Skip to main content

Fraud Types Every Merchant Should Know

Written by Indre Daubaraite

Understanding how online fraud occurs is the first step toward protecting your business. Below is a summary of the primary fraud typologies every e-store should know, outlining how bad actors operate and the direct impact on your store.

What is "Card Payment Fraud"?

Card Payment Fraud occurs when stolen, leaked, or cloned credit card details are used to make unauthorised purchases online. Unlike direct bank payments—which require bank-level biometrics or Strong Customer Authentication (2FA)—card transactions remain uniquely vulnerable to compromised credentials. When the legitimate cardholder notices the unrecognised charge and files a dispute with their issuing bank, your store is left facing unexpected chargebacks, lost inventory, and non-refundable payment processing fees.

You can read more here

Common Examples:

  • Card Testing Bots: Automated scripts executing rapid, small-value card purchases to identify active card numbers stolen from external data breaches.

  • High-Value Resale Theft: Fraudsters placing large orders for easily resold goods (e.g., consumer electronics, designer items, digital gift cards) using stolen credit card details.

Warning Signs:

  • Multiple Failed Attempts: Several consecutive payment rejections on the same IP address or checkout session right before a transaction succeeds.

  • Mismatched Locations: A non-local or foreign billing card paired with a local parcel locker, pickup point, or freight forwarding address.

  • Abnormal Checkout Velocity: Multiple orders placed in rapid succession under different customer names but using identical contact numbers or IP addresses.

How to Reduce Risk:

  • Review large orders manually: Flag high-value purchases—especially those exceeding your store's average basket size—to check for red flags like foreign cards, mismatched billing/shipping addresses, or brand-new guest accounts before processing fulfilment.

  • Wait until payment is confirmed: Pause fulfilment until the payment status is fully settled and cleared by the gateway, ensuring the transaction has successfully passed 3D Secure / SCA checks rather than relying solely on initial order creation notices.

  • Use signature delivery for high-value goods: Mandate direct signature confirmation upon courier delivery for expensive items rather than leaving shipments in unverified drop locations, creating concrete proof of receipt that protects against chargeback claims.

If you receive a dispute…

  • Provide clear proof of delivery to the bank: Share signed courier receipts, tracking logs, and 3DS verification.

  • Respond to the chargeback before the deadline with evidence: Compile and submit all order documentation before the deadline.

  • Report suspicious fulfilment patterns: Share details of recurring suspicious buyers or delivery locations with Montonio to help strengthen network-wide fraud protection.

Case example

  • Scenario: A €950 order for high-end headphones is placed via guest checkout and completed.

  • Dispute Filed: Two weeks later, the true cardholder files a dispute claiming unauthorised card use.

  • Impact: You receive a dispute notification, funds are reversed, and you are hit with a dispute fee.


What is "Account Takeover Fraud"?

Account Takeover Fraud occurs when bad actors use stolen login credentials to hijack a legitimate customer's account. By leveraging saved payment details and established trust history, the fraudster quickly places unauthorised orders—often swapping the shipping address right before checkout to intercept the goods before the true owner notices.

You can read more here

Common Examples:

  • Credential Stuffing: Automated tools testing stolen username and password lists from past data breaches to log into customer accounts.

  • Saved Payment Abuse: Hijacking an active customer profile to purchase high-value goods using previously saved card or checkout details.

Warning Signs:

  • Sudden Profile Changes: Immediate edits to the account's email address, primary phone number, or shipping details prior to an order.

  • Unusual Order Volume: A sudden flurry of high-value or rapid purchases from an account that has been inactive for a long time.

  • Location Discrepancies: Login or order placement from an IP address or region that drastically differs from the account's historical activity.

How to Reduce Risk:

  • Promote strong passwords: Encourage customers to use unique, complex passwords and security hygiene during account creation.

  • Monitor unusual orders: Set up flags for sudden profile modifications (like address changes) made right before placing high-value orders.

  • Contact customers to verify: Reach out directly to account owners via verified phone numbers or secondary contacts when high-risk account activity is detected.

If You Receive a Dispute:

  • Provide account activity logs: Submit login timestamps, IP address records, device signatures, and address modification histories.

  • Respond before the deadline: Compile and submit all order documentation before the deadline.

  • Report suspicious fulfilment patterns: Share details of compromised accounts or suspicious delivery destinations with Montonio to help strengthen network-wide protection.

Case Example

  • Scenario: A fraudster buys a batch of leaked passwords online and successfully logs into a customer's registered account. They select a €500 store gift card or digital voucher using the customer's saved credit card and checkout instantly.

  • Dispute Filed: Three days later, the account owner checks their bank statement, discovers the unrecognised transaction, and files a dispute for fraudulent account access.

  • Impact: The digital voucher has already been redeemed, the funds are reversed from your account, and you incur a dispute fee.


What is "Friendly Fraud"?

Friendly Fraud occurs when a real customer makes a legitimate purchase on your e-shop, receives the items, and then disputes the charge directly with their bank. The buyer falsely claims they never authorised the order, or lies about non-delivery or damaged goods to secure a chargeback refund while keeping the merchandise.

You can read more here

Common Examples:

  • "Unrecognised" Claim Abuse: A customer or family member completes a legitimate purchase, receives the items, and then files a dispute claiming they didn't authorise the transaction.

  • False Non-Delivery: A customer receives a tracked package containing high-value items and falsely reports to their issuing bank that the parcel was never delivered or arrived as an empty box.

Warning Signs:

  • Post-Delivery Disputes: Chargeback claims filed days or weeks after courier tracking confirms successful delivery to the customer's address.

  • Frequent Claims: Repeat customers who regularly report missing items, partial deliveries, or request chargebacks without contacting your support team first.

  • Vague Explanations: Disputes submitted to the issuing bank with vague, shifting, or contradictory reasoning.

How to Reduce Risk:

  • Use tracked + insured shipping: Ship all orders via tracked courier services with step-by-step dispatch and final delivery confirmations.

  • Keep proof of delivery (tracking, photos, invoices): Retain detailed records, including courier POD signatures, delivery photos, parcel weights, and order invoices.

  • Blacklist customers who issue suspicious chargebacks: Block accounts, email addresses, and shipping details associated with previous fraudulent chargebacks from placing future orders.

If You Receive a Dispute:

  • Provide clear proof of delivery to the bank: Submit signed courier receipts, tracking logs, and fulfilment timestamps showing successful delivery.

  • Respond before the deadline: Compile and submit customer communication history, order invoices, and proof of delivery before the deadline.

  • Report suspicious fulfilment patterns: Share details of buyers engaging in recurring chargeback abuse with Montonio so suspect profiles can be flagged across the merchant network.

Case Example

  • Scenario: A customer orders €450 worth of clothing, accepts the parcel upon courier arrival, and completes the delivery.

  • Dispute Filed: Two weeks later, the buyer contacts their bank and disputes the transaction, claiming unauthorised card use.

  • Impact: You receive a dispute notification, funds are reversed, and you are hit with a dispute fee.


What is "Identity Fraud (Pay Later & Financing)"?

Identity Fraud in Pay Later (BNPL) or instalment financing occurs when a fraudster uses stolen personal information—such as national ID codes, names, and phone numbers—to apply for credit financing on your e-shop. The bad actor secures the goods immediately, leaving the identity theft victim with payment demands for purchases they never made and exposing your store to disputed orders.

You can read more here

Common Examples:

  • Synthetic Identity Creation: Combining real personal identification codes with fake phone numbers and emails to bypass automated soft credit checks during checkout.

  • Stolen Credential Financing: Using stolen personal details from data leaks to secure instant Pay Later approval for high-value physical goods.

Warning Signs:

  • Data Discrepancies: Mismatches between the customer's identity details on the Pay Later application and the shipping address or phone number provided.

  • High-Risk Contact Details: Use of disposable email addresses, temporary phone numbers, or brand-new contact details on accounts placing large Pay Later orders.

  • Multiple Credit Requests: Repeated financing applications submitted in quick succession under different names from the same IP address or device.

How to Reduce Risk:

  • Rely on provider-level identity checks: Montonio’s financing partners (e.g., Inbank) automatically perform identity verification (such as Smart-ID, Mobile-ID, or eID) during the application process to block fraudulent credit requests.

  • Cross-check order and financing data: Flag orders where the approved financing applicant's name differs significantly from the recipient name or shipping destination.

  • Hold physical shipments on flagged profiles: Pause dispatch on high-value financed orders directed to parcel lockers or temporary addresses if contact details cannot be verified.

If You Receive a Financing Fraud Notice:

  • Verify courier hand-off records: Gather courier handover timestamps, parcel weights, and locker retrieval signatures showing physical dispatch.

  • Confirm applicant identity match: Check whether the delivery recipient name matches the approved buyer details on the original order.

  • Submit evidence to Montonio: Provide requested fulfilment and delivery proof directly to Montonio’s team so they can represent your case to the financing partner before the review window expires.

Case example:

  • Scenario: A fraudster uses a victim's stolen name and personal identification code to purchase a €800 laptop using instant Pay later financing, routing delivery to an automated parcel locker.

  • Dispute Filed: A month later, the victim receives a debt collection notice for the Pay later loan, realises their identity was stolen, and files an identity theft dispute.

  • Impact: Because identity checks are handled by the financing provider (Inbank), the lender absorbs the financial loss. However, your team must still pull and submit courier fulfilment logs to Montonio to prove valid dispatch.


What is "Refund & Return Fraud"?

Refund & Return Fraud occurs when bad actors manipulate your store's return policy to secure an unauthorised refund while keeping the original product. By shipping back empty boxes, swapping merchandise for cheap counterfeits, or making false missing-item claims, fraudsters drain your profit margins through inventory loss, shipping fees, and wasted administrative time.

You can read more here

Common Examples:

  • "Empty Box" / Item Swap Schemes: Returning an empty parcel, bricks, or low-value substitute items while claiming the original high-value product was returned in full.

  • Double Dipping: Requesting a direct store refund or replacement item from merchant support while simultaneously filing a payment dispute with the bank or payment gateway.

Warning Signs:

  • Weight Mismatches: Significant discrepancies between the carrier's registered parcel dispatch weight and the weight recorded upon return arrival.

  • Immediate Return Requests: Rapid requests for refunds or store credit immediately after order delivery, often paired with refusal to provide photo evidence of damaged goods.

  • Aggressive Pressure Tactics: Customers demanding instant manual processing of refunds before the returned parcel has arrived at your warehouse or passed inspection.

How to Reduce Risk:

  • Inspect returns before refunding: Wait until returned items arrive at your warehouse and pass physical quality inspection before issuing a refund.

  • Log carrier package weights: Compare outbound shipping weights with inbound return parcel weights to spot empty boxes or item swaps early.

  • Require photo/video evidence: Mandate photos or videos of defective items or damaged packaging before authorising return shipping labels or replacements.

If You Receive a Dispute Relate to Fraudulent Return Claim:

  • Provide warehouse inspection proof: Gather unboxing photos, return log timestamps, and weight documentation showing the discrepancy or missing item.

  • Check active order refund status: Verify whether a refund or replacement was already issued internally before responding to formal dispute claims.

  • Submit evidence to Montonio: Compile and submit return receipts, customer communication logs, and warehouse inspection notes before the deadline.

Case Example

  • Scenario: A customer orders a €700 designer jacket, requests a return claiming it was the wrong size, and ships back a parcel.

  • Dispute Filed: Upon arrival at the warehouse, the returned package is found to contain an empty garment bag and a cheap sweater, but the customer demands an immediate full refund.

  • Impact: The merchant denies the refund based on inspection logs. The buyer then files a payment chargeback claiming non-refunded returned goods, putting the €700 and shipping costs at risk.


What is "Promotion Abuse"?

Promotion Abuse occurs when bad actors or opportunistic shoppers exploit coupon codes, referral rewards, or new-customer discounts to gain unearned financial perks. By creating multiple fake profiles to repeatedly claim "first-order" deals, shoppers drain marketing budgets, erode profit margins, and create artificial order spikes without bringing in genuine new customers.

You can read more here

Common Examples:

  • Multi-Accounting / Promo Stacking: Creating dozens of fake customer accounts using temporary email addresses to repeatedly claim "first-order" discount codes or welcome gifts.

  • Referral Loops: Setting up secondary accounts to refer oneself, claiming both the referrer reward and the referee sign-up bonus.

Warning Signs:

  • Identical Checkout Footprints: Multiple new account registrations sharing identical shipping addresses, payment methods, or IP addresses, but using different email accounts to apply the same coupon code.

  • Single-Item Promo Orders: A high volume of guest orders containing only the exact minimum spend required to trigger a discount code or free gift.

  • Affiliate / Code Spikes: A sudden surge in orders utilizing single-use or influencer-specific codes originating from suspicious or unusual referral channels.

How to Reduce Risk:

  • Limit promo codes per device or payment method: Restrict new-customer discounts so they can only be redeemed once per unique card number, phone number, or delivery address.

  • Set strict terms on promotional campaigns: Require minimum order thresholds, restrict promo codes on easily resold items, and disable code stacking at checkout.

  • Monitor registration patterns: Flag accounts that share matching shipping destinations or payment details when claiming sign-up incentives.

If You Identify Promotion Abuse:

  • Cancel orders violating terms: Cancel pending orders that explicitly breach your published promotion terms and conditions before dispatching stock.

  • Audit referral and campaign logs: Cross-reference promo code usage against account creation timestamps and customer shipping addresses to identify loop networks.

  • Blacklist abusive buyer details: Block recurring abusive email domains, shipping addresses, or phone numbers in your e-shop platform settings to prevent future code redemptions.

Case Example

  • Scenario: A buyer creates ten different email accounts to repeatedly apply a single-use "€15 Welcome Discount" across ten individual orders of skincare products, using the exact same payment card and shipping address for every checkout.

  • Why This Is Suspicious: Paying for ten "first-time customer" orders with the exact same bank card and sending every parcel to the same house shows the buyer is intentionally making fake accounts to reuse a discount meant for brand-new shoppers.

  • Impact: The e-shop sends out all ten orders before noticing the matching details, losing €150 in direct sales income, wasting money on ten individual courier fees for a single buyer, and burning through promotional stock without gaining any new customers


What is “Affiliate & Referral Fraud”?

Affiliate & Referral Fraud occurs when dishonest marketing partners or users manipulate tracking links, discount codes, or referral systems to generate unearned commission payouts. Instead of driving real business, bad actors drain your reward budgets by claiming credit for organic sales, creating fake referral leads, or buying through their own links to collect payouts.

You can read more here

Common Examples:

  • Cookie Stuffing / Attribution Hijacking: Forcing hidden affiliate tracking cookies onto a user's browser without their knowledge so that when they make an organic purchase, the affiliate unfairly receives the commission.

  • Self-Referral Abuse: Creating fake accounts to buy items through one's own referral link or discount code. Buyers do this to stack welcome discounts with referral cashback, effectively getting items below cost or pocketing unearned rewards on purchases they were already going to make.

  • Brand Name Bidding: Placing search ads on your store's exact brand name. This steals your organic search traffic and competes directly against your own marketing ads, forcing you to pay an affiliate fee for sales you would have made for free or through your own campaigns.

Warning Signs:

  • Suspicious Order Clusters: Multiple orders coming through a single referral code in minutes, especially if paired with new guest accounts or matching user details.

  • High Order Cancellations & Returns: A high volume of canceled orders or immediate returns coming from traffic tied to a specific referral link right after a commission is logged.

  • Matching Buyer & Partner Info: An affiliate payout request where the bank account, email domain, or address matches the buyer details on recent checkout logs

How to Reduce Risk:

  • Hold payouts: Wait 30 days before paying out referral rewards so you have enough time to catch returned orders, self-referrals, or canceled accounts.

  • Match partner and buyer records: Before approving payouts, compare the affiliate’s account info with recent buyer details in your store admin and Montonio dashboard to spot matching names, shipping addresses, or phone numbers.

  • Set strict program rules: Explicitly ban self-referrals and search engine ad bidding on your brand name in your terms, reserving the right to void payouts for suspicious traffic.

If You Identify Affiliate Fraud:

  • Reverse pending commissions: Freeze and/or reject unverified or suspicious commission payouts before funds leave your account.

  • Terminate abusive affiliate accounts: Immediately block and remove partners who violate program terms or engage in automated traffic manipulation.

  • Audit historical payouts: Cross-reference past transactions connected to affiliates against store return and dispute logs to check for wider losses

Case Example:

  • Scenario: A customer creates five fake accounts to buy high-value items through their own "Refer-a-Friend" link, collecting a €20 store credit bonus on each order.

  • Why This Is Suspicious: The buyer uses different email aliases to trigger the referral bonus, but sends every order to the same home address and pays with the exact same bank account.

  • Impact: The e-shop gives away €100 in unearned cash rewards to an existing customer, lowering store profits without gaining a single new customer.


Montonio Recommendations

Use the below recommendations to evaluate order risk before fulfilling purchases or issuing refunds. These recommendations highlight key operational signals across common fraud typologies. Keep in mind that a triggered check does not automatically mean fraud - legitimate orders often raise signals when customers buy gifts or update delivery addresses. Treat these recommendations as a guide to review order/ transaction details before taking action.

Card Payment Fraud

  • Review Multiple Checkout Rejections: Check if the payment failed multiple times before finally clearing on the same session or IP address.

  • Inspect Foreign Card + Local Pickup Combos: Verify orders paid with an overseas card but directed to a local parcel locker or pickup point.

  • Monitor Rapid Checkout Velocity: Watch for multiple orders placed in quick succession under different names that share the same phone number or IP footprint.

Account Takeover Fraud

  • Verify Last-Minute Address Modifications: Inspect high-value orders or digital gift card purchases placed immediately after an account changes its delivery address or email.

  • Check Behaviour Shifts on Old Accounts: Cross-reference sudden large purchases on long-inactive accounts against past ordering history and typical customer spend.

Friendly Fraud

  • Cross-Check Dispute & Claim History: Review whether a buyer requesting a refund has a pattern of claiming non-delivery or filing chargebacks without first contacting your support team.

  • Hold Refunds Pending Delivery Log Updates: Pause immediate replacement or refund requests if customer explanations are contradictory or if courier delivery logs have not yet finalised.

Identity Fraud (Pay Later & Financing)

  • Match Applicant vs. Recipient Names: Compare the name on the approved Pay Later agreement directly with the recipient name on the shipping label.

  • Flag High-Risk Contact Coordinates: Exercise caution on high-value financed orders using temporary email aliases, brand-new phone numbers, or unverified parcel locker destinations.

Refund & Return Fraud

  • Require Visual Proof for Claims: Mandate photo or video evidence of damaged or missing items before issuing instant refunds or return labels.

  • Compare Outbound vs. Inbound Parcel Weights: Check inbound return parcel weights against outbound carrier dispatch logs to catch empty box or item swap attempts early.

Promotion Abuse

  • Audit Matching Customer Footprints: Flag multiple "first-time customer" discount orders sharing the exact same shipping address, credit card, or payment footprint.

  • Identify Single-Item Promo Baskets: Review guest checkout orders containing only the bare minimum spend required to trigger a welcome voucher or free gift.

Affiliate & Referral Fraud

  • Check Partner & Buyer Overlaps: Verify that referral code owners do not share bank details, surnames, or physical shipping addresses with the purchasing customer.

  • Inspect Instant Referral Order Clusters: Audit sudden surges where dozens of purchases use the same referral code within minutes under newly created guest profiles.

Did this answer your question?