What Is Friendly Fraud? The Rules That Let You Fight It
The real cardholder disputes a real purchase. Visa built a remedy for it, and qualifying depends on data most merchants hash before they can use it.
By Jeffrey Anderson

- Friendly fraud is a chargeback filed by the genuine cardholder on a purchase they made and received. No fraud control catches it, because the card was never stolen.
- Visa uses the term in its own rules and handles it under Dispute Condition 10.4, Other Fraud in the Card-Absent Environment, which is why it is counted as fraud rather than as a service complaint.
- An issuer whose cardholder files five or more separate fraud disputes within twelve months must formally review that account for first-party fraud abuse. Serial disputers do eventually surface.
- Compelling Evidence 3.0 is the remedy. It requires two previous undisputed transactions on the same payment credential processed more than 120 calendar days earlier, plus matching device ID, device fingerprint or IP address and one further identifier.
- Visa requires those identifiers in clear text and explicitly not hashed, naming a minimum of 15 characters for a device ID. Teams that hash identifiers as standard practice cannot produce qualifying evidence, so it needs to be a deliberate decision.
- Qualifying for Compelling Evidence 3.0 excludes the fraud from the VAMP ratio, so it removes the event from the measure your acquirer watches rather than merely winning the case. From 24 October 2026 Visa expands the remedy to support multi-merchant transactions as evidence.
What is friendly fraud? It's a chargeback filed by the real cardholder over a purchase they actually made and received. Nobody stole the card. The customer disputed a legitimate charge instead of asking you for a refund, and you carry the loss plus a fee.
It's the hardest dispute category to prevent, because every fraud control you own is looking for the wrong thing. The card wasn't stolen, so there's nothing to detect.
Visa Uses the Term Too
This isn't just merchant slang. Visa's own rules describe expanding a remedy "to further reduce friendly fraud from the ecosystem" (Visa Core Rules, 18 April 2026).
The formal machinery sits under Dispute Condition 10.4, Other Fraud in the Card-Absent Environment. That's the reason code a cardholder's bank uses when the cardholder says they didn't authorise an online purchase. Most friendly fraud arrives wearing that label, which is why it's counted as fraud rather than as a service complaint.
Visa also calls the underlying behaviour first-party fraud, and it's specific enough about it to make issuers investigate.
Issuers Have to Investigate Repeat Disputers
Here's a published rule almost no merchant knows about.
"An Issuer whose Cardholder has 5 or more separate Dispute category 10 (Fraud) Disputes within a maximum period of 12 months must perform a formal review of the Cardholder account and related Disputes to determine if first-party fraud abuse is occurring."
Five fraud disputes in twelve months forces the bank to look at its own customer. That's a real check on serial disputers, and it's worth knowing when someone tells you the system only ever protects the cardholder. It doesn't help you with a first-time disputer, but the pattern does eventually surface.
The Remedy Visa Built for It
Compelling Evidence 3.0 is the rule that lets you win these when you have the right data. The qualifying test is precise, so it's worth reading rather than paraphrasing.
The dispute becomes invalid where the same payment credential, meaning the Visa account number or token, was used in two previous transactions that the issuer did not report as fraud, processed more than 120 calendar days earlier, and both of the following hold:
- Either a detailed description of the merchandise or services for the disputed transaction and the two previous ones, or, for e-commerce processed with Visa Secure carrying ECI 7 and a CAVV, a purchase order number instead.
- The device ID, device fingerprint, or IP address from the undisputed transactions matches the disputed one, plus at least one more matching element.
Visa is exact about what those elements have to look like. The customer account or login ID "must be a unique identifier that the Cardholder uses to authenticate on the Merchant's e-commerce site or application at the time of the Transaction, and must be a value that the Cardholder recognizes in clear text and not hashed." A full delivery address must include street, city, state or province, postal code and country, also in clear text. A device ID must be verifiable by the cardholder, such as an IMEI, "at least 15 characters, in clear text, and not hashed."
Clear text, not hashed, repeated three times. If your engineering team hashes identifiers before storage, which is normally good practice, you cannot produce qualifying evidence. That's a decision worth making deliberately rather than discovering during a dispute.
What Changes in October 2026
Visa is widening this. Effective 24 October 2026, it's expanding the availability and application of the CE3.0 remedy for Dispute Condition 10.4, and the framework will support multi-merchant transactions as evidence to qualify for liability protection.
Multi-merchant matters. Today you prove the customer's history with you. Under the expansion, transaction history across merchants can support the case, which helps businesses whose customers buy infrequently and could never assemble two prior undisputed purchases in-house.
Don't Game It
Visa monitors the data merchants submit to claim this protection. If it determines a merchant is falsifying data to gain protection, it notifies the acquirer and merchant of the violation, and the merchant loses the ability to use the 10.4 pre-arbitration remedy for that payment credential until the acquirer confirms in writing that the underlying activity is corrected.
It Counts Against You Either Way
Under VAMP, fraud and disputes are combined into one count-based ratio on card-absent volume (Visa). A friendly fraud chargeback lands in that number whether or not you later win it.
There's one meaningful exception, and it's the strongest argument for getting your data right: fraud that qualified for Compelling Evidence 3.0 is excluded from the ratio. Qualifying doesn't just win the case, it removes the event from the measure your acquirer watches. Our guide to calculating your true chargeback ratio covers what else drops out.
Prevention That Actually Works
Most friendly fraud is a recognition problem or a friction problem, not a dishonesty problem.
Fix the descriptor first. Visa requires the merchant name to be used consistently across receipts, authorizations, clearing records and dispute records. If yours shows a parent company nobody recognises, you're manufacturing disputes.
Make cancelling easy. Subscription businesses generate first-party disputes when cancelling is harder than calling the bank. That's a design choice you can reverse.
Answer support fast. A dispute is what a customer does when you don't reply.
Send a receipt that names the product, not just an amount, so the charge is identifiable weeks later.
Use pre-dispute alerts. Refunding through an alert stops the chargeback being recorded at all.
Store the CE3.0 fields in clear text, deliberately, for the identifiers Visa names.
We go deeper on the layered approach in ecommerce fraud prevention, and chargeback versus refund versus dispute explains why customers choose the expensive route.
Frequently Asked Questions
What is friendly fraud?
A chargeback filed by the genuine cardholder for a purchase they made and received. The card was never stolen, which is why standard fraud screening cannot catch it.
Is friendly fraud the same as first-party fraud?
Effectively yes. Visa uses first-party fraud in its rules and friendly fraud in its commentary. Both describe the real cardholder disputing their own legitimate purchase.
Can I win a friendly fraud chargeback?
Yes, through Compelling Evidence 3.0, if the same card made two previous undisputed purchases from you more than 120 calendar days earlier and you can match device ID, device fingerprint or IP address plus another identifier, all in clear text.
Why does my hashed data disqualify me?
Because Visa requires the identifiers to be values the cardholder recognises in clear text and explicitly not hashed. Hashing is good security practice generally, but it makes those specific fields unusable as dispute evidence.
Does anything happen to customers who do this repeatedly?
Yes. An issuer whose cardholder has five or more separate fraud disputes within twelve months must formally review that account to determine whether first-party fraud abuse is occurring.
Does winning remove it from my chargeback ratio?
Winning by itself does not, but fraud that qualified for Compelling Evidence 3.0 is excluded from the VAMP ratio. That is a stronger reason to capture the right data than the individual case value.
What's changing in October 2026?
From 24 October 2026 Visa is expanding the CE3.0 remedy for Dispute Condition 10.4, and the framework will support multi-merchant transactions as qualifying evidence, which helps merchants whose customers buy too rarely to build a history in-house.
Losing money to disputes on sales you actually delivered? Apply free for an account with dispute handling included, or talk to a specialist about what your data can already prove.
Jeffrey Anderson, Merchant Placement Specialist
Merchant placement specialist at Gray Merchants. Jeffrey works directly with acquiring-bank underwriting teams across the firm’s 70+ banking relationships to place high-risk and hard-to-place businesses, structure multi-MID accounts, and keep flagged merchants processing. His writing draws on the placement files he works every week: what underwriters ask for, why accounts get declined, and what keeps an approved account open.