TL;DR: friendly fraud
- A chargeback filed by the actual cardholder on a purchase they actually made. Not a stolen card. Not criminal. Just the money back and the goods kept.
- 60-80% of e-commerce chargebacks, per Visa, Mastercard, and MRC surveys. Digital goods and subscriptions sit at the top of that range.
- Standard evidence wins 15-20%. Visa CE 3.0 evidence wins 40-60%. The delta is device continuity across two or more prior undisputed orders.
Friendly fraud is not fraud in the traditional sense
The word "fraud" implies a criminal. Friendly fraud is not that. The customer really did buy the thing. They really did receive it. They really did (usually) use it. Then they filed a chargeback claiming they did not authorize the purchase, did not receive it, or did not get what was promised.
This is your customer. Not a Russian bot ring. Not a stolen card. A real person with a real card who made a real purchase and is now taking your money back through their bank.
There are three patterns of friendly fraud in 2026:
-
Confusion friendly fraud. The customer forgot the purchase, does not recognize the merchant descriptor on their statement, or does not remember the recurring subscription. They dispute it as an unrecognized transaction. This is the largest bucket.
-
Remorse friendly fraud. The customer bought the product, used it, decided they did not want to pay for it, and filed a chargeback instead of a refund request. Common in digital goods, subscriptions, and any e commerce with a return friction the customer did not want to navigate.
-
Cyber shoplifting. The customer deliberately gamed the chargeback process to get the money back while keeping the goods. They knew what they were doing. This is the smallest bucket but the fastest growing.
Detection has to distinguish among the three because the merchant response is different for each.
Why merchants lose friendly fraud disputes
The card networks tilt the burden of proof toward the cardholder in a dispute. The merchant has to prove the transaction was authorized, that the goods were delivered, and that the delivered goods matched the description. Standard merchant evidence covers:
- The order confirmation
- The shipping tracking number
- The delivery confirmation
None of that proves the cardholder was the one who received the goods. Signature on delivery is proof for one specific address on one specific day. It says nothing about the cardholder's device, prior order history, or pattern of behavior.
Without further evidence, the issuing bank rules in the cardholder's favor because the merchant has not disproved the dispute claim. This is why merchant win rates on friendly fraud have historically sat at 15 to 20 percent.
Visa Compelling Evidence 3.0 rewrites the win rate
Visa CE 3.0 (published in April 2023, enforceable through 2024) adds a merchant evidence category the prior framework did not have: pattern of prior legitimate behavior. Specifically, CE 3.0 accepts:
- Two or more prior successful undisputed transactions on the same payment method
- The same IP address, device ID, or shipping address across the disputed and prior transactions
- Prior transactions of similar amount or category
If a merchant can show that the cardholder placed two prior orders from the same device fingerprint that shipped to the same address without dispute, and the disputed transaction was placed from the same device to the same address, the disputed transaction is presumed legitimate.
The win rate on CE 3.0 evidence submissions runs 40 to 60 percent depending on the merchant category and the quality of the device intelligence. That is a two to three times improvement over standard evidence, on the largest category of chargebacks merchants face.
The catch: CE 3.0 requires the merchant to have already captured the device intelligence at the time of the transaction. Retroactive collection does not work. If you were not fingerprinting at checkout when the disputed transaction happened, you cannot produce CE 3.0 evidence for it.
The evidence checklist
To submit CE 3.0 evidence that wins, you need six things captured at every transaction:
- Device fingerprint at checkout, stable across sessions, tied to the transaction ID.
- IP address at the moment of the transaction, geolocated and enriched (residential vs data center, VPN detection).
- Shipping address with billing address delta flagged.
- Prior order history for the same payment method, tied to the same device fingerprint or shipping address.
- Session timeline showing the browsing pattern before checkout (product page, cart, checkout, submit).
- Delivery confirmation with the signature or authenticated delivery proof.
Items 1, 2, and 5 are the ones most merchants miss. Standard e commerce platforms do not capture them at all, or capture them into logs that get rotated before a dispute arrives 60 days later. Device intelligence platforms like cside's chargeback evidence solution capture and retain them for the CE 3.0 evidence window.
When to fight, when to concede
Not every friendly fraud dispute is worth fighting. The three factors that determine fight economics:
- Transaction value. Below your average per dispute cost (dispute fee plus staff time, typically 25 to 50 USD), fighting loses money.
- CE 3.0 evidence availability. If you have the prior order history and device continuity, the win rate justifies the fight. If you do not, the win rate is 15 to 20 percent and you are gambling.
- Customer lifetime value. If the disputing customer is a high LTV account, fighting hard poisons the relationship. Sometimes the right business decision is to eat the chargeback and keep the customer.
The right pattern for most merchants is to fight aggressively on transactions above 100 USD with complete CE 3.0 evidence, concede on transactions below 25 USD, and case by case for the middle.
Related reading
- Chargeback fraud prevention: how device evidence wins disputes in 2026
- Merchant chargeback prevention: the 2026 playbook
- Browser fingerprinting for fraud prevention: how it works and why it matters
- Transaction and payment fraud detection software: the checkout evidence gap
- Types of credit card fraud your CS team will see in 2026








