First-Party Fraud: When Your Customer IS the Fraudster
Quick answer
First-party fraud occurs when a legitimate customer — using their own identity and card — intentionally disputes a valid charge. Unlike stolen-card fraud, they pass every verification check because everything is genuinely theirs. It costs US merchants $100+ billion annually, and up to 60% of the average merchant's chargebacks are first-party fraud disguised as legitimate disputes.
First-party fraud is the most under-reported and least understood category of chargeback abuse. Because the customer is real, the card is real, and the transaction is genuine, merchants often accept the loss without realising they had a winnable case. Compelling Evidence 3.0 changed that — but only if you collect the right data at the time of transaction.
What Is First-Party Fraud (vs Third-Party Fraud)
The distinction matters for how you detect it, respond to it, and fight it:
| Dimension | Third-party fraud | First-party fraud |
|---|---|---|
| Who commits it | Someone else — uses stolen identity or card | The real account holder |
| Identity authenticity | False — stolen or synthetic | Genuine — their own real identity |
| Passes KYC/verification | Sometimes — depends on sophistication | Always — because it is genuinely theirs |
| Chargeback claim | "I didn't make this purchase" | "Item not received" / "Not as described" / "I cancelled" |
| Winnable via representment | Rarely — cardholder is a victim | Yes — CE 3.0 can shift liability |
| Prevention method | Fraud scoring, velocity, device checks | Behavioral analytics, dispute history linking |
Common first-party fraud scenarios: a customer orders a dress for an event, wears it, returns it (wardrobing); a subscriber uses a service for a full month then disputes the charge as "not authorised"; a buyer claims an item "never arrived" when carrier tracking confirms delivery.
Types of First-Party Fraud
Chargeback abuse / friendly fraud
The most common form. Customer makes a legitimate purchase, receives the goods or services, then disputes the charge claiming non-receipt, not as described, or unauthorised transaction. Accounts for the majority of first-party fraud chargebacks.
Return fraud
Customer uses the product, then returns it claiming defect or non-delivery. Or returns a different (cheaper/damaged) item in the original packaging. The chargeback follows when the return is rejected.
Wardrobing (wear-and-return)
Predominantly in fashion and luxury. Customer buys an item, wears it to an event, returns it. If the return is declined (item clearly used), the customer files a chargeback claiming item was not as described.
BNPL default fraud
Customer uses Buy Now Pay Later to acquire multiple high-value items, disputes all charges before payments are due. Particularly prevalent in fashion and electronics.
Bust-out schemes
Customer builds purchase history and positive account standing over time, then places a large order (or multiple orders), disputes everything simultaneously, and disappears. Common in subscription and digital goods.
Why It's Impossible to Catch at Checkout
This is what makes first-party fraud uniquely difficult. At the point of transaction, the customer presents no anomalies — because everything is genuinely theirs:
- Legitimate identity: real name, real address, real date of birth
- Legitimate card: their own card, passes full AVS verification
- Passes 3D Secure: they authenticate with their own bank because it's their account
- No velocity flags: often a returning customer with prior purchase history
- No IP anomalies: ordering from home, familiar device
Standard fraud tools — which look for mismatches, stolen credentials, and anomalies — produce no signal because there are no anomalies to detect. The fraud signal only becomes visible in retrospect: in the dispute pattern, across multiple transactions over time.
Key insight
First-party fraud cannot be prevented at checkout with fraud scoring. It is detected through post-transaction behavioral analysis and combated through representment and customer blocklisting — not pre-authorisation controls.
Behavioral Red Flags (Patterns, Not Single Transactions)
No single transaction signals first-party fraud at point of sale. These patterns become visible in your dispute and order history:
⚑ Multiple chargebacks from same customer identity
Match dispute history across email, phone, shipping address, and device — not just card number. A customer who rotates cards but reuses their email or home address is a high-confidence repeat offender.
⚑ Disputes always for high-value orders
First-party fraudsters are rational economic actors. They dispute high-value transactions and accept low-value ones. If a customer's disputes are consistently in the top quartile of order value, it's intentional.
⚑ Pattern of "item not received" on confirmed-delivered shipments
If carrier tracking shows delivery and the customer disputes non-receipt, that is a strong indicator of friendly fraud — especially if it happens more than once.
⚑ Dispute filed immediately after subscription renewal
A common pattern: customer uses service through the free trial or billing period, then disputes the renewal charge as "unauthorised" minutes after it posts.
⚑ Returns after extended use period
In fashion and luxury: customer purchases, uses product, files a return request 20–25 days later (just before the return window closes), and disputes when the return is declined as worn.
⚑ Contact support → dispute immediately after being told no
A customer who contacts support requesting a refund, is declined, and then files a chargeback within 24 hours is escalating to dispute what they were denied in customer service.
First-Party Fraud Checklist: 10 Questions Before Refunding
Before accepting a chargeback loss or issuing a pre-emptive refund, run through these questions. If 3+ are "yes," fight the dispute rather than surrendering.
Is delivery confirmed by carrier tracking to the address provided at checkout?
Did the customer contact support before filing the chargeback (and were they declined)?
Was the chargeback filed more than 30 days after the transaction (suggesting product was received and used)?
Has this customer email, phone, or address appeared in a prior chargeback?
Is the disputed order in the top 25% of this customer's order history by value?
Did the customer use the service or access the digital goods (login logs, usage data)?
Does the dispute reason code mismatch the actual situation (e.g., "not received" but tracking shows delivered)?
Was 3DS authentication completed successfully at the time of transaction?
Are there 2+ prior undisputed transactions from the same device or IP within 120 days (CE 3.0 qualifying)?
Does the chargeback come within 7 days of a subscription renewal or auto-charge?
How to Fight First-Party Fraud with Compelling Evidence 3.0
Compelling Evidence 3.0 (CE 3.0) is the most powerful tool available for fighting first-party fraud on Visa disputes. Introduced in April 2023, it lets merchants shift liability by proving the cardholder recognised the merchant in prior transactions.
CE 3.0 qualifying criteria
- Two prior transactions from the same device fingerprint or IP address as the disputed transaction
- Within 120 days of the disputed transaction (365 days for digital goods/services)
- Neither prior transaction was disputed — they must be clean, non-refunded transactions
- Dispute reason code: CE 3.0 applies to Visa reason code 10.4 (card absent fraud)
When CE 3.0 criteria are met, Visa can stop the dispute before it becomes a chargeback — a "no-chargeback" outcome where neither party wins or loses in the traditional sense, but you avoid the ratio impact and the fee.
Documents to gather for a CE 3.0 response:
- Device fingerprint log for all 3 transactions (disputed + 2 prior)
- IP address at time of each transaction, with geolocation
- Login session logs showing the cardholder accessed their account
- Email confirmation of prior orders (showing same email address)
- Shipping address match across transactions
- Delivery confirmation for prior orders (to show undisputed successful fulfilment)
CE 3.0 requires device/IP data collection at purchase
CE 3.0 only works if you captured device fingerprint and IP address at the time of each qualifying transaction. If you are not currently collecting this data, the evidence doesn't exist retroactively. Implement session logging and device fingerprinting now — every transaction without it is a future CE 3.0 case you can't build.
Win rates for well-evidenced CE 3.0 responses run 50–70%, making first-party fraud (under Visa 10.4) one of the highest-ROI categories to fight through representment. The average repeat offender commits 9+ incidents — identifying and blocklisting them after the first successful representment prevents compounding losses.
Frequently Asked Questions
What is the difference between first-party and third-party fraud?+
How common is first-party fraud in eCommerce?+
Can I win a chargeback where the customer is committing friendly fraud?+
What is Compelling Evidence 3.0 and how does it help fight first-party fraud?+
How do I identify repeat first-party fraudsters?+
ChargeMate identifies first-party fraud patterns and builds CE 3.0 evidence packages.
$10/case. No monthly fees. Only pay when we work a dispute.
See outsourcing plans →