Sardine named a Leader in The Forrester Wave™: Financial Crime Management Solutions, Q3 2026

Learn More
The Saturday Fraud Strategist

それは本人による不正ですか、それとも第三者による不正ですか?

6 min

不正攻撃を受けたとき、次に問うべきなのは、実際にどのような種類の不正に直面しているのかということです。ファーストパーティー不正とサードパーティー不正の違いは、単なる技術的な区別ではありません。その違いによって、対応方法や導入すべきツールが根本的に変わります。両者の違いを見分けられない、あるいはその違いを重要だと考えていないチームがあまりにも多いことに、私はいつも驚かされます。

今回のエピソードでは、その問題を解決する方法を取り上げます。

このエピソードでお届けする内容:

  • ファーストパーティ詐欺とサードパーティ詐欺の基本的な定義
  • 実務上、この2つを区別する具体的な兆候
  • チームが誤ったツールを導入し、高い代償を払った2つの実例
  • 第三者による不正は一般に考えられているよりも検知しやすく、本人による不正は検知が難しい可能性がある理由
  • 不正の種類ごとに必要となる具体的なツール構成
  • 不正防止ツールの多くが、デフォルトで第三者による不正を想定して構築されている理由

次のような方は、ぜひこのエピソードをお聴きください:

  • 不正率が上昇している原因を突き止めようとしているものの、ファーストパーティー不正とサードパーティー不正のどちらに直面しているのか判断できずにいる方
  • KYCによる本人確認やデバイスフィンガープリンティングを用いた不正対策ツールを導入したものの、期待した成果が得られていない
  • アカウント乗っ取りの検知を担当しており、実際に重要なシグナルをより明確に把握したい
  • 適切な不正の種類に適切なツールを組み合わせることで、不正防止の投資対効果を社内に示す必要がある
  • マネーミュールの検知や、どちらのカテゴリーにも明確に当てはまらない共謀型不正の事例に対応している
エピソードノートと重要なポイント

ファーストパーティ詐欺とサードパーティ詐欺の根本的な違い

第三者による不正とは、何者かが決済手段や他人の身元情報を盗んだり、架空の身元情報を一から作り上げたりして、別人になりすますことを指します。一方、本人による不正とは、実在する顧客が自分自身の身元情報を使いながら、合意した内容を守る意思がまったくないことを指します。その手口は、チャージバック詐欺、返品詐欺、プロモーションの不正利用など、さまざまな形で現れます。理屈の上では単純に聞こえますが、実際には両者の境界はすぐに曖昧になります。この区別を誤ることは、不正対策チームが犯し得る最も損失の大きいミスの一つです。

確認すべきポイント

ファーストパーティ詐欺は、デバイス間やIPネットワーク間に関連性が見られないケースとして現れる傾向があります。取引後1週間以内に早期のチャージバックが発生する一方、地域情報の不一致といった典型的な不正の兆候がなく、十分な利用履歴があるアカウントにもかかわらず、アカウント乗っ取りを示す検知フラグがまったくありません。サードパーティ詐欺は、ほぼ正反対の特徴を示します。デバイス間やIPネットワーク間に強い共通の関連性があり、不自然なほど問題がないものの新規に作成されたばかりの本人確認情報、別人とされる複数の人物がほぼ同じ形式のメールアドレスを使用しているといった異常なパターン、さらに地域情報の不一致と異常に高いカード発行会社の承認拒否率が同時に見られます。

コストの高い2つの事例

あるフィンテック企業では、明らかなファーストパーティ詐欺が発生していました。そこで、より厳格なKYC本人確認、多要素認証、デバイスフィンガープリンティングに多額の投資を行いましたが、詐欺率は上昇し続けました。これらのツールは本人確認を行うものですが、ファーストパーティ詐欺の実行者はすでに正当な本人情報を持っています。一方、あるSaaSプラットフォームでは、典型的なサードパーティ詐欺に直面していました。同社は取引履歴の分析、信用リスクのスコアリング、アカウント利用期間に基づくルールに注力しました。しかし実際には、詐欺の80%がわずか3つのIPネットワークから発生していたことを、ずっと見落としていたのです。

見破りやすいのはどちらか

盗用された、または合成された身元情報を利用した不正行為は、実際の口座名義人の行動とは明らかに異なるため、高い精度で検知可能なパターンが生じます。一方、ファーストパーティ不正は、本人が支払いをしないと決める直前まで行動がまったく正常に見えるため、検知がより困難です。場合によっては、決済が完了した後に初めて支払わないと決めることもあります。そのため、取引時点での検知はほぼ不可能です。すべての事例が明確に一つのカテゴリーに分類できるわけではありません。マネーミュールの検知や共謀による不正は、ファーストパーティ不正とサードパーティ不正が重なり合い、実際に切り分けることが難しい最も典型的な例です。

適切なツールキット

不正防止業界は、主に第三者による不正の検知を中心に発展してきました。多くのチームが初めて深刻な当事者による不正に直面した際に苦戦する大きな理由も、そこにあります。まったく別の問題を解決するために作られたツールを使おうとしている可能性があるのです。ほとんどの企業は、この2種類の不正に同時に対処しています。成果を上げているチームは、1つのツール群ですべてをカバーしようとするのではなく、それぞれに特化した対策を構築しています。

最後に押さえておきたいポイント

不正対策チームが犯す最も高くつく過ちは、質の悪いツールを選ぶことではありません。間違った問題に対して、適切なツールを選んでしまうことです。ファーストパーティ不正とサードパーティ不正の違いは、単なる学術的な区別ではありません。どのシグナルに注目し、どのツールを導入し、最終的に不正対策への投資が本当に成果を上げるかなど、その後のすべてを左右する最初の診断項目です。ほとんどの企業は両方の不正に同時に直面しています。つまり、本当に重要なのは、どちらか一方のアプローチを選ぶことではなく、どちらをいつ適用すべきかを見極めることです。

リソースとリンク

私の、そして願わくばあなたにとってもお気に入りのテーマについて、まだ話し足りませんか?ぜひ「The Saturday Fraud Strategist」ニュースレターをご購読ください。

つながる:Chen Zamir | LinkedIn
「The Saturday Fraud Strategist」主宰
フィンテック企業のよりスマートな不正対策構築を支援
『The Fraud Fighter’s AI Playbook』共著者

Episode transcript
Chen Zamir
Chen Zamir
00:06
When you get hit by a fraud attack, your first question should be, how bad is it? But the second question should be, what kind of fraud am I dealing with? The difference between first party fraud and third party fraud isn't just technical. It fundamentally changes how you respond, what tools you deploy, and ultimately how successful you'll be at stopping it. Yet, I'm constantly amazed by how many teams can't tell the difference or worse, don't think it matters. So, today I'm going to break down how to identify which type of fraud you're facing and why getting it right is so critical to your business.
Chen Zamir
Chen Zamir
00:44
Let's start with the basics. Third party fraud happens when someone steals payment methods or identities or creates completely new but fake synthetic identities with the intention to defraud your business. The fraudster pretends to be someone else entirely. First party fraud happens when real customers use their real identities but have no intention of honoring their commitments. They are who they say they are but their intentions are fraudulent. Whether they commit chargeback fraud, returns fraud, promo abuse, or any other form of policy abuse. Sounds simple on paper, right? The problem is that in the real world, the lines get blurry fast.
Chen Zamir
Chen Zamir
01:26
After years of working with fraud teams across dozens of fintechs, I've noticed distinct patterns that separate these fraud types. So, let's talk about what you should be looking for. Starting with firstparty fraud, fraud cases that are notably not connected by online assets, device IDs or IP networks. Early chargeback maturation, especially in the first week after transactions. Absence of traditional fraud signals like geo mismatches or bad links. Higher transaction velocity is also often the only suspicious signal and established account history with no ATO indicators. Now, to be clear, I don't mean that you need to see all of these signals in the same account to say it's first party fraud. These are just examples for what to look for when tagging the loss events. Now, let's compare it to third party fraud. Here, you want to look for strong connections between fraud cases like shared devices or IP networks, abnormal shared behavioral patterns, for example, identical email conventions across supposedly different people. So John Smith777@gmail.com, jane smith777@gmail.com and so on. Suspiciously new yet clean identity assets like emails and phone numbers. Geographic mismatches like a new foreign country IP addressing your US service and unusually high issuer decline rates. So it's pretty clear that the difference is stark once you know what to look for. Yet, I regularly encounter teams using the wrong detection methods for the fraud type they're actually facing. And by the way, just to get it out of the way, and as I mentioned a minute ago, in some fraud technologies, the lines get blurry. This is often the case with money mules, money laundering, and collusion fraud. So, unfortunately, it's not so easy sometimes to tell the difference.
Chen Zamir
Chen Zamir
03:20
Here's what I keep seeing in the industry. Companies implementing the wrong solutions because they haven't properly identified what they're up against. And it happens so frequently that I'm starting to think it's the rule, not the exception. And it cost these companies millions. Why? Because fraud tools, like all tools, are built to solve specific problems. Use them on the wrong problem and you're essentially throwing money away. Let me give you some real examples I've encountered. A fintech dealing with obvious first party fraud, early chargebacks in established accounts decided to invest heavily in advanced KYC verification, multifactor authentication, and device fingerprinting upgrades. Unsurprisingly, their fraud rates kept climbing because these tools verify identity, something first party fraudsters already have legitimately. Then there's the opposite scenario, a SAS platform hit by classic third party fraud. Connected devices, new email accounts focused on transaction history analysis, credit risk scoring, and account tenure rules. Meanwhile, they completely missed that 80% of their fraud was coming from the same three IP networks. There's also a critical insight here that is worth highlighting. Third party fraud is actually easier to fight effectively. Why? Because fraudulent behavior patterns are distinctly different from legitimate user behavior. When someone is using a stolen identity, they behave differently than the real account owner would. These differences create detectable patterns that separate good users from fraudsters with high accuracy. First party fraud, however, is trickier because the user's behavior often appears perfectly normal until the moment they decide not to pay. And sometimes that decision is made after the payment was made, which makes it nearly impossible to detect at the time of payment. So, what do you do?
Chen Zamir
Chen Zamir
05:18
As you can learn from the examples I just shared, how you prepare and react to these two different threats is unsurprisingly different as well. Here are the hallmarks of good fraud prevention for each fraud type. And you want to make sure that you can tick most boxes. Let's start with uh third party fraud. You want to look at KYC, identity and document verification, device fingerprinting and IP intelligence, velocity counters and network analysis, behavioral biometrics, identity intelligence like email, phone, etc. Two factor authentication or multifactor authentication. For firstparty fraud, you want to look at consortium data, dynamic returns and refunds policy, chargeback dispute management, and device fingerprinting, which is mainly relevant for account sharing and promo use. See, what works for one fraud type likely won't work for the other. And that's why it's so critical to know what you're actually facing.
Chen Zamir
Chen Zamir
06:21
When you look at its roots, you realize that the fraud prevention industry was built primarily around third-party fraud detection. That's why so many teams struggle when facing first party fraud. They're using tools designed for a completely different problem. So before investing in another solution, make sure you've correctly identified what you're up against. And the telltale signs are there if you know what to look for. But here's the thing, most businesses face both types simultaneously. And the most successful fraud teams deploy targeted approaches for each rather than trying to find a one-size fits-all solution because it's simply doesn't work. Anyway, that's all for today and I'll see you next Saturday.