SardineCon SF/2026

Learn More
Fraudology

Mastercard Scam Merchant Monitoring and the AI Hallucination Problem

Graphic for "Fraud/ol/ogy" podcast episode #405, featuring guest Dr. Nicola Harding and Karisse Hendrick, shown in two headshots.

Welcome back to Fraudology.

I’m coming to you from a beachside work-cation in Florida for this one, right after the Accertify Global Customer Summit. And yes, the setting was beautiful.

In this episode, I’m joined by Dr. Nicola Harding to talk through two things that may seem separate at first: AI hallucinations in fraud and Mastercard’s new scam merchant monitoring program.

When you look closer, they are connected by the same bigger issue.

Fraud teams are being asked to make faster, more complex decisions in environments where the signals are moving earlier, the liability is shifting, and the tools we use to interpret risk are not always as reliable as they sound.

That matters.

On one side, we have LLMs being used in risk management, fraud research, and operational decision-making. And as we discuss in this episode, that gets risky fast when AI starts producing confident answers from incomplete or open-source information. Especially in fraud, where the most useful knowledge is often proprietary for a reason.

On the other side, Mastercard’s scam merchant monitoring program creates a much more aggressive framework for identifying and investigating merchants that may be tied to scams. The new thresholds, refund and chargeback monitoring, and 72-hour merchant investigation window put real pressure on merchants, acquirers, and payment teams.

So this episode is really about accountability.

Who owns the decision?

Who validates the signal?

Who understands the context?

And what happens when either a model or a merchant program gets treated like it can operate without the right human expertise around it?

What you’ll hear in this episode:

  • What Mastercard’s scam merchant monitoring program means for merchants and acquirers
  • Why the Mastercard scam merchant dashboard matters for e-commerce fraud teams
  • How refund and chargeback monitoring may affect new merchant risk reviews
  • Why the 72-hour merchant investigation window creates operational urgency
  • How AI hallucinations in fraud can distort risk analysis and decision-making
  • Why LLM hallucinations are especially risky when fraud knowledge is proprietary
  • Why fraud and cybersecurity teams need to break down silos as signals move earlier in the attack path

You should listen to this episode if you:

  • Work in fraud operations, merchant risk, payments, or e-commerce fraud
  • Are responsible for Mastercard chargeback thresholds or scam merchant investigation workflows
  • Need to understand how the Mastercard scam merchant monitoring program may affect your team
  • Are evaluating LLMs in fraud risk management or AI-generated fraud research
  • Care about domain expertise, fraud and cybersecurity alignment, and operational readiness

If you liked this episode, be sure to subscribe and review the podcast on iTunes, Spotify, YouTube, or wherever you listen to podcasts. It really helps with getting the word out.

Episode notes & key takeaways

This episode sits at the intersection of two very different but very important fraud problems.

The first is AI hallucination risk. Not the funny kind where a chatbot makes up something harmless and everyone moves on. I mean the kind where an AI tool produces a confident fraud analysis, citation, recommendation, or risk interpretation that is not actually grounded in reality.

That is a problem.

Fraud teams do not operate in a world where all the useful information is public. A lot of the best fraud intelligence lives inside internal systems, proprietary rules, investigations, chargeback patterns, merchant histories, cybersecurity data, and operational experience. So when an LLM tries to reason from open-source data alone, it can miss the exact context that matters most.

The second issue is Mastercard’s scam merchant monitoring program, which puts more pressure on merchants and acquirers to identify, investigate, and act on scam-related merchant activity quickly. This is not just a policy update. It is an operational readiness issue.

And that is where the two themes connect.

Fraud teams are being asked to move faster while the risk signals get more complex. That means the companies that do well here will not be the ones that blindly trust every dashboard, every model output, or every surface-level metric.

They will be the ones that understand the signals, validate the data, and bring the right domain expertise into the decision.

Why Mastercard scam merchant monitoring changes the pressure on acquirers

Mastercard’s scam merchant monitoring program is designed to identify merchants that may be connected to scams, deceptive activity, or harmful selling practices. That means the focus is not just traditional card-not-present fraud. It is merchant behavior, refund patterns, chargebacks, issuer complaints, authorization performance, and whether a merchant looks like it may be creating risk for the network.

For acquirers, that changes the posture.

It is not enough to wait until the damage is obvious. Acquirers need to be able to investigate quickly, understand merchant risk signals, and make a call on whether a merchant is legitimate or needs to be terminated.

That is a very different kind of pressure.

  • Mastercard scam merchant monitoring increases the need for faster merchant risk review
  • Acquirers may need stronger workflows for scam merchant investigation
  • Merchant risk teams should watch refund, chargeback, and authorization patterns together
  • The 72-hour merchant investigation window makes operational readiness critical

Why refund and chargeback monitoring matters for new merchants

One of the most important pieces of this program is the way it looks at refunds and chargebacks together for newer merchant accounts.

Scam merchants do not always show up through one clean signal. Sometimes the pattern is a mix of complaints, refunds, chargebacks, low authorization performance, and behavior that looks just legitimate enough to keep operating.

At first glance, a refund might look like customer service.

But when you dig in, refunds can also be a signal that something else is happening. Especially when they are paired with complaints, chargeback activity, or sudden approval rate changes.

For fraud teams, the takeaway is simple: do not look at these signals in isolation.

  • Refund and chargeback monitoring can reveal scam patterns earlier
  • New merchant accounts may need closer review during the first six months
  • Mastercard scam thresholds create a stronger incentive to monitor risk continuously
  • E-commerce fraud teams should connect merchant behavior to customer complaint signals

Why AI hallucinations are dangerous in fraud risk management

AI hallucinations in fraud are risky because they can create confidence where there should be caution.

A model can summarize. It can draft. It can organize information. It can even help teams move faster.

But if the source data is incomplete, wrong, or missing the proprietary context that fraud teams rely on, the output can fall apart very quickly.

This is where domain expertise matters. A fraud professional can look at a polished AI-generated statement and ask, “Wait, does that actually make sense?” A model does not always know when it is outside its lane.

And in fraud risk management, that distinction matters.

  • LLM hallucinations can distort fraud analysis and operational recommendations
  • Open-source AI tools may miss proprietary fraud patterns
  • Domain expertise helps teams validate whether an AI output is usable
  • AI should support fraud operations, not replace human judgment

Why fraud and cybersecurity silos are becoming a bigger liability

One of the bigger themes coming out of the Accertify Global Customer Summit was that fraud signals are moving up-funnel.

That means the first signs of risk may not show up at the transaction anymore. They may show up earlier through account activity, device behavior, phishing, malware, credential abuse, or other cybersecurity signals.

So if fraud and cybersecurity teams are still operating in separate lanes, that creates a gap.

And criminals tend to like gaps.

Fraud teams need visibility into the signals that happen before payment. Cybersecurity teams need to understand how those signals eventually turn into e-commerce fraud, payment fraud, merchant risk, or chargebacks.

The more connected those teams are, the earlier they can see the pattern.

  • Fraud and cybersecurity silos make it harder to detect risk early
  • Up-funnel signals can help teams understand fraud before the transaction
  • Payment fraud prevention works better when teams share context
  • Cross-functional visibility helps reduce blind spots in fraud operations

Why domain expertise still has to anchor the decision

This episode keeps coming back to one point: tools are useful, but expertise is still what turns information into judgment.

That applies to AI hallucinations. It applies to Mastercard scam merchant monitoring. It applies to merchant risk. It applies to fraud and cybersecurity alignment.

A dashboard can flag a threshold.

A model can summarize a pattern.

A report can identify a risk.

But someone still has to understand what it means.

That is where experienced fraud professionals matter most. They know when a merchant pattern looks wrong. They know when a policy threshold needs operational support. They know when an AI answer sounds too clean. They know when different signals are pointing to the same underlying problem.

The cost of getting this wrong is not just a bad report or a messy workflow. It can be losses, liability, terminated merchants, missed scam networks, or decisions made from information that was never properly validated.

Final takeaway

The Mastercard scam merchant monitoring program is another reminder that fraud prevention is becoming more connected, more time-sensitive, and more operationally demanding.

At the same time, AI hallucinations are a reminder that faster information is not always better information.

So the real takeaway is not just “watch the thresholds” or “be careful with AI.”

It is this: fraud teams need stronger context.

Context across merchant risk.

Context across fraud and cybersecurity.

Context across refunds, chargebacks, complaints, and authorization behavior.

Context across AI outputs and the proprietary knowledge that models do not automatically have.

Because in fraud, the tools can help you see more.

Connect with Karisse Hendrick | LinkedIn

  • Host of the Fraudology Podcast
  • Award-Winning Cyberfraud Expert
  • Ecommerce Fraud Prevention Consultant
  • Startup Advisor, Keynote Speaker, and
  • Consultant to Fortune 500 merchants

Guests

Dr. Nicola Harding
Episode transcript
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
00:02
Welcome to Fraudology Podcast, where we dive into the science and study of online fraud from the perspective of an ecommerce fraud fighter. I'm Karisse Hendrick. Welcome to this week's episode of the Fraudology Podcast. Well, if my background or microphone sound even just a little bit different, that's because I am not in my home office this week. When I ran into a merchant at a recent event I was at, which I will talk about in a minute, she joked with me that she never knows where in the world I am because either on the podcast or she's part of one of my biweekly merchant groups, often I have new backgrounds. I've been traveling a lot this year since February.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
00:45
I spent two weeks in Maui with my husband, which was just absolutely magical, and then I went to the MAG Conference in San Diego. A few weeks later, I went to MRC in Vegas. A few weeks after that, I went to Fraud Fight Club in North Carolina. And then after North Carolina, I went straight to San Francisco to see family friends and spend some time with them, and then back home. And then a few weeks after that, I flew into Tampa, but stayed in Saint Petersburg for the Accertify Customer Summit. So that's where I've been this week. I decided to make it a work vacation and, you know, was at the conference for three days, and then myself and a very good fraud friend who was also at the conference, we decided to stay a few extra days, rented an Airbnb on the beach with a private pool. I really don't want to leave. And it's just, it's been perfect weather. I think that's pretty, you know, pretty common for Florida, but it's a long flight back to Washington State. So I didn't want to just come for three days and then go back.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
01:51
Plus, you know, if you can do it, it's fun. And, you know, she and I have traveled a fair amount together over the years, so we split the house well and just do our own thing sometimes and then hang out and talk fraud other times. I'm sure if anyone staying at the condos next to us, there's like a condo building on either side of this house, they're probably really sick of hearing us talking about fraud, but that's okay. Anyway, today I wanted to talk about a few things. So one was I was going to give a little bit of a recap from the Accertify Customer Summit. I was very grateful that they allowed me to come and asked me to come, especially because that is a rarity. Usually it's strictly for customers. So there's a few things that I got out of it that I wanted to share, and there were also a few things I got out of it that I can't share yet, but will once I'm told I can.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
02:45
I'm also going to share with you a LinkedIn post about fraud and ChatGPT that kind of proves the point that both Holly and I were making on our previous episode just about data sources and things like that, and AI hallucinations and all of that, that I think could be really helpful if you are being told that you have to use an LLM for part of your job. I know there's a couple companies, they've been told they must be using an LLM, you know, a ChatGPT, a Claude, that's whatever it is for 25% of their job by X date. You'll want to probably share this story with your bosses if that's the case. So I will share that. And then we'll talk. The main topic I wanted to talk about is Mastercard's new scam program. If you're on LinkedIn at all, and if you're on fraud LinkedIn at all, you've probably seen a couple of posts about it over the last few weeks. It's kind of Mastercard's version of VAMP. It's very different, but it has similar goals. So I'll go through that program, and it has some pretty significant repercussions if you are included in that and if your metric gets you above a threshold.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
03:56
So I think it's important to be aware of if you are an ecommerce merchant, and even if you aren't, I think it's good to be aware of what the card brands are doing and what they're requiring of ecommerce merchants. So this is today's agenda. Diving into the Accertify Global Customer Summit, it was a great opportunity to network with about 150 people that work for merchant companies, merchant fraud fighters. If you're not familiar with companies that work with Accertify, I don't know which ones are public and which ones aren't. So I'm not going to name any, but I'm going to say they are primarily the largest brands in retail, in travel, in airlines, in some restaurants, a lot of different areas. But I would say 80% of their clients are household names. And Accertify is probably the longest running fraud tool out there.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
04:52
I remember when their very first sales rep came and pitched it to me when I worked for a startup in Seattle in probably 2009, right around there in 2008, 2009, something like that. And at the time I was impressed that they were building something like that, but it was very similar to what I had built with our dev team at the time for what we needed for our business model. So we didn't go with it, but it was impressive and it has since grown immensely since then. I was curious to know what was new for Accertify and got to learn a lot about that, as well as got to network with existing fraud friends and met several new ones. And my hope is that a lot of them will join us at the Merchant Fraud Alliance in October. That would be a lot, a lot of fun. I hope every merchant joins us at the Merchant Fraud Alliance in October. But I specifically, you know, one of the reasons I went to this event was to get the word out a little bit more. So it was a great opportunity for that.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
05:54
They had a lot of networking opportunities, a lot of fun mixed in with sessions. And, you know, some on the big stage, some in breakouts, some were trainings, some were trainings on their new products, some were topics that people really care about in this industry and that, you know, they wanted to learn more about. Of course, AI was a topic of conversation. The theme of the event was how cybersecurity and fraud are better together, really talking about how fraud signals are moving up funnel. They're not just at point of checkout anymore. So there's a lot of fraud signals, especially for account protection, whether that's new account protection or account takeover protection, that type of thing, that live up funnel. And therefore, you need to make friends with your cybersecurity team. And they released a proprietary survey that they had commissioned that had a lot of really great benchmarking metrics that I've never seen published before, especially around cross-functional organizations working together. And they correlated that with their customers' fraud statistics. So like approval rate, chargeback rate, fraud rate, etcetera, to really demonstrate that there is, at least, a correlation, if not a causation, between cybersecurity and fraud working together and, you know, good outcomes in fraud metrics.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
07:22
So that's probably, I'm not saying anything specific, but that's probably all I can say for now. I did ask permission to share some of the statistics, and they said I absolutely can once the study is published, which will probably be in June. So you can look forward to that episode. I was really impressed with the questions they asked and the answers that came out of them. There's some good strategic direction, not only for this topic of fraud and cybersecurity working together, but for other things that we've all been asking for for a long time on the merchant side. So I think that will be something to look forward to. One of the breakout sessions that I attended was done by, you know, one of my favorite recent guests, Holly Sandberg. She did a terrific session on providing metrics with counterbalances to executives and senior leadership. She created a really great template for an executive scorecard and, you know, which metrics you should be measuring and then which metrics kind of counter those metrics and keep them honest.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
08:24
For instance, you can't just look at your fraud rate and say, woohoo, we're catching all the fraud without looking at your approval rate too. And you may be catching all the fraud, but your approval rate might be, you know, in the gutter and you're not approving enough orders. So you need to have both of those metrics to balance things out. That's just one example of the metrics that she shared. I thought it was a really good session and I asked her to please present it in a little bit of a different way with a different title and with a little different information, a few more specifics at MFA. So if you're looking for another reason to go to Merchant Fraud Alliance, that session is going to be fire. And I haven't told Holly this yet, but I want it on the big stage. I don't want it in one of the smaller breakout sessions because I think it's that good. And I think it's something that everybody needs to learn and wants to learn.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
09:17
I think communication with cross-functional teams as well as communicating with leadership are two things that we, on a whole, don't do well. And a lot of us recognize that and want to be informed by people who are doing it well. And Holly definitely is. So she'll be the perfect person to present on that. And if she wants a co-presenter, I will get her one, but she doesn't need one. Okay, well now I wanted to read this post from Nicola Harding. I found it really fascinating. It kind of made me laugh. It was the first thing I read one morning this week and I just, I kind of laughed to myself. And then my friend that was with me, I was like, what's so funny? And I read the post and, you know, as only fraud nerds would get it, she got it.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
10:06
So here's the post from Nicola and then I'll share some of my thoughts. EY. So like that EY, one of the top four biggest consultancies in the world, just published and then quietly pulled a 44-page cybersecurity report on fraud in loyalty schemes, all because it was riddled with AI hallucinations, fabricated citations and footnotes pointing to pages that don't exist, including a McKinsey report referred to throughout, a reference throughout that simply does not exist anywhere. So they were citing this McKinsey report of data, and that McKinsey report doesn't exist. This was not caught by EY's own review process, but by an external AI detection firm. As a criminologist, Nicola Harding, if you don't know her, has her doctorate. She's Dr. Nicola Harding and has her doctorate in criminology. I've gotten to see her speak in person and she is a wealth of knowledge on fraud.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
11:07
So as a criminologist who is an expert in this area, I can tell you that loyalty card fraud absolutely exists and it matters. The problem is that research like this doesn't just embarrass the firm that published it. It poisons the well. Hallucinated data gets picked up by other researchers, surfaces in AI search results, and corrupts the broader evidence base that practitioners, policymakers, and prosecutors rely on. That's not a minor quality control failure, it actually does serious harm to a field. AI is not the villain here. You wouldn't argue an accountant shouldn't use a calculator, but you would expect that accountant to be trained, accredited, and exercising professional judgment, not outsourcing the thinking to the tool and skipping the part where they check the workings.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
11:53
Research requires human judgment acquired through years of training, selecting appropriate methodology, reviewing the literature, understanding not just whether a source exists, but what the findings mean within the broader body of knowledge on a topic. That cannot be automated, and it shouldn't be. Research doesn't just need to be done, it needs to be presented within context by experts that understand the data in great detail and can defend the research and its implications. Fraud and financial crime prevention is an area where the stakes of getting it wrong are high. It is also increasingly an area where even the largest firms appear to believe they can blog expertise rather than invest in it. They cannot, and cases like this show exactly why.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
12:41
So there was an article, FT Times or yeah, the Financial Times that exposed this, but I really liked Dr. Nicola Harding's perspective on this and her take on this. My comment to her was, I was wondering when this would happen. AI is incapable of saying it doesn't know something, so it hallucinates. There's also the point, and if you've listened to this podcast in the last month or two, you know what point I'm about to make, that its data sources are open sources. And most of the real knowledge in fraud is either internal within companies or stored within the minds of fraud fighters. It's purposeful to keep what little advantage we have away from the criminals. And then I asked as a side note, did anyone copy or download this study before it was pulled? I'd love to read it, mostly for pure entertainment value.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
13:30
And she said, oh, all good points. And then she said, I have not. I don't have it, but I wonder if it's around. Shall we ask ChatGPT? Unfortunately, some of those points that may have been hallucinated in EY's study may now be in ChatGPT. So that if somebody, you know, asked ChatGPT about loyalty fraud, they may cite this EY study that was all based on AI hallucinations. That's part of the problem. The other part of the problem is this, not, you know, to have true expertise on a topic like loyalty fraud, you can't trust open source information. It's going to be all generalized. They're not going to be talking about the tools that you can specifically use to prevent loyalty fraud or even how hard it's impacting companies because a lot of impacted companies won't publicly say how much loyalty fraud is impacting them.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
14:19
So loyalty fraud is one of those that's kind of like account takeover fraud where it doesn't really have a metric. The metric you'll get, you know, you'll know it's happening when customer service is getting the calls of saying, you know, my air miles have been drained or my hotel points have been drained, or, you know, someone cashed in this voucher that I had because of how many times I've shopped with you, those type of things. And so they don't have the clear feedback loop that card fraud, traditional card fraud has with chargebacks. So there's a lot of nuances there that AI just doesn't have access to and doesn't know. So they'll make it up. And I did find it funny that one of the top four, you know, consulting firms that writes these big research papers obviously used AI to write it and didn't have a professional in the fraud industry read over it to verify that it was accurate. That is something I would have been happy to do had they asked, but now instead it's pretty embarrassing for them.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
15:20
But I think that this is a good article to share or posting to share with leadership if they are asking you to rely on LLMs to do research, as well as if they're thinking about using LLMs to replace somebody in strategy or someone in operations and fraud leadership. They cannot just ask ChatGPT a question and get the right answer. Just like with that example I've given earlier about, you know, what's pizza fraud? What's, you know, this kind of fraud? What's that kind of fraud? When Frank, we kind of did that in a group text I was a part of and then others did it too, ChatGPT was just making up different types of fraud that kind of made sense for pizza, right? I think one of them was pizza fraud is when someone goes into a pizzeria and steals a pizza. That's not, that's not fraud and that's theft.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
16:11
There were other examples as well that I can't remember, but there's no such thing as pizza fraud. But it couldn't say that. It was incapable of saying that. So instead, it made something up. How do you know if AI is making something up or not? You have an expert employed in your company who knows to spot BS and not, or at least knows who to ask. If they don't know, they can ask someone else in the fraud industry and say, does this sound right? You have to have someone with expertise and knowledge. You can't just rely on open source information for our industry. Maybe for others, but not for our industry. So that was the story. Like I said, I thought it was pretty funny, but also telling about the future that we are walking into or running into at this point.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
18:07
All right, let's talk about Mastercard's Scam Merchant Program, shall we? So Mastercard's new Scam Merchant monitoring is going to go into effect July 24th of 2026. They just announced it a few weeks ago. Its purpose is to find scam merchants. What they mean by scam merchants are merchants that are scamming consumers. The ones that pop up with a, you know, new merchant ID and they're offering free trials or they're shipping things like, or they're not shipping things at all, or they're promising something that they don't deliver on. Or, you know, they're promising something large and you get something small, or they're promising something, you know, that works and you get something that's broken. Those type of companies. Scam merchants. And so the way that Mastercard thinks that they can find them is by looking at a few key criteria. And they kind of have a multi-trigger framework is what they're calling it. But any one of these conditions can initiate a required investigation.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
19:10
So one of the more straightforward triggers is a breakdown in authorization performance. If a merchant's approval rate drops sharply over a short period, for example, a decline of 50 percentage points or falling below the 30% overall, that alone can put them into scope. The measurement window is tight. Acquirers are given a minimum of a 72-hour period or actually, oh no, this is different. This is not the acquirers. This is the measurement window for approvals falling quickly, a minimum 72-hour period with at least 25 transactions. So when any one of these triggers is, or one of these conditions is triggered, it'll initiate a required investigation with your acquirer. The acquirer has 72 hours to investigate and either provide Mastercard with an explanation on why this merchant is not scamming and not illegitimate. They have to provide a legitimate reason for that condition to be triggered, or they need to terminate that merchant and no longer allow them to accept Mastercards.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
20:18
And by the way, you can't just accept Visa without Mastercard. So if you're shut down for Mastercard, you also can't accept Visa. That merchant would only be allowed to accept Amex or Discover or maybe PayPal, which would greatly cripple online businesses. I'm reading from a post by Rick Lynch, who's been in the chargeback space for a long time. He goes on to say, there is also a direct escalation path from Mastercard itself. If a merchant is the subject of a Global Rules Investigation Program, or GRIP letter, that independently triggers the requirement to investigate. For newer merchants, defined as those with less than six months of processing history, there's an additional layer of sensitivity tied to issuer behavior and early performance signals. In those cases, just two different issuers reporting scam-related transactions under the manipulation of cardholder fraud classification is enough to initiate the process.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
21:16
So if you're a new merchant under six months and two issuers report that their cardholders have claimed that they were manipulated in some way, that's enough to initiate the investigative process within 72 hours. That can result in terminating your ability to accept Mastercard. The same applies if two issuers initiate chargebacks that reference scams or similar behavior. That's going to be more complicated because there are cardholders that claim that a merchant scammed them and they really didn't, right? So that's something to watch out for. Then there's a 5% threshold, and it sits specifically in this category. If a newer merchant, so I think within six months, sees more than 5% of its transactions result in refunds and chargebacks over a 30-day rolling period and has processed at least 500 transactions, that condition alone can trigger monitoring. So outside of that early life window, those issuer count and 5% thresholds are not explicitly defined as triggers in the same way. So I think that's important to know.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
22:26
But if you have a new merchant account and the combination of refunds and chargebacks equal more than 5% of your total volume of sales, you could be at risk for having your account activity investigated by your acquirer and possibly shut down. I think it's really interesting that they are combining refunds and chargebacks together. I understand why, but at the same time, Mastercard owns Ethoca, and when merchants enroll in Ethoca, they're enrolling in alerts that can allow them to issue refunds to avoid chargebacks. So they're kind of saying that for these purposes alone, but still for these purposes, Ethoca's not going to help you. It's going to hurt you. It's not going to, it's just, well, maybe it's not going to hurt you, but it's not going to help you because it's going to increase your refund amount. Additionally, there are some merchants that issue a lot of charge, or a lot of refunds because they have a lot of returns, right? A lot of retailers have a lot of legitimate returns that could look fishy to this, you know, program. You could be, you know, under monitoring. Granted, it is if you have, you know, at least 500 transactions, but I think in a 30-day rolling period. But I think most people on the merchant side that are listening to this podcast would very much blow that out of the water. So I think this applies to everyone.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
23:52
What they're not saying right now is if this applies to merchants that are older than six months. I don't know the answer to that. I have seen some people say it does. I have seen some people say it doesn't. I have heard other people say, well, they're rolling it out for the first six months, you know, of a merchant's lifetime now. But they're going to see how it goes and they're going to start tracking this metric more. And now that they can track this metric, if they see a high number of enterprise merchants, for example, that have a combined rate of refunds plus chargebacks divided by sales for that 30-day rolling period, it's not a calendar 30 day, it's a 30-day rolling period, that, you know, there could be repercussions. Right now, it hasn't been said one way or another, but I do think it's, you know, it's worth being aware of.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
24:41
Beyond performance and issuer-driven signals, third-party and network alerts can also initiate the process. If a merchant is flagged by a merchant monitoring service provider or through Mastercard's own monitoring programs, that alone can be sufficient. Once any of these conditions are met, the timeline is clear. The acquirer or payment facilitator has 72 hours to initiate an investigation, and if the merchant is confirmed to be conducting scam activity, they are required to block that merchant from processing Mastercard transactions. Separate from the trigger events themselves, Mastercard is reinforcing expectations around ongoing monitoring. Acquirers are expected to continuously evaluate transaction patterns, refund and chargeback activity, fraud indicators, and behavior that doesn't align with the merchant's stated business model. So if you say that you are a hotel but then you're only processing $20 transactions, that's going to look weird, or, you know, those type of things.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
25:48
There is also an expectation to review Mastercard's fraud and loss database on a daily basis for new signals. I think that's more for the acquirer than the merchant. Taken together, this is not a single metric program. It's a system with multiple entry points where performance changes, network escalation, issuer activity, and third-party alerts can all independently set the process in motion. So again, that's starting July 24th of 2026. I think most companies that are listening to this now on the ecommerce side have had their MIDs for way longer than six months. But I think it's important to be aware that Mastercard is tracking this data. This is new math that we don't usually do, right? Similar to VAMP, we don't usually do the exact math that they require for VAMP.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
26:38
We hadn't up until this time combined TC40s with chargeback numbers and then divided those by the number of sales. That was a new metric for us to start computing. Now there's a new metric to compute for Mastercard risk, and that is refunds plus chargebacks divided by sales, number of sales, the number of refunds plus number of chargebacks divided by number of sales. I think it's important to know that that's how things are being measured because you want to stay underneath those thresholds. And again, that threshold is 5%. I would hope that you would want to stay under that threshold for lots of reasons, specifically revenue. But at the same time, like I said, there are multiple reasons why merchants refund orders and some of them are very legitimate. I think that this could also impact subscription merchants who will often refund the last month of a transaction because they know that the cardholder can issue a chargeback.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
27:42
So, you know, technically the issuer, or the cardholder, can issue a chargeback for the last three months. So they'd rather give an appeasement refund of one month and then tell them, no, you can't get a refund at all, and then they go to their bank and find out they can charge back three months. So subscription merchants, high-risk merchants, some retailers, I think maybe over 500 basis points, I don't know, you know, it might be over that 5%. It's important to, you know, be aware of. All right, that is it for me today. That was kind of a shorter episode, just around 30 minutes or so. And it's not just because I want to get back to floating in the pool, I promise. But that was really, those are really the three things I wanted to update you on. I am expecting to have a guest for next week's episode. Also, Fraudology is coming to YouTube soon. This is kind of against my will, but it's been strongly encouraged by several people and as well as by my sponsor that I branch out to YouTube. So why not now?
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
28:49
So that will be happening in the next few weeks. Don't forget to look into the Merchant Fraud Alliance October 6th and 7th in Chicago. You're not going to want to miss it. Otherwise you're going to have significant FOMO. I promise. I am putting a lot of time and effort into sourcing the best speakers and, you know, representing the best companies. And by having those people in a room, those are conversations you get to have as well. And there will be the ability in the app to set up meetings with people. You can also set up your own schedule for meetings. There's just all kinds of cool features. So it's a great way to meet new people and see familiar faces as well.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
29:29
So with that, I'm going to talk to you more next week, but I hope that you are having a great day and I'll talk to you soon.