Third-Party Fraud
Third-party fraud happens when someone uses another person's identity or account without their permission to gain money, credit, or other resources. The real person whose information was taken is a genuine victim who did not take part in or authorize the activity. Examples include using stolen credit card details or taking over someone else's account.
Third-party fraud refers to financial crimes committed by an unauthorized or unknown entity that appropriates a genuine victim's identity or account credentials, in whole or in part, without consent. It is distinguished from first-party (friendly) fraud, in which the legitimate account holder is complicit, because in third-party fraud the identified individual is a true victim rather than a participant. Common manifestations include identity theft, use of stolen payment card data, and account takeover; the specific mechanism, fraud channel (card-present versus card-not-present), and resulting liability treatment depend on the scenario and are governed by applicable card brand and network rules, which vary by region.
Why it matters
Third-party fraud matters because it involves a genuine victim who did not authorize or participate in the fraudulent activity, which shapes how the incident is investigated, how liability is assigned, and how remediation proceeds. Correctly identifying an event as third-party fraud, rather than first-party (friendly) fraud where the legitimate account holder is complicit, is critical for accurate case handling. Misclassifying one as the other can lead to wrongful denial of a legitimate victim's dispute or, conversely, to absorbing losses that should have been challenged.
For payment security and fraud teams, third-party fraud spans multiple channels and mechanisms, including use of stolen payment card data, identity theft, and account takeover. Because it can occur in both card-present and card-not-present contexts, no single detection or authentication control addresses it fully; each control targets a different point in the transaction and carries its own trade-offs. The resulting liability treatment depends on the specific scenario and is governed by applicable card brand and network rules, which vary by region and change over time, so teams should confirm current rules rather than assume a fixed outcome.
Because exact figures for fraud losses and prevalence depend on the source, period, and methodology, this entry describes the concept qualitatively. Treating third-party fraud as a distinct category helps organizations build proportionate victim-remediation processes, distinguish true victims from complicit account holders, and tune detection controls with an understanding of the false-positive and false-negative trade-offs involved.
Who it's relevant to
Inside Third-Party Fraud
Common questions
Answers to the questions practitioners most commonly ask about Third-Party Fraud.