GuideJune 2026 · 8 min read

First-Party Fraud: When Your Customer IS the Fraudster

OG
Olga Gavrina · Founder, ChargeMate · Certified Chargeback Expert · June 2026

Quick answer

First-party fraud occurs when a legitimate customer — using their own identity and card — intentionally disputes a valid charge. Unlike stolen-card fraud, they pass every verification check because everything is genuinely theirs. It costs US merchants $100+ billion annually, and up to 60% of the average merchant's chargebacks are first-party fraud disguised as legitimate disputes.

First-party fraud is the most under-reported and least understood category of chargeback abuse. Because the customer is real, the card is real, and the transaction is genuine, merchants often accept the loss without realising they had a winnable case. Compelling Evidence 3.0 changed that — but only if you collect the right data at the time of transaction.

What Is First-Party Fraud (vs Third-Party Fraud)

The distinction matters for how you detect it, respond to it, and fight it:

DimensionThird-party fraudFirst-party fraud
Who commits itSomeone else — uses stolen identity or cardThe real account holder
Identity authenticityFalse — stolen or syntheticGenuine — their own real identity
Passes KYC/verificationSometimes — depends on sophisticationAlways — because it is genuinely theirs
Chargeback claim"I didn't make this purchase""Item not received" / "Not as described" / "I cancelled"
Winnable via representmentRarely — cardholder is a victimYes — CE 3.0 can shift liability
Prevention methodFraud scoring, velocity, device checksBehavioral analytics, dispute history linking

Common first-party fraud scenarios: a customer orders a dress for an event, wears it, returns it (wardrobing); a subscriber uses a service for a full month then disputes the charge as "not authorised"; a buyer claims an item "never arrived" when carrier tracking confirms delivery.

Types of First-Party Fraud

Chargeback abuse / friendly fraud

The most common form. Customer makes a legitimate purchase, receives the goods or services, then disputes the charge claiming non-receipt, not as described, or unauthorised transaction. Accounts for the majority of first-party fraud chargebacks.

Return fraud

Customer uses the product, then returns it claiming defect or non-delivery. Or returns a different (cheaper/damaged) item in the original packaging. The chargeback follows when the return is rejected.

Wardrobing (wear-and-return)

Predominantly in fashion and luxury. Customer buys an item, wears it to an event, returns it. If the return is declined (item clearly used), the customer files a chargeback claiming item was not as described.

BNPL default fraud

Customer uses Buy Now Pay Later to acquire multiple high-value items, disputes all charges before payments are due. Particularly prevalent in fashion and electronics.

Bust-out schemes

Customer builds purchase history and positive account standing over time, then places a large order (or multiple orders), disputes everything simultaneously, and disappears. Common in subscription and digital goods.

Why It's Impossible to Catch at Checkout

This is what makes first-party fraud uniquely difficult. At the point of transaction, the customer presents no anomalies — because everything is genuinely theirs:

  • Legitimate identity: real name, real address, real date of birth
  • Legitimate card: their own card, passes full AVS verification
  • Passes 3D Secure: they authenticate with their own bank because it's their account
  • No velocity flags: often a returning customer with prior purchase history
  • No IP anomalies: ordering from home, familiar device

Standard fraud tools — which look for mismatches, stolen credentials, and anomalies — produce no signal because there are no anomalies to detect. The fraud signal only becomes visible in retrospect: in the dispute pattern, across multiple transactions over time.

Key insight

First-party fraud cannot be prevented at checkout with fraud scoring. It is detected through post-transaction behavioral analysis and combated through representment and customer blocklisting — not pre-authorisation controls.

Behavioral Red Flags (Patterns, Not Single Transactions)

No single transaction signals first-party fraud at point of sale. These patterns become visible in your dispute and order history:

  • Multiple chargebacks from same customer identity

    Match dispute history across email, phone, shipping address, and device — not just card number. A customer who rotates cards but reuses their email or home address is a high-confidence repeat offender.

  • Disputes always for high-value orders

    First-party fraudsters are rational economic actors. They dispute high-value transactions and accept low-value ones. If a customer's disputes are consistently in the top quartile of order value, it's intentional.

  • Pattern of "item not received" on confirmed-delivered shipments

    If carrier tracking shows delivery and the customer disputes non-receipt, that is a strong indicator of friendly fraud — especially if it happens more than once.

  • Dispute filed immediately after subscription renewal

    A common pattern: customer uses service through the free trial or billing period, then disputes the renewal charge as "unauthorised" minutes after it posts.

  • Returns after extended use period

    In fashion and luxury: customer purchases, uses product, files a return request 20–25 days later (just before the return window closes), and disputes when the return is declined as worn.

  • Contact support → dispute immediately after being told no

    A customer who contacts support requesting a refund, is declined, and then files a chargeback within 24 hours is escalating to dispute what they were denied in customer service.

First-Party Fraud Checklist: 10 Questions Before Refunding

Before accepting a chargeback loss or issuing a pre-emptive refund, run through these questions. If 3+ are "yes," fight the dispute rather than surrendering.

1

Is delivery confirmed by carrier tracking to the address provided at checkout?

2

Did the customer contact support before filing the chargeback (and were they declined)?

3

Was the chargeback filed more than 30 days after the transaction (suggesting product was received and used)?

4

Has this customer email, phone, or address appeared in a prior chargeback?

5

Is the disputed order in the top 25% of this customer's order history by value?

6

Did the customer use the service or access the digital goods (login logs, usage data)?

7

Does the dispute reason code mismatch the actual situation (e.g., "not received" but tracking shows delivered)?

8

Was 3DS authentication completed successfully at the time of transaction?

9

Are there 2+ prior undisputed transactions from the same device or IP within 120 days (CE 3.0 qualifying)?

10

Does the chargeback come within 7 days of a subscription renewal or auto-charge?

How to Fight First-Party Fraud with Compelling Evidence 3.0

Compelling Evidence 3.0 (CE 3.0) is the most powerful tool available for fighting first-party fraud on Visa disputes. Introduced in April 2023, it lets merchants shift liability by proving the cardholder recognised the merchant in prior transactions.

CE 3.0 qualifying criteria

  • Two prior transactions from the same device fingerprint or IP address as the disputed transaction
  • Within 120 days of the disputed transaction (365 days for digital goods/services)
  • Neither prior transaction was disputed — they must be clean, non-refunded transactions
  • Dispute reason code: CE 3.0 applies to Visa reason code 10.4 (card absent fraud)

When CE 3.0 criteria are met, Visa can stop the dispute before it becomes a chargeback — a "no-chargeback" outcome where neither party wins or loses in the traditional sense, but you avoid the ratio impact and the fee.

Documents to gather for a CE 3.0 response:

  • Device fingerprint log for all 3 transactions (disputed + 2 prior)
  • IP address at time of each transaction, with geolocation
  • Login session logs showing the cardholder accessed their account
  • Email confirmation of prior orders (showing same email address)
  • Shipping address match across transactions
  • Delivery confirmation for prior orders (to show undisputed successful fulfilment)

CE 3.0 requires device/IP data collection at purchase

CE 3.0 only works if you captured device fingerprint and IP address at the time of each qualifying transaction. If you are not currently collecting this data, the evidence doesn't exist retroactively. Implement session logging and device fingerprinting now — every transaction without it is a future CE 3.0 case you can't build.

Win rates for well-evidenced CE 3.0 responses run 50–70%, making first-party fraud (under Visa 10.4) one of the highest-ROI categories to fight through representment. The average repeat offender commits 9+ incidents — identifying and blocklisting them after the first successful representment prevents compounding losses.

Frequently Asked Questions

What is the difference between first-party and third-party fraud?+
Third-party fraud = someone else uses your identity or card without consent. First-party fraud = you use your own genuine identity and card to dispute a legitimate transaction you authorised. First-party fraudsters pass every verification check because everything is authentically theirs.
How common is first-party fraud in eCommerce?+
Industry estimates: 40–60% of all chargebacks for the average merchant. For digital goods and subscriptions, up to 70–80%. Total annual cost to US merchants exceeds $100 billion. The average repeat offender commits 9+ incidents before being identified.
Can I win a chargeback where the customer is committing friendly fraud?+
Yes — first-party fraud is one of the most winnable chargeback categories. Compelling Evidence 3.0 (Visa) lets you submit prior undisputed transactions from the same device/IP to prove account ownership. Well-evidenced CE 3.0 cases win at 50–70%.
What is Compelling Evidence 3.0 and how does it help fight first-party fraud?+
CE 3.0 is a Visa rule (2023) allowing merchants to prove a disputed transaction is consistent with the cardholder's authenticated purchase history. Submit 2 prior undisputed transactions from the same device fingerprint or IP within 120/365 days, and Visa can stop the dispute before a formal chargeback is filed.
How do I identify repeat first-party fraudsters?+
Link dispute history across email, shipping address, phone number, and device fingerprint — not just card number. Fraudsters rotate cards but often reuse their real identity markers. A customer with 2+ chargebacks across any card in 12 months warrants blocklisting.

ChargeMate identifies first-party fraud patterns and builds CE 3.0 evidence packages.

$10/case. No monthly fees. Only pay when we work a dispute.

See outsourcing plans →