Refund Fraud
Refund fraud is a type of payment fraud in which someone abuses a merchant's, government's, or company's return or refund process to obtain money or reimbursement they are not entitled to. This can include falsely claiming a refund for an item that was never purchased or not actually returned, or manipulating the refund process for monetary gain. Related scams may also promise to 'recover' money already lost in exchange for an upfront payment.
Refund fraud (also called return fraud, refund abuse, or refund theft) is a category of payment fraud in which an individual or group manipulates a refund, return, or reimbursement process to obtain funds without legitimate entitlement. Techniques vary and may include claiming reimbursement for products never purchased, returning items with intent formed at time of purchase, exploiting duplicate or counterfeit items, or falsely asserting non-receipt. The evidence describes refund fraud primarily in the merchant and consumer-refund context; note that some sources also apply an umbrella meaning that can extend to government reimbursement schemes such as tax-refund fraud (filing false returns to obtain a government refund), which is a distinct variant with its own controls and authorities. Refund fraud is governed operationally by merchant policy and, where card refunds are involved, by card brand and network rules that vary by region and change over time; it is not addressed by any single dedicated PCI DSS requirement, since PCI DSS focuses on protecting account data rather than refund-process abuse. Detection typically relies on transaction and returns-pattern analytics, which involve false-positive and false-negative trade-offs and do not eliminate fraud on their own.
Why it matters
Refund fraud directly erodes merchant margins because it converts a legitimate customer-service process — the return and refund workflow — into a channel for extracting funds. Unlike some card-not-present fraud that hinges on stolen account data, refund fraud often exploits merchant policy and process weaknesses rather than PCI-scoped account data, which means controls designed to protect cardholder data do not address it. There is no single dedicated PCI DSS requirement aimed solely at refund-process abuse, since PCI DSS focuses on protecting account data; instead, mitigation relies on merchant policy, returns analytics, and, for card refunds, card brand and network rules that vary by region and change over time.
Who it's relevant to
Inside Refund Fraud
Common questions
Answers to the questions practitioners most commonly ask about Refund Fraud.