# Template 01: Fraudulent (and Unrecognized)

**Stripe category:** `fraudulent` · also use for `unrecognized`
**Typical codes:** Visa 10.4 (card-absent fraud) · Mastercard 4837 (no cardholder authorization), 4863 (does not recognize) · Amex F29, 176

**The claim:** "I didn't make this purchase" or "I don't recognize this charge." Stripe notes that "unrecognized" is "effectively indistinguishable from the Fraudulent reason" ([Stripe](https://docs.stripe.com/disputes/categories)).

---

## What the bank needs to see

One or more of these ([Stripe: dispute categories](https://docs.stripe.com/disputes/categories)):

- The real cardholder (or someone they authorized, like a family member or employee) made the payment.
- The payment was authenticated with 3D Secure, so liability shifted to the issuer. Stripe adds the 3DS data for you.
- You already refunded it.
- The customer withdrew the dispute or admitted they recognize the charge.
- **Visa only:** Compelling Evidence 3.0 (see below).

## Fight or accept?

| Situation | Decision |
|---|---|
| You see logins and usage after purchase from the same IP/device as the purchase, and the email matches the cardholder | **Fight** |
| Returning customer with 2+ undisputed payments on the same card, 120–364 days old (Visa) | **Fight with CE 3.0** |
| Payment was 3DS-authenticated | **Fight** (Stripe adds 3DS evidence) |
| Account was created minutes before purchase, never used, IP country ≠ card country, disposable email | **Accept.** This is probably real fraud. Revoke access. Add a Radar rule. |
| Several payments on different cards from the same IP in one hour | **Accept all of them**, revoke access, and look at card testing defenses |

## Visa Compelling Evidence 3.0 check (2 minutes)

From [Stripe: Visa CE 3.0](https://docs.stripe.com/disputes/api/visa-ce3):

- [ ] Visa dispute with network reason code **10.4**
- [ ] At least **2 earlier payments** on the **same payment method**, paid and never disputed, not validation charges
- [ ] Those payments are **120 to 364 days** before the disputed one
- [ ] All three payments match on **2 main elements** (customer purchase IP + device fingerprint *or* device ID), or **1 main + 1 secondary** (shipping address, customer email, customer account ID)
- [ ] Product descriptions for the disputed and earlier payments, and the type set to `merchandise` or `services`

If eligible, Stripe usually pre-fills the fields. **Don't edit pre-filled CE 3.0 fields**: Stripe warns that changes can affect eligibility ([Stripe](https://docs.stripe.com/disputes/responding)). Still fill in the normal evidence too, in case the CE 3.0 submission is rejected.

## Evidence to attach (digital product / SaaS)

| Evidence | Stripe field | What to put in it |
|---|---|---|
| Customer IP at purchase | `customer_purchase_ip` | From your checkout logs or the Stripe payment |
| Customer name | `customer_name` | As entered at checkout |
| Customer email | `customer_email_address` | The account email |
| Access and activity logs | `access_activity_log` | Logins, downloads, feature use **after** payment, with IPs and timestamps. Highlight matches with the purchase IP or device. |
| Other evidence | `uncategorized_file` / `uncategorized_text` | Device location at time of purchase; device ID; earlier undisputed payments on the same card; any proof a household member made it; CVC check result if it failed but was approved or was unchecked |
| Customer communication | `customer_communication` | Any email from the customer's address after purchase (support requests, replies to onboarding) |

## Rebuttal letter

```
Re: Dispute on charge [CHARGE_ID], [AMOUNT] [CURRENCY], [PURCHASE_DATE]

We believe this payment was made by the cardholder, and ask that this dispute be reversed.

[PRODUCT_NAME] is a [one-line description, e.g. "web-based AI writing tool, billed monthly"].
The customer bought [PLAN] on [DATE] at [TIME TZ] using the email [EMAIL].

Timeline
1. [DATE TIME]: Purchase from IP [IP], [CITY/COUNTRY], device [DEVICE/BROWSER]. (Exhibit A)
2. [DATE TIME]: Access email delivered to [EMAIL]. (Exhibit B)
3. [DATE] to [DATE]: [N] logins from the same IP/device as the purchase, using [specific features: e.g. "created 37 documents"]. (Exhibit C)
4. [If applicable] [DATE]: Customer emailed support from [EMAIL] about [topic], confirming they had access. (Exhibit D)
5. [If applicable] The same card paid us on [DATE] and [DATE] without any dispute. (Exhibit E)
6. [DATE]: Dispute opened. No contact from the customer before the dispute. / The customer contacted us on [DATE] and said [summary].

[If 3DS] The payment was authenticated with 3D Secure.
[If CE 3.0] This dispute qualifies for Visa Compelling Evidence 3.0; matching prior transactions are included.

Evidence attached
A. Purchase record with IP and device
B. Delivery email log
C. Account activity log after purchase
D. Customer emails
E. Prior undisputed payments on the same card

We ask that this dispute be reversed in our favor.
[YOUR NAME], [BUSINESS NAME], [SUPPORT EMAIL]
```

## Mistakes that lose this one

- Sending activity logs that start **before** the payment, or without IPs.
- Arguing "the customer agreed to our terms". In a fraud dispute, the question is *who* paid, not whether the terms were fair.
- Fighting obvious fraud. You lose the fee, the time, and the rate still goes up.

## Prevent the next one

Recognizable descriptor. Receipts with your brand and support email. Collect IP and email on every payment. 3DS for elevated risk. Refund early fraud warnings on small charges.

*Made by Dan Shipped — @danshipped. Not legal advice.*
