Skip to main content
Blog
Blog

Friendly fraud in 2026: why the customer wins the chargeback (and how to actually fight back)

Friendly fraud is not fraud in the traditional sense. It is a legitimate cardholder disputing a charge they actually made. Here is why most merchants lose these disputes and what CE 3.0 evidence changes.

Jul 19, 2026 6 min read
Friendly fraud: why the customer wins the chargeback and how CE 3.0 evidence changes the outcome

TL;DR: friendly fraud

  • A chargeback filed by the actual cardholder on a purchase they actually made. Not a stolen card. Not criminal. Just the money back and the goods kept.
  • 60-80% of e-commerce chargebacks, per Visa, Mastercard, and MRC surveys. Digital goods and subscriptions sit at the top of that range.
  • Standard evidence wins 15-20%. Visa CE 3.0 evidence wins 40-60%. The delta is device continuity across two or more prior undisputed orders.

Friendly fraud — the customer becomes the attacker

Friendly fraud is not fraud in the traditional sense

The word "fraud" implies a criminal. Friendly fraud is not that. The customer really did buy the thing. They really did receive it. They really did (usually) use it. Then they filed a chargeback claiming they did not authorize the purchase, did not receive it, or did not get what was promised.

This is your customer. Not a Russian bot ring. Not a stolen card. A real person with a real card who made a real purchase and is now taking your money back through their bank.

There are three patterns of friendly fraud in 2026:

  1. Confusion friendly fraud. The customer forgot the purchase, does not recognize the merchant descriptor on their statement, or does not remember the recurring subscription. They dispute it as an unrecognized transaction. This is the largest bucket.

  2. Remorse friendly fraud. The customer bought the product, used it, decided they did not want to pay for it, and filed a chargeback instead of a refund request. Common in digital goods, subscriptions, and any e commerce with a return friction the customer did not want to navigate.

  3. Cyber shoplifting. The customer deliberately gamed the chargeback process to get the money back while keeping the goods. They knew what they were doing. This is the smallest bucket but the fastest growing.

Detection has to distinguish among the three because the merchant response is different for each.

How to reduce friendly fraud — three approaches

Why merchants lose friendly fraud disputes

The card networks tilt the burden of proof toward the cardholder in a dispute. The merchant has to prove the transaction was authorized, that the goods were delivered, and that the delivered goods matched the description. Standard merchant evidence covers:

  • The order confirmation
  • The shipping tracking number
  • The delivery confirmation

None of that proves the cardholder was the one who received the goods. Signature on delivery is proof for one specific address on one specific day. It says nothing about the cardholder's device, prior order history, or pattern of behavior.

Without further evidence, the issuing bank rules in the cardholder's favor because the merchant has not disproved the dispute claim. This is why merchant win rates on friendly fraud have historically sat at 15 to 20 percent.

Visa Compelling Evidence 3.0 rewrites the win rate

Visa CE 3.0 (published in April 2023, enforceable through 2024) adds a merchant evidence category the prior framework did not have: pattern of prior legitimate behavior. Specifically, CE 3.0 accepts:

  • Two or more prior successful undisputed transactions on the same payment method
  • The same IP address, device ID, or shipping address across the disputed and prior transactions
  • Prior transactions of similar amount or category

If a merchant can show that the cardholder placed two prior orders from the same device fingerprint that shipped to the same address without dispute, and the disputed transaction was placed from the same device to the same address, the disputed transaction is presumed legitimate.

The win rate on CE 3.0 evidence submissions runs 40 to 60 percent depending on the merchant category and the quality of the device intelligence. That is a two to three times improvement over standard evidence, on the largest category of chargebacks merchants face.

The catch: CE 3.0 requires the merchant to have already captured the device intelligence at the time of the transaction. Retroactive collection does not work. If you were not fingerprinting at checkout when the disputed transaction happened, you cannot produce CE 3.0 evidence for it.

The evidence checklist

To submit CE 3.0 evidence that wins, you need six things captured at every transaction:

  1. Device fingerprint at checkout, stable across sessions, tied to the transaction ID.
  2. IP address at the moment of the transaction, geolocated and enriched (residential vs data center, VPN detection).
  3. Shipping address with billing address delta flagged.
  4. Prior order history for the same payment method, tied to the same device fingerprint or shipping address.
  5. Session timeline showing the browsing pattern before checkout (product page, cart, checkout, submit).
  6. Delivery confirmation with the signature or authenticated delivery proof.

Items 1, 2, and 5 are the ones most merchants miss. Standard e commerce platforms do not capture them at all, or capture them into logs that get rotated before a dispute arrives 60 days later. Device intelligence platforms like cside's chargeback evidence solution capture and retain them for the CE 3.0 evidence window.

When to fight, when to concede

Not every friendly fraud dispute is worth fighting. The three factors that determine fight economics:

  1. Transaction value. Below your average per dispute cost (dispute fee plus staff time, typically 25 to 50 USD), fighting loses money.
  2. CE 3.0 evidence availability. If you have the prior order history and device continuity, the win rate justifies the fight. If you do not, the win rate is 15 to 20 percent and you are gambling.
  3. Customer lifetime value. If the disputing customer is a high LTV account, fighting hard poisons the relationship. Sometimes the right business decision is to eat the chargeback and keep the customer.

The right pattern for most merchants is to fight aggressively on transactions above 100 USD with complete CE 3.0 evidence, concede on transactions below 25 USD, and case by case for the middle.

A friendly-fraud dispute defended in cside

Mike Kutlu
Client-Side Security Consultant

Client-side security consultant at cside. 10+ years of experience implementing technology solutions for enterprises (previously at Oracle, Cloudflare, and Splunk). Now helping teams use client-side intelligence to catch & reduce fraud.

FAQ

Frequently Asked Questions

Friendly fraud is a chargeback filed by the legitimate cardholder for a purchase they actually made. The cardholder may have forgotten the purchase, disagree with the outcome, be experiencing buyer's remorse, or be deliberately gaming the chargeback process to keep the goods and get a refund. Unlike criminal fraud, the cardholder is not disputing that they made the transaction, only that they authorized it or received what was promised.

Chargeback fraud is the broader category. Friendly fraud is a subset in which the fraud is by the legitimate cardholder rather than a criminal. First party misuse and cyber shoplifting are other terms for the same thing. Merchants typically use friendly fraud when they want to emphasize the customer's role and chargeback fraud when they want to emphasize the merchant loss.

Estimates vary by industry and payment method, but 60 to 80 percent of dispute filings in card not present e commerce are friendly fraud rather than criminal fraud (Visa, Mastercard, and merchant surveys converge in this range). For digital goods and subscriptions the share is at the top of the range. For physical goods delivered by tracked shipping the share is lower but still a majority.

Visa Compelling Evidence 3.0 (CE 3.0) is a merchant evidence framework that lets merchants present device intelligence, delivery confirmation, prior order history, and other signals to disprove a friendly fraud dispute. When submitted correctly, CE 3.0 evidence overturns 40 to 60 percent of eligible disputes. Without it, merchants win 15 to 20 percent.

cside's device intelligence captures a stable device fingerprint at checkout and ties it to the transaction. When a friendly fraud dispute arrives, cside surfaces the device continuity evidence (same device, same shipping address, prior successful orders from the same device) that Visa CE 3.0 accepts. See our chargeback fraud prevention guide for the full evidence checklist.

Monitor and Secure Your Third-Party Scripts

Gain full visibility and control over every script delivered to your users to enhance site security and performance.

Start free, or try Business with a 14-day trial.

cside dashboard interface showing script monitoring and security analytics
Related Articles
Book a demo