First-Party Misuse
First-party misuse occurs when a legitimate cardholder or account holder disputes a charge or manipulates their own account to gain money or goods, rather than a criminal using a stolen identity. A common example is a customer who received a product or service but files a chargeback claiming otherwise. This behavior is often described as 'friendly fraud' because it comes from the account's rightful owner rather than an outside attacker.
First-party misuse refers to disputes or chargebacks initiated by the genuine cardholder or account holder based on false or erroneous claims, or to the manipulation of one's own identity or account for personal or financial gain, as distinct from third-party fraud involving compromised credentials or stolen identities. According to the Merchant Risk Council, first-party misuse can account for a substantial share of fraud-related chargebacks for some merchants, though exact figures depend on source, period, and methodology. Because these disputes originate from the legitimate account holder, they are difficult to detect with controls designed for unauthorized-use fraud, and their handling is governed by card brand and network dispute and chargeback rules, which vary by region and change over time. Note that some sources use the term more broadly to include misconduct originating from within an organization; practitioners should confirm the intended scope in any given context.
Why it matters
First-party misuse is difficult to address because the person initiating the dispute is the legitimate account holder rather than an outside attacker using stolen credentials. Controls designed to detect unauthorized-use fraud, such as device fingerprinting, credential-compromise signals, or checks for stolen identity data, are largely ineffective here because the transaction was genuinely authorized by the rightful cardholder. This means merchants can face financial loss and operational cost even when their upstream fraud defenses are working as intended.
The scale of the problem can be significant for some merchants. According to the Merchant Risk Council, first-party misuse can account for a substantial share of fraud-related chargebacks for some merchant members, though exact figures depend on source, period, and methodology and should not be assumed to apply uniformly across businesses or regions. Because these disputes are resolved under card brand and network dispute and chargeback rules, which vary by region and change over time, the remedies and evidence requirements available to a merchant are not fixed and must be confirmed against current network rules.
Practitioners should also note terminology ambiguity: some sources use "first-party fraud" or "first-party misuse" more broadly to include misconduct originating from within an organization, rather than only cardholder-initiated chargeback abuse. Confirming the intended scope in any given context helps avoid misclassifying the problem and applying the wrong controls or metrics.
Who it's relevant to
Inside First-Party Misuse
Common questions
Answers to the questions practitioners most commonly ask about First-Party Misuse.