The Friendly Fraud Problem: When the Customer Is the Fraudster

The Friendly Fraud Problem: When the Customer Is the Fraudster | HL Hunt
Institutional Outlook

The Friendly Fraud Problem: When the Customer Is the Fraudster

Our fraud series has mapped the professionals: the synthetic identity factories, the account takeover supply chain, the social engineers, the check washers. The final report in the series is about amateurs — because the leading fraud type in the world is now committed by ordinary customers disputing their own real purchases. First-party fraud has surged to roughly 36% of all reported fraud globally, up from ~15% a year earlier, surpassing scams for the top spot, with e-commerce exposure around $130 billion a year — a crime wave with no criminals in the usual sense, normalized by social media as a "hack," and aimed at a dispute system built on the assumption that cardholders tell the truth. This is the anatomy of cyber-shoplifting: who does it, why it spread, what it costs, and how the system is learning to tell honest disputes from convenient ones.

By the HL Hunt Research Desk · 22 min read · Updated July 2026

The core thesis

The chargeback was designed as consumer protection's nuclear option: a mechanism ensuring that when a card is stolen or a merchant doesn't deliver, the cardholder isn't the one holding the loss. Its design assumption — reasonable in 1974 — was that invoking it is rare, adversarial, and honest. Our thesis is that friendly fraud is what happens when that assumption meets one-click dispute buttons and a generation taught to treat the button as a free returns program with no return shipping: the protection mechanism has been quietly repriced by its users as a convenience feature, and the system's economics — issuers finding it cheaper to write off small disputes than investigate them, merchants losing most contested "fraud" claims by default — reward the reinterpretation. The result is a fraud category with no stolen credentials, no malware, and no organized rings required: the payment instrument works exactly as designed, and the fraud is entirely in the intent — which is precisely why every automated defense built for the professional fraud economy fails against it. You cannot device-fingerprint a lie.

What makes this a systems story rather than a morality tale is the same dynamic we documented in the credit file's dispute machinery: a consumer-protection right, industrialized by volume, degrading for everyone. As abuse share rises, the system's rational responses — more evidence requirements, more dispute friction, more algorithmic skepticism of cardholder claims — tax the honest disputant with the real stolen card and the genuinely missing package. The dispute right runs on credibility the way currency runs on trust, and friendly fraud is counterfeiting: each fake claim spends the credibility that real claims depend on. The interesting question this report tracks isn't whether merchants can win more representments — it's whether the networks can re-anchor the dispute system's honesty assumption with data before the assumption, and the consumer trust built on it, finishes eroding.

You cannot device-fingerprint a lie. The payment worked exactly as designed — the fraud is entirely in the intent, which is why every defense built for professional fraud fails against the amateur kind.

The abuse readings

GaugeReadingContext
Share of all reported fraud~36%, up from ~15% a year earlierNow the leading fraud type globally, surpassing scams
E-commerce exposure~$130B annuallyAgainst global chargeback volume ~$34B, projected ~$42B by 2028
Share of disputesMajority (merchant estimates) vs. ~20–30% (network figures)Intent is unprovable at scale — the honest measurement spread
Merchants reporting first-party fraud79% in 2024, up from 34% in 2023With 83% of enterprise merchants reporting increases over three years
All-in merchant cost~$3.75–4.60 per disputed dollar~$74 average handling cost per dispute; up ~37% since 2020
Behavioral markers~65% remorse-driven; 40–50% repeat within 60 days; 42% of Gen Z admit itThe normalization signature: it works once, it becomes a habit
System perception83% of issuers: "customers know how to file"; 77% of merchants: "too easy"Both sides of the counter agree on the mechanism

The taxonomy: confusion, remorse, and the serial disputer

Precision matters here, because the category spans innocence to larceny and the remedies differ. Tier one — honest confusion: the unrecognized billing descriptor (the single largest manufacturer of accidental disputes), the spouse's or teenager's purchase, the forgotten subscription, the merchant name that doesn't match the storefront. No intent, fully preventable by the merchant, and the reason descriptor hygiene is the cheapest fraud tool in payments. Tier two — opportunistic remorse: the purchase regretted after arrival, converted to a dispute because the chargeback path is easier than the return policy — the driver behind roughly 65% of first-party disputes. The tell is the behavioral economics: the customer isn't lying about the transaction, they're lying about the category, filing "unauthorized" or "not received" because those boxes refund faster than "changed my mind." Tier three — the serial disputer: deliberate cyber-shoplifting as a habit — high-value electronics, digital goods, and services ordered with the dispute pre-planned, the behavior repeating (40–50% re-offend within 60 days) because the first success teaches that it works. Tier one deserves prevention; tier two deserves friction and evidence; tier three deserves detection and refusal — and the sophistication of modern dispute defense is mostly the discipline of not treating all three as one enemy.

42%
Share of Gen Z shoppers who admit to committing first-party fraud — the normalization statistic. Social media reframed the dispute button as a "financial hack," and 40–50% of first-time friendly fraudsters repeat within 60 days. It works once; it becomes a habit. (industry survey data)

The normalization machine

Fraud waves usually spread through tooling; this one spread through permission. The mechanism is visible in the survey data: platforms full of "free money" content teaching the dispute script, 42% of Gen Z admitting the behavior, issuers themselves (83%) attributing the surge to customers who've learned the process, and a repeat rate that reveals habit formation rather than desperation. Three accelerants made the culture shift durable. The interface: one-click dispute filing inside banking apps — a deliberate consumer-experience improvement that also removed the friction, the phone call, and the mild social cost that once made false claims feel like lying to a person. The pandemic cohort effect: the e-commerce surge introduced tens of millions to disputes for legitimate reasons (genuine delivery chaos), teaching the mechanism's reliability at population scale. The moral framing: the counterparty is perceived as a faceless platform that "can afford it" — the same rationalization retail shrink runs on, now executable from a couch. The desk's read: this is less a fraud epidemic than a norm change being processed through fraud statistics — which matters strategically, because norms respond to different levers than criminal enterprises do: visible consequences, friction at the moment of filing, and the quiet knowledge that the system remembers.

The economics: why the system pays out

The abuse persists because, transaction by transaction, everyone's incentives point toward paying it. The issuer's math: investigating a $48 dispute costs more than $48 — so small claims get written off in the cardholder's favor as a service cost, which from the filer's side looks like a 100% success rate on small-ticket abuse. Regulation reinforces the tilt: liability rules and customer-retention economics both push issuers toward believing their cardholder. The merchant's math: fighting costs time and evidence for historically poor win rates on "fraud" reason codes; every $1 disputed costs $3.75–4.60 all-in; and the deeper exposure isn't the money — it's the ratio: dispute rates feed the network monitoring programs, and a merchant pushed past thresholds faces reserves, penalty pricing, or termination from their processing relationship — meaning serial disputers don't just steal products, they consume the merchant's standing in the payment system itself. The network's math: the dispute right underwrites consumer confidence in cards — the willingness to type a card number into an unknown website is the product — so the networks tolerate abuse up to the point where it threatens the asset it protects. That point, the data above suggests, is roughly now — which is why the counterattack finally has network-level teeth.

The counterattack

The defense stack, in order of leverage. Prevent tier one entirely: recognizable descriptors, instant receipts, order tracking, and self-service cancellation — the merchant who makes refunds easier than disputes converts remorse into a return instead of a chargeback, the arithmetic from the refund playbook. Intercept: prevention alert networks let merchants refund a filed dispute before it becomes a chargeback — expensive per incident, cheap against ratio damage. Evidence at transaction time: the verification stack from the chargeback playbook — matched verification data, device and login history, delivery confirmation — assembled when it's free, not at representment when it's gone. The structural shift — network evidence frameworks: the card networks' newer compelling-evidence regimes let merchants answer an "unauthorized" claim with the cardholder's own history — prior undisputed purchases from the same device, account, and credentials — which requalifies the dispute out of the fraud category before it lands. This is the system re-anchoring its honesty assumption with data: you claim you've never transacted here; the record shows you have, twelve times, from this phone. And pattern detection at the edge: dispute-propensity scoring quietly declining the serial abuser's next order — the merchant-side mirror of the issuer's fraud models, closing the loop the first success opened. None of it eliminates the category; together, the stack converts friendly fraud from an invisible tax into a managed risk with a price.

Who pays: the dispute commons

The bill lands in three places, none of them labeled. Honest consumers pay in price: the ~$130B exposure is a cost of goods sold like any shrink, passed through as margin — cyber-shoplifting, like the physical kind, is paid for by the customers who don't do it. Honest merchants pay in fragility: for a small business, dispute ratios are existential in a way dollar losses aren't — a handful of serial abusers can push a clean merchant into monitoring programs, and the defensive spending (34% of merchants now staff dedicated dispute teams; a quarter run five or more tools) is capacity diverted from everything else. And honest disputants pay in credibility: as abuse share rises, every legitimate claim — the actually-stolen card from the takeover economy, the package genuinely never delivered — meets a system trained by the fakes to ask for more proof, with more friction, more slowly. This is the same commons erosion as the credit file's dispute flood, and it points at the same resolution: the era of the asserted claim is ending, and the era of the evidenced claim — prior history, device records, delivery data, adjudicated by machine — is replacing it, for the abuser and the honest customer alike. The dispute right will survive. Its innocence won't.

Scenarios and what we're watching

ScenarioShape of the worldSignposts
Base case — the managed taxAbuse share plateaus at highs; evidence frameworks claw back the provable cases; friendly fraud settles in as a priced, monitored cost like retail shrinkFirst-party share of fraud readings; representment win rates under evidence rules; dispute-ratio distributions
Bull case — the data re-anchorNetwork evidence regimes plus issuer-side pattern flags make false "unauthorized" claims reliably losable; filing friction rises modestly; the norm reverses as the hack stops workingIssuer adoption of pre-dispute history checks; repeat-disputer decline; Gen Z admission-rate surveys
Bear case — the trust spiralAbuse keeps compounding; defenses harden into friction that degrades honest disputes; consumer confidence in the card guarantee erodes — pushing volume toward rails with weaker protections and re-importing the fraud problem thereDispute denial rates on legitimate claims; consumer trust surveys; protection-rule arbitrage across rails

What we're watching: the evidence frameworks' win-rate data (the empirical test of whether history beats assertion); issuer-side abuse flagging and its false-positive politics; the filing-friction experiments (every added step cuts abuse and honest claims together — the calibration is the story); and the admission-rate surveys, because this is ultimately a norms war, and norms announce their direction in what people will say out loud. The fraud series closes where it began: every payment system is a trust machine, and the hardest attacks come not from those who break the rules but from those who discover the rules will pay them to lie. The professionals taught the system to verify identity. The amateurs are teaching it to verify honesty — and that lesson, uncomfortable as it is, was probably overdue.

Frequently asked questions

What is friendly fraud?

A legitimate cardholder disputing a legitimate purchase — from honest descriptor confusion to deliberate cyber-shoplifting — usually keeping the goods while taking the refund.

How big is the first-party fraud problem?

The leading fraud type globally: ~36% of reported fraud (up from ~15%), ~$130B in e-commerce exposure. Dispute-share estimates range from ~20–30% (networks) to a majority (merchant analyses) — intent is hard to measure; the direction isn't.

What does a chargeback actually cost a merchant?

~$3.75–4.60 all-in per disputed dollar (~$74 handling average) — plus ratio exposure: enough disputes threaten the merchant account itself via network monitoring thresholds.

How do merchants fight friendly fraud?

Layered: descriptor and refund hygiene to prevent confusion, alerts to intercept, transaction-time evidence, network compelling-evidence frameworks that answer claims with the cardholder's own purchase history, and pattern detection for serial abusers.

Key takeaways

  • First-party fraud is now the world's leading fraud type — a crime wave of amateurs, executed through a protection mechanism working exactly as designed.
  • The taxonomy matters: confusion gets prevented, remorse gets friction and evidence, serial abuse gets detected and refused.
  • It spread as a norm, not a tool — one-click filing, pandemic-taught mechanics, and social-media permission, with repeat behavior revealing habit formation.
  • Everyone's per-transaction incentives favor paying out — which is why the fix had to be structural: evidence frameworks that answer assertion with history.
  • The bill lands on honest consumers (price), honest merchants (ratio fragility), and honest disputants (credibility) — the dispute commons, eroding and re-anchoring at once.

This report is for general information only. Figures are drawn from publicly reported network, processor, and industry research including Visa, LexisNexis, and merchant field studies, and change with each reporting cycle.