GuideJune 2026 · 13 min read

Chargeback Fraud: How to Detect and Fight It [2026]

Chargeback fraud now represents 36% of all eCommerce fraud — up from 15% just two years ago. Unlike stolen-card fraud, the person filing the false dispute is often your own customer. Here is how to identify it, document it, and win the representment.

Fight chargeback fraud with the right evidence, structured correctly

ChargeMate builds reason-code-matched dispute responses in minutes.

Try free →

What Is Chargeback Fraud?

Chargeback fraud is the deliberate misuse of the chargeback dispute system to obtain a refund while keeping the goods or services purchased. The cardholder contacts their bank, claims the charge was unauthorized or the product was never received, and the bank reverses the payment — leaving the merchant out of both the money and the merchandise.

There are two fundamentally different categories of fraud chargebacks, and they require different responses:

True fraud (third-party fraud)

A stolen or compromised card is used without the real cardholder's knowledge. The cardholder files a dispute because they genuinely did not make the purchase. Merchants can often win these disputes by demonstrating that authorization was obtained and that the shipping address matched the billing address — or by showing that 3D Secure authentication was completed.

First-party fraud / friendly fraud

The actual cardholder makes a legitimate purchase, receives the goods or services, and then files a false dispute claiming the transaction was unauthorized, the item never arrived, or the product was defective. The transaction was fully authorized — the fraud happens after the fact, through the dispute mechanism. This is the growing problem, and it requires a different evidence strategy.

The scale of the problem has become extraordinary. First-party fraud accounted for 36% of all eCommerce fraud in 2024, up from 15% in 2023 — a more than doubling in a single year. According to Signifyd, the rate is rising 33% annually. LexisNexis research has found that 16% of consumers admit to filing a false chargeback claim at least once. The total projected exposure to eCommerce merchants from first-party fraud is $132 billion.

That figure — $132 billion — is not chargeback losses alone. It includes the compounding costs: lost merchandise, lost fulfillment cost, chargeback fees, representment labor, and the downstream penalties from elevated chargeback ratios. US merchants lose an average of $4.61 for every $1 of fraudulent transaction value. At an average resolution cost of $82 per dispute in 2026, even a moderate dispute volume creates a serious operational burden.

Why first-party fraud is harder to fight: With true fraud, the merchant is often a victim alongside the cardholder. With first-party fraud, the merchant is the sole victim — and the person filing the dispute has more information about the transaction than the bank does. The burden of proof falls entirely on you.

The good news: fraud chargebacks have a 36.5% median win rate in representment (Accertify). Non-fraud chargebacks win at 56.6%. Those numbers are winnable — but only if you understand what type of fraud you are dealing with and structure your evidence accordingly. See also the friendly fraud guide for a deeper look at first-party fraud patterns.

5 Types of Chargeback Fraud

Chargeback fraud is not monolithic. Each type shows up differently in your dispute queue and requires specific evidence to counter it. Understanding the pattern behind a dispute is the first step to defeating it.

1. “Item Not Received” Abuse

What the merchant sees: A dispute filed under Visa 13.1, Mastercard 4855, or Amex C08 — goods or services not received. The customer claims the order never arrived.

What actually happened: The order was delivered. The customer received it, may have used it, and filed a dispute anyway — hoping the carrier tracking record is not clear enough or that the merchant won't respond.

How to detect it: Carrier tracking shows a confirmed delivery scan at the customer's address. The customer did not contact you before filing. The delivery address matches the billing address. The account shows no prior complaints or returns.

This is the most common type of chargeback fraud for physical goods merchants. It is also one of the most winnable — delivery confirmation with a matching address is compelling evidence that issuers take seriously.

2. “Item Not as Described” Exaggeration

What the merchant sees: A dispute coded as item significantly not as described (Visa 13.3, Mastercard 4853). The customer claims the product was completely different from what was advertised.

What actually happened: The goods were received and largely matched the description. The customer may have had a minor complaint that was resolved or ignored — or no complaint at all before going straight to the bank.

How to detect it: No return request was made. No customer service contact prior to the dispute. Your product listing accurately describes the item. The customer has made similar purchases without complaints before.

Your best defense: screenshots of the product listing at the time of purchase, your return policy (which the customer bypassed), and any pre-dispute customer service records.

3. Subscription Cancellation Disputes

What the merchant sees: A dispute on one or more recurring charges after the customer claims they cancelled or never authorized the subscription.

What actually happened: The customer signed up for a free trial or subscription and did not cancel through your system before the renewal. They may have used the service for months before disputing, or they may dispute historical charges they legitimately authorized.

How to detect it: Your records show active logins during the disputed billing periods. Cancellation logs show no request from this customer. The signup confirmation email was opened.

For subscription fraud, the evidence that issuers find most persuasive is proof of service usage during the disputed periods — login timestamps, feature access logs, content delivery records. See the improve chargeback win rates guide for subscription-specific evidence tips.

4. Family Fraud

What the merchant sees: An unauthorized transaction dispute. The cardholder says they did not make the purchase.

What actually happened: A family member — a child, spouse, or partner — used the cardholder's card to make the purchase. The cardholder genuinely may not have known about it, but the transaction was made from a recognized device at the billing address, not by a fraudster.

How to detect it: The device used to place the order is the same device used to log into the account previously. The IP address is within the customer's home network. The billing and shipping address are identical. The account has a history of purchases.

Family fraud is common in gaming, app stores, and digital goods. Device fingerprint and IP geolocation data are your key evidence here — they show the purchase was made from the cardholder's own household.

5. Serial Chargeback Fraudsters

What the merchant sees: Multiple chargebacks from the same customer — or patterns of disputes across multiple accounts with shared identifiers (email domain, IP range, shipping address).

What actually happened: The customer has developed a deliberate strategy of buying and disputing. They know from experience that merchants often don't respond to small disputes, so they target lower-value orders and repeat across different merchants.

How to detect it: Your own order history shows prior disputes from the same customer. Fraud screening tools surface the email or device as known in fraud databases (e.g., SEON, Kount). The customer's account was created shortly before a large first purchase.

Serial fraudsters rely on merchants not sharing data. Block them at the account level after confirming the pattern, flag them in your fraud tool, and include the full dispute history in your representment evidence.

How to Detect Chargeback Fraud

Most chargeback fraud leaves a trail — but only if you know where to look. The signals below should be part of a standard triage checklist for every dispute you receive. Strong signals alone can be enough to win a representment; a combination of medium signals together also builds a compelling case.

SignalWhat to CheckStrength
Delivery confirmedCarrier tracking showing delivery scan at matching addressStrong
Customer contacted usEmail, chat, or phone record prior to dispute being filedStrong
Multiple orders, same addressPattern of purchases from this address with frequent subsequent disputesStrong
Social media evidenceCustomer posted about receiving or using the product after alleged non-receipt dateStrong
IP address matchesLogin and order IP matches billing country and prior sessionsMedium
Customer account historyPrevious orders from same card without prior disputesMedium
Device fingerprintSame device used for order as used in prior legitimate sessionsMedium
Login after deliveryCustomer logged into their account after the alleged non-receipt dateStrong

Document every signal you find before drafting your response. Issuers respond to specificity — “the customer logged into their account on March 14, three days after the alleged non-receipt date” is far more persuasive than a general claim that the order was delivered.

Why Merchants Lose Chargeback Fraud Cases

Losing a winnable fraud dispute is almost always an operational failure, not a legal one. The transaction was legitimate — the evidence exists. The problem is that the evidence was not collected, was not organized correctly, or was not submitted in time. These are the most common reasons merchants lose:

No documentation of delivery

If you cannot produce carrier tracking with a confirmed delivery scan at the customer's address, the issuer has no way to verify your claim. For high-value orders, requiring a signature on delivery solves this problem entirely.

No customer communication record

If you have email or chat threads with the customer but they are stored in a system you cannot export quickly, they might as well not exist. Every dispute response window is short — 20 to 45 days depending on the network. You need to be able to pull records fast.

Missing authorization proof

For fraud-coded disputes (Visa 10.4, MC 4837), authorization data is the first thing an issuer looks for. This means the AVS result, CVV match, 3DS authentication code, and IP geolocation at time of purchase. Your payment processor can provide this data — request it proactively.

Response submitted too late

Visa allows 30 days from the chargeback notification. Mastercard allows 45 days. American Express typically allows 20 days. These deadlines are absolute — a late response is automatically rejected, no matter how strong the evidence. Set calendar reminders the moment a chargeback appears in your dispute portal.

Generic response without specific evidence

A cover letter that says 'the order was delivered and the customer is lying' is not a dispute response — it is noise. Issuers process thousands of chargebacks per week. A response with no specific dates, no tracking numbers, no screenshots, and no structured argument will be rejected. Every claim you make must be supported by an attached document.

Evidence Strategy for Winning Fraud Disputes

The right evidence depends on the reason code. Submitting delivery proof for a fraud-coded dispute — when the issuer is looking for authorization data — is a mismatch that weakens your response. Structure your evidence package in the order the issuer is trained to expect.

Ranked evidence guide (most to least persuasive)

1

Signed proof of delivery with matching name and address

Definitive for goods-not-received disputes. A signature showing the cardholder's name received the parcel at the billing address closes the case.

2

Carrier tracking showing confirmed delivery

Most persuasive when the delivery scan is at the same address as the billing address. Include a screenshot of the full tracking history, not just the final scan.

3

Customer login after alleged non-receipt date

A server log showing the customer accessed their account — and especially used features tied to the disputed product — after the date they claim they never received anything is highly compelling.

4

Email or chat confirming receipt

Any message where the customer references the order positively, asks a follow-up question about the product, or confirms delivery. Even a support ticket asking about a feature of the received product is useful.

5

IP address and geolocation match

The IP used to place the order matches the customer's account login history and their billing country. Shows the order was placed from a known device, not a stolen card.

6

Prior purchase history from same card without disputes

Demonstrates the card was known and used legitimately before. Issuers weight this when assessing whether the cardholder is a genuine fraud victim or a repeat disputant.

Evidence by reason code

Reason CodeDescriptionPrimary Evidence
Visa 10.4Card-absent fraudAuthorization data, CVV/AVS match, 3DS auth code, IP match, CE 3.0 prior transactions
MC 4837No cardholder authorizationAuthorization data, device fingerprint, login history, IP address, prior order history
Visa 13.1Merchandise / services not receivedCarrier tracking with delivery confirmation, signature on delivery, login after delivery date
MC 4855Goods or services not providedDelivery tracking, proof of digital delivery, login/usage logs, customer communication
Visa 13.3Not as describedProduct listing screenshots, description accuracy proof, no prior complaint record, return policy
MC 4853Cardholder disputeTerms of service, product description, communication record, lack of complaint before dispute

For full reason code definitions and response guides, see the chargeback reason codes directory.

Compelling Evidence 3.0 for Visa Fraud Disputes

In April 2023, Visa introduced Compelling Evidence 3.0 (CE 3.0) — a framework that fundamentally changed the balance of power in first-party fraud disputes on the Visa network. For the first time, merchants have a formal mechanism to shift liability for fraud chargebacks back to the card issuer.

CE 3.0 applies specifically to Visa reason code 10.4 (card-absent fraud / unauthorized transaction). To qualify, the merchant must demonstrate:

  • At least two prior undisputed transactions from the same cardholder, on the same device, within 120 to 365 days before the disputed transaction
  • The prior transactions and the disputed transaction share the same device fingerprint (or IP address)
  • The prior transactions were not themselves chargebacks or disputed

When a merchant successfully invokes CE 3.0, the chargeback liability shifts to the issuing bank — the bank, not the merchant, absorbs the loss. Even if the cardholder continues to insist the transaction was unauthorized, the bank cannot reverse the transaction back to the merchant. The dispute is closed in the merchant's favor.

Why this is a game-changer for friendly fraud: Before CE 3.0, a cardholder could dispute any transaction as “unauthorized” and the merchant had limited recourse. CE 3.0 recognizes that when the same person has used the same device to buy from you multiple times without disputing, the “I didn't authorize this” claim is highly implausible — and Visa now formalizes that logic as a liability shift mechanism.

How to prepare for CE 3.0 in advance

CE 3.0 only works if you have been collecting the right data from the start. That means:

  • Capturing and storing device fingerprint data at the time of every transaction (using a fraud tool like Kount, SEON, or your payment processor's built-in fingerprinting)
  • Recording the IP address used at checkout for every order
  • Storing this data alongside the transaction record so it can be retrieved when a dispute arrives — potentially months later
  • Linking device and IP data to your Stripe (or other processor) transaction IDs so you can pull CE 3.0 qualifying evidence quickly

Merchants who are not collecting device fingerprint data today are leaving CE 3.0 on the table. It is the most powerful tool available for fighting first-party fraud on Visa — but it only works with historical data.

Prevention Strategies

The best chargeback fraud response is one you never have to write. These prevention measures reduce both the frequency of fraud disputes and the effort required to win the ones that do occur.

Use clear, recognizable billing descriptors

A significant share of chargebacks — including many coded as fraud — happen because customers don't recognize the charge on their statement. Your billing descriptor should match your brand name, not your LLC name. Including a customer service phone number in the descriptor reduces unrecognized-charge disputes by 20–40% in studies.

Send delivery confirmation emails with tracking

Automated post-shipment emails with a tracking link serve two purposes: they improve the customer experience, and they create a paper trail you can attach to a dispute response. The email timestamp, combined with the carrier delivery scan, is a strong evidence combination.

Implement 3D Secure for high-risk orders

For orders above your average order value, or flagged by your fraud tool, requiring 3DS authentication shifts liability to the issuing bank on Visa and Mastercard transactions. This does not prevent disputes from being filed, but it means you have an authentication record that is highly persuasive — and in the EU triggers the PSD2 liability shift.

Capture device fingerprint and IP per transaction

This is the foundational requirement for Visa CE 3.0. Even if you are not planning to use CE 3.0 immediately, collecting device and IP data at checkout costs nothing and gives you retroactive protection when a dispute arrives months later.

Respond to customer complaints before they escalate

Many chargebacks happen because a customer could not reach you or did not know how to request a refund. Prominently display your customer service email and response time commitment. A customer who gets a fast, fair resolution does not file a chargeback. Proactive resolution costs less than a chargeback fee.

Flag and block known fraudsters

After winning a representment against a customer who filed a false dispute, flag that customer in your system and block their email, card BIN, and device from placing future orders. Selling to a known fraudster again is not worth the next dispute cycle.

If dispute volume is high enough that prevention and response are taking significant staff time, consider professional outsourcing. The ChargeMate outsourcing service manages the full dispute lifecycle — from evidence gathering to submission — so your team can focus on the business.

Frequently Asked Questions

What is the difference between chargeback fraud and true fraud?
True fraud occurs when a stranger uses stolen card details to make an unauthorized purchase — the cardholder had no involvement in the transaction. Chargeback fraud (also called friendly fraud or first-party fraud) is the opposite: the real cardholder makes a legitimate, authorized purchase and then files a false dispute claiming it was unauthorized or that the goods were never received. True fraud is a crime committed against the cardholder; chargeback fraud is a crime committed by the cardholder against the merchant.
Can merchants be penalized for too many fraud chargebacks?
Yes. Visa and Mastercard both operate chargeback monitoring programs. Visa's Dispute Monitoring Program (VDMP) triggers at 100 disputes and a 0.9% dispute ratio per month. Mastercard's Excessive Chargeback Program (ECP) triggers at 100 chargebacks and a 1.5% ratio. Merchants in these programs face monthly fines, additional fees per dispute, and ultimately risk having their merchant account terminated — meaning they can no longer accept card payments.
What is Visa Compelling Evidence 3.0?
Visa Compelling Evidence 3.0 (CE 3.0), introduced in April 2023, allows merchants to shift liability back to the card issuer on fraud-coded Visa disputes (reason code 10.4). To qualify, merchants must prove that the same cardholder made at least two prior undisputed transactions using the same device fingerprint and IP address within 120–365 days before the disputed transaction. If the evidence meets Visa's criteria, the issuer — not the merchant — absorbs the loss, even if the cardholder claims the transaction was fraudulent.
How long do merchants have to respond to a fraud chargeback?
Response windows vary by card network: Visa gives merchants 30 days from the chargeback notification date to submit a representment; Mastercard allows 45 days; American Express typically allows 20 days. These deadlines are strict — missing them means the chargeback is automatically upheld regardless of how strong your evidence is. Most processors display the deadline clearly in their dispute management portal, but it is worth double-checking against network rules for your specific reason code.
How does ChargeMate help fight chargeback fraud?
ChargeMate generates tailored dispute response letters matched to the specific chargeback reason code and card network. For fraud-coded disputes, ChargeMate structures your evidence in the order issuers and networks expect — authorization proof, delivery records, login history, IP match, device fingerprint — and formats the entire package as a ready-to-submit PDF. For Visa CE 3.0 cases, ChargeMate identifies when the framework applies and guides you through assembling the qualifying prior transaction evidence. You can also outsource dispute management entirely to the ChargeMate team.

ChargeMate

Win more fraud chargebacks — without the manual work

ChargeMate generates reason-code-matched dispute responses structured exactly the way issuers expect. Upload your evidence and get a ready-to-submit PDF in minutes.

Try ChargeMate free →

Related Guides