First-Party vs Friendly vs True Fraud: A Merchant's Field Guide
True (third-party) fraud is a stolen card used by a criminal — the cardholder is a victim. First-party fraud is the legitimate cardholder disputing their own valid purchase; friendly fraud is the common subset driven by confusion or convenience. True fraud usually falls on the merchant; first-party fraud can be fought and won with evidence.
Three chargebacks land in your queue, all coded as fraud. One is a stolen card. One is a customer who forgot they subscribed. One is a customer who knows exactly what they’re doing and wants their money back anyway. They look identical on the surface — and each one needs a completely different response.
The three types, defined
The word “fraud” hides three very different situations. Getting the labels right is the first step to responding correctly.
True fraud (third-party fraud). A criminal uses a stolen or compromised card to make a purchase the real cardholder never authorized. The cardholder is a genuine victim. When they spot the charge, they dispute it — correctly. This is the “real” fraud everyone pictures, and it’s often the minority of fraud-coded chargebacks today. It frequently traces back to earlier card testing, where stolen numbers are validated before use.
First-party fraud. The legitimate cardholder disputes a charge they actually made. The card wasn’t stolen; the account holder placed the order and then filed a dispute. First-party fraud is the umbrella term for any dispute where the person who made the purchase is the same person disputing it.
Friendly fraud. A common subset of first-party fraud — usually the softer, higher-volume cases driven by honest confusion (an unrecognized descriptor, a forgotten subscription) or convenience (disputing is easier than requesting a refund). The line between “friendly fraud” and “first-party fraud” is blurry, and many people use the terms interchangeably. The distinction that matters: friendly fraud often isn’t malicious, while deliberate first-party abuse — sometimes called cyber-shoplifting — is outright theft. We go deep on this in friendly fraud.
Comparison at a glance
| True fraud (third-party) | First-party fraud | Friendly fraud (subset) | |
|---|---|---|---|
| Who made the purchase | A criminal with a stolen card | The real cardholder | The real cardholder |
| Who files the dispute | The victimized cardholder | The cardholder | The cardholder |
| Cardholder’s intent | Legitimate — they’re a victim | Ranges from confused to deliberate | Usually confusion or convenience |
| Was the dispute valid? | Yes | No — the charge was authorized | No |
| Typical liability | Merchant (in card-not-present) | Merchant, unless you fight and win | Merchant, unless you fight and win |
| Winnable via representment? | Rarely | Often | Often |
| Best defense | Prevention at checkout | Evidence + prevention | Evidence + prevention |
The single most important row is the last three. True fraud is prevented; first-party and friendly fraud are fought.
Who bears the liability
Liability is where these types diverge most sharply.
For true third-party fraud in card-not-present transactions, the loss typically lands on you, the merchant. You accepted a card without confirming the real owner made the purchase, so the network holds you responsible. This is why prevention — AVS, CVV, and especially 3-D Secure — is your only real lever. On qualifying 3-D Secure transactions, fraud liability shifts to the issuer, which is the closest thing to protection you get against true fraud.
For first-party and friendly fraud, liability starts with you but isn’t fixed. Because the transaction was genuinely authorized by the person disputing it, the facts favor you — and representment can shift the liability back to the issuer when you document the case well. This is what makes these disputes winnable: you’re not arguing against reality, you’re proving it.
How the fight differs by type
Your response should match the type. Spending effort on the wrong fight wastes time and money.
True fraud: don’t fight, prevent
If a card was genuinely stolen, the cardholder is a victim and the dispute is legitimate. Representment almost never wins, and pursuing it wastes resources. Your entire strategy is upstream prevention: strong AVS/CVV checks, 3-D Secure, velocity limits, and fraud scoring to stop the transaction before it happens. Once a true-fraud chargeback lands, accept it and tighten the gate that let it through.
First-party and friendly fraud: fight with evidence
Here the truth is on your side, so you document it. The winning evidence is transaction and behavioral proof that the real cardholder made and benefited from the purchase:
- Order records tying the purchase to the customer’s account
- AVS and CVV matches showing the buyer knew the card details
- Delivery confirmation with tracking to the cardholder’s verified address
- IP, device, and login history placing the customer at the transaction
- Prior undisputed purchase history (the backbone of Visa’s Compelling Evidence 3.0)
- Customer communications showing they had and used the product
Submit the right evidence for the specific reason code, before the deadline, and these disputes are frequently winnable. Where deliberate first-party abuse is involved, the fight also serves as a deterrent — and in serious or repeated cases, knowingly disputing valid charges is itself fraud that can carry legal consequences, covered in can you go to jail for chargeback fraud.
Telling them apart in practice
You rarely get a label on the chargeback — you infer the type from the reason code plus the order data. The tell is the mismatch between the claim and the evidence:
- Fraud claim + delivery to the cardholder’s verified address + AVS/CVV match + prior clean history → almost certainly first-party or friendly fraud. A thief doesn’t ship to the victim’s house.
- Fraud claim + shipment to an unfamiliar address + unusual device/IP + mismatched data → likely true third-party fraud.
- A wave of tiny fraud disputes across many cards → the downstream result of card testing, a true-fraud problem at the source.
Reading this correctly per dispute is what lets you fight the winnable ones and prevent the rest — instead of blindly fighting everything or accepting everything.
Where automation helps
Sorting fraud types and assembling reason-code-specific evidence per dispute, before each deadline, is exactly where manual programs break down. DisputeDash detects each dispute the moment your processor reports it, gathers the right evidence for the reason code — order data, delivery and tracking, AVS/CVV, IP, and customer comms — builds the rebuttal, and submits on time. It focuses on the disputes worth fighting (first-party and friendly), where evidence wins, holding an average win rate near 87% across 12,000+ disputes on a flat fee with no commission.
The bottom line
True fraud is a stolen card and a victimized cardholder — prevent it at checkout, because you rarely win it. First-party fraud is the legitimate cardholder disputing their own valid purchase, and friendly fraud is its common, softer subset — both are winnable with evidence because the transaction was real. Read the reason code against the order data to tell them apart, then match your response to the type: prevention for true fraud, representment for the rest.
Win more chargebacks, automatically.
DisputeDash gathers the evidence, builds the rebuttal, and submits before the deadline — across Stripe, PayPal, Braintree, PayArc and more. Flat fee, no commission.
Start free — keep 100%