The Friendly Fraud Problem
That is the challenge at the heart of first-party misuse which is more commonly, if slightly misleadingly, called friendly fraud. It is not a new phenomenon, but it is growing fast, it is structurally difficult to detect, and it sits in an uncomfortable space for the payments industry.
The scale of the problem
According to the LexisNexis Risk Solutions' 2025 Cybercrime Report, which analysed over 104 billion global transactions, first-party fraud has become the single leading type of fraud globally, representing 36% of all reported fraud in 2024, more than doubling from 15% the year before.¹ Their Global State of Fraud and Identity Report 2026 confirms that this trajectory has continued, noting that first-party fraud has doubled year on year and is adding new challenges for risk management teams.²
Chargeback volumes tell the same story from a different angle. Chargebacks911, a chargeback management platform, tracks this closely. Their 2026 Chargeback Field Report projects global chargeback volume reaching 337 million transactions by 2026, up 41% from 2023.³ The Merchant Risk Council's Global Fraud Survey 2025 found that 64% of merchants reported increasing rates of first-party misuse, with more than one in four seeing increases of 25% or more.⁴
These are largely merchant-facing figures, but the implications run upstream. For issuers and acquirers, every disputed transaction requires investigation, often with limited information, under regulatory timelines that structurally favour the cardholder, and with no reliable way to distinguish a genuine fraud victim from someone exploiting the dispute process.
Why it is so difficult to catch
What makes first-party misuse genuinely hard to manage is that it produces no red flag signal at the point of transaction. The cardholder is who they say they are. The card is theirs. The authentication completes normally. The purchase is real. Nothing in the transaction itself indicates a dispute is coming.
The answer cannot be to treat every customer as a suspect. The answer is to give issuers better context, so they can distinguish confusion, genuine fraud and deliberate misuse with more confidence."
- Manuel Bärtschi, Senior Product Manager Secure Payments, G+D Netcetera
The implication of this is significant: controls that work at the transaction level do not address fraud that originates after the transaction, in the dispute process itself.
The information asymmetry is structural. Issuers are, by design, positioned to advocate for their cardholders. PSD2 Article 73 requires institutions to refund unauthorised transactions; this is an obligation that is entirely appropriate when the customer is a genuine fraud victim. But it becomes considerably more complicated when they are not.⁶
The deliberate and the accidental
Not all first-party misuse is intentional, and the distinction matters for how institutions respond.
A meaningful share of disputes arise from genuine confusion: a forgotten subscription renewal, a billing descriptor that does not match the merchant's trading name, a family member using a shared card. Chargebacks911 estimates that one in five consumers has at some point disputed a charge they actually authorised.³ These are not malicious customers; they are customers who did not recognise a legitimate charge and took the path of least resistance.
The deliberate cases are different in character, even if they look identical at the surface. A cardholder who disputes a purchase in full knowledge, retains the goods, and collects the refund is committing fraud, but the evidence required to demonstrate that is rarely available to the issuer at the point of dispute. Repeat behaviour is often the only reliable signal, and Chargebacks911 reports that 50% of first-time friendly fraudsters go on to repeat the behaviour within a staggering 60 days of a successful claim.³
The cost compounds accordingly. LexisNexis's True Cost of Fraud research calculates that US merchants lose $4.61 for every $1 of actual fraud when chargeback fees, operational costs, and lost inventory are included; this is a 32% increase since 2022.¹ The operational burden falls not only on merchants but on the issuers and acquirers that must process, investigate, and adjudicate each dispute.
Where the industry is heading
The Juniper Research forecast that global e-commerce fraud losses will climb from $44.3 billion in 2024 to $107 billion by 2029. This is a 141% increase and reflects a broader acceleration that first-party misuse is actively contributing to.⁸
The regulatory response so far has focused primarily on consumer protection: clearer billing descriptors, easier cancellation flows, faster dispute resolution timelines. In the UK, the Payment Systems Regulator's mandatory reimbursement rules are one example: 88% of in-scope APP fraud losses were reimbursed to victims in their first year, according to UK Finance's Annual Fraud Report 2026.⁹ These are reasonable measures that address the accidental end of the spectrum. They do not, however, address the deliberate end, and in some cases may inadvertently facilitate it, making the dispute process easier to initiate also makes it easier to abuse.
The industry's longer-term answer will require better data sharing between merchants and issuers at the point of dispute, so that prior transaction behaviour can be used as evidence when a claim does not hold up.
No single issuer, acquirer or merchant sees the whole picture. A sustainable data-sharing approach is about turning isolated detections into shared intelligence, without creating unnecessary friction for legitimate customers."
- Manuel Bärtschi, Senior Product Manager Secure Payments, G+D Netcetera
The need for finding balance is a genuine one. Tightening dispute processes too aggressively risks penalising genuine fraud victims, and creating an environment that is not customer-friendly. On the other hand, making no change to the status quo risks sustaining a structural incentive for misuse.
The G+D Netcetera Email Newsletter
Talk to our experts
Sources
- LexisNexis Risk Solutions, Cybercrime Report: The Calm Before the Storm?, May 2025. https://risk.lexisnexis.com/global/en/about-us/press-room/press-release/20250513-cybercrime-report
- LexisNexis Risk Solutions, Global State of Fraud and Identity Report 2026, 2026. https://risk.lexisnexis.com/global/en/insights-resources/research/global-state-of-fraud-and-identity
- Chargebacks911, 2026 Chargeback Field Report. https://chargebacks911.com/chargeback-field-report
- Merchant Risk Council, Global Fraud Survey 2025, 2025. https://info.merchantriskcouncil.org/hubfs/Documents/Reports/Fraud%20Reports/2025_Global_Fraud_and_Payments_Report.pdf
- European Banking Authority and European Central Bank, 2025 Report on Payment Fraud, December 2025. https://www.eba.europa.eu/sites/default/files/2025-12/1709846a-84d9-47cf-86a0-b155efb34d66/EBA%20and%20ECB%20Report%20on%20Payment%20Fraud.pdf
- European Parliament and Council, Directive (EU) 2015/2366 (PSD2), Article 73.
- Merchant Risk Council, First-Party Misuse AKA Friendly Fraud. https://merchantriskcouncil.org/learning/mrc-exclusive-reports/global-payments-and-fraud-report/2024-global-payments-and-fraud-report
- Juniper Research, Online Payment Fraud Report 2024–2029. https://www.juniperresearch.com/press/pressreleasesecommerce-fraud-to-exceed-107bn-in-2029/
- UK Finance, Annual Fraud Report 2026. https://www.ukfinance.org.uk/system/files/2026-06/UK%20Finance%20Fraud%20Report%202026.pdf