Discover UA02 - Fraud: Card Not Present
This is the Discover code for a customer denying an online or phone order: UA02. Looking for Visa 10.4, Mastercard 4837 or Amex F29?
Read the code off your notice: a dot means Visa, four digits and no dot is Mastercard, one letter and two digits is Amex. Get that right first, because the response deadline runs from 20 days on Amex to 45 on Mastercard.
- UA02 is Discover's main fraud code for e-commerce and card-not-present orders. The cardholder says they didn't authorize the charge.
- ProtectBuy (Discover's 3D Secure) is the defense that actually works. Full authentication shifts liability to the issuer.
- Without it you're arguing with AVS/CVV results, delivery proof, and device logs. That wins sometimes, not most of the time.
- You get 30 calendar days on the chargeback. Only 14 on a retrieval request.
- The retrieval is the cheaper fight. It's the one people skip.
A cardholder told Discover they didn't place an order you fulfilled. Online, phone, or mail. That's UA02. It's the same complaint as Visa 10.4 and Mastercard 4837. On Discover it's the fraud code you'll see most.
Overview
A cardholder says the charge wasn't theirs, and no card was present. Discover files UA02. That's online checkout, phone orders, mail orders, and anything else where the card never physically showed up. There's no chip read to fall back on. Everything you'll argue with is data you captured at checkout.
When This Code Applies
- Cardholder denies making an online purchase
- Stolen card credentials used for a CNP transaction
- Account takeover resulting in unauthorized orders
- Family member makes purchase without cardholder knowledge
- Friendly fraud (cardholder authorized the purchase but denies it)
Conditions for Valid Dispute
Issuer Must Verify
- Cardholder didn't authorize the transaction
- Transaction happened in a card-not-present environment
- Dispute filed within the allowable time frame
- Cardholder didn't benefit from the transaction
Transaction Must Be
- E-commerce (online checkout)
- Mail order or telephone order (MOTO)
- Recurring billing without proper ProtectBuy authentication
- Any other environment where the card never physically appears
Time Frames
| Stage | Window |
|---|---|
| Retrieval request response | 14 calendar days |
| Chargeback response | 30 calendar days |
| Second chargeback | 30 calendar days |
Discover Retrieval Process
Discover usually sends a retrieval request before the chargeback. That's your first and cheapest line of defense. Answer it well and the chargeback may never happen.
A good retrieval response can stop the chargeback before it exists. You get 14 days. You'd build the same file later anyway.
ProtectBuy (3D Secure) Liability Shift
Full Liability Shift (Issuer Liable)
The issuer eats the loss when all three of these are true:
- ProtectBuy challenge completed by cardholder
- ECI 05 = fully authenticated
- Valid cryptogram present
Who Carries the Loss, by ECI
| Scenario | ECI | Who pays |
|---|---|---|
| Fully authenticated | 05 | Issuer |
| Authentication attempted, issuer unavailable | 06 | Reduced merchant liability |
| Authentication failed or not attempted | 07 | Merchant, in full |
| ProtectBuy not implemented | N/A | Merchant, in full |
Representment Options
1. ProtectBuy Authentication
When to use: ProtectBuy ran and it passed.
Evidence required:
- ECI value showing full authentication (05)
- Cryptogram/CAVV
- Authentication timestamp
- ProtectBuy transaction ID
2. AVS and CVV Match
When to use: AVS and CVV both matched.
Evidence required:
- AVS response showing match (full or partial)
- CVV2/CID match confirmation
- Delivery confirmation to the AVS-verified address
3. Delivery Confirmation
When to use: It got delivered. You've got tracking.
Evidence required:
- Carrier tracking showing delivered status
- Signature confirmation
- Delivery address matching billing or AVS-verified address
- Photo proof of delivery (if available)
4. Digital Goods Access
When to use: They used it. You've got logs.
Evidence required:
- IP address at time of download or access
- Access/usage logs showing activity after purchase
- Account login history
- Download confirmation records
5. Prior Transaction History
When to use: They've bought before and never disputed.
Evidence required:
- Previous undisputed transactions from the same account
- Matching email, device, or IP across transactions
- Established customer relationship documentation
6. Cardholder Communication
When to use: You've got the cardholder on record about the order.
Evidence required:
- Order confirmation sent to and opened by cardholder
- Customer service correspondence about the order
- Chat transcripts or call recordings
- Shipping address confirmation from cardholder
Required Documentation
| Evidence Type | Strength |
|---|---|
| ProtectBuy authenticated (ECI 05) | Very Strong |
| AVS match + CVV match + signed delivery | Strong |
| Tracking delivered + AVS match | Medium-Strong |
| Prior undisputed transactions + device match | Medium |
| No authentication or delivery proof | Very Weak |
Win Rate Expectations
| Defense Type | Expected Win Rate |
|---|---|
| ProtectBuy authenticated (ECI 05) | 70-85% |
| AVS + CVV + delivery proof | 45-60% |
| Prior transaction history + device match | 35-50% |
| Standard evidence only | 25-40% |
| No evidence | Under 15% |
Read that table as a decision, not trivia. Without ProtectBuy your best case is a coin flip.
Prevention Strategies
Authentication
- Turn on ProtectBuy (3D Secure 2.0) - Moves the loss to the issuer
- Run the frictionless flow - Most customers never see it
- Challenge the risky ones - Only when a signal fires
Verification
- Require CVV2 every time - Collect the code, no exceptions
- Check AVS - Every order, not just the big ones
- Verify email addresses - A bounced confirmation is a signal
- Call for the big ones - High-value or high-risk orders
Evidence Collection
- Log everything - IP, device fingerprint, timestamps, session data
- Keep the conversation - Emails, chat logs, call recordings
- Require delivery confirmation - Tracking, plus signature on big orders
- Track account history - Today's boring order is tomorrow's evidence
Fraud Screening
- Real-time scoring - Catch it at checkout, not later
- Velocity checks - Flag ordering patterns that aren't normal
- Device fingerprinting - Match devices across sessions
- Address validation - Cross-check shipping against billing
Common Mistakes
- Skipping ProtectBuy - You're eating avoidable fraud
- No delivery confirmation - You can't prove they got it
- Ignoring retrieval requests - They don't go away, they escalate
- Dumping files on the issuer - A messy packet reads weak
- Not logging device data - No proof they were there
Related Codes
- UA01 - Fraud: Card Present
- UA05 - Fraud: Chip Card Counterfeit
- UA06 - Fraud: Chip Card Lost/Stolen
- UA11 - Cardholder Claims Fraud
Next Steps
Got this chargeback?
- Check whether ProtectBuy ran → ECI 05 and you're in good shape
- Pull AVS/CVV results → Document the match status
- Gather delivery proof → Tracking, signature, address match
- Look for prior undisputed orders → Same device, email, or IP?
- Respond within 30 days → Representment Workflow
Prevent future UA02 chargebacks:
- Implement 3D Secure / ProtectBuy for liability shift
- Set up dispute alerts to refund before chargeback
- Configure fraud detection to catch unauthorized use early
See Also
- 3D Secure Implementation - ProtectBuy setup and configuration
- What proof each network accepts - Evidence requirements
- Friendly Fraud - First-party abuse patterns
- Third-Party Fraud - True unauthorized fraud
- Account Takeover - ATO defense
- Device Fingerprinting - Proving cardholder involvement
- AVS & CVV - Address and security code verification
- Velocity Rules - Fraud pattern detection
- Risk Scoring - Pre-transaction screening
- Chargeback Alerts - Deflect before filing
- Discover Reason Codes - All Discover codes
- Visa 10.4 - CNP Fraud - Visa equivalent
- Mastercard 4837 - Fraud - Mastercard equivalent
- Amex F29 - CNP Fraud - Amex equivalent