Friendly Fraud: What It Is, Why It Happens, and How to Prevent It Before It Hits Your Bottom Line

A Woman Looking at Sticky Notes about friendly fraud prevention

Originally published December 18, 2025. Last updated September 18, 2026 as a Wyllo-owned definitional guide, with 2025 and 2026 data from Visa, Mastercard, the MRC, LexisNexis Risk Solutions, Juniper Research, and the Federal Reserve, plus a comparison of friendly fraud, first-party fraud, and true fraud.

Friendly fraud is when a real customer makes a legitimate purchase with their own payment method, then disputes the charge with their bank instead of contacting the merchant. The transaction was authorized. The goods or services were delivered. The chargeback arrives anyway, usually coded as “fraud” or “unauthorized,” and the merchant loses the revenue, the product, and a dispute fee.

That definition sounds simple. In practice, friendly fraud is one of the hardest problems in ecommerce risk because the order looked normal when it was approved and the customer is, by every conventional signal, real. Visa’s own research puts friendly fraud at around 20% of all fraudulent disputes globally, and up to 30% for high-volume online merchants. More than half of merchants told Visa that first-party misuse is their primary dispute challenge.

This guide covers what friendly fraud is, how it differs from first-party fraud and true fraud, why it happens, the signals that precede it, and how to prevent it without adding friction for the customers who deserve none.

What Is Friendly Fraud?

Friendly fraud (also called first-party misuse, chargeback fraud, or first-party fraud depending on who is speaking) describes a chargeback filed by the actual cardholder, or someone in their household, against a purchase that was genuinely made. The Merchant Risk Council prefers the term “first-party misuse” and notes that the problem represents up to 80% of all fraud-related chargebacks for many of its merchant members.

The word “friendly” refers to the source, not the intent. Intent sits on a spectrum. At one end is an honest mistake: a parent who does not recognize a teenager’s purchase, or a subscriber who forgot a renewal. At the other is deliberate abuse: a shopper who received the item, kept it, and disputed the charge to get it for free.

Merchants experience friendly fraud almost entirely through the chargeback process. Because the cardholder tells their bank the charge was unauthorized or the goods never arrived, these disputes usually land under fraud or “item not received” chargeback reason codes such as Visa 10.4 (Fraud, Card-Absent Environment), Mastercard 4837 (No Cardholder Authorization), or Visa 13.1 (Merchandise or Services Not Received). The reason code says fraud. The order history says otherwise. That gap is where the whole problem lives.

Friendly Fraud vs. First-Party Fraud vs. True Fraud

The three terms overlap and are often used interchangeably, but the distinctions matter for how you respond. True fraud is a payment security problem. Friendly fraud is a customer experience and evidence problem. Deliberate first-party fraud is a policy and enforcement problem.

Friendly fraud First-party fraud True fraud
Who made the purchase The cardholder or someone in their household The cardholder A criminal using stolen card or account credentials
Was the transaction authorized Yes Yes No
Intent Often confusion, forgetfulness, or frustration; sometimes opportunistic Deliberate. The customer knows the charge is valid and disputes it anyway Deliberate theft
Typical reason codes Fraud (10.4, 4837), item not received (13.1), not as described Fraud, item not received, credit not processed Fraud (10.4, 4837, 4840)
What the merchant can do Prevent with clarity, communication, and fast resolution; represent with compelling evidence Detect patterns across orders, accounts, and disputes; represent aggressively; restrict repeat abusers Block at checkout with risk screening; chargeback liability often covered by a guarantee
Best owned by CX and payments Risk and CX together Fraud and risk

The Federal Reserve’s payments improvement team frames the deliberate version as “authorized party fraud” and found it made up 37% of fraud events across financial services globally in 2025. Its June 2026 analysis notes the behavior “may resemble normal behavior,” which is exactly why traditional fraud controls struggle with it.

In everyday merchant usage, “friendly fraud” is the umbrella term and “first-party fraud” is the deliberate subset. This guide follows that convention. For how friendly fraud relates to returns abuse, see friendly fraud vs. returns fraud.

Why Friendly Fraud Happens

Most friendly fraud is not driven by bad actors. It is driven by breakdowns in communication, expectations, and customer experience, plus a dispute process that is easier to use than most merchants’ support channels. The root causes tell you where prevention pays off.

Subscription confusion. Recurring billing is the largest source of “unauthorized” disputes for subscription brands. Customers forget they enrolled, misunderstand renewal frequency, or believe they canceled when they did not. The FTC reopened rulemaking on negative option marketing in March 2026, seeking comment on practices that prevent consumers from canceling recurring charges. Regulators are watching the same friction points that generate disputes.

Family and household purchases. A child buys in-app content, a partner orders a gift, a roommate uses a shared card. The cardholder sees an unfamiliar charge and calls the bank. Visa lists household misuse as one of the four primary forms of friendly fraud.

Unrecognized billing descriptors. If the name on the statement does not match the brand the customer bought from (a parent company name, an abbreviation, a processor label), the charge looks like fraud. The customer is acting in good faith. The descriptor failed them.

Buyer’s remorse and slow support. A customer wants a refund, cannot reach support quickly, or hits a return window that already closed. The bank’s dispute button is one tap away, and many customers do not know that a chargeback and a refund are different things.

Fulfillment gaps. Delayed shipments, a package marked delivered that the customer cannot find, duplicate orders, or unclear confirmation emails all push customers to question whether the transaction was legitimate.

Deliberate abuse. A smaller but growing share of customers know exactly what they are doing. Visa describes “free goods” attempts (disputing to keep the item) and return policy abuse (disputing after the return window) as established patterns. Juniper Research projects friendly fraud will grow from 22% of chargebacks globally in 2026 to 28% by 2031, with the value of transactions lost rising from $8.1 billion to nearly $16 billion.

The 2026 MRC Global eCommerce Payments and Fraud Report found 64% of merchants reporting rising first-party misuse, with one quarter seeing increases of 25% or more. Whatever the intent behind any single dispute, the trend line is clear.

How to Spot Friendly Fraud Before It Starts

Friendly fraud can feel unpredictable, but most disputes are preceded by patterns. The order itself is rarely the signal. The signal lives in what happens around the order: account behavior, support interactions, subscription engagement, and prior dispute history. This is what customer intentionality looks like in practice.

Behavioral signals that precede a dispute:

  • Disengaged subscribers. Customers who skip shipments, pause, stop opening emails, or fail a payment retry are the ones most likely to be surprised by the next renewal.
  • Repeated dunning cycles. Multiple retries make a customer assume the charge is an error, or frustrate them enough to dispute the eventual successful attempt.
  • Support contact with no resolution. An unanswered ticket, a stalled refund request, or negative sentiment in a chat transcript often shows up a week or two before the chargeback does.

Intent signals that separate honest mistakes from deliberate abuse:

  • Dispute history across orders and accounts. A customer who has filed “item not received” claims on three prior orders, or who appears under multiple linked accounts with similar patterns, is telling you something. A single order view never surfaces this.
  • Claim frequency. High claim rates relative to order count, especially on easily resold items, correlate with first-party abuse.
  • Delivery confirmed, dispute filed anyway. Proof of delivery plus a tracked account login after the delivery date is one of the strongest indicators that a fraud claim is not what it says it is.

For a deeper checklist, see five signs a chargeback is actually fraud. The point is not to treat every customer as a suspect. It is to know which disputes deserve a proactive refund, which deserve a clarifying email, and which deserve a representment package.

How to Prevent Friendly Fraud Without Adding Friction

Prevention works best when it removes the reasons customers dispute in the first place, then builds the evidence to win the disputes that arrive anyway. Six practices do most of the work. For the broader chargeback playbook, start with how to prevent chargebacks in ecommerce in 2026.

Clear Descriptors and Transparent Billing

Align your billing descriptor with the brand name customers actually recognize, add a customer service phone number or URL where the processor allows it, and reinforce what the statement will say in the order confirmation and shipping emails. This alone removes a meaningful share of “I don’t recognize this charge” disputes.

Proactive Subscription Communication

Send renewal reminders before the charge, not after, with the product, the amount, the date, and a one click path to skip, pause, or cancel. Put the cancel button inside the account portal rather than behind a support ticket. Customers who feel in control of a subscription rarely dispute it. Merchants who protect subscription commerce well treat this as part of the risk program, not just retention.

Fast Refunds for Real Mistakes

When a customer contacts you with a legitimate problem, resolve it faster than their bank would. A refund costs the order value. A chargeback costs the order value, the goods, a dispute fee, and a mark against your chargeback ratio. Make refund paths obvious across email, chat, and self service, and let CX agents act without escalation on clear cases.

Compelling Evidence Collection

Both major networks now give merchants structured ways to overturn friendly fraud disputes with data, but only if you have been collecting that data all along.

Under Visa’s Compelling Evidence 3.0, a merchant facing a 10.4 fraud dispute can shift liability back to the issuer by showing two prior undisputed transactions from the same cardholder, between 120 and 365 days old, where at least two core data elements match the disputed order (user ID, IP address, shipping address, device ID), one of them the IP address or device ID. Visa reports that nearly 90% of enterprise merchants now use compelling evidence to challenge invalid disputes.

Mastercard’s First-Party Trust program works at both authorization and dispute time. Merchants share a device factor (IP address, device ID, or fingerprint) and a delivery factor (shipping address, email, or phone), and disputes meeting the criteria qualify for chargeback protection. Mastercard expanded the program to Canada, Latin America, the Caribbean, and Asia Pacific in June 2025, citing a forecast that global chargeback costs will reach $42 billion by 2028, with nearly half reported as fraudulent.

The practical takeaway: log device IDs, IP addresses, account logins, delivery confirmations, and support interactions on every order, stored where your dispute team can retrieve them in minutes. Evidence you cannot find is evidence you do not have.

Intent-Aware Risk Signals Across the Journey

Friendly fraud does not show up on the checkout screen. It shows up in the relationship between checkout, delivery, account activity, support, and prior disputes. A risk intelligence layer that connects those signals, applies your merchant-specific context, and recognizes linked accounts and repeat patterns is what makes it possible to tell the forgetful subscriber from the serial disputer before the chargeback lands. That lets you refund one customer instantly and route the other to review, without slowing down everyone in between.

Representment for the Deliberate Cases

Some disputes will still arrive. When the evidence shows delivery, account activity, and prior undisputed purchases, chargeback representment is worth the effort, and CE 3.0 and First-Party Trust have made it more winnable than it was two years ago. Track win rates by reason code so you know which fights to pick. For customers whose dispute history crosses a clear threshold, requiring additional verification on future orders is a proportionate response.

Friendly Fraud in Subscription Commerce

Subscription brands carry a disproportionate share of friendly fraud because every renewal is a fresh chance for a customer to be surprised. Churn signals and dispute signals are often the same signals viewed from different teams.

That is the logic behind the Wyllo integration with Stay AI, a subscription management platform for Shopify brands. Stay AI surfaces subscriber level behavior such as skipped shipments, pause requests, failed retries, and declining engagement, which tend to appear weeks before a customer contacts their bank. Wyllo connects those signals with transaction, device, account, and dispute intelligence, so a subscription team can intervene with a reminder or an easy cancellation before the renewal becomes a chargeback, and can bring the combined record to representment when a dispute does arrive. Read more in the Wyllo and Stay AI partnership announcement.

How Wyllo Helps

No single transaction reveals friendly fraud. It becomes visible only when checkout, delivery, account behavior, support conversations, and dispute history are read together, with the merchant’s own context applied. That is the view Wyllo, the risk intelligence platform for commerce, is built to give you, with the recommendation arriving inside the tools your team already works in rather than in a report nobody opens mid-dispute.

  • Wyllo Claim and Policy Abuse Prevention identifies the account, claim, and dispute patterns behind friendly fraud and deliberate first-party abuse, including linked accounts and repeat disputers, so you can catch it before it becomes a chargeback.
  • Wyllo Chargeback Management turns representment into a structured workflow, assembling the compelling evidence networks now reward and tracking win rates by reason code.
  • Wyllo CX Support puts risk context and next best actions inside your CX platform, so an agent handling a refund request knows whether they are talking to a confused subscriber or a repeat disputer.
  • Wyllo Payment Fraud Protection captures the device, identity, and behavioral data at checkout that later becomes your strongest evidence, while keeping approval rates high for real customers.

Insight first.

Frequently Asked Questions

What is friendly fraud?

Friendly fraud is a chargeback filed by a legitimate cardholder against a purchase they, or someone in their household, actually made. The transaction was authorized and typically fulfilled, but the customer disputes it with their bank as unauthorized or not received rather than seeking a refund from the merchant. Visa estimates it represents around 20% of fraudulent disputes globally and up to 30% for high-volume online merchants.

What is the difference between friendly fraud and first-party fraud?

In merchant usage, friendly fraud is the umbrella term for any dispute filed by the real cardholder against a legitimate charge, whether from confusion or intent. First-party fraud (or first-party misuse, the MRC’s preferred term) usually refers to the deliberate subset: the customer knows the charge is valid and disputes it anyway. The Federal Reserve calls this “authorized party fraud.” Card networks often use the terms interchangeably.

How is friendly fraud different from true fraud?

True fraud involves a criminal using stolen card or account credentials; the real cardholder never authorized the purchase. Friendly fraud involves the real cardholder disputing a charge they did authorize. Because the transaction itself was valid, checkout fraud rules alone cannot stop it. Prevention depends on clear billing, proactive communication, strong evidence collection, and intent signals read across the customer journey.

Why does friendly fraud happen?

The most common causes are subscription confusion (forgotten renewals, failed cancellations), household purchases the cardholder did not recognize, unclear billing descriptors, buyer’s remorse paired with slow support, fulfillment gaps such as delayed or misdelivered packages, and a smaller share of deliberate abuse. The 2026 MRC report found 64% of merchants reporting rising first-party misuse.

How can merchants prevent friendly fraud?

Match your billing descriptor to your brand name, send renewal reminders with easy cancel options, resolve legitimate refund requests faster than the bank would, and log device IDs, IP addresses, logins, and delivery confirmations on every order. Use connected risk signals across checkout, account, support, and dispute history to separate honest mistakes from repeat abuse, and represent the deliberate cases with Visa Compelling Evidence 3.0 or Mastercard First-Party Trust data.

Can merchants win friendly fraud chargebacks?

Yes, increasingly so. Visa Compelling Evidence 3.0 lets merchants shift liability on 10.4 fraud disputes by showing two prior undisputed transactions (120 to 365 days old) with matching device or IP data. Mastercard’s First-Party Trust program offers chargeback protection when merchants share device and delivery data. Visa reports nearly 90% of enterprise merchants now use compelling evidence to challenge invalid disputes.

Bringing It Together

Friendly fraud is not a fraud problem in the traditional sense, and treating it like one leads to the wrong fixes: tighter checkout rules that decline good customers and never touch the disputes filed weeks later. It is a clarity problem, a communication problem, and an evidence problem, with a deliberate minority underneath that deserves a firmer response.

The industry is moving in a helpful direction. Visa and Mastercard have both built structured paths for merchants to prove a purchase was legitimate, and both reward the merchants who collect the right data before a dispute exists. The cost of overcorrecting is real, too: LexisNexis Risk Solutions found in 2026 that every dollar lost to fraud costs US retail and ecommerce merchants about $5.13, and that 56% of US retailers report increased customer churn tied to their anti-fraud measures.

The merchants who handle friendly fraud well read intent across the whole customer journey, refund the honest mistakes quickly, and document the rest. Precision over paranoia.

Curious how an intent-aware risk intelligence approach would change your friendly fraud rate? Start with Wyllo Claim and Policy Abuse Prevention for catching disputes before they become chargebacks, or explore the broader Wyllo platform for connected intelligence across the full customer journey.

More from the blog

Customer Stories

Join our Newsletter

Subscribe to our weekly newsletter to get the latest news, updates, and amazing offers.

Want to Learn More?

If you’re an ecommerce brand looking to improve post-purchase experience without increasing risk, this is a partnership worth exploring. Chat with our team to see it in action.

You might also like

Install Wyllo

Select your ecommerce platform to start your free two-week trial.​

See Wyllo in Action

Contact the Wyllo team and we’ll be in touch within one business day to schedule your personalized demo. 

Let's find those
bad actors.

Contact the Wyllo team and we’ll review your system together to identify the bad actors.