Free guide: How to use AI in compliance
Back

First-party fraud

Updated September 18, 2026

Table of contents

First-party fraud is fraud committed by a customer in their own name: applying for credit or an account with no intention of paying, misrepresenting income or circumstances, disputing legitimate charges, or abusing refunds and promotions. Unlike third-party fraud, no identity is stolen, so identity verification alone does not catch it.

The distinction matters because the controls differ. Third-party fraud is stopped at onboarding by proving the applicant is who they claim to be. First-party fraud passes that check by definition, and is caught by consistency, history and behaviour. Synthetic identity fraud sits in between: the identity is invented from real fragments, so it is neither fully the applicant’s own nor stolen from a single victim, and it is covered in fullz and synthetic identity fraud.

Types of first-party fraud

  • Application fraud: overstating income, hiding debts or falsifying employment to obtain credit or an account.
  • Bust-out fraud: building up credit lines over months with good behaviour, then maxing them out and disappearing.
  • Chargeback and dispute abuse: buying goods or services and then falsely claiming they were not received or not authorised, sometimes called friendly fraud.
  • Refund and promotion abuse: exploiting returns policies, sign-up bonuses or referral schemes, often across multiple accounts.
  • Mule behaviour: lending one’s own account to move someone else’s money, which is first-party in the sense that the identity is real and the account holder is the actor.

Why first-party fraud is hard to catch

The applicant is real, the documents are genuine, and at onboarding the intent to defraud has not yet produced any behaviour. Detection therefore relies on signals a document check cannot provide: whether this person has opened several accounts under different details, whether the declared income and address hold up against independent sources, whether the device and location match the story, and what the account does after it opens.

How first-party fraud is detected

  • Duplicate and linked account detection: the same face, device, address or bank account behind multiple applications.
  • Consistency checks: proof of address and income documents in the same name, geolocation that matches the declared country, no VPN or proxy masking.
  • Velocity and behaviour after onboarding: rapid drawdown, unusual dispute rates, or transactions that do not fit the profile.
  • Shared intelligence: fraud databases and consortium data flag applicants with prior first-party fraud markers.

How Zyphe addresses first-party fraud

Zyphe’s fraud detection software runs the signals a genuine document cannot fake: biometric uniqueness across a flow (the same face under different details), proof of address with name matching, device fingerprinting with GPS versus IP country and VPN or proxy detection, and transaction monitoring with velocity counters and shared-counterparty detection after the account opens. The identity check itself is covered by KYC software.

Michelangelo Frigo Written by Michelangelo Frigo (Co-Founder at Zyphe) Reviewed September 18, 2026 Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.

Frequently Asked Questions

First-party fraud is fraud a customer commits in their own name: obtaining credit or an account with no intention of paying, misrepresenting income or circumstances, disputing legitimate charges, or abusing refunds and promotions. No identity is stolen, which is what separates it from third-party fraud.

In third-party fraud the fraudster uses someone else’s identity, so it is caught by proving who the applicant is. In first-party fraud the applicant is who they say they are and the fraud is in their intent or their claims, so it is caught by consistency, linked-account detection and behaviour after onboarding rather than by identity verification.

Inflating income on a loan application, running up credit lines and vanishing (bust-out), falsely disputing card payments for goods that were received, opening several accounts to collect sign-up bonuses, and lending one’s own account to move a stranger’s money.

Friendly fraud is one type of first-party fraud: a customer disputes a legitimate charge with their card issuer to obtain a refund while keeping the goods or service. The word friendly refers to the customer relationship, not to the intent.

Detect duplicate and linked accounts through biometric uniqueness and device signals, check declared details against independent sources such as proof of address and geolocation, monitor velocity and dispute behaviour after onboarding, and share fraud markers through consortium data. Identity verification alone does not stop it, because the identity is genuine.

Stop synthetic and deepfake fraud at the door

Zyphe combines liveness, document and AI checks with privacy-first storage.

Book a demo