Knowledge Base
How to Review Fraud Activity in Fraud Signal™
Learn how to review fraud reports, transaction patterns, unauthorized claims, TC40 activity, merchant trends, and available payment context.
- Product area
- Fraud Signal™
- Support category
- Fraud and VAMP
- Article type
- Reference
Fraud activity is one of the least visible parts of a merchant's payment operation — and one of the most consequential, because reported fraud counts into card-network monitoring whether or not a chargeback ever follows. Fraud Signal™ helps merchants review fraud reports alongside the transaction and merchant context needed to understand them. This reference explains what to review, how the records relate, and what the data does and does not prove.
What Fraud Signal™ Helps Merchants Review
Fraud Signal™ brings fraud-report activity together with available payment context: the transaction amount and time, card-not-present or card-present context, the merchant ID and processor involved, the payment channel, and related order, customer, and refund history. Fraud Signal™ does not independently determine whether a transaction was fraudulent — it organizes the reported activity and the surrounding records so the merchant can investigate with context.
Fraud Reports vs Chargebacks
A fraud report and a chargeback are different records. A fraud report is the issuer's record that a cardholder claimed fraud on a transaction; a chargeback is a financial dispute that moves money. A transaction may have fraud-report activity without a visible chargeback, and a chargeback may arrive without a fraud report the merchant can see. The difference between TC40 fraud reports and TC15 disputes guide explains how the two record types travel on separate tracks.
Start With the Transaction Context
A fraud report becomes useful once it is matched to its transaction. Review the available context for each reported transaction:
- Transaction amount and transaction time
- Card-not-present or card-present context
- Merchant ID, processor, and payment channel
- Customer account and order history
- Refund history on the same transaction
- Authentication data and device context where available
Context is what separates likely stolen-card activity from a claim on an otherwise normal-looking order. Patterns should be investigated with transaction and customer context, not assumed from the report alone.
Review Fraud Activity Over Time
Individual reports matter less than the trend. Review fraud-report volume across recent weeks and months for each merchant account, and compare the fraud-report date against the transaction date to understand how quickly claims follow orders. Reported fraud accumulates into the measurements card networks use for merchant monitoring, so the monthly trajectory matters more than any single report.
Compare Fraud Reports With Dispute Activity
Compare fraud-report activity with dispute activity on the same accounts. A processor's standard chargeback report may not include every fraud signal, which is how a merchant can look healthy on chargebacks while reported fraud climbs. Where a report and a dispute reference the same transaction, review the reason code and dispute date together with the fraud-report date to understand the sequence.
Review Activity by Merchant Account and Payment Channel
Fraud rarely distributes evenly. Break the reported activity down by merchant ID, processor, payment channel, product, and traffic source. Concentration is a finding: activity clustered on one MID, one product, or one acquisition channel points at a specific fixable cause rather than a general fraud problem.
| Signal | What It May Show | What to Review Next |
|---|---|---|
| New fraud report | A cardholder claimed fraud on a transaction | The matched transaction, order, customer, and refund context |
| Increase in fraud-report volume | A growing pattern rather than isolated claims | The time period, products, and channels driving the increase |
| Repeated unauthorized claims | Possible stolen-card activity — or recurring customer confusion | Authentication data, device context, and customer order history |
| Activity concentrated on one MID | An account-specific exposure | That account's channels, products, and processor reporting |
| Activity concentrated on one product or channel | A specific offer or traffic source attracting fraud | The source's traffic quality and the checkout controls in front of it |
| Fraud reports without matching chargebacks | Reported fraud that standard chargeback reports will not show | Whether the pattern is growing and which transactions it touches |
| Chargebacks without visible fraud reports | Disputes arriving through other conditions or gaps in visibility | The reason codes involved and the connected reporting sources |
Investigate Sudden Changes
A sudden change in fraud-report activity deserves investigation before interpretation. Check whether volume, traffic sources, or product mix changed at the same time; whether a card-testing burst shows up in authorization activity; and whether a single event — a campaign launch, a new channel, a checkout change — lines up with the shift in reports.
What a TC40 Fraud Report Means
On the Visa network, the fraud report is the TC40 fraud report: the issuer's record that a cardholder reported a transaction as fraud. A TC40 record is a fraud report and not itself a chargeback — it does not move money, and merchants generally do not respond to it directly. Its weight is cumulative, because reported fraud counts into network monitoring measurement even when no dispute follows.
What Fraud Data Does Not Prove
A fraud report reflects an unauthorized transaction claim — it does not prove the transaction was actually fraudulent, and it does not identify who made the purchase. Some reported transactions involve genuine third-party fraud; others involve customer confusion or friendly fraud. Not every disputed legitimate transaction is friendly fraud, and the friendly fraud and first-party misuse guide covers how to tell the patterns apart. Treat classification as a working hypothesis to investigate, not a label the data assigns.
When to Escalate a Fraud Trend
Escalate when fraud-report volume rises sharply, when activity concentrates on one product or channel and internal changes have not slowed it, when card-testing behavior persists after blocking, or when a meaningful share of reports cannot be matched to transactions. Contact Payment Defender Support with the merchant account, the time period, and the pattern you are seeing.
Related Payment Defender Resources
The related guides below continue the workflow where fraud review connects to monitoring and dispute response.
Was This Guide Helpful?
