Skip to main content
Category: Chargebacks and Disputes

Friendly Fraud

Also known as: First-party fraud, Chargeback fraud
Simply put

Friendly fraud happens when a real cardholder buys something and then disputes the charge with their bank, claiming it was unauthorized or fraudulent even though the purchase was legitimate. This is often done to get money back while keeping the goods or services. In some cases, it can overlap with genuine unauthorized use, such as when a card or account was actually used by someone else without permission.

Formal definition

Friendly fraud, sometimes referred to as chargeback fraud or first-party fraud, is a form of payment fraud in which a legitimate cardholder disputes a valid transaction through the issuer's chargeback process rather than seeking resolution or a refund directly from the merchant. The disputed purchase was authorized and completed by the cardholder or an authorized user, but is later claimed as fraudulent or unauthorized, often to retain the goods or services while recovering funds. Practitioners should distinguish friendly fraud from true third-party card-not-present or card-present fraud, where the transaction was genuinely conducted without the cardholder's consent; evidence indicates that some cases classified as friendly fraud may involve actual unauthorized use of stolen card or account credentials, making intent and classification difficult to determine. Dispute handling, representment, and liability outcomes are governed by card brand and network rules, which vary by region and change over time.

Why it matters

Friendly fraud is difficult for merchants and issuers to detect because the disputing party is the genuine cardholder rather than an external attacker. Unlike third-party card-not-present or card-present fraud, where credentials are used without the cardholder's consent, friendly fraud involves a transaction that was authorized and completed by the cardholder or an authorized user, then later claimed as unauthorized. This blurs the line between legitimate disputes and abuse of the chargeback process, and it can result in merchants losing both the goods or services and the associated revenue when a chargeback is upheld.

Classification is a persistent challenge. Evidence indicates that some cases labeled as friendly fraud may involve actual unauthorized use of stolen card or account credentials, meaning a customer may genuinely not recognize a charge. Because intent is often impossible to establish with certainty, treating all disputes as deliberate abuse risks penalizing legitimate cardholders, while treating none as abuse leaves merchants exposed. This trade-off between false positives and false negatives makes friendly fraud harder to address than many external fraud types.

Dispute handling, representment, and liability outcomes are governed by card brand and network rules, which vary by region and change over time. As a result, the tools available to contest a chargeback, the evidence required, and the ultimate allocation of liability are not fixed and should be confirmed against current, region-specific network rules rather than assumed.

Who it's relevant to

Merchant Risk and Fraud Teams
These teams bear the direct financial impact when a chargeback is upheld and must weigh the cost of contesting disputes against the risk of alienating genuine cardholders. Because intent is often unclear and some disputes reflect true unauthorized use, they must build processes that distinguish abusive claims from legitimate ones without over-flagging real customers.
Acquirers and Payment Processors
Acquirers and processors facilitate representment and dispute handling on behalf of merchants and must apply the card brand and network rules that govern liability and evidence requirements. Since these rules vary by region and change over time, they need to keep dispute workflows aligned with the current published rules of the relevant networks.
Issuers and Cardholder Dispute Handlers
Issuers receive and adjudicate the initial dispute and must balance protecting cardholders who may have experienced genuine unauthorized use against the possibility of first-party abuse. Because a customer's credentials may in fact have been stolen, issuers cannot assume every dispute is either legitimate or fraudulent without further evaluation.
Fraud Analysts
Analysts classifying disputes must recognize that friendly fraud overlaps with true card-not-present and card-present fraud, making intent and categorization difficult. Misclassification affects fraud metrics and downstream detection models, so analysts should treat classification as uncertain rather than definitive when supporting evidence of intent is absent.

Inside Friendly Fraud

First-Party Misuse
Friendly fraud, also called first-party fraud, occurs when a legitimate cardholder (or an authorized user of the account) disputes a genuine, authorized transaction as unauthorized or otherwise improper, seeking a chargeback rather than resolving the issue with the merchant.
Chargeback Mechanism
The dispute is processed through the card brand and network chargeback rules, which vary by region and change over time. Friendly fraud typically exploits the chargeback process rather than any technical compromise of cardholder data.
Intent Spectrum
Friendly fraud spans a range from deliberate abuse (knowingly disputing a valid purchase to obtain goods or services for free) to non-malicious disputes (buyer's remorse, unrecognized descriptors, forgotten purchases, or family-member use). Distinguishing intent is difficult and often not directly observable.
Distinction From Other Fraud Types
Friendly fraud differs from card-not-present fraud involving stolen credentials, account takeover, and synthetic identity fraud, because the transaction was genuinely authorized by the rightful account holder. It is often categorized separately as chargeback fraud when the dispute is used to reverse a legitimate charge.
Merchant Impact and Evidence
Merchants may contest disputes through representment, submitting compelling evidence permitted under the applicable network rules. Whether a dispute is reversed depends on card brand and network rules, which vary by region and change over time.

Common questions

Answers to the questions practitioners most commonly ask about Friendly Fraud.

Is friendly fraud always intentional theft by the cardholder?
No. Friendly fraud, sometimes called first-party fraud, covers a spectrum of behavior. Some disputes are deliberate attempts to obtain goods or services while reclaiming payment, but many arise from genuine confusion, such as an unrecognized merchant descriptor, a forgotten recurring charge, a purchase made by a family member, or a buyer's remorse dispute filed instead of requesting a refund. Because intent is difficult to establish from transaction data alone, treating every case as deliberate fraud can misclassify legitimate confusion, so many teams distinguish intent qualitatively rather than assuming it.
Does friendly fraud mean the merchant did something wrong or failed a security control?
Not necessarily. Friendly fraud typically involves a transaction the legitimate cardholder authorized, so it is not primarily a failure of authentication or a payment security control such as EMV chip authentication or 3-D Secure. Those controls address unauthorized use and, where applicable, can influence liability under card brand and network rules, but they are not designed to resolve disputes where the genuine account holder later contests a charge they made. Friendly fraud is largely a disputes, evidence, and customer-experience problem rather than a breach of cardholder data or an access-control weakness.
How can a merchant gather evidence to represent a friendly fraud chargeback?
Merchants typically compile records that tie the transaction to the cardholder and to fulfillment, which may include order confirmations, delivery or access logs, IP and device information, prior purchase history, communications, and evidence the customer used the goods or services. The specific evidence accepted, the representment process, and applicable time frames are governed by card brand and network rules, which vary by region and change over time, so teams should confirm current requirements for the relevant network. Compelling evidence programs offered by some networks may apply to certain card-not-present dispute categories, subject to their published conditions.
What operational steps may help reduce the incidence of friendly fraud?
Common measures are intended to reduce confusion and remove reasons to dispute rather than to authorize transactions: using a clear, recognizable billing descriptor; sending order and shipping confirmations; making refund and cancellation paths easy to find; and providing responsive customer support before a dispute is filed. For recurring billing, advance renewal notices and easy cancellation may reduce disputes over subscriptions. These measures may mitigate volume but do not eliminate friendly fraud, and their effectiveness varies by merchant, product, and customer base.
How should a fraud team distinguish friendly fraud from account takeover or true unauthorized use?
The distinction turns on whether the legitimate account holder authorized the transaction. Account takeover and true card-not-present fraud involve a third party acting without authorization, often visible through anomalous device, location, credential, or behavioral signals. Friendly fraud generally shows signals consistent with the genuine cardholder, such as a known device, matching history, and normal usage. Because these indicators can overlap, classification is probabilistic and carries false-positive and false-negative trade-offs; teams often review disputed cases individually rather than relying on a single indicator.
Can automated detection reliably flag friendly fraud at the point of transaction?
Detection at authorization is limited because friendly fraud usually looks legitimate at purchase time, with the dispute arising later. Models may score post-purchase dispute risk using historical dispute behavior, product category, and customer patterns, but such scoring produces both false positives, which can penalize good customers, and false negatives, which miss disputes. These tools are intended to prioritize review and inform decisions rather than to identify intent definitively, and their accuracy depends on data quality, tuning, and the population being scored.

Common misconceptions

Friendly fraud results from a data breach or stolen card data, so stronger encryption or tokenization would stop it.
Friendly fraud involves transactions genuinely authorized by the legitimate cardholder, so controls that protect cardholder data at rest or in transit do not address it. It is a dispute-process abuse rather than a data-compromise event.
Authentication controls such as 3-D Secure or strong customer authentication prevent friendly fraud.
These controls help reduce unauthorized card-not-present fraud by verifying the transacting party, but because friendly fraud is initiated by the legitimate account holder, authentication may not eliminate it. Any liability shift associated with such authentication is governed by card brand and network rules, which vary by region and change over time.
Every friendly fraud dispute is deliberate theft by the customer.
Disputes range from intentional abuse to honest confusion, such as unrecognized billing descriptors or purchases made by a family member. Intent is difficult to determine, and treating all disputes as malicious can increase false positives and harm legitimate customers.

Best practices

Use clear, recognizable billing descriptors and transaction details so cardholders are less likely to file disputes over unrecognized charges.
Retain order records, delivery confirmation, and customer communications that may serve as compelling evidence for representment under the applicable card brand and network rules, confirming current requirements against the relevant network documentation.
Provide accessible customer support and straightforward refund and cancellation paths to help resolve issues before they escalate to chargebacks.
Analyze dispute patterns to distinguish likely first-party misuse from honest confusion, recognizing that intent is difficult to determine and detection carries false-positive and false-negative trade-offs.
Where appropriate, apply authentication measures such as 3-D Secure to reduce unauthorized card-not-present fraud, while confirming any associated liability treatment against current, region-specific network rules and not relying on it to eliminate friendly fraud.
Monitor chargeback ratios and coordinate with acquirers on program thresholds, keeping in mind that chargeback and dispute rules are set by card brands and networks and vary by region and over time.