Fraudulent Transaction
A fraudulent transaction is any payment made without the legitimate authority of the account holder. Also called transaction fraud, it covers a stolen card used at checkout, a payment authorized under deception, and a genuine purchase the real cardholder later denies making — three very different problems that share one label.
| Also called | Transaction fraud, payment fraud, unauthorized transaction |
| Third-party fraud | The account holder did not authorize it and did not benefit |
| Authorized push payment fraud | The account holder authorized it, having been deceived |
| First-party fraud | The account holder authorized it and later denies doing so |
| Card-present | Physical card at a terminal — largely addressed by EMV chip |
| Card-not-present | Online and over the phone, where the card need not exist physically |
| Detection window | Milliseconds at authorization |
| Merchant consequence | Chargeback, plus fees and a ratio that affects processing terms |
| Hardest category | First-party, because every technical signal says the transaction was legitimate |
How it works
Three categories, distinguished by who authorized the payment and who benefited. The distinction determines which controls can possibly help.
Third-party fraud is the classic case: someone else uses the credentials. Card-present versions have declined sharply since EMV chip adoption made counterfeiting impractical. Card-not-present fraud absorbed the displaced volume, because online a card number and a few data points are the whole credential.
Authorized push payment fraud inverts the problem. The account holder makes the payment themselves, having been convinced to — an invoice redirected, a romance built over months, a caller impersonating the bank’s fraud team. Every authentication check passes because the genuine customer performed every step. Controls designed to confirm identity are structurally blind to it, since identity was never in question.
First-party fraud, sometimes called friendly fraud, is the cardholder making a genuine purchase then disputing it. Some is deliberate; a meaningful share is a family member’s purchase, or a subscription forgotten. It is the hardest to detect because the device, location, behavior and credentials all really are the customer’s.
Detection at authorization scores the transaction against the account’s history, device and behavioral signals, and network patterns, then approves, declines or steps up — in milliseconds. False declines are the underappreciated cost: a wrongly declined legitimate customer often does not return.
Why it matters for identity verification
Transaction fraud is where account-opening decisions eventually surface. An account opened with a stolen or fabricated identity generates fraudulent transactions from its first day, and no amount of transaction monitoring recovers what was lost by letting it open.
Verification at onboarding narrows what monitoring has to catch. It removes accounts that never had a legitimate owner, and it attaches verified identity attributes to the rest — which makes network analysis meaningful, because linking accounts by verified identity is far stronger than linking them by shared device.
For the step-up decision, identity verification is the escalation itself. When a transaction scores as risky, the useful question is whether the person acting is the account’s verified owner — and answering it takes a live biometric check against the identity captured at onboarding. That converts a binary approve-or-decline into a third option that recovers legitimate customers instead of losing them. Microblink’s payment card capture with fraud signals supports that at the point of entry, and the payment fraud workflow combines card, document and biometric signals in one decision.
The three categories compared
| Third-party | Authorized push payment | First-party | |
|---|---|---|---|
| Who authorized it | Not the account holder | The account holder, deceived | The account holder |
| Who benefits | The fraudster | The fraudster | The account holder |
| Authentication passes | Not if checks are strong | Yes — genuine customer, genuine device | Yes |
| Detectable at authorization | Often | Rarely | Almost never |
| Primary defense | Identity and device verification | Payee verification, friction on new payees | Evidence and dispute representment |
| Who absorbs the loss | Issuer or merchant, by scheme rules | Often the customer, though rules are shifting | Merchant, via chargeback |
What it can’t be solved by
Authentication does not stop authorized push payment fraud. The genuine customer authenticates correctly. Stronger authentication makes the fraudulent payment more securely authorized, which is why the effective controls are payee verification and deliberate friction on first payments to new recipients.
Transaction monitoring cannot fix onboarding. An account that should never have opened generates fraud from day one. Monitoring reduces the loss; it does not recover the decision.
Declining more is not a strategy. Tightening thresholds cuts fraud and cuts revenue, usually faster. False declines carry a long tail — the customer who was wrongly declined at checkout frequently does not come back, and that cost never appears in a fraud report.
First-party fraud resists technical controls entirely. When the device, location, credentials and behavior all really are the customer’s, no signal separates a real dispute from a false one. It is handled through evidence and representment rather than detection.
Frequently asked questions
What is the difference between a fraudulent transaction and a chargeback?
A fraudulent transaction is the unauthorized payment. A chargeback is the mechanism reversing it. Not all chargebacks follow fraud — many stem from service disputes or first-party fraud, where the transaction was validly authorized.
What is authorized push payment fraud?
Fraud where the account holder makes the payment themselves after being deceived — an invoice redirected, an impersonated bank official, a romance scam. Because the genuine customer authorizes every step, authentication controls cannot detect it.
Can fraudulent transactions be detected in real time?
Third-party fraud often can, by scoring identity, device, behavioral and network signals at authorization within milliseconds. Authorized push payment and first-party fraud are much harder, because the legitimate account holder really is performing the action.
Who is liable for a fraudulent transaction?
It depends on category and jurisdiction. Third-party card fraud generally falls on the issuer or merchant under scheme rules. Authorized push payment losses have often fallen on the customer, though regulatory reallocation toward banks is underway in several markets.
Related reading
- Marketplace fraud — how transaction fraud plays out on two-sided platforms
- Fraud detection — the systems that score transactions at authorization
- Fullz — the stolen data that funds third-party transaction fraud
- Card-not-present fraud — where the volume moved after EMV