What is first-party fraud?
First-party fraud happens when the customer who owns the account is the one committing the abuse—false chargebacks, lying about non-receipt, or farming incentives—rather than an external attacker.
Why ATO playbooks fail here
The device and password are genuine. Fingerprint novelty will not fire. You need history: prior chargebacks, promo clusters, and velocity of disputes, plus lists of customers already confirmed abusive.
How Naiza applies it
Send payment, dispute, and payout events with a stable customer id. Use rules and lists. Chargeback-fraud and promo-abuse glossary pages cover the usual subtypes. REVIEW before BLOCK on a first dispute.
AML overlap
First-party abuse is not automatically money laundering. If the same customer starts moving third-party funds, that is a different typology—screen counterparties and watch velocity of payouts.
Frequently asked questions
Short answers written so search and answer engines can cite them.
What is friendly fraud?
A first-party chargeback where the cardholder denies a purchase they made or authorized. Treat it as a dispute pattern, not as ATO, unless device context says otherwise.
How is first-party fraud different from ATO?
ATO uses stolen credentials on a new device. First-party fraud uses the real customer. Detection leans on history and lists, not only new-device rules.
Should we auto-block after one chargeback?
Usually no. One dispute can be legitimate. Clusters, repeat BINs, and listed customers are stronger BLOCK conditions.