Fraud Basics
Fraud 101: What Is Fraud?
Absolute basics for someone who has never looked at fraud: what is fraud, how is it different from other crimes, and why does it matter
For education only. We do not guarantee that this guide is accurate, complete, or up to date. Research the topic yourself and check current, reliable sources before acting.
In this guide
Fraud is intentional deception to obtain money, goods, access, or information someone shouldn't have. Legally, it requires three elements: intent to deceive, a false statement or act, and resulting harm to a victim. This article covers what fraud is, who commits it, where attacks happen across the customer journey, and what working in fraud prevention actually looks like.
1. The Story
Elena was halfway through her afternoon queue when she stopped scrolling.
John Smith. $5 shoelaces. Account created eleven minutes ago.
She clicked into the session data. In those eleven minutes, he'd viewed 340 product pages. A page every two seconds. No human browses that fast.
She pulled up the device fingerprint. Same browser config she'd seen 23 times today. All new accounts. All small orders. All shipping to different residential addresses in Ohio.
The IP traced to a data center in Lithuania. Card passed AVS. Everything else screamed automation.
She ran the BINs from the day's flagged orders. Same issuer pattern across dozens of accounts. Restaurant breach, probably. They were testing which cards still worked. Five bucks ships, the card's good, they sell it for fifteen on a dark web marketplace.
The shoelaces were never about the shoelaces.
By 5 PM, Elena had blocked 847 orders. Over $4,000 in merchandise that would've walked out the door, plus the chargebacks that would've followed.
This story is fictional, but the patterns are real.
2. Why This Matters
This is where your journey into fraud begins.
If you're reading this, you're probably starting a career in fraud prevention, moving into a fraud-adjacent role, or just curious about how digital crime actually works. Whatever brought you here, understanding fraud isn't optional anymore. It touches every online business, every payment system, every customer interaction.
In 2024, U.S. consumers reported losing $12.5 billion to fraud across 2.6 million reports filed with the FTC, and 38% of those reports indicated an actual financial loss.[1] The FBI's Internet Crime Complaint Center logged 859,532 complaints that same year, totaling $16.6 billion in losses, a 33% jump over the prior year. Cyber-enabled fraud was responsible for roughly 83% of those losses.[2] Investment scams drove over $5 billion of the FTC total. Imposter scams accounted for nearly $3 billion more.[1]
Everything else in this learning center builds on these concepts.
3. What Is Fraud?
At its core, fraud is lying to get something valuable. That's it. A person (or bot, or criminal organization) deceives someone to obtain money, goods, access, or information they shouldn't have.
Three elements make something legally "fraud":
- Intent - The person meant to deceive (accidents don't count)
- Deception - They said or did something false
- Harm - Someone lost something because of it
Think of it like a counterfeit bill. The counterfeiter intends to trick you. The fake bill is the deception. You lose real money when you accept it. That's fraud.
What are the two big categories of fraud?
Third-party fraud is what most people picture: a criminal uses someone else's stolen identity or payment information. The victim is an innocent person whose data was compromised.
Elena's case is third-party fraud. Real cardholders had their numbers stolen. Criminals used those numbers. The cardholders are victims.
First-party fraud is trickier. Here, the "victim" is actually the perpetrator. A customer buys a TV, receives it, then calls their bank claiming "I never got it." They keep the TV and get their money back. The merchant loses both.
This is also called "friendly fraud" (though there's nothing friendly about it) or "chargeback fraud."
Hybrid fraud blurs the line. Maybe someone bought stolen account credentials, used them to make purchases, then filed a chargeback claiming they were hacked. Are they the victim or the criminal? Often both.
When the Merchant Is the Fraud
Most fraud training assumes the merchant is the victim. But sometimes the merchant is the problem.
Merchant fraud is when a business itself operates deceptively. They take payments and never ship products. They sell counterfeits as authentic goods. They charge cards without authorization. Customers usually get their money back through the chargeback system, so the real victims here are the acquiring banks and processors that ultimately absorb the chargebacks.
Bust-out fraud is more elaborate. A criminal sets up what looks like a legitimate merchant, processes transactions normally for a few months to build trust with payment processors, then suddenly maxes out their processing limits with stolen cards. By the time chargebacks roll in, the "merchant" has vanished with the money.
Payment processors and acquiring banks spend significant resources trying to spot these schemes before the bust-out happens.
4. Who Commits Fraud?
Fraudsters aren't a single type. They range from opportunistic individuals to sophisticated criminal enterprises.
The Opportunist
A regular customer sees a loophole. Maybe they realize they can claim packages never arrived, or abuse a generous return policy. They're not "criminals" in their own mind. They're just gaming the system.
Opportunists often escalate. What starts as one fake chargeback becomes a pattern. They share tricks with friends. Small losses become systemic problems.
The Professional
Professional fraudsters treat fraud as a job. They have tools, techniques, and specialized knowledge. They might focus on a specific attack type (carding, account takeover, refund abuse) and get very good at it.
Many work in loose networks, buying and selling stolen data, sharing methods, and collaborating on attacks.
The Organization
Organized fraud rings operate like businesses. They have roles: people who steal data, people who validate it, people who cash out, people who recruit money mules. They have supply chains, quality control, and customer service (for their criminal clients).
Some rings are local crews. Others span continents. The most sophisticated ones launder millions annually.
5. Where does fraud happen?
Fraud can hit almost any point in a customer journey. Here are the hot spots:
| Stage | What Happens | Example Attack |
|---|---|---|
| Signup | New account creation | Fake accounts for abuse or selling |
| Login | Accessing existing account | Credential stuffing, account takeover |
| Payment | Making a purchase | Stolen cards, card testing |
| Fulfillment | Receiving goods/services | Shipping to reshippers, claiming non-delivery |
| Refund | Returning or disputing | False claims, return fraud, chargebacks |
| Loyalty | Points and rewards | Points theft, promo abuse |
| Support | Customer service | Social engineering agents for refunds/access |
Criminals look for the weakest point. If your login is tight but your support team gives out password resets easily, they'll call support and lean on social engineering.
6. What does a fraud analyst actually do?
If you're fighting fraud professionally, your job has four parts:
Detect patterns that predict loss. You're looking for signals: velocity spikes, geographic impossibilities, device anomalies, behavioral mismatches. Elena spotted a browsing pattern that was mechanically impossible for a human. That was detection.
Decide what to do about it. Not every suspicious signal means fraud. You have to choose: approve, deny, or ask for more verification. Too aggressive, and you block good customers. Too lenient, and you eat losses.
Explain your reasoning. To colleagues, to managers, to auditors, sometimes to regulators or law enforcement. Your decisions need to be defensible. "It felt wrong" isn't enough. "The device fingerprint matched 23 other accounts created today from a Lithuanian data center" is.
Improve the system over time. Fraud evolves. Yesterday's rules become today's bypassed controls. You're constantly tuning, testing, and building new defenses.
7. Key Takeaways
- Fraud is deception for gain. Three elements: intent, deception, harm.
- Third-party fraud uses stolen identities. First-party fraud is the customer lying.
- Fraudsters range from opportunists to organized rings. Treat all of them seriously.
- Every customer touchpoint is an attack surface. Signup, login, payment, fulfillment, refunds, support.
- Your job: detect, decide, explain, improve. It's part pattern recognition, part judgment call, part continuous learning.
Next up: Common Fraud Types breaks down the specific attack methods you'll encounter.
8. Key Terms
| Term | Definition |
|---|---|
| Fraud | Intentional deception to obtain something of value |
| Third-party fraud | Criminal uses someone else's stolen identity or payment info |
| First-party fraud | Customer deceives the merchant (also: friendly fraud, chargeback fraud) |
| Merchant fraud | The merchant itself operates deceptively (fake products, unauthorized charges) |
| Bust-out fraud | Criminal sets up fake merchant, builds trust, then processes stolen cards and disappears |
| Card testing | Using small purchases to verify stolen card numbers work |
| Velocity | The rate of actions over time (high velocity often signals automation) |
| Device fingerprint | Unique characteristics of a browser/device used to identify repeat visitors |
| Chargeback | Customer disputes a charge with their bank, forcing merchant to refund |
| Money mule | Person who moves fraudulent funds, often unknowingly recruited |
9. References
1. FTC Consumer Sentinel Network Data Book 2024 (March 2025) (pp. 4-5: $12.5B in 2024 fraud losses across 2.6M reports, 38% loss rate, over $5B in investment scams, nearly $3B in imposter scams)
2. FBI IC3 2024 Internet Crime Report (pp. 4, 11: 859,532 complaints in 2024, $16.6B in losses, 33% increase over 2023, cyber-enabled fraud ~83% of losses)
CHECK YOUR UNDERSTANDING
Fraud 101 Quiz
1. A customer calls your bank claiming someone opened a credit card in their name. They never applied for the card, and the mailing address on the application is an apartment they've never lived at. Your manager asks whether this is first-party or third-party fraud. What do you tell them?
- First-party fraud, because the customer is the one reporting it
- Third-party fraud, because someone used the customer's identity without their knowledge
- Friendly fraud, because the customer is disputing a charge
- Merchant fraud, because the credit card company approved a bad application
Show answer and explanation
Third-party fraud, because someone used the customer's identity without their knowledge
Third-party fraud occurs when someone uses stolen credentials or identity without the victim's knowledge. The victim here is real and unaware, which distinguishes it from first-party fraud where the account holder is the one committing fraud.
2. You're reviewing a case where a customer bought a $2,000 laptop, received it, and then filed a chargeback claiming the transaction was unauthorized. Shipping records confirm delivery to the customer's home address. Which type of fraud does this most likely represent?
- Third-party fraud using a stolen card
- First-party (friendly) fraud by the actual cardholder
- Merchant fraud through false advertising
- Account takeover by an external attacker
Show answer and explanation
First-party (friendly) fraud by the actual cardholder
When the legitimate cardholder makes a purchase, receives the goods at their own address, and then disputes the charge as unauthorized, this is first-party or "friendly" fraud. The customer is exploiting the chargeback process.
3. A new customer creates an account, adds a payout method from an unrecognized device, and immediately requests a large withdrawal. Your fraud system flags it. What control approach makes the most sense?
- Block all transactions from new devices automatically
- Require step-up authentication (like a verification call) for this high-risk action
- Auto-approve because the account credentials are valid
- Only allow withdrawals on weekdays during business hours
Show answer and explanation
Require step-up authentication (like a verification call) for this high-risk action
Risk-based step-up authentication adds friction only when behavior is risky (new device + high-value action), without blocking all new device activity. This balances security with customer experience.
4. Your team's monthly report shows the transaction approval rate dropped from 94% to 87%, but actual fraud losses stayed flat. Your VP asks what's going on. What is the most likely explanation?
- Fraudsters found a way to bypass your detection system
- Your rules are too aggressive, blocking legitimate customers (false positives increased)
- Customers are spending less, so fewer transactions are qualifying
- The chargeback window hasn't closed yet, so losses will appear later
Show answer and explanation
Your rules are too aggressive, blocking legitimate customers (false positives increased)
When approval rates drop but losses stay flat, the system is blocking more good transactions without catching more fraud. This means false positives increased, which hurts revenue and customer experience without improving fraud prevention.
5. You're training a new analyst and show them a flagged transaction. The alert fired because the customer made 5 purchases in 10 minutes from a new IP address, then changed their shipping address. The new analyst asks which of these signals actually matters for fraud detection. What do you say?
- Only the IP change matters, since velocity is normal for sales events
- All three signals (velocity, new IP, address change) compound to suggest potential fraud
- Only the shipping address change matters, since IP changes happen on mobile networks
- None of these are fraud signals without a chargeback to confirm fraud
Show answer and explanation
All three signals (velocity, new IP, address change) compound to suggest potential fraud
Individual signals can have innocent explanations, but the combination of rapid purchases, unfamiliar IP, and address change creates a pattern worth investigating. Fraud detection relies on multiple signals compounding, not single indicators.