Credit card companies need to spend vast resources on fraud protection because their underlying protocol offers virtually none. Credit cards, after all, don't even have a basic "password." It's like the difference between an online bank account with no password but with a team of "fraud protectors," and a bank account with good two factor authentication. You can argue that both are forms of "fraud protection," but I vastly prefer the latter.