Skip to main content

Fraud Types

TL;DR

A taxonomy of fraud patterns for merchants.


Which Fraud Type Is YOUR Problem?

If you see...Start here
Chargebacks on legitimate ordersFriendly Fraud
Many small transactions, then fraudCard Testing
Good customer suddenly acting strangeAccount Takeover
New account, immediate high spendingThird-Party Fraud or Account Fraud
Coordinated attack across accountsFraud Rings
Return/refund abuseRefund Fraud
Promotion/coupon exploitationPromo Abuse

Classification Framework

Fraud can be classified by who commits it:

TypeActorKey Characteristic
First-PartyYour customerUses own identity to defraud you
Third-PartyExternal fraudsterUses stolen card at your store
Fake IdentityUnknownFabricated persona, not a real person

Quick Reference

By Method

Fraud TypeDescriptionWhen You See It
Account FraudFake account signupsBot attacks, promo farming
Account TakeoverHijacked customer accountsPassword breaches, phishing
Card TestingValidating stolen cardsSmall transaction bursts
Fraud RingsOrganized multi-account attacksCoordinated patterns
TriangulationThree-party resale schemeMarketplace fraud

Post-Transaction Fraud

Fraud TypeDescriptionYour Defense
Friendly FraudDispute legitimate purchaseEvidence collection, CE 3.0
Refund FraudExploit return policiesPolicy enforcement
Promo AbuseGame promotions/discountsDevice linking, limits

Comparison at a Glance

TypeWho LosesDetection DifficultyCan You Fight Chargebacks?Primary Defense
Third-PartyYou (without 3DS)MediumRarely (unless 3DS)3D Secure
Friendly FraudYouHighYes (with evidence)Evidence collection, CE 3.0
First-PartyYouMediumYesPolicy enforcement
Fake IdentityYouHighSometimesIdentity verification
ATOCustomer + YouMediumYesMFA, behavioral analytics
Card TestingYouLowN/AVelocity rules, CAPTCHA
Fraud RingsYouHighSometimesDevice fingerprinting

Prevention Priority

For most merchants, focus resources in this order:

1. High Impact, Easier to Prevent

TypeAction
Third-Party FraudEnable 3D Secure for liability shift
Card TestingAdd velocity rules and CAPTCHA
Account FraudRequire email/phone verification

2. High Impact, Harder to Prevent

TypeAction
Friendly FraudCollect evidence, implement CE 3.0
Refund FraudTighten policies, track patterns
Account TakeoverRequire MFA, monitor logins

3. Specialized Threats

TypeAction
Fraud RingsDevice fingerprinting, consortium data
Promo AbuseDevice linking, redemption limits
TriangulationShipping address analysis