Skip to main content

Fraud Classification

TL;DR
  • First party: the person is lying. Own identity, own details, false claim
  • Second party: they handed it over. Mule, family member, or someone talked into it
  • Third party: nobody gave them anything. It was taken
  • Synthetic: there's no real person behind it
  • Your response differs: 3DS for third party, evidence for friendly fraud, payout controls for second party
  • The industry doesn't agree on any of this. Every competing definition is quoted below, so you can check us

This is the reference page for fraud classification. Other pages give a short definition and link here.

We take a position below. Then we show every competing definition we found, so you can judge it.

Quick Classification

What You SeeLikely TypeYour Response
Customer disputes legitimate purchaseFriendly FraudCollect evidence, fight with CE 3.0
Card used by someone who was never given accessThird-Party FraudEnable 3DS for liability shift
Same device, many accountsFraud RingDevice fingerprinting, block infrastructure
Burst of small transactionsCard TestingVelocity rules, CAPTCHA
Good customer acting strangeAccount TakeoverMFA, behavioral analytics
Excessive returns/refundsRefund FraudPolicy enforcement, tracking
Promo/coupon abusePromo AbuseDevice linking, limits
Fake account signupsAccount FraudEmail/phone verification
Mismatched identity infoFake IdentityIdentity verification

The Four Types, Defined

We're going to be direct about this, because most sources aren't.

TypeThe testIn one line
First partyIs the person lying?They're using their own identity, not hiding who they are, and lying about something
Second partyDid they hand it over?The real owner gave their details, card or account to someone else
Third partyWere they authorized?Somebody who was never given access is using it
SyntheticIs this a real person?An identity built from real and fake pieces, made to deceive

First party: the person is lying

They aren't hiding who they are. Their name is their name, their address is their address. The lie is about something else.

Two shapes, and they're the same act:

  • Lying about facts. Inflating income on an application, misstating what a business does
  • Lying about an event. Saying they didn't make a purchase they made

That second one is what most merchants meet, and it's usually called friendly fraud.

Not repaying isn't fraud

A customer who borrows and can't pay hasn't lied. That's credit risk, and it's a pricing problem rather than a fraud problem. A customer who lied to get the money committed fraud. The lie is the line, and plenty of published definitions blur it.

Second party: they handed it over

Someone gave their identity, card, account or device to another person. The details are genuine because they really are genuine. The owner participated.

Why they did it varies enormously, and the reason doesn't change the classification:

SituationStill second party?
Paid to let their account move money (a money mule)Yes
Lent a card to a parent, sibling or partnerYes
Talked into it on the phone, or by a fake job adYes
Pressured or controlled by someone elseYes
An employee abusing internal accessNo. That's insider fraud, and it goes under first party
Classifying is not blaming

Second party covers people who were paid and people who were tricked. Same classification, completely different culpability. Say which one you're looking at, separately.

Somebody deceived by a phone call still handed their details over. That's second party. They're also a victim. Both are true.

Third party: nobody gave them anything

The person using the card or identity was never given access to it. It was taken, not handed over. Stolen card data, a breached account, a hijacked login.

That's the whole difference from second party. Did the owner hand it over, or did somebody take it?

Synthetic: there's no real person

An identity assembled from real and fabricated details. It's built to look like someone who doesn't exist. There's no victim to notify and no cardholder to call. Nobody's identity was fully used.

Two forms, using the Federal Reserve's terms:

TermWhat it isAlso called
ManipulatedA real person using a substantially different SSN or key detailFirst-party synthetic, hybrid
FabricatedNo real person behind it at allThird-party synthetic, full

Worked example: "my family member used my card"

This is the most common ambiguous case a merchant sees, and it lands in a different class depending on one fact. Most sources file it all as friendly fraud. That's wrong, and it changes what you should do.

What actually happenedClassWhat you do
Cardholder gave the card to a relative, then disputed the chargeFirst partyThey're lying. Fight it with evidence
Cardholder gave the card to a relative, and genuinely forgotFirst party, but not deliberateStill their charge. Usually cheaper to refund and fix your descriptor
Cardholder knowingly let a relative use it to move moneySecond partyTreat as mule risk, not a dispute
Relative took the card without askingThird partyA real unauthorized use. The cardholder is a victim

Amex names this on its own merchant material, describing charges made by "family or staff." A large share of what merchants log as fraud is a second cardholder in the same house or business, and much of that isn't fraud at all.

The question to ask, and it's one question: did the cardholder hand the card over?


Does the Rest of the Industry Agree?

Mostly yes on first, third and synthetic. Not at all on second. Here's the evidence, so you can check us.

Key Fact: the card networks lead with this vocabulary in marketing. They barely use it in their rules. Both Visa and Mastercard say "first-party misuse" publicly. It appears nowhere in Visa's 925-page Core Rules. Nor in Mastercard's rules, nor its 1,153-page chargeback guide. So "the networks define it this way" means someone is quoting a brochure.

Where the numbering comes from

This explains most of the confusion. A normal transaction has two parties: you and your customer.

PartyWho that is
First partyyour customer
Second partyyou, the merchant
Third partyan outsider who was never in the transaction

So read strictly, "second-party fraud" should mean fraud committed by the merchant. Nobody uses it that way. The term got invented later, for a real problem that needed a name. It landed in a slot that was already taken. That's why no two sources define it the same way.

First party: two camps, one act

Lenders describe the application.

SourceWhat they say
Experian"an individual who makes a promise of future repayment in exchange for goods / services without the intent to repay"
TransUnion"misrepresenting one's personal information in order to receive a product or service to which they have no entitlement." Also calls it "credit muling"
Equifax"an individual intentionally misrepresents their identity and/or gives false information for financial or material gain"
Socure"the use of one's own identity to open an account and/or commit a dishonest act for personal or financial gain"
DataVisor"the fraudster is not misrepresenting who they are, but rather, they're being deceptive about their information, and their intentions"

Payments people describe the dispute.

SourceWhat they say
Ethoca (Mastercard)first-party fraud and friendly fraud "mean the same thing and are often used interchangeably. It's when a customer identifies a legitimate purchase on their transaction statement as fraudulent and disputes it"
Mastercard"When cardholders dispute a genuine transaction, that's first-party misuse or 'friendly' fraud"
Sift"chargeback fraud, dispute fraud, first-party fraud, first-party misuse, and friendly fraud all describe when an authorized cardholder makes a purchase... and later claims that the purchase was fraudulent"
Signifyd"any type of fraud that involves using a real, genuine identity to defraud an ecommerce company"
Forter"also known as friendly fraud... where actual customers commit fraud by disputing legitimate transactions"
BioCatch"commonly known as friendly fraud, occurs when a customer consciously disputes a transaction to avoid payment or gain a refund"

Those look like two definitions. They're one act seen at two moments. Lying about your income and lying about a purchase are both lying. Both use your own real identity. That's why we test for the lie instead of picking a camp.

It matters when you read a number. "First-party fraud is up 40%" tells you nothing on its own. Ask what it counts: loan applications, disputed charges, or both. Visa's own commissioned research concedes it: "This abuse of the dispute system has many names, such as first-party fraud, friendly fraud, and dispute misuse. Regardless of what it is called..."

SentiLink has said it plainly in print. First: "First Party Fraud has differing definitions depending upon who or what company you ask." Then: "The definition of First Party Fraud is confusing and can be interpreted both as (1) credit risk or (2) fraud risk."

Second party: five different definitions

Every source below describes something real. They disagree about how willing the person had to be.

How willing was the account holder?ExampleWho calls this second party
Paid volunteer. Knew, took a cutclassic money muleExperian, TransUnion, SEON, Persona, KYCAID, FraudNet, Sardine
Helping someone. Knew, wasn't paidlending a card to a relativeiDenfy, Linkurious, Persona
Tricked. Handed details over believing a liephishing, fake job adEquifax Canada
Coerced. Under someone else's controltrafficking, an abusive relationshipAlloy, TrustDecision
Not the account holder at allan employee abusing accessAU10TIX, NordVPN

Some of the wording, so you can see the gap:

SourceWhat they say
Experian"An individual knowingly gives their identity or personal information to another person, to commit fraud"
Sardine"fraud enabled by an account holder who knowingly lets someone else use their identity or account." The test is "willing complicity by the account owner"
Persona"essentially permission to engage in 'light identity theft'... both individuals are active participants in the fraud"
KYCAID"an authentic customer willingly shares their identity, account, or device with a criminal... Signals are genuine because, literally, they are. Intent is the issue"
Alloy"one person exerting psychological control over another in order to commit fraud"
AU10TIX"collusion between a member of the organization or business and an external party"
NordVPN"the perpetrator has a pre-existing relationship with the target or is an insider"

Two of those point at opposite people. For Experian, the second party is the customer who handed their details over. For AU10TIX, it's the employee.

And "knowingly" is doing a lot of work. Sardine's test is willing complicity. Read strictly, that drops the person who was tricked by a fake job ad and the person under someone else's control. They handed over the same details, and the money moves the same way. We keep them in, and treat classification and culpability as separate questions.

We take the first four rows and reject the fifth. Handing something over is one act, whatever the reason. It's also something you can observe. An employee abusing access never handed over anything of their own. Insider fraud also has a mature home already, in the ACFE's occupational fraud framework.

Third party: everyone agrees

SourceWhat they say
Experianused "without their consent or knowledge"
TransUnion"the person whose information is being used is unaware and has not given consent"
FICO"an unknown or unauthorized entity commits fraud"
Ethoca (Mastercard)"an unauthorized person gets ahold of someone's payment card information and credentials and makes purchases"
SEON"the use of an individual's details to commit financial crime. Often known as identity theft"
AU10TIX"an external entity, unrelated to the organization or individual"
Sardine"fraud committed with a real victim's stolen identity, credentials, or account, without their knowledge or consent"

FICO and Ethoca both use the word "unauthorized," which is the test we use.

Synthetic: defined, but never filed

The Federal Reserve put 12 fraud experts in a room to settle it. They landed on this: "the use of a combination of personally identifiable information (PII) to fabricate a person or entity in order to commit a dishonest act for personal or financial gain."

SentiLink: "fraudsters combine fictitious and/or real information to create new identities with the intent to defraud."

Notice what the Fed never says: which party bucket it belongs in. That isn't an oversight. Ask "whose identity was it" and there's no answer.

The industry couldn't agree either. FICO ran a LinkedIn poll in September 2020. Its 42 respondents split almost evenly three ways: first party, third party, or its own category. Focal and Linkurious fold it into first party. We keep it separate, and so does the Fed.

Some vendors aren't sorting by actor at all

This is the deepest reason two lists don't line up, and almost nobody names it.

Everything above sorts by who did it. Some vendors sort by when it happened instead: at the application, at the transaction, or on the account afterwards.

Sardine does this. It makes application fraud a class of its own, "lying on the form," and files three things underneath it:

Sardine's subtypeWhere we put it
Stolen identityThird party
Synthetic identityIts own class
First-party fraudFirst party

So one of their classes contains three of ours. Neither list is wrong. They answer different questions, and a term that's a subtype in one is a top-level class in the other.

What to do with that. When a vendor's taxonomy doesn't match yours, check the axis before you argue about definitions. Ask: is this sorted by who, or by when? A lot of what looks like disagreement is one list sorted by actor and another sorted by stage, set side by side as though they measured the same thing.

When a vendor quotes you a number

Ask one question: does that figure count loan applications, disputed charges, or both?

LexisNexis counts both. That's why its numbers look larger than everyone else's. "First-party fraud is 36% of all fraud" measures something different from a chargeback-abuse figure.


By Actor

First-Party Fraud (Your Customer)

The customer is real and uses their own identity, but abuses your policies.

SubtypeDescriptionDefense
Friendly FraudDisputes legitimate purchaseEvidence collection, CE 3.0
Refund FraudExploits return policiesPolicy enforcement
Promo AbuseGames promotions/discountsDevice linking, limits
Insider fraudAn employee abuses their accessRole-based access, reviews

Chargeback outcome: Winnable with proper evidence

Second-Party Fraud (Your Customer, Working For Someone Else)

The real owner handed over their details, card or account. The identity is genuine because it really is genuine. The money goes to somebody else. Most merchants meet this as a marketplace or payout problem rather than at checkout.

SubtypeDescriptionDefense
Money muleAccount exists to receive and forward fundsPayout pattern review, no-trade sellers
Family and friendsA relative uses the card with permissionAsk before treating it as fraud
Talked into itFake job ad, phone scam, romance scamTreat the holder as a victim
Account farmingAged accounts sold on for their historyDormant-then-active review

Chargeback outcome: Rarely a chargeback. It shows up as account closure and payout risk

Watch the line here

Someone talked into handing over their details is second party, because they handed them over. They're also a victim. Classification and culpability are separate questions, and you should answer both.

Third-Party Fraud (Taken, Not Given)

Somebody who was never given access is using the card or identity. It was taken, not handed over. If the owner handed it over, however they were persuaded, that's second party instead.

SubtypeDescriptionDefense
Stolen CardUses compromised card3D Secure, AVS/CVV
Card TestingValidates stolen cardsVelocity rules, CAPTCHA
Account TakeoverHijacks customer accountMFA, behavioral analytics

Chargeback outcome: Hard to win unless you have 3DS liability shift

Fake Identity Fraud

Fraudster creates fabricated or mixed identity information.

SubtypeDescriptionDefense
Fake IdentityFabricated personaIdentity verification
Account FraudFake account signupsEmail/phone verification

Chargeback outcome: Sometimes winnable with identity mismatch evidence

Organized Fraud

This one is a different question. The classes above ask who the actor was. This asks how many. A fraud ring is usually third-party fraud at scale.

SubtypeDescriptionDefense
Fraud RingsMulti-account attacksDevice fingerprinting, consortium data
TriangulationResale scheme using a fake storefrontShipping address analysis

Chargeback outcome: Document network evidence for representment


Classification Decision Tree


Response by Classification

Fraud TypeImmediate ActionPreventionChargeback Strategy
Friendly FraudCollect delivery proofClear descriptors, communicationCE 3.0, device data
Second-PartyReview payouts, close if confirmedPayout change controlsRarely applicable
Third-PartyCancel/refund if caughtEnable 3DSRely on liability shift
Card TestingBlock IP/deviceVelocity limits, CAPTCHAN/A (usually declined)
ATOLock account, notify customerMFA, device recognitionShow account compromise
Refund FraudFlag accountEnforce policiesDocument abuse pattern
Promo AbuseRevoke benefitsDevice linkingN/A (usually internal)
Fraud RingBlock infrastructureDevice fingerprintingShow organized pattern

The Part Nobody Selling Software Will Tell You

A share of what gets counted as first-party fraud isn't fraud. It's people who can't pay.

  • LexisNexis runs a whole category called "distressed consumers," separate from fraud
  • Visa's commissioned research found consumer motivations split roughly evenly between wanting to avoid payment and facing economic hardship
  • LexisNexis again: first-party fraud is "exacerbated by periods of inflation and the rising cost of living"

One more finding, before you build rules around age. The behavior is "not limited to younger demographics."

That matters for policy. A customer in genuine difficulty responds to a payment plan. A serial abuser doesn't. Treat both as fraud and you lose the first group.