Fraud Types
- By actor: First-party (your customer, lying), second-party (they handed their details to someone else), Third-party (taken, never given), Fake identity (no real person). Full definitions
- Seen a different definition elsewhere? The industry doesn't agree. Here's who says what
- First-party subtypes: Friendly fraud (chargeback abuse), Refund fraud (return exploitation), Promo abuse (discount abuse)
- By method: Account fraud (fake signups), ATO (account hijack), Card testing (validation), Fraud rings (organized attacks)
- Focus your resources on prevention. Chargebacks from true fraud are hard to win
Most merchants only have one or two of these. Work out which before you read further.
Which Fraud Type Is YOUR Problem?
| If you see... | Start here |
|---|---|
| Chargebacks on legitimate orders | Friendly Fraud |
| Many small transactions, then fraud | Card Testing |
| Good customer suddenly acting strange | Account Takeover |
| New account, immediate high spending | Third-Party Fraud or Account Fraud |
| Coordinated attack across accounts | Fraud Rings |
| Return/refund abuse | Refund Fraud |
| Promotion/coupon exploitation | Promo Abuse |
| ACH returns or unauthorized bank debits | ACH Fraud |
| Customer sent a payment, then said they were scammed | ACH Fraud |
| A seller or customer account exists to receive and forward money | Second-party fraud |
How to Find Out What Fraud Type You Have
Don't buy a tool yet. Find out what you've actually got:
- Pull your last 30 chargebacks (or however many you have from the last 6 months)
- Tag each one into one of four buckets:
- Third-party fraud - Stolen card, customer says "I didn't do this" and they're telling the truth
- Friendly fraud - Customer made the purchase but disputes it anyway
- Billing confusion - Customer didn't recognize the charge on their statement
- Service issue - Customer had a real problem with the product or delivery
- Count. Your biggest bucket is your problem.
Most SMBs under $1M are over 70% friendly fraud and billing confusion. If that's you, the fix is operational, not technical. Better descriptors, easier refunds, clearer emails. Not fraud scoring or device fingerprinting. Read Friendly Fraud first, then Descriptors and Comms, and buy nothing until you have.
Classification Framework
Sorted by who commits it:
| Type | Actor | Key Characteristic |
|---|---|---|
| First-Party | Your customer | Own identity, and they're lying |
| Second-party | Your customer, for somebody else | They handed their card or account over. The money goes elsewhere |
| Victim-initiated | Your customer | They sent it themselves. Somebody deceived them into it |
| Third-Party | External fraudster | Never given access. It was taken |
| Fake Identity | Nobody real | Real and fake details mixed. No such person |
Second-party and victim-initiated look alike and aren't. One handed over an account. The other sent a payment. Both may have been deceived, and the deception doesn't change which one it is. Ask what they gave away: access, or money?
Most taxonomies leave both middle rows out. They're the ones where your customer is telling the truth and still lost the money.
It barely happens on cards. A criminal with a stolen number does the initiating there. It happens constantly on ACH and push payments, where your customer taps send.
How the Federal Reserve Classifies This
The Fed publishes two classification models, free and open. They're worth knowing for one reason. Nobody's selling you anything with them.
FraudClassifier opens with a different question than this page does. Not "who is the fraudster" but "who initiated the payment?" Everything else hangs off that.
| Who initiated it | How | Then |
|---|---|---|
| Authorized Party | Acted fraudulently | Embezzlement, False Claim, Synthetic ID |
| Authorized Party | Was manipulated | Products and Services Fraud, Relationship and Trust Fraud |
| Unauthorized Party | Took over the account | Compromised credentials |
| Unauthorized Party | Misused account information | Digital payment, physical forgery |
| Unauthorized Party | Modified the payment | Compromised credentials, impersonation, physical alteration |
Check the rail before you map it onto cards. The Fed built this for a different problem. Jim Cunha of the Boston Fed, in the announcement, says it addresses "the industrywide challenge of inconsistent classifications for fraud involving ACH, wire, or check payments." Cards weren't the target.
That's why the two schemes look like they disagree. Phish a customer, then use their card yourself. You initiated the payment. Third-party here, Unauthorized Party there, no argument. Now phish a customer into sending the money. They initiated it. The Fed calls that Authorized Party Was Manipulated. Here it's the victim-initiated row above.
One place the Fed splits from this page. It files Synthetic ID under Authorized Party Acted Fraudulently. That treats the fabricated persona as an account holder with rights. This page gives fake identity its own actor row instead. At your checkout there's nobody real to hold responsible.
ScamClassifier is the companion. It sorts the scam itself into nine types. The Fed says it can run before or after FraudClassifier. Reach for it when you're describing what happened to a person, not to a payment.
| On this site | FraudClassifier |
|---|---|
| First-party, friendly fraud | Authorized Party Acted Fraudulently → False Claim |
| Refund fraud run by your own staff | Authorized Party Acted Fraudulently → Embezzlement |
| Fake identity | Authorized Party Acted Fraudulently → Synthetic ID |
| Victim-initiated | Authorized Party Was Manipulated |
| Second-party, knowing | Authorized Party Acted Fraudulently |
| Second-party, deceived into it | Authorized Party Was Manipulated |
| Third-party, card testing | Unauthorized Party → Misused Account Information |
| Account takeover | Unauthorized Party → Took Over Account |
Quick Reference
By Method
| Fraud Type | Description | When You See It |
|---|---|---|
| Account Fraud | Fake account signups | Bot attacks, promo farming |
| Account Takeover | Hijacked customer accounts | Password breaches, phishing |
| ACH Fraud | Unauthorized bank debits, BEC | ACH returns, payment redirects |
| Card Testing | Validating stolen cards | Small transaction bursts |
| Fraud Rings | Organized multi-account attacks | Coordinated patterns |
| Triangulation | Three-party resale scheme | Marketplace fraud |
| BEC & Phishing | Attacks on your operations | Fake invoices, credential theft |
First-Party Fraud Subtypes
These are all forms of first-party fraud. The customer is the fraudster:
| Fraud Type | Description | Your Defense |
|---|---|---|
| Friendly Fraud | Dispute legitimate purchase | Evidence collection, CE 3.0 |
| Refund Fraud | Exploit return policies | Policy enforcement |
| Promo Abuse | Game promotions/discounts | Device linking, limits |
Comparison at a Glance
| Type | Who Loses | Detection Difficulty | Can You Fight Chargebacks? | Primary Defense |
|---|---|---|---|---|
| Third-Party | You (without 3DS) | Medium | Rarely (unless 3DS) | 3D Secure |
| First-Party | You | High | Yes (with evidence) | Policy enforcement, evidence collection |
| ↳ Friendly Fraud | You | High | Yes (CE 3.0) | Descriptors, evidence, easy refunds |
| ↳ Refund Fraud | You | Medium | N/A | Policy enforcement, pattern tracking |
| ↳ Promo Abuse | You | Medium | N/A | Device linking, limits |
| Fake Identity | You | High | Sometimes | Identity verification |
| ATO | Customer + You | Medium | Yes | MFA, behavioral analytics |
| Card Testing | You | Low | N/A | Velocity rules, CAPTCHA |
| Fraud Rings | You | High | Sometimes | Device fingerprinting |
Prevention Priority
For most merchants, in this order:
1. High Impact, Easier to Prevent
| Type | Action |
|---|---|
| Third-Party Fraud | Enable 3D Secure for liability shift |
| Card Testing | Add velocity rules and CAPTCHA |
| Account Fraud | Require email/phone verification |
2. High Impact, Harder to Prevent
| Type | Action |
|---|---|
| Friendly Fraud | Collect evidence, implement CE 3.0 |
| Refund Fraud | Tighten policies, track patterns |
| Account Takeover | Require MFA, monitor logins |
3. Specialized Threats
| Type | Action |
|---|---|
| Fraud Rings | Device fingerprinting, consortium data |
| Promo Abuse | Device linking, redemption limits |
| Triangulation | Shipping address analysis |
Popular in This Section
- Third-Party Fraud - Stolen cards used at your store
- Friendly Fraud - Legitimate purchases disputed dishonestly
- Account Takeover - Hijacked customer accounts
- Card Testing - Small transactions to validate stolen cards
- Refund Fraud - Return and refund exploitation
Related Topics
- 3D Secure - Liability shift for fraud
- AVS & CVV - Payment verification
- Device Fingerprinting - Tracking fraudsters
- Velocity Rules - Pattern detection
- Risk Scoring - Combining signals
- Compelling Evidence - Fighting chargebacks
- Chargeback Prevention - Stop disputes