By NHI Mgmt Group Editorial TeamBased on SumSub: “Gaming the System: The Rise of First Party Fraud” (June 8, 2026)

TL;DR: First party fraud is becoming a scalable criminal model as legitimate customers exploit refunds, disputes, chargebacks, subscriptions, and reimbursement systems for personal gain, according to SumSub’s conversation with Monzo Bank’s Richard Bromley. The risk is no longer just transaction abuse; it is governance drift across identity verification, behavioural signals, and dispute handling.


At a glance

What this is: This is an analysis of first party fraud, showing how legitimate customers can abuse refunds, disputes, chargebacks, subscriptions, and reimbursement processes at scale.

Why it matters: It matters because IAM, fraud, and dispute teams must govern identity trust and claimant credibility across customer journeys, not just defend against external attackers.


Context

First party fraud happens when a legitimate customer misrepresents a transaction, refund request, chargeback, subscription issue, or reimbursement claim for personal gain. The core governance problem is not access control in the narrow sense, but trust decisions made after identity has already been established.

For banks, fintechs, merchants, and payment providers, the pressure point is the gap between verified identity and verified intent. Behavioural signals, investigator expertise, and cross-industry intelligence become part of the control stack because standard onboarding assurance does not prevent a customer from gaming downstream dispute processes.


Key questions

Q: What breaks when refund and dispute workflows trust verified customers by default?

A: Verified identity does not prove claim legitimacy. When refund and dispute workflows assume that an authenticated customer is automatically entitled to reversal or reimbursement, first party fraud can pass through as normal service friction. The failure is a post-onboarding trust gap: teams validate the account holder, but not the intent behind the claim.

Q: Why does first party fraud create losses even when onboarding is strong?

A: Onboarding controls prove the customer exists, not that later claims are honest. Once the account is live, fraudsters can exploit chargebacks, refunds, subscriptions, and reimbursement processes using ordinary customer channels. That is why strong enrolment does not eliminate downstream payment abuse or dispute manipulation.

Q: What are the signs that a refund or chargeback claim may be abusive?

A: Repeated claims, inconsistent stories, high-velocity disputes, device or session anomalies, and patterns that mirror known playbooks are common indicators. Teams should also watch for claim behaviour that changes depending on the channel or agent, since genuine victims are usually more stable in narrative and sequence.

Q: How should banks and merchants govern first party fraud across teams?

A: Treat it as a shared governance issue across fraud, payments, disputes, and customer operations. Standardise claim typologies, escalate high-risk cases for investigator review, and measure repeat abuse separately from legitimate loss. That alignment helps organisations distinguish true victims from customers who are gaming the system.


Technical breakdown

Why verified identity does not stop claimant abuse

Verified identity answers who the customer is, not whether the claim is truthful. In first party fraud, the same person who passed onboarding can later exploit refunds, chargebacks, subscription terms, or reimbursement workflows. That makes post-authentication governance the hard part: the abuse happens inside an already trusted relationship, so risk teams must judge behaviour, context, and claim consistency rather than relying on identity proof alone.

Practical implication: move fraud controls downstream into dispute intake, refund review, and reimbursement adjudication.

Behavioural signals as a fraud control layer

Behavioural signals help distinguish normal customer friction from deliberate abuse. In this context, teams look for patterns such as repeated claims, inconsistent narratives, device or session anomalies, and escalation behaviour that does not match genuine victim journeys. Machine learning can surface patterns at scale, but investigator expertise is still needed to avoid overblocking legitimate claims and to understand new abuse tactics as they emerge.

Practical implication: combine automated scoring with investigator review for high-impact refund and dispute decisions.

Why the term “friendly fraud” weakens governance

The phrase “friendly fraud” softens a real governance issue by implying accidental behaviour or minor misuse. The article’s framing is more accurate: this is identity-backed abuse of payment and reimbursement systems, sometimes opportunistic and sometimes organised. Calling it by its proper name matters because it changes how teams allocate controls, classify loss, and coordinate with peers across sectors.

Practical implication: reclassify the risk as intentional claimant abuse in policy, metrics, and fraud typologies.


Threat narrative

Attacker objective: The objective is to obtain refunds, reimbursements, credits, or chargeback wins without a genuine loss or entitlement.

  1. Entry occurs through a legitimate customer relationship, where the individual already has a verified account and access to payment or reimbursement channels.
  2. Abuse begins when that customer submits false scam claims, refund requests, chargeback disputes, or subscription complaints to trigger payouts or credits.
  3. Escalation happens when repeated claims, social media playbooks, or organised groups industrialise the behaviour into a repeatable fraud model.
  4. Impact is financial loss, inflated dispute handling costs, and weaker trust in legitimate customer claims.
  • Coupang Signing Key Breach: Unrevoked signing key credentials expose 33.7 million records after employee offboarding failure at Coupang.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

First party fraud is an identity governance problem disguised as a payments problem. The customer is authenticated, onboarded, and often low-friction by design, which means the control failure appears later in the lifecycle when intent must be evaluated. That shifts the real governance burden from proving identity to proving claim legitimacy. Practitioners should treat dispute handling as a governed identity decision point, not just an operational workflow.

“Friendly fraud” is too soft a label for a repeatable abuse pattern. When legitimate account holders deliberately exploit refund or reimbursement schemes, the issue is not friendliness, it is claimant fraud with measurable loss characteristics. Clear typology matters because it changes how teams segment cases, train investigators, and align fraud, payments, and customer operations. Practitioners should standardise language before they standardise detection.

Behavioural signals are now part of the trust boundary. The article makes clear that identity verification alone is insufficient once abuse happens after onboarding. That means velocity, sequence, narrative consistency, and channel behaviour become governance inputs, not just detection features. Practitioners should design dispute controls to read behaviour over time, not just static account attributes.

Cross-industry collaboration is no longer optional in claimant abuse. The same patterns move across merchants, banks, fintechs, and subscription businesses, which makes isolated internal data incomplete. Shared typologies, investigator experience, and peer signal exchange are what turn isolated casework into durable governance. Practitioners should assume first party fraud is a networked problem, not a single-organisation anomaly.

Named concept: dispute intent governance. The article points to the need to govern what a claimant intends, not only who the claimant is. That concept sits between fraud operations and identity governance and is likely to become a more important control layer as payment ecosystems automate more decisions. Practitioners should treat intent review as a formal control domain.

From our research library:

What this signals

Dispute intent governance: The next maturity step is to govern the intent behind a claim, not only the identity that submitted it. That means refund, chargeback, and reimbursement workflows need behavioural context before they become payout decisions.

For identity and fraud teams, the signal is clear: customer trust must be continuously evaluated after onboarding, because the same verified account can become the channel for abuse. The practical boundary is no longer login, it is claim credibility.

Behavioural scoring, investigator judgement, and cross-industry intelligence are becoming the control set that separates genuine loss from organised claimant abuse. Organisations that still treat these cases as isolated operations issues will undercount risk and overpay for it.


For practitioners

  • Tighten dispute intake controls Require stronger evidence, structured reason codes, and claim-history checks before refund or chargeback escalation. The goal is to separate genuine customer harm from repeat claimant abuse at the first decision point.
  • Use behavioural scoring in claim review Combine device signals, velocity, narrative consistency, and prior dispute patterns to score claims before payout or reversal. Behaviour should influence review depth even when the account identity is verified.
  • Train investigators on abuse typologies Give fraud and disputes teams shared playbooks for false scam claims, refund abuse, subscription traps, and reimbursement exploitation. Consistent typologies reduce case drift and improve escalation decisions.
  • Align fraud and customer operations metrics Track approved claims, false positives, repeat claim rates, and operational loss separately so the organisation can see whether controls are stopping abuse or merely shifting it elsewhere.

Key takeaways

  • First party fraud turns verified customer relationships into a fraud surface when refund and dispute processes trust intent too easily.
  • The article highlights abuse across refunds, disputes, chargebacks, subscriptions, and reimbursement systems, which means the risk is broader than transaction reversal alone.
  • Practitioners need behavioural review, investigator expertise, and shared typologies to distinguish genuine claims from identity-backed abuse.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, while GDPR defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsClaim review depends on governed trust decisions after identity is established.
Recommendation — Apply PR.AA-05 to control who can approve refunds, reversals, and dispute outcomes.
CIS Controls v8CIS-5 — Account ManagementCustomer account lifecycle and repeat-claim handling affect fraud governance.
Recommendation — Use CIS-5 to review account activity and flag repeated abuse patterns across customer records.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeDispute approval paths should limit who can authorise high-risk reversals.
Recommendation — Apply AC-6 to restrict refund and chargeback approval authority to the minimum required roles.
GDPRArt.32 — Security of processingFraud decisioning often processes personal data and behavioural evidence.
Recommendation — Apply Art.32 to protect claimant data used in fraud and disputes decisioning.

Key terms

  • First Party Fraud: Fraud committed by a real, verified customer who abuses legitimate access to obtain refunds, disputes, chargebacks, or reimbursements. The identity is authentic, but the behaviour is deceptive. In practice, the control problem shifts from proving who the user is to proving whether the claim is consistent, credible, and repeatable.
  • Claimant Abuse: Claimant abuse is the misuse of refund, dispute, or reimbursement processes by a person who is technically authorised to use them. It differs from external fraud because the abuse is carried out through normal customer channels, which makes behavioural review and investigation quality essential controls.
  • Behavioural Signal: A pattern in how a user acts over time that can help distinguish normal activity from abuse. In fraud operations, behavioural signals include timing, repetition, device consistency, channel switching, and claim history. They are most useful when combined with human review and case context.
  • Dispute Intent Governance: Dispute intent governance is the discipline of assessing whether a payment claim, refund request, or reimbursement is made in good faith. It extends identity governance into post-onboarding decisioning, where intent, evidence, and repeat behaviour matter more than the fact that the customer is authenticated.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org