Contracargos?
Ya no es problema tuyo.
Recupera cuatro veces más Contracargos y prevención , hasta un 90 % de las entradas, gracias a IA y a una red global de 20 000 comercios.
En resumen:
- Distinguish issuer approval, account access, and cardholder consent.
- Investigate the payment and surrounding account activity without assuming intent.
- Verify liability protection on the specific transaction and dispute type.
- Use the current refund or dispute workflow and retain traceable evidence.
An unauthorized transaction is a payment made without the relevant account holder’s permission. A merchant investigating an unauthorized-payment complaint should distinguish payment approval, account access, cardholder consent, and any applicable liability protection.
Separate Approval, Authentication, and Authorization
| Record | What It Indicates | What It Does Not Establish Alone |
|---|---|---|
| Issuer payment approval | The payment passed the issuer’s authorization decision | That the legitimate cardholder consented |
| Successful account login | The credentials or session were accepted | Who controlled the account at that moment |
| Address or security-code check | The submitted details matched the check performed | Physical possession of the card or cardholder identity |
| Authentication result | The recorded authentication process and outcome | Protection against every dispute reason |
| Delivery or access record | Fulfillment or account activity | Permission to make the original payment |
Stripe’s fraud guidance notes that an approved payment can still involve stolen credentials. OWASP’s transaction authorization guidance distinguishes logging in from authorizing a specific sensitive action.
Investigate Without Assuming the Cause
- Identify the exact payment, order, amount, and date.
- Check whether the complaint is a support request, inquiry, or filed dispute.
- Review account recovery, login, contact changes, and order changes around the purchase.
- Retrieve available authentication and payment records.
- Check fulfillment, support communication, and existing refunds.
- Record confirmed facts, conflicting evidence, and what remains unknown.
A changed address can warrant review, but it may reflect travel, a gift, or a move. A familiar device can provide context without excluding compromise. Avoid using one signal as the basis for an accusation.
For coordinated payment attempts, see card testing. For other attack patterns, use the ecommerce fraud guide.
Choose the Action From the Payment State
If the order is not fulfilled, review whether a pause, cancellation, or supported refund is appropriate. If a dispute is open, follow its instructions instead of automatically issuing another credit.
Use refund and dispute reconciliation to confirm what money has moved. Explain the actual action to the customer without describing a pending refund as completed.
Assess Liability on the Specific Transaction
Merchant liability can depend on the payment method, channel, authentication result, dispute reason, and applicable rules. 3D Secure may shift liability for eligible fraud disputes, subject to conditions and exceptions. The absence of a liability shift does not explain every outcome.
See Stripe’s authentication documentation for a processor-specific example. Fraud liability protection does not resolve a delivery or quality complaint.
Consumer reimbursement rights are separate. In the US, the CFPB’s Regulation E definitions define unauthorized electronic fund transfers and exceptions. Do not apply a debit-account liability summary to every credit-card, business-account, or cross-border case.
Build an Evidence-Based Response
If a challenge is supported and permitted, explain the relevant facts. Include authentication records, account history, communication, and fulfillment evidence where they address the claim. Do not state that a login, security-code match, or shipment proves consent on its own.
Use the representment guide and standardized evidence records to retain identifiers and timestamps. Missing evidence does not prove true fraud, and account matches do not prove first-party misuse. Record the limits of your conclusion.
Reduce Recurrence Across the Account Lifecycle
Review account recovery, sensitive changes, saved-payment use, and fulfillment changes as well as checkout. Give customers a clear way to report unexpected activity and route reports to someone who can act.
Use payment fraud prevention to assign control ownership. If post-purchase review is needed, explore Chargeflow Prevent alongside payment and account-security controls.
Preguntas frecuentes
Does payment approval prove cardholder consent?
Issuer approval does not independently prove cardholder consent. Compromised payment credentials can still receive approval.
Does a login prove who placed the order?
A login shows account access, but the account or session may have been compromised. Review surrounding transaction and security records.
Does 3D Secure remove every merchant liability?
3D Secure can shift liability for eligible fraud disputes under applicable rules. It does not eliminate every dispute type or exception.
Should I always refund an unauthorized-payment complaint?
Investigate the payment state and evidence, then follow the appropriate provider workflow. Check existing refunds and open disputes before another financial action.
Contracargos?
Ya no es problema tuyo.
Recupera cuatro veces más Contracargos y prevención , hasta un 90 % de las entradas, gracias a IA y a una red global de 20 000 comercios.













.png)


