What is third-party fraud? | Transmit Security

Smash Security Threats Like Pro!

Transmit Security is serving up unbeatable protection – and custom pickleball paddles at RSA 2025. Book a meeting to grab yours and take your security game to the next level!

Glossary

What is third-party fraud?

Third-party fraud is fraud committed using a real victim’s stolen identity without their knowledge. Learn how it differs from first-party and synthetic fraud.
by Transmit Security

Third-party fraud is fraud committed using a real person’s stolen identity or account without their knowledge or consent, the "classic" fraud in which an innocent victim is impersonated by a criminal. It’s the counterpart to first-party fraud (where the real customer is the fraudster) and distinct from synthetic identity fraud (where the identity is fabricated).

The defining feature is a genuine, unwitting victim. Someone’s identity or account is used against them, and when they discover it, they can report it, which is both a detection signal and the reason third-party fraud is the type most people picture when they hear "fraud."

How third-party fraud works

It starts with stolen data or credentials (obtained through breaches, phishing, malware, or the dark web) which the fraudster uses to impersonate the victim. From there it takes familiar forms: account takeover of the victim’s existing accounts, new-account fraud opened in the victim’s name, or unauthorized transactions using stolen payment details. The victim is the source of trust the fraudster exploits and, ultimately, the party harmed.

Third-party vs. first-party vs. synthetic

These three categories are the backbone of fraud taxonomy. Third-party fraud uses a real victim’s real identity without consent. First-party fraud is the real customer defrauding the business using their own identity. Synthetic identity fraud fabricates an identity with no single real owner. The distinction matters because detection differs: third-party fraud is caught by verifying identity and detecting impersonation and takeover; first-party by behavioral patterns and history; synthetic by data validation and pattern detection. A program that only defends against third-party fraud (the traditional focus) leaves the other two largely open.

How it’s detected and prevented

Because third-party fraud hinges on impersonation, the defenses target exactly that: strong identity verification at onboarding to stop stolen and synthetic identities, phishing-resistant authentication to prevent account takeover, and device and behavioral signals to spot when an account is being accessed by someone other than its owner. Since it’s fueled by stolen data, reducing reliance on stealable secrets (going passwordless, avoiding knowledge-based checks) shrinks what stolen data can accomplish. And because the victim can report it, those reports feed detection and recovery.

Why third-party fraud still dominates the conversation

Third-party fraud is what most fraud tooling was originally built to stop, and it remains the largest category people associate with the word "fraud." That focus is a double-edged sword. On one hand, the defenses against it (identity verification, strong authentication, takeover detection) are mature and effective. On the other, the industry’s historical fixation on third-party fraud is exactly why first-party and synthetic fraud grew unchecked for so long: they don’t look like an impostor attacking a victim, so tools tuned for impersonation miss them. A modern fraud program keeps its strong third-party defenses while deliberately extending coverage to the first-party and synthetic categories that impersonation-focused systems overlook. Understanding third-party fraud as one of three distinct problems (not the whole of fraud) is the starting point for closing those gaps.

Frequently asked questions

Is third-party fraud the most common type?

It’s the most recognized and the traditional focus of fraud tools, though first-party and synthetic fraud have grown rapidly and are often underdefended.

What is third-party fraud?

Fraud committed using a real victim’s stolen identity or account without their knowledge or consent.

How is it different from first-party fraud?

Third-party fraud impersonates an innocent victim; first-party fraud is the real customer committing fraud with their own identity.

How is third-party fraud detected?

Through identity verification, phishing-resistant authentication, and device/behavioral signals that spot impersonation and takeover.

Related: Identity Theft · Account Takeover (ATO) · Friendly / First-Party Fraud · Synthetic Identity Fraud · Identity Verification (IDV)

Request a Demo

By clicking the button, you agree to the Terms and Conditions