Fraudulent Transaction

A fraudulent transaction is any payment made without the legitimate authority of the account holder. Also called transaction fraud, it covers a stolen card used at checkout, a payment authorized under deception, and a genuine purchase the real cardholder later denies making — three very different problems that share one label.

Also called Transaction fraud, payment fraud, unauthorized transaction
Third-party fraud The account holder did not authorize it and did not benefit
Authorized push payment fraud The account holder authorized it, having been deceived
First-party fraud The account holder authorized it and later denies doing so
Card-present Physical card at a terminal — largely addressed by EMV chip
Card-not-present Online and over the phone, where the card need not exist physically
Detection window Milliseconds at authorization
Merchant consequence Chargeback, plus fees and a ratio that affects processing terms
Hardest category First-party, because every technical signal says the transaction was legitimate

How it works

Three categories, distinguished by who authorized the payment and who benefited. The distinction determines which controls can possibly help.

Third-party fraud is the classic case: someone else uses the credentials. Card-present versions have declined sharply since EMV chip adoption made counterfeiting impractical. Card-not-present fraud absorbed the displaced volume, because online a card number and a few data points are the whole credential.

Authorized push payment fraud inverts the problem. The account holder makes the payment themselves, having been convinced to — an invoice redirected, a romance built over months, a caller impersonating the bank’s fraud team. Every authentication check passes because the genuine customer performed every step. Controls designed to confirm identity are structurally blind to it, since identity was never in question.

First-party fraud, sometimes called friendly fraud, is the cardholder making a genuine purchase then disputing it. Some is deliberate; a meaningful share is a family member’s purchase, or a subscription forgotten. It is the hardest to detect because the device, location, behavior and credentials all really are the customer’s.

Detection at authorization scores the transaction against the account’s history, device and behavioral signals, and network patterns, then approves, declines or steps up — in milliseconds. False declines are the underappreciated cost: a wrongly declined legitimate customer often does not return.

Why it matters for identity verification

Transaction fraud is where account-opening decisions eventually surface. An account opened with a stolen or fabricated identity generates fraudulent transactions from its first day, and no amount of transaction monitoring recovers what was lost by letting it open.

Verification at onboarding narrows what monitoring has to catch. It removes accounts that never had a legitimate owner, and it attaches verified identity attributes to the rest — which makes network analysis meaningful, because linking accounts by verified identity is far stronger than linking them by shared device.

For the step-up decision, identity verification is the escalation itself. When a transaction scores as risky, the useful question is whether the person acting is the account’s verified owner — and answering it takes a live biometric check against the identity captured at onboarding. That converts a binary approve-or-decline into a third option that recovers legitimate customers instead of losing them. Microblink’s payment card capture with fraud signals supports that at the point of entry, and the payment fraud workflow combines card, document and biometric signals in one decision.

The three categories compared

  Third-party Authorized push payment First-party
Who authorized it Not the account holder The account holder, deceived The account holder
Who benefits The fraudster The fraudster The account holder
Authentication passes Not if checks are strong Yes — genuine customer, genuine device Yes
Detectable at authorization Often Rarely Almost never
Primary defense Identity and device verification Payee verification, friction on new payees Evidence and dispute representment
Who absorbs the loss Issuer or merchant, by scheme rules Often the customer, though rules are shifting Merchant, via chargeback

What it can’t be solved by

Authentication does not stop authorized push payment fraud. The genuine customer authenticates correctly. Stronger authentication makes the fraudulent payment more securely authorized, which is why the effective controls are payee verification and deliberate friction on first payments to new recipients.

Transaction monitoring cannot fix onboarding. An account that should never have opened generates fraud from day one. Monitoring reduces the loss; it does not recover the decision.

Declining more is not a strategy. Tightening thresholds cuts fraud and cuts revenue, usually faster. False declines carry a long tail — the customer who was wrongly declined at checkout frequently does not come back, and that cost never appears in a fraud report.

First-party fraud resists technical controls entirely. When the device, location, credentials and behavior all really are the customer’s, no signal separates a real dispute from a false one. It is handled through evidence and representment rather than detection.

Frequently asked questions

What is the difference between a fraudulent transaction and a chargeback?

A fraudulent transaction is the unauthorized payment. A chargeback is the mechanism reversing it. Not all chargebacks follow fraud — many stem from service disputes or first-party fraud, where the transaction was validly authorized.

What is authorized push payment fraud?

Fraud where the account holder makes the payment themselves after being deceived — an invoice redirected, an impersonated bank official, a romance scam. Because the genuine customer authorizes every step, authentication controls cannot detect it.

Can fraudulent transactions be detected in real time?

Third-party fraud often can, by scoring identity, device, behavioral and network signals at authorization within milliseconds. Authorized push payment and first-party fraud are much harder, because the legitimate account holder really is performing the action.

Who is liable for a fraudulent transaction?

It depends on category and jurisdiction. Third-party card fraud generally falls on the issuer or merchant under scheme rules. Authorized push payment losses have often fallen on the customer, though regulatory reallocation toward banks is underway in several markets.

Related reading

Discover Our Solutions

Exploring our solutions is just a click away. Try our products or have a chat with one of our experts to delve deeper into what we offer.

Report
Mapping the Rise of AI-Powered Identity Fraud

AI didn't just make fraud faster. It made it a system. We analyzed millions of identity interactions to map how identity attacks are evolving across regions, attack types, and sophistication levels — and what organizations need to rethink to keep pace.

See the Data
This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.