Fraud Classification
- First party: the person is lying. Own identity, own details, false claim
- Second party: they handed it over. Mule, family member, or someone talked into it
- Third party: nobody gave them anything. It was taken
- Synthetic: there's no real person behind it
- Your response differs: 3DS for third party, evidence for friendly fraud, payout controls for second party
- The industry doesn't agree on any of this. Every competing definition is quoted below, so you can check us
This is the reference page for fraud classification. Other pages give a short definition and link here.
We take a position below. Then we show every competing definition we found, so you can judge it.
Quick Classification
| What You See | Likely Type | Your Response |
|---|---|---|
| Customer disputes legitimate purchase | Friendly Fraud | Collect evidence, fight with CE 3.0 |
| Card used by someone who was never given access | Third-Party Fraud | Enable 3DS for liability shift |
| Same device, many accounts | Fraud Ring | Device fingerprinting, block infrastructure |
| Burst of small transactions | Card Testing | Velocity rules, CAPTCHA |
| Good customer acting strange | Account Takeover | MFA, behavioral analytics |
| Excessive returns/refunds | Refund Fraud | Policy enforcement, tracking |
| Promo/coupon abuse | Promo Abuse | Device linking, limits |
| Fake account signups | Account Fraud | Email/phone verification |
| Mismatched identity info | Fake Identity | Identity verification |
The Four Types, Defined
We're going to be direct about this, because most sources aren't.
| Type | The test | In one line |
|---|---|---|
| First party | Is the person lying? | They're using their own identity, not hiding who they are, and lying about something |
| Second party | Did they hand it over? | The real owner gave their details, card or account to someone else |
| Third party | Were they authorized? | Somebody who was never given access is using it |
| Synthetic | Is this a real person? | An identity built from real and fake pieces, made to deceive |
First party: the person is lying
They aren't hiding who they are. Their name is their name, their address is their address. The lie is about something else.
Two shapes, and they're the same act:
- Lying about facts. Inflating income on an application, misstating what a business does
- Lying about an event. Saying they didn't make a purchase they made
That second one is what most merchants meet, and it's usually called friendly fraud.
A customer who borrows and can't pay hasn't lied. That's credit risk, and it's a pricing problem rather than a fraud problem. A customer who lied to get the money committed fraud. The lie is the line, and plenty of published definitions blur it.
Second party: they handed it over
Someone gave their identity, card, account or device to another person. The details are genuine because they really are genuine. The owner participated.
Why they did it varies enormously, and the reason doesn't change the classification:
| Situation | Still second party? |
|---|---|
| Paid to let their account move money (a money mule) | Yes |
| Lent a card to a parent, sibling or partner | Yes |
| Talked into it on the phone, or by a fake job ad | Yes |
| Pressured or controlled by someone else | Yes |
| An employee abusing internal access | No. That's insider fraud, and it goes under first party |
Second party covers people who were paid and people who were tricked. Same classification, completely different culpability. Say which one you're looking at, separately.
Somebody deceived by a phone call still handed their details over. That's second party. They're also a victim. Both are true.
Third party: nobody gave them anything
The person using the card or identity was never given access to it. It was taken, not handed over. Stolen card data, a breached account, a hijacked login.
That's the whole difference from second party. Did the owner hand it over, or did somebody take it?
Synthetic: there's no real person
An identity assembled from real and fabricated details. It's built to look like someone who doesn't exist. There's no victim to notify and no cardholder to call. Nobody's identity was fully used.
Two forms, using the Federal Reserve's terms:
| Term | What it is | Also called |
|---|---|---|
| Manipulated | A real person using a substantially different SSN or key detail | First-party synthetic, hybrid |
| Fabricated | No real person behind it at all | Third-party synthetic, full |
Worked example: "my family member used my card"
This is the most common ambiguous case a merchant sees, and it lands in a different class depending on one fact. Most sources file it all as friendly fraud. That's wrong, and it changes what you should do.
| What actually happened | Class | What you do |
|---|---|---|
| Cardholder gave the card to a relative, then disputed the charge | First party | They're lying. Fight it with evidence |
| Cardholder gave the card to a relative, and genuinely forgot | First party, but not deliberate | Still their charge. Usually cheaper to refund and fix your descriptor |
| Cardholder knowingly let a relative use it to move money | Second party | Treat as mule risk, not a dispute |
| Relative took the card without asking | Third party | A real unauthorized use. The cardholder is a victim |
Amex names this on its own merchant material, describing charges made by "family or staff." A large share of what merchants log as fraud is a second cardholder in the same house or business, and much of that isn't fraud at all.
The question to ask, and it's one question: did the cardholder hand the card over?
Does the Rest of the Industry Agree?
Mostly yes on first, third and synthetic. Not at all on second. Here's the evidence, so you can check us.
Key Fact: the card networks lead with this vocabulary in marketing. They barely use it in their rules. Both Visa and Mastercard say "first-party misuse" publicly. It appears nowhere in Visa's 925-page Core Rules. Nor in Mastercard's rules, nor its 1,153-page chargeback guide. So "the networks define it this way" means someone is quoting a brochure.
Where the numbering comes from
This explains most of the confusion. A normal transaction has two parties: you and your customer.
| Party | Who that is |
|---|---|
| First party | your customer |
| Second party | you, the merchant |
| Third party | an outsider who was never in the transaction |
So read strictly, "second-party fraud" should mean fraud committed by the merchant. Nobody uses it that way. The term got invented later, for a real problem that needed a name. It landed in a slot that was already taken. That's why no two sources define it the same way.
First party: two camps, one act
Lenders describe the application.
| Source | What they say |
|---|---|
| Experian | "an individual who makes a promise of future repayment in exchange for goods / services without the intent to repay" |
| TransUnion | "misrepresenting one's personal information in order to receive a product or service to which they have no entitlement." Also calls it "credit muling" |
| Equifax | "an individual intentionally misrepresents their identity and/or gives false information for financial or material gain" |
| Socure | "the use of one's own identity to open an account and/or commit a dishonest act for personal or financial gain" |
| DataVisor | "the fraudster is not misrepresenting who they are, but rather, they're being deceptive about their information, and their intentions" |
Payments people describe the dispute.
| Source | What they say |
|---|---|
| Ethoca (Mastercard) | first-party fraud and friendly fraud "mean the same thing and are often used interchangeably. It's when a customer identifies a legitimate purchase on their transaction statement as fraudulent and disputes it" |
| Mastercard | "When cardholders dispute a genuine transaction, that's first-party misuse or 'friendly' fraud" |
| Sift | "chargeback fraud, dispute fraud, first-party fraud, first-party misuse, and friendly fraud all describe when an authorized cardholder makes a purchase... and later claims that the purchase was fraudulent" |
| Signifyd | "any type of fraud that involves using a real, genuine identity to defraud an ecommerce company" |
| Forter | "also known as friendly fraud... where actual customers commit fraud by disputing legitimate transactions" |
| BioCatch | "commonly known as friendly fraud, occurs when a customer consciously disputes a transaction to avoid payment or gain a refund" |
Those look like two definitions. They're one act seen at two moments. Lying about your income and lying about a purchase are both lying. Both use your own real identity. That's why we test for the lie instead of picking a camp.
It matters when you read a number. "First-party fraud is up 40%" tells you nothing on its own. Ask what it counts: loan applications, disputed charges, or both. Visa's own commissioned research concedes it: "This abuse of the dispute system has many names, such as first-party fraud, friendly fraud, and dispute misuse. Regardless of what it is called..."
SentiLink has said it plainly in print. First: "First Party Fraud has differing definitions depending upon who or what company you ask." Then: "The definition of First Party Fraud is confusing and can be interpreted both as (1) credit risk or (2) fraud risk."
Second party: five different definitions
Every source below describes something real. They disagree about how willing the person had to be.
| How willing was the account holder? | Example | Who calls this second party |
|---|---|---|
| Paid volunteer. Knew, took a cut | classic money mule | Experian, TransUnion, SEON, Persona, KYCAID, FraudNet, Sardine |
| Helping someone. Knew, wasn't paid | lending a card to a relative | iDenfy, Linkurious, Persona |
| Tricked. Handed details over believing a lie | phishing, fake job ad | Equifax Canada |
| Coerced. Under someone else's control | trafficking, an abusive relationship | Alloy, TrustDecision |
| Not the account holder at all | an employee abusing access | AU10TIX, NordVPN |
Some of the wording, so you can see the gap:
| Source | What they say |
|---|---|
| Experian | "An individual knowingly gives their identity or personal information to another person, to commit fraud" |
| Sardine | "fraud enabled by an account holder who knowingly lets someone else use their identity or account." The test is "willing complicity by the account owner" |
| Persona | "essentially permission to engage in 'light identity theft'... both individuals are active participants in the fraud" |
| KYCAID | "an authentic customer willingly shares their identity, account, or device with a criminal... Signals are genuine because, literally, they are. Intent is the issue" |
| Alloy | "one person exerting psychological control over another in order to commit fraud" |
| AU10TIX | "collusion between a member of the organization or business and an external party" |
| NordVPN | "the perpetrator has a pre-existing relationship with the target or is an insider" |
Two of those point at opposite people. For Experian, the second party is the customer who handed their details over. For AU10TIX, it's the employee.
And "knowingly" is doing a lot of work. Sardine's test is willing complicity. Read strictly, that drops the person who was tricked by a fake job ad and the person under someone else's control. They handed over the same details, and the money moves the same way. We keep them in, and treat classification and culpability as separate questions.
We take the first four rows and reject the fifth. Handing something over is one act, whatever the reason. It's also something you can observe. An employee abusing access never handed over anything of their own. Insider fraud also has a mature home already, in the ACFE's occupational fraud framework.
Third party: everyone agrees
| Source | What they say |
|---|---|
| Experian | used "without their consent or knowledge" |
| TransUnion | "the person whose information is being used is unaware and has not given consent" |
| FICO | "an unknown or unauthorized entity commits fraud" |
| Ethoca (Mastercard) | "an unauthorized person gets ahold of someone's payment card information and credentials and makes purchases" |
| SEON | "the use of an individual's details to commit financial crime. Often known as identity theft" |
| AU10TIX | "an external entity, unrelated to the organization or individual" |
| Sardine | "fraud committed with a real victim's stolen identity, credentials, or account, without their knowledge or consent" |
FICO and Ethoca both use the word "unauthorized," which is the test we use.
Synthetic: defined, but never filed
The Federal Reserve put 12 fraud experts in a room to settle it. They landed on this: "the use of a combination of personally identifiable information (PII) to fabricate a person or entity in order to commit a dishonest act for personal or financial gain."
SentiLink: "fraudsters combine fictitious and/or real information to create new identities with the intent to defraud."
Notice what the Fed never says: which party bucket it belongs in. That isn't an oversight. Ask "whose identity was it" and there's no answer.
The industry couldn't agree either. FICO ran a LinkedIn poll in September 2020. Its 42 respondents split almost evenly three ways: first party, third party, or its own category. Focal and Linkurious fold it into first party. We keep it separate, and so does the Fed.
Some vendors aren't sorting by actor at all
This is the deepest reason two lists don't line up, and almost nobody names it.
Everything above sorts by who did it. Some vendors sort by when it happened instead: at the application, at the transaction, or on the account afterwards.
Sardine does this. It makes application fraud a class of its own, "lying on the form," and files three things underneath it:
| Sardine's subtype | Where we put it |
|---|---|
| Stolen identity | Third party |
| Synthetic identity | Its own class |
| First-party fraud | First party |
So one of their classes contains three of ours. Neither list is wrong. They answer different questions, and a term that's a subtype in one is a top-level class in the other.
What to do with that. When a vendor's taxonomy doesn't match yours, check the axis before you argue about definitions. Ask: is this sorted by who, or by when? A lot of what looks like disagreement is one list sorted by actor and another sorted by stage, set side by side as though they measured the same thing.
Ask one question: does that figure count loan applications, disputed charges, or both?
LexisNexis counts both. That's why its numbers look larger than everyone else's. "First-party fraud is 36% of all fraud" measures something different from a chargeback-abuse figure.
By Actor
First-Party Fraud (Your Customer)
The customer is real and uses their own identity, but abuses your policies.
| Subtype | Description | Defense |
|---|---|---|
| Friendly Fraud | Disputes legitimate purchase | Evidence collection, CE 3.0 |
| Refund Fraud | Exploits return policies | Policy enforcement |
| Promo Abuse | Games promotions/discounts | Device linking, limits |
| Insider fraud | An employee abuses their access | Role-based access, reviews |
Chargeback outcome: Winnable with proper evidence
Second-Party Fraud (Your Customer, Working For Someone Else)
The real owner handed over their details, card or account. The identity is genuine because it really is genuine. The money goes to somebody else. Most merchants meet this as a marketplace or payout problem rather than at checkout.
| Subtype | Description | Defense |
|---|---|---|
| Money mule | Account exists to receive and forward funds | Payout pattern review, no-trade sellers |
| Family and friends | A relative uses the card with permission | Ask before treating it as fraud |
| Talked into it | Fake job ad, phone scam, romance scam | Treat the holder as a victim |
| Account farming | Aged accounts sold on for their history | Dormant-then-active review |
Chargeback outcome: Rarely a chargeback. It shows up as account closure and payout risk
Someone talked into handing over their details is second party, because they handed them over. They're also a victim. Classification and culpability are separate questions, and you should answer both.
Third-Party Fraud (Taken, Not Given)
Somebody who was never given access is using the card or identity. It was taken, not handed over. If the owner handed it over, however they were persuaded, that's second party instead.
| Subtype | Description | Defense |
|---|---|---|
| Stolen Card | Uses compromised card | 3D Secure, AVS/CVV |
| Card Testing | Validates stolen cards | Velocity rules, CAPTCHA |
| Account Takeover | Hijacks customer account | MFA, behavioral analytics |
Chargeback outcome: Hard to win unless you have 3DS liability shift
Fake Identity Fraud
Fraudster creates fabricated or mixed identity information.
| Subtype | Description | Defense |
|---|---|---|
| Fake Identity | Fabricated persona | Identity verification |
| Account Fraud | Fake account signups | Email/phone verification |
Chargeback outcome: Sometimes winnable with identity mismatch evidence
Organized Fraud
This one is a different question. The classes above ask who the actor was. This asks how many. A fraud ring is usually third-party fraud at scale.
| Subtype | Description | Defense |
|---|---|---|
| Fraud Rings | Multi-account attacks | Device fingerprinting, consortium data |
| Triangulation | Resale scheme using a fake storefront | Shipping address analysis |
Chargeback outcome: Document network evidence for representment
Classification Decision Tree
Response by Classification
| Fraud Type | Immediate Action | Prevention | Chargeback Strategy |
|---|---|---|---|
| Friendly Fraud | Collect delivery proof | Clear descriptors, communication | CE 3.0, device data |
| Second-Party | Review payouts, close if confirmed | Payout change controls | Rarely applicable |
| Third-Party | Cancel/refund if caught | Enable 3DS | Rely on liability shift |
| Card Testing | Block IP/device | Velocity limits, CAPTCHA | N/A (usually declined) |
| ATO | Lock account, notify customer | MFA, device recognition | Show account compromise |
| Refund Fraud | Flag account | Enforce policies | Document abuse pattern |
| Promo Abuse | Revoke benefits | Device linking | N/A (usually internal) |
| Fraud Ring | Block infrastructure | Device fingerprinting | Show organized pattern |
The Part Nobody Selling Software Will Tell You
A share of what gets counted as first-party fraud isn't fraud. It's people who can't pay.
- LexisNexis runs a whole category called "distressed consumers," separate from fraud
- Visa's commissioned research found consumer motivations split roughly evenly between wanting to avoid payment and facing economic hardship
- LexisNexis again: first-party fraud is "exacerbated by periods of inflation and the rising cost of living"
One more finding, before you build rules around age. The behavior is "not limited to younger demographics."
That matters for policy. A customer in genuine difficulty responds to a payment plan. A serial abuser doesn't. Treat both as fraud and you lose the first group.
Related Topics
- Fraud Types Overview - Detailed guides for each type
- First-Party Fraud - Customer abuse in detail
- Third-Party Fraud - Used without consent
- Friendly Fraud - Customer disputes
- Fake Identity Fraud - Fabricated personas
- 3D Secure - Liability shift for third-party fraud
- Device Fingerprinting - Linking fraud cases
- Compelling Evidence - Fighting chargebacks