ArticlesShopifyHow to fight a fraudulent chargeback on Shopify

How to fight a fraudulent chargeback on Shopify

Ben Woodward

GM, Redo

How to fight a fraudulent chargeback on Shopify

I once sorted a quarter of one store's fraud-coded disputes into three piles: the card was genuinely stolen, the cardholder did not recognise the charge, and the cardholder knew exactly what they bought. The piles were nowhere near equal, and the smallest one was actual fraud.

Every one of them arrived tagged as fraud in the Shopify admin. That is the whole difficulty with this reason code.

Three problems, one label

Shopify's help centre documents Fraudulent as the cardholder not authorising the charge, and keeps a separate Unrecognized category for a customer who does not recognise the merchant name on their statement. Issuers do not always split them that cleanly, so the codes you receive will blur.

True third-party fraud. Someone else used the card. The cardholder is telling the truth. Your evidence will not identify the buyer, because the buyer went to some trouble not to be identified.

Unrecognized. The purchase was real, the customer forgot, or the billing descriptor on the statement bears no resemblance to the store name. This is a labelling failure, not a crime, and it is enormously common. If your descriptor reads CORP*RDO and your store is called something else entirely, you are manufacturing these.

First-party misuse. The customer bought it, received it, and disputed it anyway. Often after a return window closed, or after a support conversation went badly.

The evidence that wins the third pile is different from the evidence that helps in the second, and nothing wins the first.

What each piece of evidence actually proves

This is where most guides stop at "submit compelling evidence." Here is what each item does and does not carry.

EvidenceStrongest againstWeak or useless against
AVS and CVV matchStolen-card claimsFirst-party misuse (the real cardholder passes their own check)
Device or IP continuityUnrecognized disputes, once tied to prior ordersA single order with no history to compare against
Prior undisputed ordersFirst-party misuseTrue third-party fraud (a thief has no order history to contradict)
Delivery to the billing addressAll three, when address and cardholder matchAny case where shipping and billing addresses diverge
Customer messages about the orderFirst-party misuse and unrecognizedTrue third-party fraud (the thief never messaged you)

AVS and CVV results. A full AVS match and a CVV pass show the person at checkout held the physical card and knew the billing address. Strong against a stolen-card claim, weak against first-party misuse, because the real cardholder passes their own AVS check trivially.

The device fingerprint and IP address. These matter most when you can show continuity: the same device or IP on this order and on earlier orders the cardholder never disputed. An IP alone proves someone was on a network. An IP that matches three previous undisputed orders to the same shipping address proves a relationship.

Prior undisputed orders. The single strongest artifact for first-party misuse. A customer with a two-year purchase history who suddenly claims they never authorised anything is making a claim their own record contradicts. This is also the backbone of Visa's Compelling Evidence 3.0 rule for reason code 10.4, which formalises exactly this argument.

Account login records. If the order was placed from a logged-in account tied to the cardholder's email, and that account existed before the disputed order, say so and show the login timestamp. Guest checkout gives you none of this, which is one quiet argument for accounts.

Delivery evidence. Carrier tracking to the cardholder's own billing address is materially stronger than tracking to any other address. If they diverge, expect to lose, and be honest with yourself about why.

The billing descriptor. Include what appears on the statement and what the store is called. For an unrecognized dispute, the mismatch is frequently the entire story, and a reviewer cannot infer it.

Customer messages. An email asking where the order is, a return request, a review, a complaint about the colour. Any of these establishes that the cardholder knew about the purchase. Merchants under-use these badly, because support conversations live in a different tool from orders.

The Shopify fraud analysis score is not evidence

Shopify's fraud analysis gives orders a risk level before you fulfill. It is a useful pre-fulfillment signal and a poor post-dispute exhibit.

The reason is simple: it is your own vendor's opinion about your own order, produced by a model the issuer cannot inspect. "Shopify rated this low risk" answers nothing the reviewer asked. A low-risk score also does not mean the transaction was authorised, only that it did not look unusual.

Use it to decide what to ship. Do not paste it into a representment and expect it to do work.

Building the response inside Shopify

Shopify says its response window is usually 7 to 21 days, and that it varies. Read the actual due date on the dispute. For Shopify Payments merchants, Shopify's documentation says it automatically collects available data and submits on the due date unless you submit sooner.

The auto-collected material covers order, address, and IP data Shopify already holds. It does not go and find the three prior undisputed orders from the same customer, the login timestamps, or the support thread where the customer described the product. Those are the items that separate a response from a form submission, and gathering them is 20 to 45 minutes per dispute.

Reclaim assembles that packet from the store's own order, customer, and conversation history and files it before the deadline. It is free: no install cost, no success fee, and the merchant keeps 100% of recovered funds. We built it that way because recovery runs on infrastructure we already operate, so charging a share of it never made sense to us.

The honest part

Accept the true fraud. If the card was stolen, the shipping address is unrelated to the cardholder, and AVS failed, you will not win, and the 40 minutes is better spent tightening checkout rules. Knowing which pile a dispute belongs to is most of the skill here.

Shopify Protect helps on part of this, not all of it. Shopify describes it as protecting eligible orders against fraudulent and unrecognized chargebacks, which by definition leaves product not received, subscription cancelled, and product unacceptable disputes with you. Check your own eligibility rules rather than assuming coverage.

And the ratio point, which vendors selling win rates skip: a fraud dispute counts toward your card network monitoring ratio whether you win the representment or not. Recovering the revenue is real. It does not undo the count. Only stopping the dispute from being filed does that, which is a different product category from representment.

Frequently asked questions

What is the difference between a Shopify fraudulent chargeback and an unrecognized one?

Shopify's help centre documents Fraudulent as the cardholder saying they did not authorise the charge, and keeps a separate Unrecognized category for a customer who does not recognise the merchant name on their statement. Issuers do not always split them cleanly, so the evidence has to cover both possibilities.

Is a Shopify fraud analysis score good evidence for a chargeback response?

No. It is your own vendor's opinion about your own order, produced by a model the issuer cannot inspect. A low-risk score does not mean the transaction was authorised, only that it did not look unusual. Use it to decide what to ship, not to argue a case.

Can I win a chargeback if the card was actually stolen?

Usually not. If the shipping address is unrelated to the cardholder and AVS failed, the evidence will not identify the true buyer, because the buyer went to some trouble not to be identified. That time is better spent tightening checkout rules than fighting the case.

Does winning a fraudulent chargeback remove it from my chargeback rate?

No. A fraud dispute counts toward your card network monitoring ratio whether you win the representment or not. Recovering the revenue is real, but it does not undo the count, only stopping the dispute from being filed does that.

Where to start

Pull your last twenty fraud-coded disputes and tag each one with a pile: stolen card, unrecognized, or first-party misuse.

If the unrecognized pile is the biggest, your next move is not a better evidence template. It is your billing descriptor, and that is a one-afternoon fix in your payment settings.