Glossary
First-party fraud (often called friendly fraud) is fraud committed by a real customer using their own genuine identity: such as disputing a legitimate purchase to get a refund while keeping the goods, or misrepresenting information to gain credit they don’t intend to repay. Because the identity is real and the account is legitimate, it defeats defenses built to catch impostors.
The "friendly" label is misleading (there’s nothing friendly about it) but it captures why it’s so slippery: the fraudster is your actual customer, not an outsider. Traditional fraud tools ask "is this really the account owner?" and the answer is yes, so they stay silent.
First-party fraud runs from calculated to accidental. At one end are people who systematically exploit dispute and refund processes for profit. In the middle are opportunists who dispute a charge they recognize because it’s easy and consequence-free. At the far end is genuine confusion (a forgotten subscription, an unrecognized billing descriptor, a family member’s purchase) which isn’t really fraud at all but shows up in the same data. Untangling intent is part of what makes first-party fraud hard.
Every signal that catches third-party fraud fails here: the identity is verified, the device is familiar, the credentials are correct, the behavior is the customer’s own. Detection has to shift to patterns and history: a customer with a suspicious pattern of disputes or returns, claims that contradict delivery or usage evidence, or behavior that statistically resembles known first-party fraud. It’s a data and analytics problem more than an identity problem, and it often requires evidence (delivery confirmation, device and usage logs) to rebut false claims.
Because it hides among legitimate customers, the goal is careful discrimination, not blunt rejection. Tactics include tracking dispute and refund history to spot abusers, capturing strong transaction evidence to contest false chargebacks, tightening policies that are being exploited (without punishing honest customers), and using ML to flag the behavioral patterns of first-party fraud. Many organizations underinvest here because it doesn’t look like classic fraud, yet it drives major losses in chargebacks, refunds, and credit, making it one of the more overlooked, high-impact areas of fraud management.
What is first-party fraud?
Fraud committed by a real customer using their own genuine identity, such as disputing a legitimate purchase.
Why is it called friendly fraud?
The term reflects that it comes from your own customer rather than an outside attacker, though it’s not benign.
Why is first-party fraud hard to detect?
The identity, device, and credentials are all legitimate, so impostor-focused defenses don’t trigger; detection relies on patterns and history.
How do you fight first-party fraud?
Track dispute/refund history, capture transaction evidence, tighten exploited policies, and use ML to spot first-party fraud patterns.
Related: Chargeback Management · Application Fraud · Promotion / Promo Abuse · Loyalty Fraud · Risk Scoring