Friendly Fraud vs True Fraud: Why the Difference Decides Your Response
True fraud is a purchase the cardholder never made; friendly fraud is a real purchase the cardholder disputes anyway. How each shows up in reason codes, and why the response to each is different.
True fraud means the cardholder never bought: a stolen card or a compromised account, disputed under a fraud reason code. Friendly fraud means the cardholder did buy and disputes anyway, under a fraud code or a consumer code. The first is fought before the sale with screening and authentication; the second after it, with evidence and service. Underwriters read a high friendly-fraud share as a product or disclosure problem.
True fraud and friendly fraud produce the same line on your chargeback report and call for opposite responses. True fraud is a transaction the cardholder never made: a stolen card, a compromised account, a card number tested against your checkout. Friendly fraud is a transaction the cardholder did make and disputed anyway, because they did not recognize the descriptor, regretted the purchase or forgot a subscription. The first is an attack from outside, stopped before the authorization with screening and authentication. The second is a failure between you and a real customer, recovered after the sale with evidence and service. Read the reason code as the cardholder's claim, not as the verdict, and sort each dispute yourself.
Two disputes that arrive on the same report
A chargeback is the issuer reversing a transaction at the cardholder's request. The report your acquirer sends lists the amount, the date, the reason code and a response deadline. It does not say whether the person who complained is a victim or your customer. That distinction is yours to establish, and everything downstream depends on it: the tool you switch on, the evidence you keep and the explanation you give the underwriter when the ratio moves.
| Question | True fraud | Friendly fraud |
|---|---|---|
| Who used the card | A third party, without consent | The cardholder, or someone in their household |
| What the cardholder says | "I never made this purchase" | "I do not recognize this", "it never arrived", "I cancelled", sometimes "I never made this purchase" |
| Reason-code family | Fraud | Fraud or consumer dispute, depending on the claim |
| Where the loss starts | At the authorization, before delivery | After delivery, in expectations or billing clarity |
| What reduces it | Address and CVV checks, velocity rules, 3-D Secure | Descriptor, receipts, refund path, disclosure, consent records |
| What recovers it | Little: authentication may shift liability to the issuer | Representment with compelling evidence, or a refund before the dispute forms |
How each one shows up in reason codes
Every dispute carries a reason code, the issuer's label for what the cardholder claimed. Visa groups fraud under its 10 series and consumer disputes under its 13 series; Mastercard uses 4837 for a transaction the cardholder says they did not authorize and 4853 for a cardholder dispute over goods or services. True fraud arrives almost always in the fraud family. Friendly fraud arrives in both: a customer who does not recognize your descriptor tells the bank they never bought, coded as fraud; a customer who wants out of a subscription says they cancelled, coded as a consumer dispute. So the fraud family is contaminated, and the code alone does not settle it; your order data does. Check these signals before you choose a bucket.
- Prior history: the same card, email or device placed earlier orders that were never disputed. A thief rarely has a history with you; a regretful customer often does.
- Address match: billing and shipping addresses agree and pass the address check. Stolen-card orders tend to ship elsewhere or fail it.
- Use after purchase: the account logged in, the file was downloaded, the parcel was signed for. Use is a strong marker of a real buyer.
- Contact: the customer wrote to support or asked for a refund before disputing. A thief on a stolen card rarely asks for one.
- Velocity: many small orders within minutes from one IP address or card range, under different names. That is card testing, and it is true fraud.
- Timing: a dispute weeks after delivery on an item the customer kept points to friendly fraud; one within hours of a large first order points the other way.
The response to true fraud: stop it before the authorization
True fraud is a security problem, and the loss is decided at the moment of authorization. Once a stolen card is approved and the goods leave, the money is gone; no proof of delivery changes who paid. The response therefore sits in front of the sale: address and CVV checks against the issuer's record, velocity rules against bursts of attempts from one source, device and IP screening against a buyer whose request comes from somewhere else. 3-D Secure adds authentication by the issuer and, on an authenticated transaction, generally shifts liability for fraud-coded disputes to the issuer. It does nothing against consumer-dispute codes, which is why it is a true-fraud tool rather than a chargeback tool; the 3-D Secure guide on this blog covers its friction and selective use.
- Decline hard address and CVV mismatches on first orders instead of reviewing them by hand.
- Rate-limit the checkout by IP address and card prefix so a testing script fails after a handful of attempts.
- Route first-time, high-ticket or out-of-region orders through 3-D Secure; keep returning customers with clean history on the frictionless path.
- Accept fraud-coded disputes you cannot defend instead of contesting them; a representment against a stolen-card claim without an authentication record rarely succeeds.
A US entity and director for your next MID
An IBOCore package supplies the US entity, the director who takes the acquirer's call, the bank account and the documents, delivered the same day payment confirms. Browse the inventory page or ask on Telegram.
The response to friendly fraud: evidence and recovery after the sale
Friendly fraud is a relationship problem, and the sale was real. Screening cannot stop it, because the buyer is the cardholder and passes every check. The first line is the billing descriptor: the name on the statement should be the brand the customer bought from, with a support contact, so a charge is recognized before it is disputed; the descriptor guide on this blog covers the format. The second line is the refund path: a customer who can cancel or refund in two steps refunds; one who has to send three emails is more likely to dispute. The third line is disclosure at checkout: price, recurrence, trial terms, delivery time and refund policy visible before the pay button, with a stored record of consent.
When a dispute still arrives, the response is representment: you ask the acquirer to return the transaction to the issuer with compelling evidence that the cardholder bought, received and used what they paid for. The evidence differs by fulfillment type, from a signed delivery to an access log or a consent record, and the compelling-evidence guide on this blog lists what to keep for each. Network rules for card-absent fraud disputes also let a merchant answer certain fraud-coded claims with earlier undisputed transactions from the same cardholder that share a device, login or delivery address: a known customer claiming not to know you. Pre-dispute alert services, offered through many acquirers and gateways, let you refund a transaction before the dispute becomes a chargeback.
- Match the descriptor to the brand on the checkout page and the receipt email, with a phone number or web address.
- Send a receipt when the order is placed and a second message when it ships, downloads or starts.
- For recurring billing, send a reminder before each renewal and offer a one-step cancellation; a dispute coded as cancelled recurring is decided on the consent record and the cancellation log.
- Publish the refund policy where the customer pays, not only in the footer, and store the version the customer accepted with a timestamp. IBOCore's document template pack ($499 one-time) includes refund policy and terms of service templates; the wording of your offer stays your decision.
Why underwriters read friendly fraud as a merchant problem
Both kinds count: neither the acquirer's ratio nor the network monitoring programs exempt a dispute because it was friendly. But the two tell the underwriter different stories. True fraud says a third party attacked the merchant, and the fix is a tool the merchant can switch on. Friendly fraud says the merchant's own customers, who paid willingly, later refused the charge. The underwriter reads that as the offer, the claims in the ads, the descriptor, the trial terms or the refund policy producing disputes. That is a product or disclosure problem, and no fraud tool fixes it.
An acquirer that notices a rising consumer-dispute share on a high-risk MID asks for policies, checkout screenshots, fulfillment records and a call with the director on file. On an IBOCore package the director, the Independent Business Operator (IBO), takes that verification call and signs what the acquirer needs; the package documents show the same person on the state filing and on the EIN letter, so the call and the file agree. The explanation of the pattern is yours, since IBOCore takes no view on your products, funnels or offers. Bring the classification from the routine below, the change you made and the month it took effect; an underwriter who sees a merchant that can name the cause of its disputes reads the ratio differently from one who cannot.
The wrong tool for the wrong fraud
Adding 3-D Secure to a friendly-fraud problem adds checkout friction and leaves the consumer-dispute count where it was: the buyer is the cardholder and passes authentication. Rewriting the descriptor after a card-testing attack is the same mistake the other way. Classify first, then spend.
A monthly routine for sorting your own disputes
- Export the month's disputes with reason code, order number and original sale date.
- For each fraud-coded dispute, run the six signals above and tag it true fraud or friendly fraud.
- For each consumer-coded dispute, tag it friendly fraud or merchant error (late shipment, wrong item, double charge), a third bucket with its own fix.
- Count the three buckets by product, traffic source and first versus repeat order. The pattern often sits in one product or one channel.
- Act on the largest bucket first: authentication and velocity rules for true fraud, descriptor and refund path for friendly fraud, operations for merchant error.
- Keep the tagged list; when the acquirer asks why the ratio moved, you answer with your classification and the change you made.
The routine also tells you which IBOCore plan your volume belongs on. The IBO package costs $999 setup, then $2,999 per month from 30 days after delivery, whatever the vertical or the billing model. In the package, if the acquirer terminates a MID, there is no clawback on IBOCore's side; the package stays yours and can be presented to another acquirer, with a dispute history you can now explain.
The next MID, with a dispute history you can explain
Packages ship the same day payment confirms; acquirer onboarding then takes 3 to 10 business days, on the acquirer's timeline. Browse the inventory page or bring your questions to Telegram.
Questions merchants ask
Does a fraud reason code always mean true fraud?
No. The code records what the cardholder told the issuer, and a customer who does not recognize a charge says they never made it. Many fraud-coded disputes are real purchases with a confusing descriptor or a forgotten renewal. Check the order against your own signals before you treat it as a stolen card.
Does 3-D Secure protect me against friendly fraud?
Only for the part that arrives under a fraud code on an authenticated transaction, where the liability shift moves the loss to the issuer. A customer who says the product did not arrive, was not as described or was cancelled files under a consumer code, and authentication is irrelevant there. Evidence and the refund path are the defense for those disputes.
Do friendly-fraud chargebacks count toward my chargeback ratio?
Yes. The acquirer's ratio and the network monitoring programs count disputes whatever the reason code. A won representment recovers the funds; whether the dispute leaves the monitoring count depends on each network's program rules. That is why refunding before a dispute forms, and fixing the descriptor and disclosure that produce friendly fraud, protect the MID more than winning disputes after the fact.
Compliance touchpoints that survive audit
Clean setups disclose beneficial ownership, file BOI, use genuine IDs, and keep the IBO informed of website and descriptor changes. Processors re-scan for prohibited products, undisclosed aggregation, and transaction laundering. Violations land on MATCH and kill future MID applications.
- AML / CDD: customer due diligence on the merchant entity.
- PEP screening: politically exposed persons get enhanced review.
- OFAC / SDN: sanctions lists checked on owners and signers.
- Website compliance: refund policy, terms, pricing visible before checkout.
Compliance shortcuts that trigger MATCH
Fake guarantors, borrowed SSNs, cloaked websites, and third-party processing through your MID are the fastest paths to MATCH listings. Recovery requires legal work and years of delay. Disclose, document, and keep the IBO in the loop.
FAQ: quick answers
How fast can I get an IBO package on IBOCore?
Available inventory ships the same day after payment. You receive Articles, EIN letter, registered agent details, bank onboarding pack and signer contact through your merchant dashboard. Processor onboarding typically follows over the next one to two weeks.
Where can I look up payment-processing jargon?
Use the Resources glossary on IBOCore (/resources) for 580+ definitions: MID, chargeback ratio, MATCH, rolling reserve, MCC, RDR, KYB and high-risk vertical vocabulary.
Ready for instant delivery?
Browse live IBO inventory or ask about your vertical on Telegram.