SardineCon SF/2026

Learn More
Fraud types4 min de lectura

¿Qué es Third-party fraud?

SUBSCRIBE

Third-party fraud is fraud committed with a real victim's stolen identity, credentials, or account, without their knowledge or consent. It is the classic outside-attacker model, and it is the type most people picture when they say the word fraud.

What is third-party fraud, in plain English?

Third-party fraud is an outside attacker using a real person's identity or account against them. The victim is genuine and uninvolved; their stolen details, credentials, or account are used to open credit, take over an account, or make payments they never authorized. This is the traditional fraud model, one clear victim, one clear fraudster, and no ambiguity about who was wronged.

It spans a wide range of attacks: account takeover, where a fraudster hijacks an existing account; application fraud, where they open new accounts in the victim's name; and card fraud, where stolen card details fund purchases. What unites them is that the real person did not know and did not consent.

Because a genuine victim exists, third-party fraud usually gets reported and disputed, which is both its defining feature and its biggest detection advantage. The victim raising the alarm is a signal you simply do not get in first-party fraud, where the account holder is the fraudster, or synthetic fraud, where no real victim exists at all.

First, second, and third-party fraud

The three-party framing turns on who the account holder is and what they knew:

What changes

Third-party fraud

First / second-party fraud

Who is the fraudster

An outside attacker

First: the account holder. Second: a party the holder invited

Victim's involvement

Unaware, no consent

First: none, they are the fraudster. Second: knowingly complicit

Is there a real victim?

Yes, a clear one

First: no. Second: blurred

Detection lever

Victim disputes and reports

Behavioral and intent signals, no victim report

Typical attacks

ATO, application fraud, card fraud

First: bust-out. Second: mule activity

Who is involved?

Who

Their role

The fraudster

An outside attacker who steals and uses the victim's identity, credentials, or account.

The victim

A real person, unaware their details are being used, who bears the initial impact and disputes it.

The institution

The bank or provider whose accounts and products are attacked and who often bears the loss.

Detection systems

Victim signals, device and behavioral anomaly detection, and PII-exposure data that flag the misuse.

What it looks like in practice

In practice

A customer's login credentials, exposed in a data breach, are used by an attacker to sign in from an unfamiliar device and location. The attacker changes the contact details, adds a new payee, and pushes a payment out of the account, all in a single session that looks nothing like the customer's usual behavior.

The device is new, the location is wrong, and the speed of the changes does not match a real user settling in. The next morning the genuine customer sees the payment, does not recognize it, and disputes it. That dispute confirms what the behavioral anomalies already suggested: an outside party took over a real person's account.

Why it matters to operators

Third-party fraud is the baseline every fraud program is built to stop, and it comes with a real advantage: the victim helps you. Disputes, reports, and complaints give you ground truth about what was fraud, which you can feed back into models and rules. Device and behavioral anomalies, plus data on which identities have been exposed in breaches, add strong detection signals on top.

The reason precise classification matters is loss and liability. Third-party fraud usually means the victim is entitled to be made whole, so getting it right is a customer and regulatory obligation. Confusing it with first-party fraud, where the real person is the fraudster, or second-party fraud, where the account holder is complicit, leads to the wrong reimbursement, the wrong liability, and mis-tuned models.

What to watch in the data

  • Device and location anomalies. Access from unfamiliar devices, geographies, or networks that do not match the real user.
  • Behavioral breaks. Sudden contact-detail changes, new payees, and out-of-pattern activity in a single session.
  • PII exposure links. Accounts tied to identities known to be compromised in breaches or on fraud markets.
  • Victim disputes. Chargebacks and reports of unauthorized activity, the ground-truth signal unique to third-party fraud.
  • Credential-stuffing signs. Bursts of login attempts and takeovers consistent with reused, leaked credentials.

Quick questions

How is third-party fraud different from first-party fraud?

In third-party fraud, an outside attacker uses a real victim's identity or account without consent. In first-party fraud, the real account holder is the fraudster, acting for their own gain. The presence of an innocent victim is the key difference.

Where does second-party fraud fit?

Second-party fraud is the middle case: the real account holder knowingly lets someone else use their account, such as acting as a money mule. Third-party fraud has an unaware victim; second-party has a complicit one.

Why is the victim signal so valuable?

Because a real victim reports and disputes the fraud, you get reliable confirmation of what actually happened. That ground truth is missing in first-party and synthetic fraud, making third-party fraud comparatively easier to detect and label.

What attacks count as third-party fraud?

Account takeover, application fraud using stolen identities, and card fraud with stolen card details are the classics. Any scheme where an outside attacker misuses a real person's identity or account without consent qualifies.

Why does correct classification matter so much?

It drives reimbursement and liability. Third-party victims are usually entitled to be made whole, so misclassifying the case as first- or second-party leads to wrong outcomes for customers, wrong liability decisions, and poorly tuned models.

How is it detected beyond victim reports?

Through device and behavioral anomaly detection that flags out-of-pattern access and actions, and through PII-exposure data that links accounts to identities known to be compromised. These catch the fraud before the victim even notices.

Go deeper

  • FTC Consumer Advice: Scams ↗ — US consumer guidance on current scams and fraud, and how to report them.
  • FBI IC3 ↗ — The FBI Internet Crime Complaint Center. Fraud reporting and annual trend reports.

Qué saber junto con Third-party fraud