Skip to main content
Category: Fraud Typologies

Third-Party Fraud

Also known as: 3rd Party Fraud, Third Party Fraud
Simply put

Third-party fraud happens when someone uses another person's identity or account without their permission to gain money, credit, or other resources. The real person whose information was taken is a genuine victim who did not take part in or authorize the activity. Examples include using stolen credit card details or taking over someone else's account.

Formal definition

Third-party fraud refers to financial crimes committed by an unauthorized or unknown entity that appropriates a genuine victim's identity or account credentials, in whole or in part, without consent. It is distinguished from first-party (friendly) fraud, in which the legitimate account holder is complicit, because in third-party fraud the identified individual is a true victim rather than a participant. Common manifestations include identity theft, use of stolen payment card data, and account takeover; the specific mechanism, fraud channel (card-present versus card-not-present), and resulting liability treatment depend on the scenario and are governed by applicable card brand and network rules, which vary by region.

Why it matters

Third-party fraud matters because it involves a genuine victim who did not authorize or participate in the fraudulent activity, which shapes how the incident is investigated, how liability is assigned, and how remediation proceeds. Correctly identifying an event as third-party fraud, rather than first-party (friendly) fraud where the legitimate account holder is complicit, is critical for accurate case handling. Misclassifying one as the other can lead to wrongful denial of a legitimate victim's dispute or, conversely, to absorbing losses that should have been challenged.

For payment security and fraud teams, third-party fraud spans multiple channels and mechanisms, including use of stolen payment card data, identity theft, and account takeover. Because it can occur in both card-present and card-not-present contexts, no single detection or authentication control addresses it fully; each control targets a different point in the transaction and carries its own trade-offs. The resulting liability treatment depends on the specific scenario and is governed by applicable card brand and network rules, which vary by region and change over time, so teams should confirm current rules rather than assume a fixed outcome.

Because exact figures for fraud losses and prevalence depend on the source, period, and methodology, this entry describes the concept qualitatively. Treating third-party fraud as a distinct category helps organizations build proportionate victim-remediation processes, distinguish true victims from complicit account holders, and tune detection controls with an understanding of the false-positive and false-negative trade-offs involved.

Who it's relevant to

Fraud Analysts
Fraud analysts must reliably separate third-party fraud, where the account holder is a genuine victim, from first-party (friendly) fraud, where the holder is complicit. This distinction drives case disposition and affects whether a dispute is treated as a legitimate victim claim, while accepting the false-positive and false-negative trade-offs inherent in detection.
Merchant Risk Teams
Merchant risk teams encounter third-party fraud through use of stolen payment card data across card-present and card-not-present channels. They should assess exposure by channel and confirm how liability is assigned under current card brand and network rules, which vary by region and change over time.
Acquirers and Payment Processors
Acquirers and processors handle disputes and liability flows tied to third-party fraud. Because liability treatment depends on the specific scenario and is governed by applicable card brand and network rules, they should confirm the current, region-specific rules rather than assume a fixed outcome.
Financial Institutions and Issuers
Issuers and financial institutions face third-party fraud through identity theft and account takeover affecting their genuine customers. They need remediation processes that treat affected customers as true victims while distinguishing those cases from first-party fraud claims.

Inside Third-Party Fraud

Definition
Third-party fraud occurs when a fraudster uses the identity, account, or payment credentials of a genuine, unrelated party without that party's knowledge or consent. It is distinguished from first-party (friendly) fraud, in which the legitimate account holder or applicant is the party misrepresenting facts or disputing valid transactions.
Stolen or Compromised Credentials
The fraudster relies on cardholder data (such as PAN, cardholder name, and expiration date) or sensitive authentication data (such as full track data, CAV2/CVC2/CVV2/CID, or PINs and PIN blocks) obtained through breaches, skimming, phishing, or other compromise. Note that sensitive authentication data must not be stored after authorization, even when encrypted.
Account Takeover (ATO)
A form of third-party fraud in which an attacker gains unauthorized access to a victim's existing account, often by defeating or bypassing authentication controls, then transacts or extracts value as if they were the genuine account holder.
Card-Present vs. Card-Not-Present Vectors
Third-party fraud can occur in card-present settings (for example, counterfeit or lost/stolen cards) or in card-not-present settings (for example, e-commerce or mail/telephone order using stolen credentials). The relevant detection and authentication controls differ by channel.
Relationship to Synthetic Identity Fraud
Synthetic identity fraud, which combines real and fabricated identity data to create a new identity, is often categorized separately from classic third-party fraud because there may be no single genuine victim whose intact identity is being impersonated. Classification can vary by institution and reporting methodology.
Liability and Chargeback Context
How liability for a third-party fraud loss is allocated between parties (for example, following a liability shift) is governed by card brand and network rules, which change over time and vary by region. The label 'third-party fraud' does not by itself determine who bears the loss.

Common questions

Answers to the questions practitioners most commonly ask about Third-Party Fraud.

Is third-party fraud the same as first-party or friendly fraud?
No. Third-party fraud involves an unauthorized actor other than the legitimate cardholder using stolen or compromised credentials or identity data to transact. First-party fraud, sometimes called friendly or chargeback fraud, involves the legitimate cardholder or account holder themselves disputing or misrepresenting a transaction they authorized. Because the parties, evidence, and dispute handling differ, conflating the two can lead to misclassified cases, inappropriate chargeback responses, and skewed fraud metrics. Confirm classification against the relevant card brand and network rules, which vary by region and change over time.
Does adding a strong authentication control like 3-D Secure eliminate third-party fraud?
No single control eliminates fraud. 3-D Secure, EMV chip authentication, strong customer authentication, and multi-factor authentication each address different risks at different points in a transaction and may help reduce certain third-party fraud vectors. However, they do not remove all exposure, can shift rather than eliminate risk, and may introduce false positives that affect legitimate customers. Third-party fraud can also migrate to channels or methods not covered by a given control, so these measures are best treated as layered mitigations rather than guarantees.
How should we distinguish third-party fraud from first-party fraud during case investigation?
Look at whether the transacting party is the legitimate account holder or an unauthorized actor. Indicators that may suggest third-party fraud include credentials or identity data that appear compromised, device and location signals inconsistent with the genuine customer, and the cardholder disclaiming any knowledge of the transaction. Because these signals produce both false positives and false negatives, corroborate with multiple data points and align the final classification with the applicable card brand and network dispute rules, which vary by region.
What data handling considerations apply when investigating third-party fraud cases?
Investigations often touch cardholder data such as the PAN, cardholder name, expiration date, and service code, which may be stored only under defined controls. Sensitive authentication data, including full track data, CAV2/CVC2/CVV2/CID, and PINs or PIN blocks, must not be stored after authorization, even when encrypted. Apply truncation, masking, tokenization, or encryption as appropriate to limit exposure of data used in case files, and confirm handling requirements against the current published PCI DSS rather than assuming a fixed requirement number.
How can detection controls for third-party fraud be tuned without harming legitimate customers?
Any detection control involves a trade-off between false positives, which decline or challenge genuine customers, and false negatives, which allow fraudulent activity through. Tuning typically involves layering signals, calibrating thresholds against observed outcomes for your portfolio, and monitoring approval and decline rates alongside confirmed fraud and dispute results. Because effectiveness depends on your data, channels, and population, evaluate changes over time rather than assuming a static configuration performs consistently.
How do liability and chargeback outcomes differ for third-party fraud versus other fraud types?
Liability shift and chargeback outcomes for third-party fraud are governed by card brand and network rules, which vary by region and change over time. Factors that may influence outcome include whether authentication such as EMV chip or 3-D Secure was used, the channel (card-present versus card-not-present), and the evidence supporting the dispute. Because these rules are not uniform, confirm the applicable current network requirements for each case rather than assuming a fixed liability result.

Common misconceptions

All disputed or fraudulent-looking transactions are third-party fraud.
Many disputes stem from first-party (friendly) fraud, where the legitimate account holder disputes a valid transaction, or from chargeback abuse. Third-party fraud specifically involves an unrelated party using a genuine victim's identity or credentials without consent, and misclassifying the two leads to incorrect controls and loss allocation.
A single authentication control, such as 3-D Secure or EMV chip authentication, stops third-party fraud.
EMV chip authentication, 3-D Secure, strong customer authentication, and multi-factor authentication address different risks at different points in a transaction. Each may help reduce specific fraud vectors but none eliminates fraud, and card-not-present or account-takeover scenarios can persist despite one control being present.
Detecting third-party fraud is simply a matter of tuning a rule or model to catch it.
Detection controls involve false-positive and false-negative trade-offs; tighter rules may block legitimate customers while looser settings let fraud through. Effective programs balance detection sensitivity against customer friction and revenue impact, and outcomes depend on data quality and channel.

Best practices

Classify fraud cases consistently as third-party, first-party/friendly, account takeover, or synthetic identity, since misclassification distorts loss metrics and drives the wrong remediation.
Apply channel-appropriate authentication—for example, EMV chip authentication for card-present, and 3-D Secure or strong customer authentication for card-not-present—recognizing that these address different risks and none alone eliminates fraud.
Ensure sensitive authentication data (full track data, CAV2/CVC2/CVV2/CID, PINs and PIN blocks) is not stored after authorization, and protect stored cardholder data under defined controls to limit the credential supply that enables third-party fraud.
Monitor for account takeover indicators such as unusual login, credential changes, and out-of-pattern transactions, while measuring and managing false-positive and false-negative rates to balance security against customer friction.
Confirm liability and chargeback handling against the current, region-specific card brand and network rules rather than assuming a fixed outcome from the fraud label alone.
Validate the scope-reduction effect of any tokenization, encryption, truncation, masking, or hashing based on its actual implementation and validation, not on the technique's name, when protecting the data targeted by third-party fraud.