Skip to main content

Fraud Types

TL;DR

Most merchants only have one or two of these. Work out which before you read further.


Which Fraud Type Is YOUR Problem?

If you see...Start here
Chargebacks on legitimate ordersFriendly Fraud
Many small transactions, then fraudCard Testing
Good customer suddenly acting strangeAccount Takeover
New account, immediate high spendingThird-Party Fraud or Account Fraud
Coordinated attack across accountsFraud Rings
Return/refund abuseRefund Fraud
Promotion/coupon exploitationPromo Abuse
ACH returns or unauthorized bank debitsACH Fraud
Customer sent a payment, then said they were scammedACH Fraud
A seller or customer account exists to receive and forward moneySecond-party fraud

How to Find Out What Fraud Type You Have

Don't buy a tool yet. Find out what you've actually got:

  1. Pull your last 30 chargebacks (or however many you have from the last 6 months)
  2. Tag each one into one of four buckets:
    • Third-party fraud - Stolen card, customer says "I didn't do this" and they're telling the truth
    • Friendly fraud - Customer made the purchase but disputes it anyway
    • Billing confusion - Customer didn't recognize the charge on their statement
    • Service issue - Customer had a real problem with the product or delivery
  3. Count. Your biggest bucket is your problem.
What Most SMBs Find

Most SMBs under $1M are over 70% friendly fraud and billing confusion. If that's you, the fix is operational, not technical. Better descriptors, easier refunds, clearer emails. Not fraud scoring or device fingerprinting. Read Friendly Fraud first, then Descriptors and Comms, and buy nothing until you have.


Classification Framework

Sorted by who commits it:

TypeActorKey Characteristic
First-PartyYour customerOwn identity, and they're lying
Second-partyYour customer, for somebody elseThey handed their card or account over. The money goes elsewhere
Victim-initiatedYour customerThey sent it themselves. Somebody deceived them into it
Third-PartyExternal fraudsterNever given access. It was taken
Fake IdentityNobody realReal and fake details mixed. No such person

Second-party and victim-initiated look alike and aren't. One handed over an account. The other sent a payment. Both may have been deceived, and the deception doesn't change which one it is. Ask what they gave away: access, or money?

Most taxonomies leave both middle rows out. They're the ones where your customer is telling the truth and still lost the money.

It barely happens on cards. A criminal with a stolen number does the initiating there. It happens constantly on ACH and push payments, where your customer taps send.

How the Federal Reserve Classifies This

The Fed publishes two classification models, free and open. They're worth knowing for one reason. Nobody's selling you anything with them.

FraudClassifier opens with a different question than this page does. Not "who is the fraudster" but "who initiated the payment?" Everything else hangs off that.

Who initiated itHowThen
Authorized PartyActed fraudulentlyEmbezzlement, False Claim, Synthetic ID
Authorized PartyWas manipulatedProducts and Services Fraud, Relationship and Trust Fraud
Unauthorized PartyTook over the accountCompromised credentials
Unauthorized PartyMisused account informationDigital payment, physical forgery
Unauthorized PartyModified the paymentCompromised credentials, impersonation, physical alteration

Check the rail before you map it onto cards. The Fed built this for a different problem. Jim Cunha of the Boston Fed, in the announcement, says it addresses "the industrywide challenge of inconsistent classifications for fraud involving ACH, wire, or check payments." Cards weren't the target.

That's why the two schemes look like they disagree. Phish a customer, then use their card yourself. You initiated the payment. Third-party here, Unauthorized Party there, no argument. Now phish a customer into sending the money. They initiated it. The Fed calls that Authorized Party Was Manipulated. Here it's the victim-initiated row above.

One place the Fed splits from this page. It files Synthetic ID under Authorized Party Acted Fraudulently. That treats the fabricated persona as an account holder with rights. This page gives fake identity its own actor row instead. At your checkout there's nobody real to hold responsible.

ScamClassifier is the companion. It sorts the scam itself into nine types. The Fed says it can run before or after FraudClassifier. Reach for it when you're describing what happened to a person, not to a payment.

On this siteFraudClassifier
First-party, friendly fraudAuthorized Party Acted Fraudulently → False Claim
Refund fraud run by your own staffAuthorized Party Acted Fraudulently → Embezzlement
Fake identityAuthorized Party Acted Fraudulently → Synthetic ID
Victim-initiatedAuthorized Party Was Manipulated
Second-party, knowingAuthorized Party Acted Fraudulently
Second-party, deceived into itAuthorized Party Was Manipulated
Third-party, card testingUnauthorized Party → Misused Account Information
Account takeoverUnauthorized Party → Took Over Account

Quick Reference

By Method

Fraud TypeDescriptionWhen You See It
Account FraudFake account signupsBot attacks, promo farming
Account TakeoverHijacked customer accountsPassword breaches, phishing
ACH FraudUnauthorized bank debits, BECACH returns, payment redirects
Card TestingValidating stolen cardsSmall transaction bursts
Fraud RingsOrganized multi-account attacksCoordinated patterns
TriangulationThree-party resale schemeMarketplace fraud
BEC & PhishingAttacks on your operationsFake invoices, credential theft

First-Party Fraud Subtypes

These are all forms of first-party fraud. The customer is the fraudster:

Fraud TypeDescriptionYour Defense
Friendly FraudDispute legitimate purchaseEvidence collection, CE 3.0
Refund FraudExploit return policiesPolicy enforcement
Promo AbuseGame promotions/discountsDevice linking, limits

Comparison at a Glance

TypeWho LosesDetection DifficultyCan You Fight Chargebacks?Primary Defense
Third-PartyYou (without 3DS)MediumRarely (unless 3DS)3D Secure
First-PartyYouHighYes (with evidence)Policy enforcement, evidence collection
Friendly FraudYouHighYes (CE 3.0)Descriptors, evidence, easy refunds
Refund FraudYouMediumN/APolicy enforcement, pattern tracking
Promo AbuseYouMediumN/ADevice linking, limits
Fake IdentityYouHighSometimesIdentity verification
ATOCustomer + YouMediumYesMFA, behavioral analytics
Card TestingYouLowN/AVelocity rules, CAPTCHA
Fraud RingsYouHighSometimesDevice fingerprinting

Prevention Priority

For most merchants, in this order:

1. High Impact, Easier to Prevent

TypeAction
Third-Party FraudEnable 3D Secure for liability shift
Card TestingAdd velocity rules and CAPTCHA
Account FraudRequire email/phone verification

2. High Impact, Harder to Prevent

TypeAction
Friendly FraudCollect evidence, implement CE 3.0
Refund FraudTighten policies, track patterns
Account TakeoverRequire MFA, monitor logins

3. Specialized Threats

TypeAction
Fraud RingsDevice fingerprinting, consortium data
Promo AbuseDevice linking, redemption limits
TriangulationShipping address analysis