and SMMP Conflict With the FTC’s Direction