top of page

From Onboarding to Chargeback: How to Break the Marketplace Fraud Cycle

36 minutes ago
9 min read

By: GatekeeperX


It all started with a pizzeria.


A new seller signed up on a food delivery platform. It passed onboarding, published its menu and started selling pizzas. Volumes were small and growth was gradual. For weeks, it behaved exactly as you would expect a new merchant to behave.


Then it asked for permission to sell alcoholic beverages. The account already had a track record and its signals looked consistent, so the request was approved. Over a single weekend, its sales grew roughly 100-fold. The marketplace paid out the proceeds. Weeks later, the chargebacks started arriving.


When the risk team checked the merchant’s location, it found that the pizzeria had never existed.

The question this case raises is not how the stolen cards were detected. It is when the fraud actually began. The answer explains why fraud prevention in marketplaces needs a different model from traditional ecommerce.


Marketplace fraud is a cycle, not an event

Fraud in a marketplace is rarely an isolated payment event. It is usually a sequence that includes:

  • a bad actor getting onto the platform;

  • building trust;

  • a change in behavior;

  • exploiting a payment method, a promotion or a money flow;

  • getting the money out.


When the chargeback arrives, it is the last symptom of that sequence, not the first. That is why a prevention model that only makes decisions at the moment of payment arrives late to much of the problem.


This is not a semantic distinction. Traditional ecommerce has two main parties: the merchant and the buyer. A marketplace has at least three: the platform, its sellers and its buyers. It also has a flow that classic ecommerce does not: money comes in through the buyer and goes out to the seller. Any of those parties can be the fraud vector, and sometimes several are at once.


What the marketplace sees that the payment doesn’t

A marketplace has an advantage it often underuses: it holds more context than any other participant in the payment chain.



A simple example makes the point. Two orders paid with similar cards for the same amount can look almost identical to an issuer. To the marketplace, they are completely different if one contains fruit, milk and baby products, and the other contains four bottles of whisky shipped to a new address from an account created yesterday.


The payment sees a scene. The marketplace sees the whole movie. Outsourcing all fraud prevention to the PSP means giving up the most valuable information the platform has: its own context.


The eight stages of the marketplace fraud cycle

The structure below is a GatekeeperX perspective for analyzing marketplace risk, not an industry standard. Each stage answers a different question and offers its own opportunity to make a decision.


1. Onboarding: who is coming in?

Fraud doesn’t always come in as a buyer. In the pizzeria case, it came in as a merchant. Seller onboarding is the first control a bad actor needs to get past, and it does so by looking legitimate enough to be approved.


Relevant signals at this stage include:

  • consistency between official or tax identification, contact details and the declared address;

  • the digital reputation of the identity;

  • the real ability to verify that the business physically exists;

  • links between the new registration and known accounts.


On the buyer side, onboarding is where the accounts later used for card testing or promotion abuse are created.


2. Account and device: who actually controls the account?

A valid identity does not guarantee that the account holder is the one operating the account. Device intelligence adds context about the environment the account is being used from. Examples include emulators, compromised environments, automation, or the same device appearing across multiple accounts. These signals help identify account takeover, multi-accounting and account farms.


3. Behavior: is the account still behaving consistently?

This is the stage the pizzeria case illustrates best. The attackers didn’t cash out on day one: they aged the account. For weeks, they built history, tenure and an apparently legitimate behavioral baseline.

The operational lesson is that tenure is not the same as trust. An account with history can become riskier, not safer, when its economic profile changes. Moving from low-ticket pizzas to higher-value, easy-to-resell alcoholic beverages is not a simple catalog update. It is a change in the type of risk the platform is taking on. That kind of change should trigger a fresh assessment, not inherit the previous approval.


4. Transaction and cart: what is being bought or sold?

Cart detail is one of a marketplace’s richest sources of signal, and also one of the easiest to evade with simple rules.


One operational case shows this well. When controls tightened around products that are obviously attractive to fraudsters, attackers found that restaurant orders had looser controls. They began buying bottled, resellable drinks inside those orders. The team created a rule to block orders made up only of drinks. The attackers responded with five drinks and one cheap side item.


The fix was not another binary rule. It was changing the question: what share of the cart’s value is made up of resellable products? Every time a rule is created, the attacker looks for the exception. Continuous, contextual variables are harder to work around than yes-or-no thresholds.


5. Payment: how is it being paid for?

Payment remains a critical stage, even if it is not the only one. Card-testing attacks are a good example of why isolated signals are not enough. A spike in attempts from cards with the same BIN can have legitimate explanations. So can a high rate of invalid-card declines. The combination of both, in real time, is what reveals an automated card-testing attack.


An uncomfortable principle also applies here: not all growth is growth. An unexpected rise in sales using cards issued in a country where the platform has no meaningful demand can look, at first glance, like good commercial news. In another operational case, it turned out to be stolen-card activity. Sudden growth is also an anomaly that deserves an explanation.


6. Network: who is this identity connected to?

Many fraudulent accounts look independent when analyzed one by one. The pattern emerges when they are connected.


Promotion abuse is the clearest example. A first-purchase coupon used by a new customer is an acquisition investment. The same coupon used by hundreds of fake accounts is a budget leak.

In practice, apparently distinct accounts end up sharing:

  • the same physical delivery point;

  • related devices;

  • minimal variations of the same email pattern.


To be accurate without penalizing legitimate customers, teams need to combine several dimensions: address, geolocation, payment method, product, time window and number of accounts involved.


The problem isn’t the account. It’s the network.


7. Payout: where is the money going?

The payout is where seller fraud gets monetized. In the pizzeria case, the attacker turned stolen card credentials into an apparently legitimate payout. The scheme looks more like fraudulent merchant activity or transaction laundering than traditional buyer fraud.


The payout is also where marketplace fraud intersects with other risks. Destination accounts, recent changes to bank details, or payouts concentrated in related account holders can add context for both fraud and AML teams. These functions have different objectives and obligations, but they may be looking at the same entities.


8. Dispute: when does the loss show up?

The chargeback belongs to this story, but it isn’t the fraud. It is the late signal that confirms the earlier sales were fraudulent.


The structural problem is timing. On the major card networks, cardholders generally have up to 120 days to open a dispute. A marketplace can settle a payout within days and receive the dispute months later, when the seller is long gone.


This stage still matters for two reasons. Good dispute and evidence management reduces losses. And every confirmed chargeback is information that should feed back into decisions at the earlier stages.


Not all fraud ends in a chargeback

Building a fraud strategy around the chargeback ratio leaves out a significant part of the problem. Promotion abuse, multi-accounting and reselling subsidized products don’t always generate disputes.


Their costs show up elsewhere in the business:

  • inflated customer acquisition costs;

  • marketing budget captured by illegitimate actors;

  • distorted retention metrics;

  • legitimate sellers competing against fraudulent accounts.


A marketplace can have a healthy chargeback ratio and still be losing money to fraud.


Factors that amplify the cycle

The patterns above appear in marketplaces in every market, but certain operating conditions make them more costly.


Increasingly fast payouts. Paying sellers quickly is a competitive advantage. With instant payments, however, the window between a sale and the money leaving shrinks, which raises the value of deciding before the payout.

Geographic coverage without physical verification. Platforms expanding into new cities or countries often operate where they cannot verify sellers in person. That was exactly one of the gaps the nonexistent pizzeria exploited.

Third-party accounts at the receiving end. Money mules, meaning accounts used to receive and move funds of illicit origin, can appear as payout destinations. Looking at where the money goes is as important as looking at where it comes from.

Valid identities in the wrong hands. A correct official ID does not guarantee that the person operating the account is its holder. Identity is a starting point, not a conclusion.


Three common mistakes in marketplace fraud prevention

Treating trust as a permanent state. An account approved at onboarding is not approved forever. Events that change the risk profile should trigger a new decision. Examples include a category change, a jump in volume, a change of payout account, or a move into high-resale products.


Relying on binary rules. Rules are useful for known patterns, policies and deterministic controls. The problem arises when they are the only mechanism. A patient attacker learns the thresholds and operates just below them. Combining rules with models, contextual variables and anomaly detection makes evasion more expensive.


Evaluating each entity in isolation. A transaction can look normal. So can an account. So can a device. The relationship between them may not. Without relationship analysis, networks of coordinated accounts remain invisible.


How to break the cycle: decide at every stage

If fraud is a sequence, prevention has to be one too. In practice, that means four shifts in approach.

Connect signals that currently live in silos. Onboarding, trust and safety, payments, promotions, finance and disputes often have their own data and their own tools. The attacker moves through all of them. The platform needs to see them together too.

Reassess at the moments that change risk. Beyond the transaction itself, it helps to define events that trigger a new decision: a new category being enabled, a change of address or bank account, a sales spike, or a request for an early payout.

Widen the decision space. Not everything comes down to approve or block. Between the two, there are other options:

  • requesting additional verification;

  • sending to manual review;

  • temporarily holding a payout;

  • restricting a category;

  • continuing to monitor.


Applying the right level of friction for the level of risk protects legitimate users without ignoring the signals.


Close the loop with learning. Every chargeback, every dispute and every network detected should improve the rules and models acting at earlier stages. If that information stays within the disputes team, the cycle doesn’t get broken.


At GatekeeperX, we approach this problem as a decision-orchestration challenge rather than a single checkpoint. The idea is to bring together, in one real-time decisioning layer:

  • identity and device signals;

  • rules and models;

  • anomaly monitoring;

  • relationship analysis across entities;

  • dispute management.


The goal is for the marketplace to act at the stage where the signal appears, not only once the loss is already visible.


Frequently asked questions

What is the marketplace fraud cycle?

It is the sequence of stages a bad actor can move through on a platform: onboarding, account control, behavior building, transaction, payment, links to other accounts, payout and dispute. Each stage generates different signals and offers a different opportunity to intervene before the loss materializes.

Why is a chargeback a late signal?

Because cardholders usually dispute a purchase weeks or months after the transaction. In a marketplace, the seller’s payout may have been settled long before. By the time the chargeback arrives, the money is gone and the bad actor may have disappeared.

What is the difference between buyer fraud and seller fraud?

In buyer fraud, the purchaser uses stolen payment methods, fake accounts or promotions abusively. In seller fraud, the merchant itself is fraudulent: it signs up to simulate sales, launder transactions or capture payouts. Marketplaces need controls for both, because the signals and the intervention points are different.

Is the PSP’s fraud screening enough?

The PSP provides valuable payment signals, but it has no access to the context the marketplace generates: the cart, the seller’s history, delivery addresses, promotions and relationships between accounts. Complementing the PSP’s controls with the marketplace’s own decisions makes it possible to detect patterns the payment alone cannot reveal.

How is promotion abuse detected?

By linking accounts that appear independent. The most useful signals are usually shared devices, common addresses or delivery points, similar email patterns, payment methods and time windows. None is conclusive on its own. Their value lies in the combination.


The chargeback was just the last signal

Back to the pizzeria. In hindsight, every stage held a signal: a registration approved at a location that couldn’t be verified, weeks of small sales, a request to change category, volume that exploded over a weekend, a payout settled and, finally, the chargebacks.


The fraud didn’t start with the first stolen card. It started when a bad actor managed to get in, look legitimate and change its behavior without those signals, taken together, leading to a different decision.


For marketplaces, the challenge is not only detecting the fraudulent transaction. It is understanding the story that unfolds before it. The future of fraud prevention isn’t blocking more. It’s deciding better, at every stage of the cycle.



Comments


bottom of page