put stingray watch in your team's slack
- open the channel your fraud team already uses.
- paste this and hit enter:
/feed subscribe https://feed.stingrayfraud.com/rss.xml - new signals post there after every refresh, twice a week. no sign-up, nothing to install on our side.
first time? slack may ask you to add its rss app. only want one panel? pick a feed at feed.stingrayfraud.com.
stingray watch
a twice-weekly feed of chargeback trends, fraud patterns, and industry signals, tracked so your team doesn't have to.
why not live? new signals land twice a week, and each one is checked against its source first. fraud trends shift over weeks, not minutes, so accuracy beats speed.
filter by fraud vector
industry news feed · last 90 days
a Cloud Security Alliance research note built from a staging server obtained by Gambit Security found one operator used three chained open-source LLM tools to autonomously breach 105 e-commerce retailers and steal 600,000+ payment card records between July and September, spending roughly $25 per target · cloudsecurityalliance.org
a Spreedly-backed survey of eCommerce merchants finds 51% expect fraud-staffing budgets to hold flat or shrink even as 63% plan to increase spending on fraud-management technology instead · pymnts.com
a coalition of major banks (including Bank of America, Capital One, NatWest, ING, and Commonwealth Bank of Australia) warns AI shopping agents are outpacing consumer fraud and data-privacy protections, as one UK retailer's AI-agent traffic jumped from 0.3% to 2.5% of searches in a year · cnbc.com
tracked an active cloud-intrusion campaign, running since May, that opens with a fake IT-helpdesk call pressuring an employee to re-register a passkey, then pivots into Microsoft Graph, SharePoint, and OneDrive data collection · microsoft.com
synthetic identity fraud, which blends real stolen data with fabricated details into ‘Frankenstein’ identities, is emerging as one of the biggest threats to financial institutions, distinct from deepfake-based impersonation · icaew.com
the Postal Service Inspector General estimates $3.1B in revenue was lost to counterfeit postage labels between March 2024 and February 2026, with fake labels openly advertised for sale online · uspsoig.gov
researcher Frank McKenna has cataloged 1,300+ spoofed vehicle-dealer websites tied to $12.4M in reported victim losses; 600 have been taken down, with 5-10 new clones still surfacing daily · frankonfraud.com
a credential-stuffing attack compromised 138,828 customer accounts in late July, exposing names, addresses, and partial payment card details · esecurityplanet.com
organized fraud rings are recycling forged identity documents and deepfakes across institutions, and one linked cluster spanned 70 identities across 13 devices · globenewswire.com
just 49% of firms use their bank-data connections to generate fraud alerts, even though 69% already use those same connections to verify account and routing numbers · pymnts.com
BOPIS (buy-online-pickup-in-store) fraud increased 65% year-over-year, as fraud extends beyond checkout into fulfillment operations · globenewswire.com
account takeover remained 2025's costliest fraud type at $15B+ in losses, even as victim count rose 18% to 6 million U.S. consumers · globenewswire.com
global chargeback volume climbed 41% from 2023 to 2026, rising from 238 million to 337 million annual disputes · chargebacks911.com
retailers lost $706B to returns and $89B to shrink in 2025, with $100B of returns flagged as preventable fraud and abuse · apprissretail.com
the most common refund and policy abuse claim is a false item-not-received report, cited by 52% of merchants · chargebackgurus.com
card-testing attacks surged 175% year-over-year and account takeover attempts jumped 78%, as e-commerce fraud pressure rose 33% in the first four months of 2026 · globenewswire.com
83.4% of enterprise merchants report friendly fraud has increased over the past three years, per its 2026 Chargeback Field Report · finopotamus.com
AI-generated damage claims are now the fastest-growing form of return abuse, as fraudsters generate convincing photos of torn or broken items to win refunds · retailgazette.co.uk
reports of account takeover rose more than 36% in 2024 versus 2023, per Federal Reserve-linked suspicious activity reporting data · deepstrike.io
post-purchase refund abuse overtakes payment fraud as e-commerce's #1 threat · chargebackgurus.com
orders placed by AI shopping agents jumped 1,247% year-over-year across one merchant network · signifyd.com
card testing shows up as a burst of low-value charges from a handful of devices or IPs, each cycling through a different stolen card number before the real chargebacks hit · cside.com
organized "refund-as-a-service" crews are socially engineering merchant support for a cut of the item price · bleepingcomputer.com
most chargebacks start as customer service failures, not fraud: the dispute only gets filed once support already dropped the ball · chargebacknerd.substack.com
SEON wins Best AI Fraud & Risk Management Solution at Tearsheet's inaugural AI Innovation Awards · seon.io
small merchants report near-impossible win rates against "friendly fraud" disputes, even with full delivery evidence · reddit.com/r/smallbusiness
acquirers are rethinking blanket reserve holds as their main tool against deferred-delivery risk · chargebacknerd.substack.com
Riskified partners with Marqeta to sharpen issuer-side decisioning on approved orders · riskified.com
flagged trends: two-sided marketplaces · last 90 days
a BrandShield trust survey of 1,029 US shoppers found 34.7% named TikTok Shop as the marketplace where they hit a scam or counterfeit purchase, ahead of eBay at 28.4%, and most cases involved brand impersonation · ppc.land
a BBC investigation found thousands of sellers wrongly suspended or permanently banned by its automated fraud-detection tools, including a seller banned over a £2 pair of sandals the AI wrongly flagged as counterfeit · rocketnews.com
Mercari Japan is barring listings of sealed Pokémon TCG 30th Celebration products from launch day (Sept 16) to block scalper resale. Single cards stay listable, and the ban lasts until a safe trading environment can be ensured · thegamer.com
new October terms double sellers' authenticity-proof window to 48 hours and give the platform authority to destroy items confirmed counterfeit after a six-week holding period · valueaddedresource.net
added a scam-verification tool to Alexa for Shopping that checks whether an email, text, or call claiming to be from Amazon is actually genuine · aboutamazon.com
disabled direct messaging in its revamped Community forum after scammers used it to send fake "eBay Security Team" account-verification phishing threats · valueaddedresource.net
cut its Purchase Protection dispute window from 100 days to 30 and doubled its human review team · ecommercebytes.com
moving to 7-day refund cycles and mandatory prepaid return labels to curb a growing wave of return fraud · jarvio.io
a refund-fraud-as-a-service ring advertised openly on Reddit and Discord was busted for bribing insiders to approve fake refunds on items like MacBook Pros · cbsnews.com
AI-generated "vintage" photos are letting sellers dropship fast-fashion as premium secondhand finds on Vinted, undetected until the item arrives · nssmag.com
claims shill-bidding on its live auctions fell nearly 80% over six months, but won't define what the figure actually counts · shopifreaks.com
triangulation fraud (fake listings that harvest card data to buy from real merchants) costs marketplaces an estimated $30B+ a year · chargebacks911.com
AI shopping agents are being used for automated card testing and rapid bulk purchasing across marketplace platforms, per Unit 42 · unit42.paloaltonetworks.com
high-risk items · what fraudsters are after right now: sneakers, streetwear, TCG/Pokémon & sports cards, bullion, electronics, designer bags
filter by category
Hong Kong police arrested four people, one with triad ties, over Pokémon card deals arranged on Facebook where sellers falsely claimed a buyer's payment had failed or landed in the wrong account to extract a second payment, netting roughly HK$101,000 (~US$13,000) across six cases · thestandard.com.hk
a wave of Pokémon card store break-ins and robberies is sweeping Canada, including a Winnipeg shop burglarized twice in a month (20,500 cards taken in the second hit) and a Central Alberta collector's binder holding a rare Umbreon ex, as seven-figure card sales fuel demand for loot that's compact and hard to trace · cp24.com
the Better Business Bureau is warning Southern Alberta and East Kootenay residents after a victim lost $700,000 CAD buying gold bars that turned out to be fake · ctvnews.ca
a federal grand jury indicted 12 people, including Coolkicks’ co-founder and six former Nike employees, in a $2 million cargo-theft conspiracy that stole shoes from Nike’s Memphis logistics hub for resale · cbsnews.com
ringleaders of a $16.2 million scheme that swapped counterfeit iPhones stamped with stolen serial numbers into Apple Stores across LA to fraudulently claim AppleCare+ warranty replacements were sentenced to federal prison · westsidetoday.com
an 84-year-old Delray Beach shoe store owner was arrested a second time after an undercover buy turned up counterfeit Louis Vuitton, Chanel, Hermès, and Goyard goods, over a year after his first counterfeit-sales arrest · cbs12.com
LA County Sheriff's raid on an Arcadia, CA warehouse seized roughly 25,900 counterfeit Nike, Adidas, and Fear of God Essentials items worth an estimated $10 million · complex.com
a Miami-Dade woman was arrested a second time for selling counterfeit Chanel, Louis Vuitton, Hermès, and Gucci goods over Instagram DMs paid via Zelle · local10.com
Pokémon Center is mass-cancelling bot-placed orders ahead of the 30th Celebration set launch, though shoppers report legitimate purchases getting swept up too · dexerto.com
StockX intercepted 100,000+ suspected fake products over the trailing 12 months, including 40,000+ sneakers worth an estimated $30 million · sneakerbinge.com
Singapore Police report 477 Pokemon card scam cases since October 2025 totaling $958,000 in losses, as scammers exploit demand for new set releases with listings that vanish after payment · bitdefender.com
UK government research finds 1 in 4 pre-loved shoppers unknowingly bought a counterfeit last year, and new IPO guidance names Hermès, Louis Vuitton, Gucci, Chanel, and Prada as the most-targeted resale brands · gov.uk
PSA reports intercepting $200M+ in counterfeit and altered cards: a 1952 Mickey Mantle submits at a 62% fake rate, and Pokémon counterfeits are up 125% year-over-year · si.com
two Alabama residents sentenced for running a counterfeit precious metals scheme that defrauded victims across Alabama, Georgia, and Florida out of $120,000+ · justice.gov
Fear of God Essentials posts a 95.75% unidentified (likely fake) rate in Entrupy's 2026 State of the Fake report, meaning nearly every submitted item can't be verified as authentic · entrupy.com
Apple and London's Met Police tighten stolen-iPhone controls, and phone theft in Westminster is down 45.8% as Stolen Device Protection blocks resale-ready factory resets · malwarebytes.com
counterfeits still slip through StockX and GOAT's paid authentication pipeline, the gap that put Nike's lawsuit against StockX on the map · blog.vendoo.co
eBay card sellers report a rising AI-driven refund scam: buyers submit AI-altered "damage" photos to pressure a refund · valueaddedresource.net
counterfeiters are cracking open genuine PSA slabs, swapping in a lower-grade card, and resealing the case, so a cert-number lookup is the only reliable tell · pregradecards.com
what is stingray
stingray is a case management platform built for e-commerce fraud teams. stingray watch tracks what's happening across the industry. stingray tracks what your own team learns, so it doesn't disappear when someone leaves.
everything ever tracked · nothing here gets removed
a Cloud Security Alliance research note built from a staging server obtained by Gambit Security found one operator used three chained open-source LLM tools to autonomously breach 105 e-commerce retailers and steal 600,000+ payment card records between July and September, spending roughly $25 per target · cloudsecurityalliance.org
a Spreedly-backed survey of eCommerce merchants finds 51% expect fraud-staffing budgets to hold flat or shrink even as 63% plan to increase spending on fraud-management technology instead · pymnts.com
Hong Kong police arrested four people, one with triad ties, over Pokémon card deals arranged on Facebook where sellers falsely claimed a buyer's payment had failed or landed in the wrong account to extract a second payment, netting roughly HK$101,000 (~US$13,000) across six cases · thestandard.com.hk
a wave of Pokémon card store break-ins and robberies is sweeping Canada, including a Winnipeg shop burglarized twice in a month (20,500 cards taken in the second hit) and a Central Alberta collector's binder holding a rare Umbreon ex, as seven-figure card sales fuel demand for loot that's compact and hard to trace · cp24.com
the Better Business Bureau is warning Southern Alberta and East Kootenay residents after a victim lost $700,000 CAD buying gold bars that turned out to be fake · ctvnews.ca
a coalition of major banks (including Bank of America, Capital One, NatWest, ING, and Commonwealth Bank of Australia) warns AI shopping agents are outpacing consumer fraud and data-privacy protections, as one UK retailer's AI-agent traffic jumped from 0.3% to 2.5% of searches in a year · cnbc.com
tracked an active cloud-intrusion campaign, running since May, that opens with a fake IT-helpdesk call pressuring an employee to re-register a passkey, then pivots into Microsoft Graph, SharePoint, and OneDrive data collection · microsoft.com
synthetic identity fraud, which blends real stolen data with fabricated details into ‘Frankenstein’ identities, is emerging as one of the biggest threats to financial institutions, distinct from deepfake-based impersonation · icaew.com
a BrandShield trust survey of 1,029 US shoppers found 34.7% named TikTok Shop as the marketplace where they hit a scam or counterfeit purchase, ahead of eBay at 28.4%, and most cases involved brand impersonation · ppc.land
a BBC investigation found thousands of sellers wrongly suspended or permanently banned by its automated fraud-detection tools, including a seller banned over a £2 pair of sandals the AI wrongly flagged as counterfeit · rocketnews.com
a federal grand jury indicted 12 people, including Coolkicks’ co-founder and six former Nike employees, in a $2 million cargo-theft conspiracy that stole shoes from Nike’s Memphis logistics hub for resale · cbsnews.com
ringleaders of a $16.2 million scheme that swapped counterfeit iPhones stamped with stolen serial numbers into Apple Stores across LA to fraudulently claim AppleCare+ warranty replacements were sentenced to federal prison · westsidetoday.com
an 84-year-old Delray Beach shoe store owner was arrested a second time after an undercover buy turned up counterfeit Louis Vuitton, Chanel, Hermès, and Goyard goods, over a year after his first counterfeit-sales arrest · cbs12.com
the Postal Service Inspector General estimates $3.1B in revenue was lost to counterfeit postage labels between March 2024 and February 2026, with fake labels openly advertised for sale online · uspsoig.gov
Mercari Japan is barring listings of sealed Pokémon TCG 30th Celebration products from launch day (Sept 16) to block scalper resale. Single cards stay listable, and the ban lasts until a safe trading environment can be ensured · thegamer.com
researcher Frank McKenna has cataloged 1,300+ spoofed vehicle-dealer websites tied to $12.4M in reported victim losses; 600 have been taken down, with 5-10 new clones still surfacing daily · frankonfraud.com
a credential-stuffing attack compromised 138,828 customer accounts in late July, exposing names, addresses, and partial payment card details · esecurityplanet.com
organized fraud rings are recycling forged identity documents and deepfakes across institutions, and one linked cluster spanned 70 identities across 13 devices · globenewswire.com
just 49% of firms use their bank-data connections to generate fraud alerts, even though 69% already use those same connections to verify account and routing numbers · pymnts.com
new October terms double sellers' authenticity-proof window to 48 hours and give the platform authority to destroy items confirmed counterfeit after a six-week holding period · valueaddedresource.net
added a scam-verification tool to Alexa for Shopping that checks whether an email, text, or call claiming to be from Amazon is actually genuine · aboutamazon.com
disabled direct messaging in its revamped Community forum after scammers used it to send fake "eBay Security Team" account-verification phishing threats · valueaddedresource.net
LA County Sheriff's raid on an Arcadia, CA warehouse seized roughly 25,900 counterfeit Nike, Adidas, and Fear of God Essentials items worth an estimated $10 million · complex.com
a Miami-Dade woman was arrested a second time for selling counterfeit Chanel, Louis Vuitton, Hermès, and Gucci goods over Instagram DMs paid via Zelle · local10.com
Pokémon Center is mass-cancelling bot-placed orders ahead of the 30th Celebration set launch, though shoppers report legitimate purchases getting swept up too · dexerto.com
BOPIS (buy-online-pickup-in-store) fraud increased 65% year-over-year, as fraud extends beyond checkout into fulfillment operations · globenewswire.com
account takeover remained 2025's costliest fraud type at $15B+ in losses, even as victim count rose 18% to 6 million U.S. consumers · globenewswire.com
global chargeback volume climbed 41% from 2023 to 2026, rising from 238 million to 337 million annual disputes · chargebacks911.com
retailers lost $706B to returns and $89B to shrink in 2025, with $100B of returns flagged as preventable fraud and abuse · apprissretail.com
the most common refund and policy abuse claim is a false item-not-received report, cited by 52% of merchants · chargebackgurus.com
card-testing attacks surged 175% year-over-year and account takeover attempts jumped 78%, as e-commerce fraud pressure rose 33% in the first four months of 2026 · globenewswire.com
StockX intercepted 100,000+ suspected fake products over the trailing 12 months, including 40,000+ sneakers worth an estimated $30 million · sneakerbinge.com
83.4% of enterprise merchants report friendly fraud has increased over the past three years, per its 2026 Chargeback Field Report · finopotamus.com
Singapore Police report 477 Pokemon card scam cases since October 2025 totaling $958,000 in losses, as scammers exploit demand for new set releases with listings that vanish after payment · bitdefender.com
AI-generated damage claims are now the fastest-growing form of return abuse, as fraudsters generate convincing photos of torn or broken items to win refunds · retailgazette.co.uk
reports of account takeover rose more than 36% in 2024 versus 2023, per Federal Reserve-linked suspicious activity reporting data · deepstrike.io
UK government research finds 1 in 4 pre-loved shoppers unknowingly bought a counterfeit last year, and new IPO guidance names Hermès, Louis Vuitton, Gucci, Chanel, and Prada as the most-targeted resale brands · gov.uk
PSA reports intercepting $200M+ in counterfeit and altered cards: a 1952 Mickey Mantle submits at a 62% fake rate, and Pokémon counterfeits are up 125% year-over-year · si.com
two Alabama residents sentenced for running a counterfeit precious metals scheme that defrauded victims across Alabama, Georgia, and Florida out of $120,000+ · justice.gov
Fear of God Essentials posts a 95.75% unidentified (likely fake) rate in Entrupy's 2026 State of the Fake report, meaning nearly every submitted item can't be verified as authentic · entrupy.com
Apple and London's Met Police tighten stolen-iPhone controls, and phone theft in Westminster is down 45.8% as Stolen Device Protection blocks resale-ready factory resets · malwarebytes.com
post-purchase refund abuse overtakes payment fraud as e-commerce's #1 threat · chargebackgurus.com
cut its Purchase Protection dispute window from 100 days to 30 and doubled its human review team · ecommercebytes.com
orders placed by AI shopping agents jumped 1,247% year-over-year across one merchant network · signifyd.com
sellers flag waves of orders from freshly created accounts within hours of each other, a card-testing pattern reported repeatedly on r/EtsySeller ahead of future chargebacks · reddit.com/r/EtsySeller
moving to 7-day refund cycles and mandatory prepaid return labels to curb a growing wave of return fraud · jarvio.io
organized "refund-as-a-service" crews are socially engineering merchant support for a cut of the item price · bleepingcomputer.com
most chargebacks start as customer service failures, not fraud: the dispute only gets filed once support already dropped the ball · chargebacknerd.substack.com
a refund-fraud-as-a-service ring advertised openly on Reddit and Discord was busted for bribing insiders to approve fake refunds on items like MacBook Pros · cbsnews.com
SEON wins Best AI Fraud & Risk Management Solution at Tearsheet's inaugural AI Innovation Awards · seon.io
AI-generated "vintage" photos are letting sellers dropship fast-fashion as premium secondhand finds on Vinted, undetected until the item arrives · nssmag.com
small merchants report near-impossible win rates against "friendly fraud" disputes, even with full delivery evidence · reddit.com/r/smallbusiness
claims shill-bidding on its live auctions fell nearly 80% over six months, but won't define what the figure actually counts · shopifreaks.com
acquirers are rethinking blanket reserve holds as their main tool against deferred-delivery risk · chargebacknerd.substack.com
counterfeits still slip through StockX and GOAT's paid authentication pipeline, the gap that put Nike's lawsuit against StockX on the map · blog.vendoo.co
eBay card sellers report a rising AI-driven refund scam: buyers submit AI-altered "damage" photos to pressure a refund · valueaddedresource.net
Riskified partners with Marqeta to sharpen issuer-side decisioning on approved orders · riskified.com
counterfeiters are cracking open genuine PSA slabs, swapping in a lower-grade card, and resealing the case, so a cert-number lookup is the only reliable tell · pregradecards.com
triangulation fraud (fake listings that harvest card data to buy from real merchants) costs marketplaces an estimated $30B+ a year · chargebacks911.com
AI shopping agents are being used for automated card testing and rapid bulk purchasing across marketplace platforms, per Unit 42 · unit42.paloaltonetworks.com
core fraud vectors · tracked and filterable in the live feed
a fraudster gains unauthorized access to a legitimate customer's account — usually via credential stuffing, phishing, or a breached reused password — then uses the stored payment methods, loyalty points, or saved info to make fraudulent purchases.
fraud involving autonomous AI shopping or browsing agents — either bad actors using automated agents for bulk card testing and scalping, or new fraud patterns and liability questions that emerge when ordinary consumers delegate purchasing decisions to an AI agent.
manipulation of bidding mechanics on live or timed auction platforms — shill bidding (fake bids to inflate price), bid shielding, and non-paying “winners” who bid with no intent to complete the purchase.
automated scripts running large volumes of small transactions against stolen card numbers to find which are still active, before using the confirmed-live ones for bigger fraudulent purchases elsewhere.
a transaction reversal a cardholder files through their bank rather than the merchant, disputing a charge as unauthorized, not-as-described, or otherwise invalid — chargebacks blend genuine fraud disputes with “friendly fraud,” where a real purchase is falsely disputed.
selling fake or unauthorized replica goods marketed as genuine — a persistent problem even on resale platforms with paid authentication pipelines, since counterfeiters continually adapt to evade whatever detection is in place.
product or service listings that misrepresent what's actually being sold — items that don't exist, are materially different from their photos/description, or exist purely to collect payment with no intent to deliver.
exploiting discount codes, referral bonuses, sign-up incentives, or promotional pricing beyond their intended use — like creating multiple fake accounts to repeatedly claim a “new customer” discount.
when a buyer receives goods or services, then falsely claims non-delivery, damage, or dissatisfaction to get a refund while keeping the item — or repeatedly exploits lenient return policies well past legitimate dissatisfaction.
fraud that manipulates a person — a customer, a support agent, an employee — into taking an action like revealing credentials, approving a refund, or redirecting a shipment, rather than exploiting a technical vulnerability.
use of payment credentials — card numbers, digital wallet access, gift card balances — obtained through data breaches, skimming, phishing, or physical theft, without the account holder's knowledge or consent.
a three-party scheme: a fraudster lists real products cheaply on a legitimate marketplace, collects payment from real buyers, then uses stolen card data to buy those items from the actual retailer and ship to the buyer — the buyer gets real goods unaware they came from a fraudulent transaction, while the cardholder behind the stolen data eventually disputes the charge.
extended glossary · e-commerce fraud & trust & safety terms, a-z
an authentication protocol (branded as Visa Secure, Mastercard Identity Check, etc.) that adds a verification step to online card payments and shifts fraud liability to the card issuer when it's used and the issuer fails to properly challenge a fraudulent transaction.
a checkout-time check that compares the billing address a shopper enters against the address the card issuer has on file, used as one signal (not proof) that the person paying is the cardholder.
the laws, regulations, and internal controls designed to stop criminals from disguising illegally obtained money as legitimate income, typically enforced through transaction monitoring and reporting requirements.
fraudsters systematically generate and test card numbers that share a bank identification number (BIN) prefix, since valid card numbers within a given BIN follow a predictable numbering pattern.
automated scripts mimicking human traffic to perform actions at scale — credential stuffing, card testing, inventory scalping, or mass fake-account creation — faster and cheaper than any human fraud ring could manage manually.
ordering multiple sizes, colors, or variations of the same item with the intent to keep only one and return the rest — each individual return is policy-compliant, but the pattern still inflates a merchant's return-processing costs.
a scam where a fraudster impersonates an executive, vendor, or colleague via email to trick an employee into an unauthorized wire transfer or a change to payment/banking details.
a fraudster builds a legitimate-looking account or credit history over time — sometimes using a synthetic identity — then maxes out available credit, credit lines, or inventory access in a short window before disappearing.
fraud on transactions where the physical card is never shown to the merchant, such as online or phone orders — the dominant fraud category for e-commerce, since the usual in-person checks (signature, chip, physical card) don't apply.
testing or using stolen card numbers to make purchases, typically with automated tools — the umbrella term that card testing and BIN attacks both fall under.
the percentage of a merchant's transactions that result in a chargeback; card networks fine or terminate merchants whose ratio exceeds set thresholds, which is why chargeback prevention is treated as an existential metric, not just a cost center.
using large lists of username/password pairs leaked in unrelated data breaches to automatically try logging into other sites, exploiting the fact that many people reuse the same password across services.
the card verification value printed on a payment card (separate from the card number), used at checkout as a check that the person paying has physical possession of the card, since it's not stored in most card-present transaction records.
a fraud-detection technique that identifies a device by its combination of browser, hardware, and configuration signals, used to recognize the same physical device operating behind multiple supposedly-unrelated fake accounts.
a seller lists and sells products they don't actually stock or control, and either never fulfills the order, ships something materially different, or sources it through another fraudulent channel to fill it.
a fraud-detection system fails to catch an actually-fraudulent transaction or account, letting it through — the failure mode that costs money directly.
a fraud-detection system incorrectly flags a legitimate customer or transaction as fraudulent, causing lost sales, a declined real customer, and support friction — the failure mode that costs revenue and trust.
fraud committed by the actual account holder against the merchant or issuer — friendly fraud, application fraud using one's own real identity, bust-out fraud — as opposed to a criminal impersonating someone else.
a cardholder disputes a legitimate charge they actually authorized — sometimes by genuine mistake or forgotten subscription, sometimes deliberately to get goods for free — and is generally considered the single largest driver of chargebacks industry-wide.
covers both card-draining (automatically guessing or scraping unused gift card balances before a legitimate buyer redeems them) and using gift cards purchased with stolen payment methods to launder value into a harder-to-trace form.
the identity-verification process businesses — especially financial and payments platforms — are legally required to run on customers before allowing certain account activity, meant to prevent fraud, money laundering, and use by sanctioned parties.
when fraud liability for a disputed transaction moves from the merchant to the card issuer — typically because the merchant used a stronger authentication method (like 3D Secure) that the issuer then failed to properly challenge.
stealing or abusing loyalty program points and rewards, often via account takeover of dormant accounts sitting on accumulated balances the real owner has forgotten about.
a person who receives and transfers illegally obtained money on behalf of someone else — often unknowingly, recruited through a fake job offer or romance scam — to obscure the money's true origin.
one person or organized group operating many accounts on the same platform, usually to evade rate limits or bans, abuse promotions repeatedly, or manipulate reviews and ratings.
the Payment Card Industry Data Security Standard — a set of security requirements every business that stores, processes, or transmits card data is contractually required to follow.
a fraudulent message impersonating a trusted party — a bank, a retailer, a coworker — designed to trick someone into revealing credentials, payment details, or clicking a malicious link.
a merchant's formal response disputing a chargeback, submitting evidence (delivery confirmation, IP logs, prior order history) that the original transaction was legitimate.
abusing a merchant's return policy — including wardrobing, receipt fraud, and returning stolen, used, or different items than what was originally purchased — distinct from refund abuse in that a real return happens, just a dishonest one.
using bots to buy limited-availability inventory — sneakers, event tickets, restocked electronics — faster than real customers can, in order to resell it at a markup.
fraudulently transferring a victim's phone number to a new SIM card under the fraudster's control, letting them intercept SMS-based one-time passcodes and account-recovery messages meant for the real owner.
illegally capturing card data from the magnetic stripe or chip during what looks like a normal transaction, usually via a hidden device attached to a card reader.
phishing conducted via SMS text message — often impersonating a delivery notification, bank alert, or account-security warning to create urgency.
adding an extra verification step — a one-time code, biometric check, 3D Secure challenge — only when a specific transaction looks risky, rather than requiring it for every checkout and adding friction to low-risk purchases.
fraud built on a fabricated identity that blends real information (like a stolen or randomly generated SSN) with fake details, designed to pass verification checks and build a credible credit history before a bust-out.
fraud committed using someone else's stolen identity or payment credentials without their knowledge — the more commonly assumed meaning of "fraud," as opposed to first-party fraud committed by a real, willing account holder.
the discipline within a company responsible for protecting users and the platform itself from fraud, abuse, harassment, and policy-violating content — overlaps with but is broader than fraud prevention alone.
a fraud-detection technique that flags unusually rapid activity — too many orders, logins, or password resets from the same card, account, device, or IP address in too short a window.
phishing conducted via phone call, often with a caller impersonating a bank's fraud department or a delivery service to extract credentials or a one-time code.
buying an item — commonly clothing for a single event — using it once, then returning it for a full refund as if it were unworn.
see how it works
stingray watch is one piece. see how stingray keeps your whole team's case knowledge in one place.
visit stingrayfraud.comget instant beta access
drop your info and unlock a live walkthrough, no waiting, no scheduling.
unlock accesssteal our chargebacks sop
free download, no strings attached. see exactly how we handle a chargeback dispute end to end.
steal itStingray Fraud Intelligence · stingrayfraud.com
This page is for educational and informational purposes only. Ticker and archive items link to third-party articles and sources. Views expressed in linked content are those of the original authors and do not reflect the views of Stingray Fraud Intelligence.