BriefingThesis
PaymentLeaks
BriefingThesis
0:00 on page
ES|EN
IN
IGNACIO DE NAVASCUÉS
EDITOR · 12Y IN PAYMENTS
Today2026-03-27

Today's briefing, and why it matters to you.

2026-03-27
Yesterday's data2026-03-27

Top 3 · Systemic Impact

TODAY
1Systemic

FTC threatens Visa, Mastercard, PayPal and Stripe over "debanking"

Why it matters: Redefines merchant onboarding/offboarding rules — processors can no longer freely deny service without risk of federal enforcement, with JPMorgan already defending a $5B lawsuit. [PYMNTS](https://www.pymnts.com/bank-regulation/2026/ftc-warns-payment-companies-against-debanking/)

SourcesPYMNTS↗
2Systemic

Constitutional crisis at the Fed — Powell threatened, gold at $5,400

Why it matters: The direct threat to central bank independence injects systemic uncertainty into all financial markets — with Powell's mandate expiring May 15 and succession blocked, the "Independence Risk Premium" is already priced into gold and yields. [MarketMinute](https://markets.financialcontent.com/stocks/article/marketminute-2026-3-26-constitutional-crisis-at-the-fed-criminal-threats-and-political-warfare-push-markets-to-the-edge)

SourcesMarketMinute↗
3Systemic

ECB excludes American cloud giants from the digital euro — full sovereignty

Why it matters: Europe is building payment infrastructure completely independent from the US — OVHcloud and Scaleway replace AWS/Azure/GCP, signaling that digital sovereignty is no longer rhetoric but executed industrial policy. [The Register](https://www.theregister.com/2026/03/26/digital_euro_sovereignty/)

---

SourcesThe Register↗

News by Impact

23 STORIES
ALTA

FSOC votes guidance to designate non-banks as systemic — PayPal, Stripe, Affirm in scope, 45-day comment period.

US Treasury

No source
ALTA

WebRTC payment skimmer bypasses CSP — 56.7% of Magento stores compromised, victims include $100B+ automaker and top-3 US bank.

Sansec

No source
ALTA

DORA Register of Information — final deadline March 31, only 6.5% passed the 116 quality checks, fines up to 2% of turnover.

PG Legal

No source
ALTA

Circle -20% triple shock — CLARITY Act prohibits yield on stablecoins, Tether hires Deloitte, Circle freezes 16 wallets.

Blockhead

No source
ALTA

NYSE + Securitize MOU for tokenized securities trading — historic milestone for on-chain capital markets.

Lowenstein

No source
ALTA

Oracle CVE-2026-21992 (CVSS 9.8) — unauthenticated RCE in banking Identity Manager, emergency patch.

Oracle

No source
ALTA

UAE launches Digital Dirham — retail CBDC, zero fees, cross-border via mBridge with Saudi Arabia, India, China, HK.

Digital Dubai

No source
ALTA

Tycoon2FA phishing-as-a-service bounces back after Europol takedown — rebuilt infrastructure the same day.

BankInfoSecurity

No source
ALTA

Colorado and Delaware advance interchange fee bans — Illinois model replicating, Illinois IFPA effective July 1.

ABA Banking Journal

No source
ALTA

RBI mandates 2FA for all digital payments from April 1 — biometrics, device tokens, PINs; cross-border CNP before October 1.

Business Standard

No source
MEDIA

Visa launches "Agentic Ready" in Europe — AI-initiated payments with issuers in real environments.

Fintech News Switzerland

No source
MEDIA

US Congress grills regulators on tech readiness in payments.

PYMNTS

No source
MEDIA

BLIK considers IPO at ~$2B — 20.7M users, 2.9B txns/year.

Strefa Inwestorow

No source
MEDIA

Vipps MobilePay launches Nordic cross-border P2P + pan-Nordic Tap to Pay, expansion to 13 countries via EuroPA.

Vipps MobilePay

No source
MEDIA

Nigeria NCC launches TIRMS — anti-fraud phone verification for banks and fintechs.

Naija247News

No source
MEDIA

Kenya-Rwanda: first fintech license passporting in Africa — potential pan-African model.

TCI South Africa

No source
MEDIA

Tether hires Deloitte for first Big Four audit — erodes USDC transparency advantage.

CNBC

No source
MEDIA

Visa Level 2 interchange sunset April 17 — B2B merchants without full data lose preferential rates.

Beacon Payments

No source
MEDIA

PQC: European central banks test post-quantum on live TARGET2.

Quantum Insider

No source
MEDIA

RBA raises rates + imminent surcharging reform — Australia diverges from peers.

RBA

No source
MEDIA

PIX MED 2.0 mandatory — Brazil tackles R$6.5B in fraud with multi-layer tracing.

TI Inside

No source
MEDIA

PSD3/PSR final texts expected Q2 2026 — APP fraud and BNPL in scope.

Norton Rose

No source
MEDIA

Leak Bazaar: criminal marketplace industrializes monetization of stolen financial data.

CybersecurityNews

No source

Exposure Check

  • Circle (USDC): -20% in one day, $5.6B in market cap evaporated. If you have exposure to USDC as a settlement rail or reserves, monitor liquidity and contagion risk. The combination of CLARITY Act + Tether audit + wallet freezing suggests structural pressure, not temporary.
  • Oracle Identity Manager: CVE 9.8 unauthenticated. If you use OIM for identity management in payments infrastructure, patch TODAY. Predecessor was actively exploited.
  • Magento/Adobe Commerce merchants: 56.7% compromised by WebRTC skimmer. If you process payments for Magento merchants, verify immediate exposure.
  • DORA non-compliance: If you operate in the EU and haven't completed the Register of Information, you have 4 days. Fines up to 2% of global turnover.
  • PayPal: CEO ousted (Mar 25), class action, -$10B market cap, now FTC debanking warning. Growing counterparty exposure.

Connect the Dots

1. [ECB excludes US cloud from digital euro] + [CIPS 8-year renewal + mBridge 95% yuan] + [UAE Digital Dirham with mBridge] → The fragmentation of financial infrastructure is no longer theoretical. Europe, China and MENA are building complete parallel stacks (cloud, settlement, CBDC). In 2-3 years there will be 3-4 incompatible payment infrastructures requiring "bridges" — the next big business in payments.

2. [FTC debanking warning to processors] + [FSOC systemic designation guidance for non-banks] + [Illinois/Colorado/Delaware interchange bans] → Coordinated attack on the payments operating model in the US. Processors are trapped: they can't reject merchants (FTC), could be regulated as systemic (FSOC), and their interchange revenue model erodes state by state. This pushes Visa/MC toward value-added models (tokenization, agentic, data) faster than expected.

3. [Circle -20% + CLARITY Act] + [Tether Deloitte audit] + [NYSE+Securitize tokenization] → The future of digital assets is securities tokenization, not yield-bearing stablecoins. US regulation closes the door on the "stablecoin as savings account" model and opens it to the "everything tokenized on regulated rails" model. Smart money has already migrated — Fink, NYSE, CME/BMO confirm it.


Active Follow-ups

  • Wero/EPI (Mar 24: 50M → Mar 27: 52.5M): +2.5M users in 3 days. Worldpay joined as Principal Member. E-commerce and POS in spring. Trajectory confirmed.
  • DORA enforcement (Mar 24 → Mar 27): March 31 deadline immovable. Only 6.5% passed quality checks. We expect a wave of fines in April.
  • Circle/stablecoins (Mar 24: SEC taxonomy → Mar 27: -20%): The SEC taxonomy that said "they're not securities" didn't protect Circle from the CLARITY Act that prohibits yield. Regulation from multiple fronts.
  • Illinois interchange (Mar 26 → Mar 27): Colorado and Delaware advance similar bills. Pennsylvania too. The domino effect we anticipated is materializing.
  • PIX MED 2.0 (Mar 24 → Mar 27): Now mandatory. BTG R$100M fraud forced acceleration. Resolution 554 auto-blocking in effect.
  • PayPal (Mar 25: CEO ousted → Mar 27: FTC warning): Accumulating pressures. Class action + leadership loss + hostile regulator.
  • Agentic payments (Mar 24: Stripe MPP + AAIF → Mar 26: MC live LatAm → Mar 27: Visa Agentic Ready EU): Three days, three moves from three different players. The race for the agentic standard accelerates weekly.

Notable Silence

  • Stripe + PayPal acquisition talk: Bloomberg reported on Mar 24 that Stripe is evaluating acquiring PayPal. With PayPal without a CEO and -$10B in market cap, the total silence from both parties is deafening. Either they're negotiating or someone killed the story.
  • SWIFT response to tokenization/mBridge: NYSE tokenizes, mBridge grows, CIPS renews — and SWIFT says nothing. Their "connector" strategy between legacy and DLT worlds should be under maximum pressure.
  • Apple/Google Pay stance on European sovereignty: ECB excludes hyperscalers from the digital euro, Wero grows to 52.5M... and neither Apple nor Google have responded publicly. Their silence suggests private negotiations or waiting for regulation to force their hand.
  • Mastercard post-BVNK acquisition: They paid $1.8B for BVNK 3 days ago and there's no integration or strategy announcement. Unusual for an M&A of this size.
  • FedNow volume data: With RTP reaching a turning point (8B projected txns) and A2A growing globally, the Fed hasn't published updated FedNow adoption data since February.

Weak Signals

Turkey suspends 9 payment entities (Sipay, Vepara, Fzypay, Papara, Ininal) Source: FintekWins (Turkish). TCMB is executing a massive crackdown against non-compliant payment fintechs. Turkey is the largest fintech market in MENA after UAE. If this becomes a pattern (like India with lending fintechs in 2024), it reduces the addressable market for Western PSPs seeking Turkish expansion. Timeline: 3-6 months for regulatory clarity.

Poland opens payment systems to fintechs + BLIK cross-border with Bizum Source: Dudkowiak (Polish), Gazeta.pl. BLIK makes first cross-border transfer with Bizum (Spain→Poland). With IPO at $2B and 2.9B txns/year, Poland is building an exportable A2A champion. If BLIK replicates the Bizum/Swish/Vipps regional expansion model, it will be the fifth European domestic scheme with cross-border ambition. Timeline: 6-12 months.

France: payment fraud +23% since January 2026, AI deepfakes Source: Le Parisien (French). 30K cards on dark web, QR fraud x4, FICOBA 1.2M accounts exposed. France is the canary in the coal mine for the impact of generative AI on payment fraud. If the trend replicates in other European markets, fraud costs could negate A2A and instant payment efficiencies. Timeline: already happening.

South Korea: $60B in crypto outflows, exchange profits -38% Source: TechFlow Post (Korean). Coincides with Project Hangang Phase 2 (CBDC for government subsidies). Korea is executing a "push-pull" — government CBDC attracts, crypto regulation repels. Replicable model for other Asian markets. Timeline: 6 months.


Convergence — 6-12 Month Thesis

Tokenization + Regulation: NYSE+Securitize MOU + ECB accepts DLT as collateral (Mar 30) + BMO tokenized cash + Larry Fink "Internet of Finance" + US Congress hearing. Tokenization now has regulated rails, institutional custodians and regulatory blessing. CLARITY Act pushes stablecoin capital toward tokenized securities. Q2-Q3 2026 will be the inflection point for institutional RWA.

Agentic Payments + AI: Stripe MPP (Mar 24) → MC live agentic LatAm (Mar 26) → Visa Agentic Ready EU (Mar 27) → IXOPAY trust framework → MAS MindForge toolkit → AAIF Linux Foundation. In 3 days, three competing standards. The race isn't about technology — it's about the protocol that becomes the "HTTP of payments between agents." FCA already flagged it as a regulatory priority.

CBDCs + Cross-border: Digital Dirham + mBridge + CIPS renewal + digital yuan with interest + Project Hangang + RBI cross-border CBDC = CBDCs are no longer pilots, they're operational infrastructure. But each one optimizes for its bilateral corridor, not global interoperability. The result: a world of 5-6 incompatible CBDC bridges that will need an interoperability meta-layer.

AI + Fraud: Tycoon2FA bounces back in one day post-Europol. WebRTC skimmer bypasses CSP. France +23% AI fraud. INTERPOL $442B global. Leak Bazaar industrializes stolen data. AI commoditizes both defense (Feedzai RiskFM, Visa Intelligent Auth) and attack (deepfakes, phishing-as-a-service). The arms race is in unstable equilibrium — the next skimmer combining agentic AI with WebRTC-style evasion will be an order of magnitude worse.

Maximum convergence (6-12 months): An AI agent executing a tokenized payment, settled in CBDC, through a cross-border bridge, verified with PQC, and monitored by an anti-fraud foundation model. Each piece exists today. Integration is the opportunity.

Parallel sovereign rails

· position, not only news3 RAILS

CIPS

CHINA · PBOC

First renewal in 8 years — dual settlement, multi-currency, Standard Bank (Africa) joins. Visa Direct+UnionPay and MC Move+Bank of Shanghai open bidirectional corridors with China. CIPS is no longer an emergency alternative; it's operational parallel infrastructure.

UPI

INDIA · RBI

Projects 240B transactions FY26, >800M daily. Expansion to Sri Lanka via LankaQR (25+ countries). RBI in talks with 4-5 central banks on cross-border CBDC. RBI imposes universal 2FA from April 1. India builds the densest rail in the world and exports it aggressively.

PIX

BRAZIL · BCB

MED 2.0 mandatory to combat R$6.5B in fraud. BCB restricts eFX operations. BTG R$100M fraud accelerates regulation. PIX continues growing but the focus is now security and control, not volume.

Archive · Past coverage

1 RELATED
2026-03-26
CLARITY Act bans yield on stablecoins — Circle -15%
VisaMastercardStripe
← 2026-03-262026-03-28 →

Never miss a briefing

Get notified every morning when the briefing is ready.

Anything to improve? Tell me.

I read everything. If anything's missing, extra, or broken in the briefing, I'd love to hear it.

PaymentLeaks

PaymentLeaks is built by Ignacio De Navascués — 12 years in the payments industry. Daily intelligence on global payments, fintech and sovereign rails, hand-curated and analyzed every morning.

Content
  • Today's briefing
  • Glossary
  • See sample
  • FAQ
About
  • About PaymentLeaks
  • Privacy
  • Terms
© 2026 PaymentLeaks · MadridIndependent analysis. Not financial advice.