Skip to main content
Category: Fraud Typologies

True Fraud

Also known as: Third-Party Fraud
Simply put

True fraud is when a criminal uses someone else's stolen card information to make purchases the real cardholder never authorized. Unlike disputes where the actual cardholder is involved, true fraud is committed by an outside bad actor who is not the legitimate account holder. It is often referred to as third-party fraud because a third party, rather than the cardholder or the merchant, is responsible for the deception.

Formal definition

True fraud, commonly categorized as a form of third-party fraud, refers to unauthorized transactions in which a bad actor uses stolen or compromised card credentials to make purchases without the legitimate cardholder's authorization. It is distinguished from first-party or friendly fraud, in which the actual cardholder disputes a genuine purchase, and from chargeback fraud, where a cardholder falsely claims a legitimate transaction as unauthorized. True fraud may occur in card-not-present or card-present contexts, including techniques such as inducing a clerk to manually key in a fake or doctored card to bypass fraud flagging. Liability outcomes for such fraud are governed by card brand and network rules, which vary by region and change over time and are outside the scope of this definition.

Why it matters

True fraud represents the category of unauthorized activity that most people picture when they think of payment fraud: a criminal, not the legitimate cardholder, uses stolen or compromised card credentials to make purchases the real account holder never approved. Distinguishing it from first-party or friendly fraud matters operationally because the response, evidence, and liability outcomes differ. When a genuine third-party criminal is involved, merchants and issuers are dealing with compromised data and an external bad actor, whereas friendly or chargeback fraud involves the actual cardholder disputing a purchase. Misclassifying one as the other can lead to wasted investigation effort, incorrect liability handling, and skewed fraud metrics.

Who it's relevant to

Fraud Analysts and Merchant Risk Teams
Analysts must separate true fraud from first-party or friendly fraud when reviewing disputes, because each requires different evidence and handling. Accurately tagging true fraud helps calibrate detection rules and interpret false-positive and false-negative trade-offs rather than conflating unrelated dispute types in the same metrics.
Issuers and Acquirers
Issuers and acquirers apply card brand and network rules to determine liability for unauthorized third-party transactions. Because those rules vary by region and change over time, correctly identifying a transaction as true fraud rather than a cardholder-initiated dispute is a prerequisite to routing it under the appropriate process.
Merchants and Point-of-Sale Operators
Merchants accepting card-present transactions should be aware of techniques such as convincing a clerk to manually key in a fake or doctored card to bypass fraud flagging. Staff training and checkout procedures can help reduce exposure to this form of true fraud, though they do not remove the risk entirely.
Compliance and Payment Security Officers
Those overseeing payment security benefit from precise fraud taxonomy when reporting on losses and evaluating controls. Distinguishing true fraud (third-party) from friendly and chargeback fraud (cardholder-initiated) supports clearer communication with card brands, networks, and internal stakeholders.

Inside True Fraud

Third-Party Fraud
True fraud, often called third-party fraud, refers to unauthorized transactions carried out by someone other than the legitimate cardholder or account owner. It is distinguished from first-party or friendly fraud, in which the genuine cardholder disputes a transaction they actually authorized.
Unauthorized Use of Cardholder Credentials
This category involves the use of a payment card, card credentials, or account details without the consent of the rightful owner. It can arise from stolen or compromised cardholder data such as PAN, expiration date, and, where obtained, sensitive authentication data like CVV2/CVC2 or track data that should not be stored after authorization.
Card-Present Scenarios
True fraud can occur in card-present environments, for example through lost or stolen cards or counterfeit cards. EMV chip authentication is intended to make counterfeiting more difficult, though it does not address card-not-present channels.
Card-Not-Present Scenarios
In card-not-present channels such as e-commerce or telephone orders, true fraud typically relies on compromised card data used without the owner's knowledge. Controls such as 3-D Secure and, in applicable regions, strong customer authentication are intended to help reduce this risk at the authentication stage.
Relationship to Account Takeover
Account takeover, in which an attacker gains control of a legitimate account, is a mechanism through which true fraud can be committed, since the resulting transactions are unauthorized by the genuine owner.
Liability and Chargeback Treatment
How true fraud is classified, disputed, and allocated between parties is governed by card brand and network rules, including any applicable liability shift. These rules vary by region and change over time, so specifics should be confirmed against current network documentation.

Common questions

Answers to the questions practitioners most commonly ask about True Fraud.

Is true fraud the same as any transaction a cardholder disputes?
No. True fraud refers to unauthorized use of a payment credential by someone other than the legitimate cardholder or account holder, such as card-not-present fraud using stolen card data or account takeover. Not every disputed transaction is true fraud. Some disputes arise from friendly or first-party fraud, where the legitimate cardholder made or authorized the purchase and later disputes it, and others stem from processing errors or unrecognized descriptors. Distinguishing true fraud from these categories matters because they have different root causes and mitigations.
Does a chargeback marked as fraud confirm that true fraud occurred?
Not necessarily. A chargeback filed under a fraud-related reason code reflects a claim routed through card brand and network dispute rules, not an independent confirmation that unauthorized use took place. Some fraud-coded chargebacks are actually first-party or chargeback fraud. Chargeback reason codes, liability, and dispute procedures are governed by card brand and network rules, which change and vary by region, so a fraud reason code should be treated as an assertion to be evaluated rather than as proof of true fraud.
How can teams distinguish true fraud from first-party fraud in their data?
Teams typically combine dispute reason codes with supporting signals such as device, IP, shipping and billing consistency, prior order history, delivery confirmation, and authentication results. Patterns where the legitimate account holder appears to have transacted and later disputes may indicate first-party fraud rather than true fraud. This separation is an analytical judgment that depends on available evidence, and misclassification in either direction affects loss attribution and model training. No single indicator confirms the category on its own.
How does labeling true fraud affect fraud detection models?
Detection models learn from how historical outcomes are labeled, so conflating true fraud with first-party or friendly fraud can bias a model toward incorrect patterns. Cleaner separation of true fraud from other dispute types is intended to improve label quality, but it introduces trade-offs, including false positives that decline legitimate customers and false negatives that miss fraud. Label accuracy depends on the evidence and process used, and changes to labeling practices should be validated against outcomes.
What authentication controls are relevant to reducing true fraud, and what are their limits?
Different controls address different points in a transaction: EMV chip authentication targets card-present counterfeit risk, 3-D Secure and strong customer authentication address card-not-present risk, and multi-factor authentication can help protect against account takeover. Each may help reduce certain true fraud vectors but none eliminates fraud, and coverage, liability effects, and applicability depend on card brand and network rules that vary by region. Controls should be selected against the specific fraud type they are intended to mitigate.
How should true fraud be tracked separately in reporting and metrics?
Practitioners commonly maintain distinct categories for true fraud, first-party or friendly fraud, chargeback fraud, and synthetic identity fraud so that loss rates and mitigation effectiveness can be measured per category. Because chargeback reason codes and dispute rules vary by card brand, network, and region, mapping raw dispute data to these internal categories requires documented, consistent criteria. Any aggregate fraud figures depend on source, period, and methodology, so definitions should be stated alongside the numbers.

Common misconceptions

All disputed or charged-back transactions are true fraud.
True (third-party) fraud involves genuinely unauthorized use by someone other than the cardholder. Many disputes are first-party or friendly fraud, in which the actual cardholder made or authorized the purchase and later disputes it. These are distinct categories and are treated differently under card brand and network rules.
Deploying EMV chip or 3-D Secure eliminates true fraud.
EMV chip authentication and 3-D Secure address different risks at different points in a transaction. EMV is intended to make counterfeit card-present fraud harder but does not protect card-not-present channels, while 3-D Secure operates at authentication for remote transactions. No single control eliminates true fraud, and fraud may shift to less-protected channels.
Storing full card data helps investigate and prevent true fraud.
Sensitive authentication data such as full track data, CAV2/CVC2/CVV2/CID, and PINs or PIN blocks must not be stored after authorization, even when encrypted. Retaining such data increases exposure that fuels true fraud rather than reducing it; some cardholder data may be stored only under defined controls.

Best practices

Classify disputes accurately by separating true (third-party) fraud from first-party or friendly fraud and chargeback fraud, since misclassification distorts fraud metrics and drives the wrong controls.
Apply authentication controls appropriate to the channel, using EMV chip authentication for card-present acceptance and 3-D Secure or applicable strong customer authentication for card-not-present transactions, recognizing each addresses a different point in the transaction.
Do not store sensitive authentication data after authorization, and limit retention of cardholder data to what is necessary under defined controls to reduce the data that could enable unauthorized use.
Monitor for account takeover indicators, since compromised accounts are a common pathway to unauthorized transactions, and pair detection with awareness of false-positive and false-negative trade-offs.
Confirm liability shift and chargeback handling for suspected true fraud against current card brand and network rules for the relevant region rather than assuming fixed outcomes.
Use layered detection and tune thresholds deliberately, treating any single control as risk-reducing rather than fraud-eliminating, and expect fraud to migrate to less-protected channels as controls are added.