What first-party fraud is, and how to tell it from third-party fraud


TL;DR
First-party fraud is a cardholder disputing a purchase they actually made. It is the same behaviour the industry used to call friendly fraud, and Visa now labels it first-party misuse in its own dispute material. Third-party fraud is a criminal using stolen credentials. They arrive as the same claim under the same Visa condition 10.4, and only your own order history separates them. It can meet the elements of fraud in law, but no merchant has a practical route to prosecuting it.
A dispute lands on a $180 order. The reason code says fraud. Your delivery confirmation says the parcel reached an address that same cardholder has used four times this year.
That is first-party fraud: the cardholder made the purchase, then told their bank they did not. The industry used to call it friendly fraud, and the card networks have been moving to the newer name. Which name each network uses decides which document holds the rule you need.
What is first-party fraud, and why do the networks call it first-party misuse?
Visa's friendly fraud explainer on corporate.visa.com, checked July 23, 2026, defines it in one line: "Friendly fraud is when a cardholder disputes a legitimate transaction that they made or someone in their household made."
The same page explains the other name directly. "It's often referred to as first-party misuse because, unlike third-party fraud, which involves stolen credentials, friendly fraud happens when a cardholder falsely claims a purchase was unauthorized or fraudulent."
Visa's Evolution of Compelling Evidence merchant FAQ, dated March 2023, is blunter: "First-party misuse occurs when cardholders report fraud on authorized transactions." Visa built Compelling Evidence 3.0 as, in that document's words, "a remedy for merchants to defend against first party misuse".
Mastercard runs both names at once. Its program is called First-Party Trust, while the June 2025 page announcing that program's expansion is published under the heading "Scaling efforts to combat friendly fraud". Mastercard blocks automated retrieval, so that is the published page title rather than a quote from the body.
American Express uses none of these words. Its merchant dispute process guide, checked July 23, 2026, walks through an Inquiry, a document request, then a Chargeback, with no mention of motive.
Banks use "first-party fraud" more broadly, covering things like credit applications made under a real identity with no intention of repaying. On a Shopify store it means the dispute case above.
The rename has not reached your dispute record
Visa's Dispute Management Guidelines for Visa Merchants, dated June 2024, does not contain the phrase "first-party misuse" anywhere. Condition 10.4 is still titled "Other Fraud, Card-Absent Environment". The new vocabulary lives in Visa's rules and programme material, not on your case.
How is first-party fraud different from third-party fraud?
The difference is who was at the keyboard, and it decides everything downstream.
| First-party fraud | Third-party fraud | |
|---|---|---|
| Who made the purchase | The cardholder, or their household | A criminal using stolen credentials |
| What the bank is told | "I did not authorise this" | "I did not authorise this", and it is true |
| Where the goods went | To the cardholder | To an address the cardholder has never seen |
| Common Visa conditions | 10.4, plus 13.1 and 13.3 | 10.4 |
| Does prevention help | Partly, by removing the confusion that triggers it | Yes, this is what fraud screening exists for |
| Is representment worth it | Often, the evidence exists | Rarely, you have no answer to a genuinely unauthorised charge |
The second row is the awkward one. Both arrive as the same sentence, under the same code, with no flag telling you which you are holding.
Visa's own June 2024 guidelines list three common causes of a 10.4, and only one is a criminal. The third is "Due to an unclear or confusing merchant name the cardholder believes the transaction to be fraudulent." In its main fraud code, Visa is telling merchants that a share of these are a naming problem. That is why your billing descriptor is a chargeback prevention tool rather than a formatting detail.
How do you tell them apart from a Shopify order?
Not with certainty. What you have is five signals that move the odds, all already in your admin.
The delivery address has history. The same address on earlier orders that were never disputed is the strongest signal you hold, and the backbone of Visa's Compelling Evidence 3.0 test.
The account has an order history. A logged-in customer with repeat orders behaves nothing like a stolen-card run. Guest checkout costs you this signal.
AVS and CVV matched. Not proof, since a criminal holding full card details passes both, but a mismatch pushes towards third-party.
The customer never contacted support. Real fraud victims rarely email you first, because they do not know who you are. Someone waiting nine days for a parcel usually does.
The dispute arrived long after delivery. Third-party fraud surfaces fast, when the real cardholder reads their statement.
Treating any one as proof is how merchants file confident representments they lose. What they do is sort a queue. A dispute carrying four of the five is worth 30 minutes of evidence assembly. One carrying none is not.
Sorting also exposes how many did not need to happen. A customer who cannot identify a charge, or who has heard nothing about a late parcel, files the same 10.4 a deliberate abuser does. Closing that gap is what preventing avoidable disputes is aimed at, a different job from fraud screening.
Is first-party fraud illegal?
It can be. That is a different sentence from "you can do something about it", and most pages blur the two.
The cardholder's side is statutory. Regulation Z, at 12 CFR 1026.13, implementing the Fair Credit Billing Act, defines a billing error to include an extension of credit not made to the consumer or a person authorised to use the account, and property or services the consumer did not accept or that were not delivered as agreed. Notice is due within 60 days of the first statement showing the charge. Filing a dispute is a right, not a wrong.
Knowingly lying inside that dispute is a different act. Federal wire fraud, 18 U.S.C. § 1343, reaches any "scheme or artifice to defraud, or for obtaining money or property by means of false or fraudulent pretenses" sent by wire in interstate commerce, and carries up to 20 years. An online dispute form is a wire.
Here is the part the vendor blogs skip. Section 1343 is a federal criminal statute, and only federal prosecutors bring it. No US Attorney is opening a file over a $180 hoodie. A merchant cannot start a prosecution, only report one. The realistic options are civil: small claims, collections, or refusing future orders, and the first two cost more than the order.
So the honest answer is yes in principle, and no in any way you can act on.
What actually works against each type
The levers attach at different points, and using the wrong one is the common mistake.
Before the order. Fraud screening, 3-D Secure, address and card verification. These are third-party tools. They do almost nothing about a real customer using their own card, because nothing about the order looks wrong.
After the order, before the dispute. This is where first-party volume actually falls: an unambiguous descriptor, delivery updates that arrive before the customer goes looking, and a refund path easier than calling the bank. The networks also push an early signal when a cardholder starts a dispute, and deflecting the dispute before it is filed is the only lever that keeps it out of your monitoring count.
After the dispute. Representment. Compelling Evidence 3.0 is the one network rule written for this behaviour, and it works by matching prior undisputed orders to the disputed one, as in how Visa Compelling Evidence 3.0 works for Shopify orders.
Be precise about what representment buys. It recovers the money. It does not remove the case from your ratio, which is why winning a chargeback does not fix your dispute ratio.
The honest part
You will misclassify some of these. A household member using the family card produces a dispute that is technically first-party and genuinely unknown to the person who filed it.
A share of what merchants file under first-party fraud is not fraud at all. It is a customer who was confused or badly served, and labelling it fraud internally is how a brand stops fixing the cause.
Be careful with the numbers you read. Visa's own page puts friendly fraud at "around 20% of all fraudulent disputes globally, and up to 30% for high-volume online merchants", citing the 2025 Global eCommerce Payments & Fraud Report. Much higher figures circulate; the ones I chased trace back to vendor surveys with no published methodology.
Compelling Evidence 3.0 has a structural hole too. It needs prior transactions roughly 120 to 365 days old, so your newest customers cannot qualify. Each dispute also carries a fee of roughly $15 to $25 whether you win or lose.
Frequently asked questions
What is the difference between first-party fraud and friendly fraud?
They describe the same behaviour: a cardholder disputing a transaction they or their household actually made. Friendly fraud is the older industry term; first-party fraud and first-party misuse are the newer network-facing labels. Visa's own friendly fraud page uses both, saying the behaviour is 'often referred to as first-party misuse' to distinguish it from third-party fraud involving stolen credentials.
Is first-party fraud the same as chargeback fraud?
Close, but not identical. Chargeback fraud usually implies deliberate intent, a customer knowingly filing a false claim to keep the goods and the money. First-party fraud and first-party misuse are broader and cover unintentional cases too, such as a cardholder who genuinely does not recognise a billing descriptor or a household member's purchase.
Is chargeback fraud illegal?
Knowingly filing a false dispute to obtain money can meet the elements of federal wire fraud under 18 U.S.C. 1343, which covers schemes to obtain money by false pretences transmitted by wire. In practice it is a federal criminal statute that only prosecutors can bring, and small-value ecommerce disputes are not prosecuted. A merchant's realistic options are civil recovery, collections, or refusing future orders.
Which reason code means first-party fraud?
There is no dedicated code. On Visa it most often arrives as condition 10.4, Other Fraud, Card-Absent Environment, which is the same code a genuine stolen-card dispute uses. It also arrives as 13.1, merchandise or services not received, and 13.3, not as described or defective, when the cardholder claims a delivery or quality problem instead of fraud.
What to check this week
Pull last quarter's 10.4 disputes and mark each against three facts you already hold. Did the delivery address appear on an earlier order? Did AVS and CVV match? Did the customer contact support before they contacted their bank?
Sort by how many of the three are true. The pile scoring three is your first-party volume, and it is worth representment time. The pile scoring zero is third-party fraud, and that is a checkout problem rather than a dispute problem.