First-Party FraudWhen the Fraudsters Are Your Customers & Why It’s So Hard to Stop Them

Ben Scrancher | June 12, 2026 | 11 min read

This featured video was created using artificial intelligence. The article, however, was written and edited by actual payment experts.

First-Party Fraud

In a Nutshell

First-party fraud is fraud committed by the customer themselves—not by a third-party criminal using stolen credentials. It includes friendly fraud chargebacks, bust-out schemes, application fraud, refund abuse, and more, costing merchants and financial institutions over $100 billion annually. What makes first-party fraud so damaging is that the perpetrator often looks like a legitimate customer right up until the moment they strike.

First-Party Fraud: How it Works, Common Tactics, Red Flags & Prevention

When people ask about fraud prevention, they generally expect a conversation about stolen credentials. The familiar story of a criminal acquiring someone else’s data and using it to make unauthorised purchases. That’s the sort of threat the industry built its detection infrastructure to catch. The more consequential problem, however, is different in kind: first-party fraud, where the person filing the dispute or walking away from the debt is the customer themselves.

No stolen credentials. No fabricated identity. Just a legitimate account being used illegitimately. And, a detection apparatus that was never designed to catch it.

First-party fraud is now a $100 billion annual problem for US merchants and financial institutions. Chargeback abuse — only one subset of the broader category — accounts for roughly half that figure. The arc of the problem is clear: as card-not-present transaction volume grows, consumers become more familiar with the dispute process, and new credit products create new vectors for intentional default, the scale compounds. Understanding what first-party fraud actually is, and why conventional fraud tools are structurally ill-suited to address it, is the prerequisite for doing anything useful about it.

What is First-Party Fraud?

First-Party Fraud

[noun]/fərst • pär • dē • frôd/

First-party fraud occurs when an individual receives goods or services after promising to make a future payment for those items. However, the buyer has no intention to do so. Examples include applying for a loan that the borrower won’t pay back or filing a false chargeback claim.

Most fraud follows a familiar pattern: a criminal acquires stolen payment credentials, uses them to make unauthorised purchases, and disappears. That is “third-party” fraud. Anomaly detection, device fingerprinting, velocity checks: all instruments designed to pick out signals that something is wrong with the identity behind a transaction.

First-party fraud is a different problem entirely. The fraudster is the customer. They are using their own identity — or a lightly modified version of it — to extract value they are not entitled to. They pass every verification check without issue because everything they are presenting is legitimately theirs. The transaction looks exactly as it should, right up until the moment it doesn’t.

What falls under the first-party fraud umbrella is considerably broader than most merchants recognise. I mentioned chargeback abuse, earlier, which is the type merchants encounter most often, but it is one tactic within a category that also includes return fraud, application fraud, bust-out schemes, BNPL default, and more. The mechanics and timing vary significantly across these tactics. The defining characteristic does not: the person committing the fraud appears, at least initially, to be a legitimate customer.

That appearance of legitimacy is precisely what makes first-party fraud so difficult to fight. Conventional fraud tools look for anomalies. First-party fraud doesn’t produce anomalies; it produces legitimate-looking activity that only reveals itself as fraud after the transaction is complete, sometimes weeks or months later. Intent is nearly impossible to prove at scale, and many cases exist in a genuine grey zone between deliberate deception and legitimate dispute.

How Much Does First-Party Fraud Actually Cost?

TL;DR

Data suggests that 9 in 10 merchants have been victims of first-party fraud in the last year. Total costs exceed $100 billion annually.

The scale deserves attention before the mechanics.

As mentioned earlier, first-party fraud costs US merchants and financial institutions more than $100 billion annually. For digital goods merchants, the exposure is even more concentrated: first-party fraud represents up to 80% of all fraud they face, making it the dominant threat in that segment by a significant margin.

The problem is not confined to large enterprises. A 2023 Visa study found that 9 in 10 UK small businesses reported being victims of first-party fraud within the prior 12 months. Internally, we estimate that up to 60% of the average merchant’s chargebacks are the result of first-party fraud.

Several forces are driving continued growth. CNP transaction volume is the structural one: the more a business processes online and mobile payments, the greater its exposure to a fraud type that thrives in environments where merchants cannot physically verify intent. Consumer familiarity compounds the problem; filing a chargeback or return claim is no longer a niche workaround, and many consumers understand the process well enough to exploit it deliberately.

BNPL options and easy credit have created new vectors for intentional default. And consequences remain minimal: few perpetrators face meaningful penalties, and once someone commits first-party fraud successfully, they are likely to engage in repeat offences.

Beyond direct financial losses, first-party fraud drives chargeback fees, inventory write-offs, and damage to a merchant’s fraud risk score with acquiring banks. The impact of each individual incident compounds in ways that don’t always surface in headline loss figures.

Common First-Party Fraud Tactics

Understanding the full range of first-party fraud tactics matters because exposure varies significantly by merchant type, transaction profile, and product category. The common thread across every variant is the same: the perpetrator is, or appears to be, a real customer using their own identity. The fraud lies in the false claim, the broken promise, or the deliberate exploitation of a system that was built on trust.

Chargeback Abuse

Chargeback fraud is the most prevalent form of first-party fraud in eCommerce. A customer makes a legitimate purchase, receives the goods or services, then files a dispute with their bank claiming the transaction was unauthorised or the item never arrived. The merchant loses the revenue, the merchandise, and absorbs a chargeback fee, all from someone who was never a fraud victim in the first place.

Goods Lost in Transit (GLIT) Fraud

A GLIT scheme involves a customer falsely claiming a shipment never arrived, typically supported by a “package not received” dispute. As high-value eCommerce shipments have proliferated, false GLIT claims have become a growing and disproportionately costly problem.

Wardrobing

Wardrobing (or “de-shopping”) occurs when a customer purchases an item — clothing, electronics, tools — with the premeditated intent to use it temporarily and return it for a full refund. Both the purchase and the return look completely routine. The fraud is entirely in the intent, which transaction data cannot reveal.

Return Fraud

Refund fraud encompasses a range of tactics: returning empty boxes, using counterfeit receipts, manufacturing damage claims, or exploiting return policy windows. Repeat offenders often probe return policies across multiple small transactions before escalating to larger schemes.

Credit Application Fraud

Application fraud involves falsifying income, employment status, or other details to obtain credit, better loan terms, or financing that a customer would not otherwise qualify for. The intent is not always clear-cut, but the financial exposure to lenders and BNPL providers is real regardless.

Bust-Out Fraud

Bust-out fraud straddles the line between first- and third-party fraud. A fraudster builds a legitimate-looking credit profile over months or years, demonstrating responsible repayment behaviour and earning higher credit limits, then suddenly maxes out every available line and disappears. The account looks entirely normal until the moment it doesn’t. That is the pattern. It shows up in every credit cycle.

Loan Stacking

Loan stacking involves applying for multiple loans simultaneously across different lenders to obtain more combined credit than any single lender would approve. The scheme exploits the lag in credit reporting to stack approvals before any lender can see the full picture. BNPL abuse has grown alongside the proliferation of BNPL financing, with some consumers taking on obligations they never intend to repay; particularly for high-value goods that can be resold before the first payment is due.

Why First-Party Fraud is so Hard to Detect

TL;DR

Traditional fraud detection is built to catch anomalies—stolen credentials, suspicious devices, mismatched identities. First-party fraudsters don't produce anomalies; they produce legitimate-looking activity that only reveals itself as fraud after the damage is done.

When a third-party fraudster uses stolen credentials, there are signals to catch. An unfamiliar device, a shipping address that doesn’t match the cardholder’s location, an IP flagged for suspicious activity. Fraud detection tools are tuned to find exactly these kinds of discrepancies. The entire infrastructure is built around the assumption that fraud looks different from legitimate behaviour.

First-party fraud doesn’t generate those signals. The fraudster is using their own information. Their device is recognised. Their shipping address is their actual address. Their identity passes verification because it is theirs. At the point of transaction, everything looks exactly as it should.

The fraud reveals itself only after the fact. Sometimes long after.

Friendly fraud surfaces weeks or months later as a dispute that is filed without a valid reason. Bust-out accounts behave normally, sometimes for years, until they suddenly max out and go silent. GLIT claims arrive after delivery confirms as successful. Wardrobing purchases and returns both look routine; the premeditated intent is invisible in the data.

Take the fight against chargebacks back to the source.

Request a Demo
The Original End-to-End Chargeback Management Platform

Intent compounds the problem. A customer might initiate a transaction with good intentions, but then decide to commit fraud after the fact. For example, one may dispute a charge because he is genuinely confused about a billing descriptor. A BNPL borrower who stops paying might do so because he’s lost his job, despite taking out the credit with the intent to pay it.

The same behaviour can be entirely legitimate or deliberately fraudulent depending on what was in the customer’s mind — and that is not something transaction data can reveal. This ambiguity is precisely what repeat offenders exploit. Once a first-party fraud attempt succeeds, the avearge perpetrator will attempt more than nine repeat incidents. They learn where the thresholds are, test the limits, and refine their approach with each successful attempt.

The result is a fundamental detection challenge. By the time first-party fraud becomes visible, it has already happened; often several times over.

First-Party Fraud Red Flags

TL;DR

No single indicator confirms first-party fraud, but examining patterns across behaviour, transactions, and account history can help detect suspicious activity.

Because first-party fraud often can’t be caught at the moment of transaction, the most effective approach is building a picture over time.

No single indicator confirms intent. Patterns across behaviour, transactions, and account history can surface elevated risk early enough to investigate. Remember, though, that the goal is scrutiny, not reflexive rejection. Overly aggressive responses generate false positives that damage legitimate customer relationships, which is a cost that doesn’t appear in fraud loss figures but shows up clearly in churn.

Red Flag

Behavioural Indicators

Repeat disputes or returns are the clearest signal. One dispute is a data point; a pattern is a red flag.

Watch also for accounts that sharply increase purchase frequency or average order value before filing disputes shortly after. This kind of escalation suggests a deliberate scheme. Disputes filed shortly after delivery confirmation, or refund requests that land precisely at the edge of a return policy window, suggest calculation rather than genuine grievance.

Red Flag

Transaction-Level Indicators

Large orders from brand-new accounts with no purchase history carry elevated risk, particularly for easily resaleable goods like electronics or luxury items. Rush shipping requests, especially in combination with other signals, can indicate intent to dispute before the transaction fully settles.

Mismatched billing and shipping addresses don’t confirm fraud, but they warrant additional scrutiny. Multiple units of the same SKU can suggest resale intent or, in return fraud cases, a plan to return only some of what was purchased.

Red Flag

Account-Level & Post-Transaction Indicators

Gradual, responsible account behaviour that suddenly reverses is an indicator of a textbook bust-out pattern.

Dispute narratives that don’t align with delivery confirmation, tracking history, or prior customer service interactions are a strong signal of manufactured disputes. Customers who insist on a refund before returning an item, or who resist providing return tracking, may be attempting to retain both the goods and the money.

Customers who go silent during the dispute process, or who fail to respond to pre-dispute outreach, should be regarded as suspect, too. They may be deliberately steering toward a formal chargeback rather than resolution.

Important!

Remember that no single indicator — or even unaggregated range of indicators — should be considered “proof” of fraud. All evidence should be considered in context. It is generally better to assume a coincidence, rather than accuse a genuine customer of fraud.

First-Party Fraud Checklist

  • Has this customer engaged in this pattern of behaviour before?
  • Did purchase frequency or AOV change dramatically before a dispute?
  • Did the buyer request a refund just before the return window closed?
  • Did an account with no purchase history submit an unusually large order?
  • Did a suspicious order involve easily resaleable goods?
  • Was there a mismatch between the customer’s billing and shipping address?
  • Did the buyer purchase multiple units with the same (or similar) SKU?
  • Did a return buyer’s pattern of behaviour change suddenly?
  • Is the buyer’s claim contradicted by delivery confirmation, tracking history, or prior customer service records?
  • Did the buyer ignore attempts to resolve a dispute before a chargeback was issued?

How to Detect & Prevent First-Party Fraud

No single tool or tactic eliminates first-party fraud. The right strategy depends on which types pose the greatest risk to your specific business. And for many types, detection and response are just as important as prevention—because the fraud only becomes visible after it happens.

This is the critical point that most fraud prevention frameworks miss: they are designed for a problem that announces itself in real time. First-party fraud does not announce itself. This is why longitudinal analysis is the most powerful detection tool available for first-party fraud.

Common QuestionWhat is longitudinal analysis?Longitudinal analysis in fraud prevention is the process of tracking user behavior, account activity, and transaction histories over an extended period. The aim is to establish a baseline of “normal” behavior, in contrast to suspicious behavior. By analyzing trends, you may detect subtle, long-term anomalies missed by isolated or single-transaction reviews.

First-party fraud reveals itself through patterns over time; single-transaction checks miss the picture entirely. Connecting behaviour across transactions, returns, disputes, and customer service contacts gives fraud teams visibility that siloed data never can. Machine learning models trained on historical fraud patterns can surface the subtle, cumulative signals that manual review can’t catch at scale.

But, as for specific subsets of first-party fraud, I recommend the following approaches:

Chargeback & Dispute Abuse Prevention

Clear billing descriptors reduce the likelihood that the “I didn’t recognise the charge” defence will work. Proactive communication at every stage of the order lifecycle — confirmation, shipping, delivery — reduces “I never received it” claims and creates a documented record that supports representment if a dispute is filed anyway.

Compelling Evidence 3.0 (CE3.0) lets merchants submit device fingerprints, IP data, and prior purchase history alongside transaction records to demonstrate the purchase was made by the account holder. Used correctly, it is one of the most effective tools available for fighting first-party chargeback misuse. Chargeback alerts give merchants real-time notification of pending disputes, creating a window to resolve issues directly before they escalate to a formal chargeback.

Representment is the last line of defence: building a response package that meets card network evidentiary standards and recovering revenue that would otherwise be written off. Customer blacklists ensure that verified repeat offenders cannot simply return under the same credentials.

Refund & Return Abuse Prevention

Clear return policies set expectations at the point of sale and close the ambiguous loopholes that repeat offenders exploit. Monitoring return frequency at the individual customer level — not just in aggregate — surfaces patterns that transaction-level reporting misses.

Requiring condition verification before issuing refunds, and offering store credit rather than cash refunds in high-risk cases, reduces the financial incentive for return fraud without requiring outright denial. If you intend to pursue this path, though, you must clearly state this before completing a transaction. Otherwise, customers will likely escalate to chargebacks.

Credit & Application Fraud Prevention

Cross-referencing application details against external data sources catches the most obvious falsification. But ongoing review of the customer’s behavior — not just at onboarding — is critical as well.

Behavioural monitoring over time provides the longitudinal view needed to identify bust-out patterns before full exposure occurs. Gradual credit limit increases based on demonstrated behaviour, rather than stated income, limit potential losses when an account eventually turns.

Important!

Some first-party fraud cannot be prevented at the point of transaction. It only becomes fraud in hindsight. For those cases, detection infrastructure, documentation practices, and response capabilities matter just as much as prevention. Sometimes even more.

How Chargebacks911 Helps Merchants Fight First-Party Fraud

The most immediate and costly first-party threat for most eCommerce merchants is friendly fraud and chargeback abuse. That is where Chargebacks911® operates.

On the prevention and deflection side: Intelligent Source Detection™ identifies the true origin of each chargeback, distinguishing first-party fraud from legitimate disputes and processing errors. Knowing what you are actually dealing with is the prerequisite for responding effectively.

We offer the broadest chargeback alerts network available on the market, enabling you to intercept disputes in real time and resolve issues directly before they escalate to a formal chargeback (and before fees and chargeback ratio damage accumulate). Order Insight and CE3.0 integration arms merchants with the transaction-level evidence needed to challenge illegitimate disputes on the terms card networks require.

On the response and recovery side: expert representment combines documented evidence with deep knowledge of card network rules to build the strongest possible case against illegitimate chargebacks. Dispute analytics surface the patterns behind first-party fraud at the account and transaction level, informing prevention strategies that reduce future exposure rather than simply managing current losses.

Chargebacks911 provides the specialized expertise and managed services to address the problem at every stage of the chargeback lifecycle.

FAQs

What is first- vs. third-party fraud?

First-party fraud is committed by an otherwise legitimate cardholder or customer, either on an individual basis or in a combined effort with another fraudster.

Third-party fraud, on the other hand, is committed by a practiced fraudster unrelated to either the customer or the merchant. This type of attack revolves around using stolen customer credentials to defraud a merchant or organization.

What is indicative of first-party fraud?

First-party fraud fraud is generally either unintentional, meaning the cardholder didn’t realize what they were doing, or it is deliberate. Deliberate first-party fraud can be further broken down into opportunistic attacks, meaning the cardholder sees an opportunity to recoup funds from a merchant that has displeased them in some way. Or, it can be an organized attempt to deliberately defraud a merchant or organization on a post-transactional basis.

Is first-party fraud serious?

Yes, it is a huge problem. First-party fraud costs merchants upward of $89 billion per year, and is responsible for up to 60% of all chargebacks.

What are the three types of fraud?

We can segment fraud into first-party, second-party, and third-party fraud.

First-party fraud is post-transactional fraud committed by the cardholder. Second-party fraud is committed by a party working along with the cardholder, either pre- or post-transaction. Third-party fraud  is fraud committed by a person unrelated to the cardholder, who uses their credit credentials to commit transactional fraud.

How do I stop first-party fraud?

You must examine your data closely and trust your internal decisioning processes. You need to build out this capacity or work with a third party who can conduct data analysis on your behalf. Once you have this system in place, identifying which type of fraud you’re dealing with gets much easier.

Like What You're Reading? Join our newsletter and stay up to date on the latest in payments and eCommerce trends.
Newsletter Signup
We’ll run the numbers; You’ll see the savings.
triangle shape background particle triangle shape background particle triangle shape background particle
Please share a few details and we'll connect with you!
Revenue Recovery icon
Over 18,000 companies recovered revenue with products from Chargebacks911
Close Form