Generative AI Fraud: What It Means for Merchant Chargebacks

Generative AI fraud is fraud run with AI tools that build fake content, like text, images, video, voice, or whole synthetic identities. For merchants it shows up as more disputes that look legitimate on the surface. They arrive under the same reason codes as ordinary fraud. The right evidence is what clears them.
I've built the evidence packet for a fraud dispute where every document the customer submitted looked real. Now I read the reason code first and build the packet to it, and that habit is what AI fraud tests hardest. By the end of this you'll know which evidence still clears these disputes.
Key takeaways
Want fewer of these reaching chargeback stage? Our dispute alerts reach you while a refund still resolves the dispute.
What is generative AI fraud?
Generative AI fraud is fraud that uses AI-generated text, images, video, voice, or synthetic identity documents to deceive a merchant, bank, or payment system. Fraudsters point the same consumer AI products everyone else uses at your checkout.
What changed is how fast the fakes get made and how real they look. A forger who once managed one usable driver's licence a day now builds hundreds. Each copies government markings well enough to clear an early check.
The Federal Reserve's FedPayments Improvement team calls synthetic identity fraud the fastest-growing fraud type globally in 2025, an eight-fold rise from 2024. Most of that growth sits in account opening. It reaches your checkout as identity fraud that clears early screening.
You're still looking at true fraud and identity fraud, built with AI tools.
The same holds when your own customer files the dispute, which is chargeback fraud whether AI wrote the claim or the customer did.
How fraudsters use generative AI against merchants
Fraudsters use generative AI to build fake identities, bypass verification, draft dispute narratives, and run the same attack at scale. Those four uses break down like this:
- Synthetic identity documents: Fabricated IDs that pass early verification.
- Deepfake voice and video bypass: Cloned audio and live video impersonation.
- AI-drafted dispute narratives: Polished dispute claims against real purchases.
- Automated fraud at scale: The same attack, run far more often.
Each one lands on your books differently, so take them in order.
1. Synthetic identity documents
A synthetic identity mixes real and invented personal data, then gets fake documents that make it look like a real person. AI systems scrape names, addresses, Social Security numbers, and job histories from breaches and public records. Then they build the driver's licence or utility bill that backs the story up.
Generative AI changed one part of this decades-old fraud. The paperwork used to be the bottleneck and the tell, and now it clears early screening.
That's where most merchants stop checking.
For you, the difference is timing. A synthetic identity behaves like a good customer for months, then runs up balances it never repays. The loss reaches you as a chargeback long after the order.
2. Deepfake voice and video verification bypass
Deepfakes defeat the verification step at signup, at login, and at the call centre. The FBI's Internet Crime Complaint Center reports criminals cloning a relative's voice in short audio clips to reach bank accounts. Its public service announcement also describes live video chats posing as executives or authority figures.
Your exposure runs through your customers' accounts. Three checks used to require a real human:
- Voice authentication at a call centre.
- A video liveness check at signup.
- A support agent hearing the account holder's voice.
Once one of those checks passes, the order that follows is an account takeover.
Your login controls only ever see a clean verification.
3. AI-drafted dispute narratives and evidence
AI writes the dispute claim, and a well-written claim reads as credible to the issuer. A customer who bought your product and wants the money back can now describe a delivery that never arrived. It reads like a real complaint and takes a minute to make.
That's first-party misuse with better prose. The behaviour is unchanged, and so is the fix, because your delivery confirmation, your terms, and your transaction record still beat a story.
The one thing that shifts is your read on the customer.
Judge the claim on your records now, because fluent prose tells you nothing about who wrote it.
4. Automated fraud at scale
AI removes the cost of each fraud attempt, so attackers run far more of them. The FBI's guidance is direct about the mechanic. Generative AI lets criminals commit fraud on a larger scale. It also corrects the errors that used to give a scheme away.
Card testing shows the shape of it. A script that runs stolen card numbers against your checkout now costs almost nothing to build.
Volume is what turns a fraud pattern into a chargeback ratio problem.
Does AI fraud change your chargeback reason code?
No. Card networks route AI-driven fraud disputes through the same fraud reason codes as ordinary fraud. The two you'll see most are Visa 10.4 (fraud, card-absent) and Mastercard 4837 (no cardholder authorization).
A chargeback reason code says what kind of dispute this is. Visa and Mastercard have no code for "AI-generated," so nobody records the tooling anywhere. Your acquirer sends the same code whether the fraudster typed a stolen card number or built a synthetic identity.
Your queue and your response process stay the same.
In our own dataset, 10.4 is the single largest specific reason code. AI-driven fraud lands in that same code, beside every other card-absent dispute. Check the exact code on your own dispute notice with our reason code lookup tool to confirm which evidence it asks for.
What changes is which evidence still works. Documents and narratives carry less weight once anyone can generate them. The burden moves onto records you kept at the time of the order.
What evidence changes when the fraud is AI-generated
When the fraud used AI-generated content, your strongest evidence ties the order to the same device, IP, or account history as earlier undisputed charges.
Visa's Compelling Evidence 3.0 is the standard packet for a 10.4 dispute, and it wins on matching data points.
You submit two prior undisputed transactions from the same cardholder. Each is dated 120 to 365 days before the disputed one. Each also shares data points with it, like device fingerprint, IP address, shipping address, or user ID. One of the two shared points has to be the IP address or the device ID, per Visa's merchant readiness guide.
Since October 17, 2025, this runs on its own for merchants on Visa Secure or Visa Data Only.
Your device and IP records from last spring exist independently of anything a fraudster generates today. A convincing licence changes how believable the story sounds, and your server logs stay exactly where they were.
Here's what survives synthetic content:
One case breaks this path entirely. A stolen card used at your store for the first time leaves no prior transactions to match, so you have nothing to submit. That's why catching the order early matters more as this fraud gets harder to spot.
How merchants can respond to generative AI fraud
Check the order against the customer's own history first, then preserve the device and IP evidence, then use pre-dispute alerts on what gets through. Run the AI-Fraud Evidence Response in that order:
- Verify the transaction pattern against the customer's own order history.
- Preserve the device ID and IP address on every order for 365 days.
- Catch the rest with a pre-dispute alert and refund inside the window.
Each step covers what the one before it misses.
1. Verify the transaction pattern
Check the order against the customer's own history before you check the documents. A synthetic identity can build a flawless licence, but it cannot build a year of orders from your store on the same device.
Pull three things at review time:
- Whether this device or IP has ordered from you before.
- Whether the shipping address matches any earlier delivery.
- Whether the account is new against a payment method that isn't.
A two-year account ordering from a device you saw last month carries a different risk from a same-day signup with overnight shipping.
This check has one real limit. A first-time customer has no pattern, and most first-time customers are real. Route those orders to manual review rather than declining them.
Decline only when a second check also fails, like the address failing AVS or the card failing CVV.
2. Preserve device and session evidence
Capture the device ID and IP address on every order and keep them for at least 365 days. Compelling Evidence 3.0 runs on that data, and you can only collect it at the time of the order. Most merchants discover during the dispute that nobody ever stored it.
Three things to confirm this week:
- Stripe and Shopify both record device and IP data on orders, so check yours.
- Your retention window covers a dispute that arrives a year after the sale.
- Your dispute-response tool can pull device ID and IP from the order record.
Keep order timestamps, delivery proof, and login records under the same 365-day window. You hold the only copy of each, timestamped before the dispute existed.
3. Catch it before it becomes a chargeback
A pre-dispute alert gives you a refund window before the chargeback is filed, so you never have to assemble evidence at all. A first-time stolen card leaves you nothing to match, and this is the layer that still applies.
Alerts come from the card networks' own programs:
- Ethoca, on the Mastercard side.
- Verifi's RDR, on the Visa side.
- Verifi's CDRN, also Visa, in the US.
Each one tells you a cardholder disputed a charge. Refund inside that window and you lose only the sale.
We connect to all three networks and match each alert to the transaction in your processor, so the refund happens without anyone watching a queue. Our chargeback alerts prevent up to 91% of chargebacks for the merchants who use them.
How generative AI is used defensively
Screening engines use AI to flag the traces synthetic content leaves behind. Both sides run on the same models, and fraud rings use them to generate content while screening engines use them to spot it.
Three traces the generation process leaves:
- Document metadata that doesn't match the document it sits in.
- Unnatural cadence in a voice clip.
- A device history that clashes with the identity claiming it.
A fraudster struggles to control those traces, because making the fake is what creates them.
Screening lowers your exposure. Look for a tool that checks all three traces above, and keep the evidence steps for the orders that still get through.
How we sourced our data
The reason-code figure in this article comes from anonymized, aggregated alert data across merchants enrolled on the Chargeback.io platform. We counted total alerts in each reason-code category. Then we report them as shares of the alerts that carried a recorded code.
These shares describe alerts our platform processed, so read them as our own merchant mix. The records behind them are the same fraud reports that flow through TC40 data on the Visa side, seen from the alert end.
FAQ
Who decides the reason code on an AI fraud dispute?
The cardholder's issuing bank picks it, from the codes the network already publishes. Your acquirer passes that code to you unchanged.
Is AI-generated fraud tracked as a share of volume?
Not reliably. No card network or public dataset splits AI-built fraud from the rest, because the dispute record never says how the fraud was made.
Can you spot AI-generated fraud before you respond?
Not by eye, and screening vendors catch only some of it. Build the packet the reason code asks for, since the evidence that wins is the same either way.
Do alerts protect against AI-generated fraud?
Alerts trigger on the dispute itself, so they cover an AI-driven dispute like any other. The alert reaches you in time to refund the charge.
