Is strong customer authentication working?

Entering a one-time password to complete an online transaction is now mandatory, so is strong customer authentication working? Or have fraudsters simply changed tactics?