Triangulatiefraude: waarschuwingssignalen, risico’s en preventietips

Chargebacks?
Dat is niet langer jouw probleem.
Haal 4x meer chargebacks terug en voorkom tot 90% van de inkomende betalingen, dankzij AI en een wereldwijd netwerk van 20.000 handelaren.
TL;DR:
- Triangulation connects a buyer’s payment to a separate stolen-card purchase.
- The delivery recipient and cardholder may both be innocent victims.
- Review connected order signals before fulfillment without treating gifts as fraud.
- Proof of delivery does not independently defeat an unauthorized-payment claim.
Triangulation fraud is an ecommerce scheme in which a fraudulent seller collects payment from a buyer, then uses stolen payment credentials to order the product from a legitimate merchant for delivery to that buyer. The buyer may receive the goods while a separate cardholder discovers an unauthorized charge.
The critical distinction is between the person receiving the package and the person whose card paid the legitimate merchant. They may both be victims. Delivery therefore does not independently establish that the cardholder authorized the purchase, even when the order reached the requested address.
Follow the Two Payments and One Shipment
Adyen’s overview of payment fraud patterns describes triangulation as a fraudulent intermediary using stolen card data to purchase goods from a third party for another buyer. Map both payment relationships before investigating the order.
| Participant | Role | What They May Observe |
|---|---|---|
| Buyer | Pays the fraudulent storefront or seller | A purchased product arrives, sometimes from an unfamiliar merchant. |
| Fraudulent seller | Collects buyer payment and places an unauthorized order elsewhere | Two separate payment relationships fund one fulfillment chain. |
| Legitimate merchant | Accepts the stolen-card order and ships the product | An apparently fulfilled order later becomes disputed. |
| Kaarthouder | Owns the payment credentials used without permission | An unfamiliar merchant charge appears on the account. |
The fraudulent seller retains the buyer’s payment while using someone else’s credentials to fund fulfillment. This is not simply an ordinary retailer earning the difference between wholesale and retail prices. The unauthorized payment is the defining feature of the scheme.
An ordinary dropshipper or reseller can use a legitimate fulfillment arrangement. Do not classify all third-party delivery or resale as triangulation fraud. Investigate the authorization and connected transaction facts.
Recognize Patterns Without Blaming the Recipient
Review unusual combinations of cards, accounts, delivery destinations, product choices, and order timing. Repeated purchases with changing payment details can warrant investigation, particularly when paired with confirmed unauthorized-payment reports. A different billing and shipping address alone is common in legitimate gift orders.
- Compare suspicious orders using permitted payment and account identifiers.
- Review material changes to shipping instructions before fulfillment.
- Preserve reports from recipients who recognize the product but not your store.
- Separate confirmed unauthorized payments from cases that are only under review.
- Check whether a pattern reflects an authorized reseller or other legitimate commercial relationship.
Avoid automatic accusations based on an address or household connection. The recipient may have paid a fraudulent storefront in good faith. The repeat-claim investigation workflow provides useful recordkeeping principles, but triangulation should not be mislabeled as friendly fraud by the innocent buyer or cardholder.
Intervene Before Goods Leave Your Control
Use contextual order review, supported authentication, and clear escalation rules for suspicious transactions. If a case needs verification, use your established secure process rather than asking the recipient to provide someone else’s card details. Do not expose payment information in email or support attachments.
For merchants using Shopify, connect order review with fulfillment status so staff can act on a concern before shipment where the workflow permits it. Keep the reason for a hold and the resolution visible to support, including cases where the customer is verified and the order proceeds.
The card-not-present fraud guide explains why payment checks and fulfillment controls need to work together. Review customer impact as well as fraud reduction: an overly broad rule can block legitimate gifts, resellers, or households while leaving a more complex pattern undetected.
Respond When the Cardholder Reports Unauthorized Payment
Start with the actual chargeback reason code, provider instructions, and case deadline. A genuine unauthorized-payment claim may be valid even when your merchant team fulfilled the order correctly. Do not assume that proof of delivery provides a basis to challenge it.
Review the transaction’s authentication and any applicable protection with your provider. Where a supported response exists, submit the relevant facts and records. Where it does not, focus on resolving the case and reducing further exposure. Automation can improve handling; it cannot turn an unauthorized purchase into an authorized one.
Use the issuer evidence guide to distinguish fulfillment evidence from authorization evidence. The case documentation workflow can help create a clear transaction timeline without claiming that every connection proves fraud.
Help Buyers and Cardholders Report the Right Transaction
A buyer who suspects a fraudulent storefront should preserve the listing, receipt, seller messages, and shipping details, then contact the marketplace or payment provider through a verified channel. A cardholder who sees an unauthorized charge should contact their card issuer or payment provider promptly. These may be different reports about different payments.
The FTC guidance for people who were scammed recommends contacting the relevant payment company and taking appropriate account-security steps. Do not promise that the buyer can keep the item or must return it to a particular address without reviewing the facts and legitimate instructions.
If your support team receives a recipient’s report, connect it to the relevant order securely. Avoid demanding an additional payment or sending sensitive cardholder details to the recipient. Preserve evidence and coordinate the next step with the payment provider and appropriate internal team.
Measure Confirmed Cases and Close the Operational Gap
Track suspected and confirmed triangulation separately from other payment fraud types. Record the source of confirmation, affected orders, goods shipped, credits, and final dispute outcomes. Do not present all ecommerce fraud losses or general card-fraud statistics as triangulation-specific losses.
Review how the order passed screening, whether a pre-shipment signal was available, and how support handled the first report. If a refund and dispute overlap, use the refund reconciliation workflow before issuing another credit. Share corrected case labels with the teams that maintain prevention rules.
Veelgestelde vragen
Can the buyer be innocent in triangulation fraud?
Yes. A buyer may pay a fraudulent seller in good faith and receive goods purchased elsewhere with stolen credentials. The buyer and the unrelated cardholder can both be victims.
Does delivery defeat a triangulation chargeback?
Delivery does not independently establish cardholder authorization. A triangulation chargeback requires review of the actual payment evidence, applicable rules, and any eligible protection.
Is dropshipping the same as triangulation fraud?
No. Legitimate dropshipping uses an authorized commercial and payment arrangement. Triangulation fraud depends on unauthorized payment credentials being used to fund fulfillment.
You can organize evidence and manage supported responses with Chargeflow’s automated chargeback recovery.

Chargebacks?
Dat is niet langer jouw probleem.
Haal 4x meer chargebacks terug en voorkom tot 90% van de inkomende betalingen, dankzij AI en een wereldwijd netwerk van 20.000 handelaren.














.png)
.webp)
.webp)
.webp)