TL;DR
- Friendly fraud is a real cardholder disputing a purchase they actually made. Stripe, Visa and Mastercard all call it first-party misuse.
- It splits in two. Accidental friendly fraud is a customer who did not recognize the charge. Deliberate friendly fraud is a customer who did.
- Juniper Research puts it at 22% of chargebacks globally in 2026, rising to 28% by 2031, with losses growing from 8.1 billion USD to nearly 16 billion.
- The accidental half is an engineering problem. A recognizable statement descriptor and a renewal reminder remove most of it.
- The deliberate half can only be answered after the fact, using the customer's own purchase history as evidence.
Who this helps: a subscription business seeing disputes from customers who plainly made the purchase, and wanting to know which of those are fixable and which have to be fought.
Almost every fraud tool you can buy is built to spot a stranger using a stolen card. Friendly fraud is the opposite problem: the name matches, the address matches, the card is the customer's own, and the purchase is real. Nothing about it looks like fraud until the dispute arrives.
What is friendly fraud?
Friendly fraud is a dispute filed by the genuine cardholder against a purchase they genuinely made. Stripe defines it as occurring "when a legitimate cardholder makes a purchase, but then disputes it at a later date", and notes it can be "accidental, because they didn't recognize the transaction on their statement, or deliberate".
The name is unhelpful and the industry knows it. Visa calls the same behaviour first-party misuse, Mastercard's program against it is called First-Party Trust, and Stripe lists all three terms as synonyms. A processor, a network and a vendor using three different words in the same week are describing one thing.
A friendly fraud chargeback looks, from the card network's side, exactly like any other dispute: the cardholder tells their bank they did not make or did not receive the purchase, and the bank takes the money back. Friendly fraud is hard to catch because nothing about the transaction is anomalous. The billing name, the address and the payment method all belong to the person using them, so fraud screening built to catch stolen cards sees a clean transaction.
How common is friendly fraud?
Friendly fraud accounts for an estimated 22% of chargebacks globally in 2026, according to Juniper Research, and is projected to reach 28% by 2031. The value lost grows from 8.1 billion USD in 2026 to nearly 16 billion by 2031, a 96% increase.
Juniper attributes the growth to a change in attitude rather than in technique. Consumers increasingly treat fraud aimed at merchants as a "victimless crime", including filing a chargeback after changing their mind about a purchase or to obtain goods without paying.
The concentration is worse for digital goods. Mastercard estimates that up to 75% of card-not-present fraud at digital goods merchants is first-party, which for a subscription business means most of what arrives labelled fraud is not theft at all.
The clean one is disputed 41 days later.
What does friendly fraud look like?
Three examples cover most of what a subscription business sees. The first two are accidental and the third is deliberate, and the difference decides what you can do about each.
The unrecognized statement line. Maya subscribes to a 12 USD a month meal-planning app. Her statement reads PADDLE.NET* MEALCO, which names neither the app nor anything she remembers buying. She calls her bank, says she does not recognize the charge, and the bank files a fraud dispute. She is a paying, satisfied customer who has just cost you a dispute and a fraud report.
The forgotten renewal. Daniel bought an annual plan for 180 USD and used it for two months. A year later the renewal lands without a reminder, he assumes it is an error, and he disputes it rather than contacting you. He never meant to defraud anyone, and a reminder 7 days earlier would have produced a cancellation instead of a chargeback.
The deliberate dispute. Leo subscribes to a design tool for a client project, uses it heavily for three weeks, finishes the project, and disputes the charge as unauthorized. The descriptor was clear and she received a reminder. No change to your billing would have prevented her dispute, and the only answer is evidence that she made and used the purchase.
What is the difference between accidental and deliberate friendly fraud?
Accidental friendly fraud is a customer who does not recognize the charge. Deliberate friendly fraud is a customer who recognizes it perfectly well and disputes anyway.
The two have almost nothing in common as problems. Accidental friendly fraud is caused by something you control: a statement line that does not name your brand, a renewal the customer forgot, a trial that converted without warning. Mastercard and Javelin found in 2026 that 48% of consumers have disputed a charge they later realized was legitimate, which says the behaviour is common and self-reported rather than telling you what share of your own disputes it accounts for.
Deliberate friendly fraud is not a communication failure. The customer knows what they bought, and the dispute is a way to keep the product without paying, so no descriptor change prevents it.
Most merchants treat both as one number and then wonder why prevention spending does not move it. Splitting them tells you which budget to use: the accidental half is a product and billing fix, and the deliberate half is an evidence problem.
How do you stop accidental friendly fraud?
Three changes remove most of it, and the first is free. Make the statement descriptor name your brand, send a renewal reminder before the charge lands, and make cancellation take fewer than three clicks.
The statement descriptor comes first because it causes the specific dispute that becomes friendly fraud: a customer reads a line they do not recognize and reports it as fraud rather than calling you. Fixing it is a settings change, and it also prevents the fraud report that comes with a fraud claim.
Renewal reminders address the second-largest cause, which is a charge the customer forgot was coming. Stripe's own guidance recommends a reminder 7 days before a yearly renewal and 2 to 3 days before a monthly one.
The reason to do this work before buying anything is that the accidental half is the only half you can remove rather than manage. A dispute that never happens costs nothing, files no fraud report, and keeps the customer. The rest of the prevention stack builds on the same order.
How do you fight deliberate friendly fraud?
Deliberate friendly fraud is contested with the customer's own purchase history. Both card networks now run programs built on the same idea: if this cardholder has bought from you before, from the same device, without disputing, the current claim is harder to sustain.
Visa's program is Compelling Evidence 3.0, and Visa publishes its criteria. A dispute qualifies when two previous transactions with the same cardholder are between 120 and 365 days old, carry no fraud report or fraud dispute of their own, and match the disputed transaction on at least two of four data points, one of which must be the IP address or the device ID.
Mastercard's program is First-Party Trust, which launched in the US in October 2024 and expanded to Canada, Latin America, the Caribbean and Asia Pacific in June 2025. The merchant shares a device signal, a delivery factor and an identity factor, either at authorization or once a dispute is threatened.
Why are subscription businesses well placed for these programs?
A subscription business generates the kind of history both programs ask for, which most merchant types never accumulate. A one-off ecommerce purchase has nothing behind it, so a first-time buyer disputing a first purchase cannot be answered this way at all.
The timing is tighter than it first looks. Visa counts only transactions at least 120 days old, so a monthly subscriber disputing their month-six charge has five prior payments of which just two, at roughly 120 and 150 days, are old enough to qualify. A subscriber needs around seven months of history before two of their charges clear the floor comfortably. Before that point, a subscription business is in the same position as the first-time buyer.
One limit applies specifically to subscriptions. Renewals are merchant-initiated, so no browser is present and no IP address or device fingerprint is captured at the time. The data Visa's rules require usually comes from the original signup, which means the signup transaction is the one that has to carry it.
What do these programs not fix?
Three things, in increasing order of importance. None of them is reversed by winning.
First, an alert does not save the sale. Chargeback alerts resolve a dispute by refunding it, so a friendly fraud dispute caught by an alert still costs you the revenue. What an alert buys is the mark on your record, not the money.
Second, the fraud report stands. When a customer describes a charge as fraud rather than as a billing problem, the bank files a TC40 report. That report counts toward your VAMP ratio on its own, and no refund, alert or won dispute removes it.
Third, and largest, friendly fraud can count against you twice. Stripe states that a transaction appearing in both the TC40 fraud report and the TC15 dispute report "will be counted twice for the VAMP count".
One customer, one charge, one false claim, and your VAMP ratio moves by two events: the fraud report and the dispute are counted separately.
FAQ
What is friendly fraud?
Friendly fraud is a dispute filed by the genuine cardholder against a purchase they genuinely made. Stripe defines it as occurring when a legitimate cardholder makes a purchase then disputes it later, either accidentally because they did not recognize the charge, or deliberately.
Is friendly fraud the same as first-party misuse?
Yes. Stripe lists friendly fraud, first-party misuse and first-party fraud as names for the same behaviour, and the card networks prefer first-party misuse in their rules because friendly describes the relationship rather than the act.
How common is friendly fraud?
Juniper Research estimates friendly fraud at 22% of chargebacks globally in 2026, rising to 28% by 2031, with losses growing from 8.1 billion USD to nearly 16 billion. Mastercard estimates up to 75% of card-not-present fraud at digital goods merchants is first-party.
What are examples of friendly fraud?
A customer who does not recognize an unfamiliar statement descriptor and reports the charge as fraud, a customer who disputes an annual renewal they forgot was coming, and a customer who uses a service for weeks and then disputes the charge as unauthorized. The first two are accidental and preventable; the third is deliberate and can only be contested with evidence.
Can you prevent friendly fraud?
You can prevent the accidental half, which is a customer not recognizing the charge, using a clear statement descriptor, a renewal reminder and an easy cancellation flow. The deliberate half cannot be prevented and has to be contested after the dispute is filed.
How do you prove friendly fraud?
Through the customer's own purchase history. Visa's Compelling Evidence 3.0 requires two prior transactions with the same cardholder between 120 and 365 days old, matching the disputed one on at least two data points including the IP address or device ID. Mastercard's First-Party Trust uses a device, delivery and identity element without publishing its thresholds.
Does winning a friendly fraud dispute clear your record?
No. The dispute counts toward your ratio whether you win or lose, and if the customer claimed fraud, the bank's TC40 report counts separately and is never removed.
Facts checked against Stripe's fraud types and monitoring programs documentation, Visa's Compelling Evidence 3.0 merchant readiness document, Mastercard's First-Party Trust product page, and Juniper Research's June 2026 friendly fraud forecast. Last reviewed 28 September 2026.