Two problems that look like one
Payment risk in gambling divides into fraud, meaning transactions that were not legitimate, and chargebacks, meaning transactions that are reversed whether or not they were legitimate.
They overlap and are not the same. A great deal of gambling fraud never produces a chargeback, and many chargebacks in this sector involve transactions the customer genuinely made. Treating them as one problem produces controls aimed at the wrong target.
The fraud types
Stolen payment instruments. A card or account is used without the owner's authorisation to fund a gambling account. The fraudster's objective is usually to extract value, either by withdrawing after minimal play or by colluding to transfer the balance elsewhere. Signals include rapid deposit followed by an immediate withdrawal request, mismatch between account details and payment instrument, and multiple instruments used on one account in a short period.
Account takeover. A legitimate customer's account is accessed by someone else, often through credential stuffing, the automated use of username and password pairs stolen in a breach elsewhere. The objective is to withdraw the balance or exploit stored payment methods. Signals include login from an unusual location or device, immediate changes to payout details, and withdrawal requests inconsistent with the customer's established pattern.
Multi-accounting. One person operating several accounts, generally to exploit promotions repeatedly. Signals include shared device fingerprints, payment instruments, addresses or behavioural patterns across nominally separate accounts.
Collusion. Coordinated play between accounts to transfer value, most relevant in poker and in some betting contexts. This is a game integrity matter as much as a payment one.
Money laundering. Using gambling accounts to change the character of funds, typically by depositing and withdrawing with limited genuine play. Signals include a low ratio of wagering to deposits, deposits from multiple sources, and withdrawal to instruments other than the deposit source, which is precisely what closed loop routing prevents.
Bonus abuse. Systematic extraction of promotional value without genuine play. This is distinct from payment fraud and is addressed better through promotional design than through payment controls.
How chargebacks work
A customer contacts their card issuer disputing a transaction, typically within 120 days of the payment under card network rules. The issuer raises a chargeback through the card scheme, the funds go back towards the customer, and the disputed amount is debited from the merchant through its acquirer or payment provider. The provider usually adds a dispute fee, and at a provider such as Stripe the fee for receiving a dispute is not returned even if the merchant wins.
The merchant may represent, contesting the chargeback by submitting evidence that the transaction was legitimate: verification records, login and device data, account activity, terms accepted and any communication. The issuer assesses this and either upholds the chargeback or reverses it. A dispute that stays contested can move to pre-arbitration and then arbitration by the card scheme, where further fees apply.
Two features of this process matter commercially.
The first is that the fee usually applies regardless of outcome. Winning a representment recovers the disputed amount but not the fee for receiving the dispute, which means high chargeback volumes are expensive even when the merchant is right.
The second is ratio monitoring. Card schemes track chargebacks as a proportion of transactions and set thresholds. Exceeding them moves a merchant into monitoring programmes carrying fines or fees and required remediation measures. Visa's acquirer monitoring programme, which in 2025 absorbed its separate fraud and dispute programmes, uses a single ratio of fraud reports plus disputes to settled card-not-present transactions, with a merchant flagged at 1,500 or more fraud reports and disputes a month and a ratio at or above a threshold that was cut from 2.2% to 1.5% in Asia Pacific, Canada, the EU and the US on 1 April 2026, so fraud reports count against a merchant even when no chargeback follows. Mastercard's Excessive Chargeback Program flags a merchant with at least 100 chargebacks in a month and a ratio of 1.5% or more, with fines that rise in steps the longer the merchant stays above the threshold and a remediation plan Mastercard may request. Persistent breach puts the acquiring relationship itself at risk.
For a high-risk merchant with a limited set of willing acquirers, that outcome is close to existential. This is why chargeback ratios receive attention far exceeding the value of the transactions involved.
Friendly fraud
Many chargebacks in gambling, as in other card-not-present sectors, involve not stolen cards but transactions the customer genuinely made. Visa calls this first-party misuse, and in 2023 changed its dispute rules to counter its rising occurrence.
The reasons vary. Some customers dispute after losing, framing a deliberate transaction as unauthorised. Some genuinely do not recognise an obscured merchant descriptor and report it in good faith. Some are covering a transaction from a partner or family member. Some have had their card used by a family member, including in some cases a minor, and the dispute is legitimate even though the transaction was made from the household. And some use chargebacks as an informal route to recover gambling losses, sometimes encouraged by third parties offering to help customers reclaim money.
This category is difficult to prevent through fraud controls, because the transaction was not fraudulent at the point it was made. The effective interventions are earlier and different.
Clear merchant descriptors reduce good-faith non-recognition disputes, and a cardholder not recognising the transaction description is a common reason banks query a payment.
Robust identity verification establishes who made the transaction, which supports representment and deters opportunistic disputes.
Detailed records of login, device, session activity and terms acceptance are the evidence on which representment succeeds or fails.
Responsive customer service resolves grievances before they become disputes, since a proportion of chargebacks are raised by customers who felt they had no other route.
Reasonable refund practice matters for the same reason. A customer with a genuine complaint who is refused a refund has an obvious next step.
Controls and their cost
Fraud controls in this sector operate at several points: at registration through identity verification and device checks, at deposit through transaction risk scoring, during play through behavioural monitoring, and at withdrawal through payout verification.
The design question is where to set them, and it involves a trade-off that operators consistently get wrong in one direction.
Every control declines some proportion of legitimate transactions. Tightening reduces fraud and reduces acceptance. The correct setting balances the cost of fraud accepted against the cost of legitimate customers declined.
The difficulty is that these costs are not equally visible. Fraud losses appear in reports: chargeback amounts, fees, investigation time. The cost of a legitimate customer wrongly declined appears nowhere. They simply do not deposit, do not return, and their absence is attributed to nothing.
That asymmetry biases operators systematically towards over-blocking, because the visible cost pushes in one direction and the invisible cost does not push back. Correcting for it requires deliberately estimating false decline volume and attaching the acquisition cost of those customers to it.
The practical approach is segmentation rather than a single threshold. A first deposit from an unverified new customer using a newly added instrument warrants controls that would be absurd applied to the hundredth deposit from a verified customer with two years of consistent history. Uniform rules across those populations mean either accepting unnecessary risk on the first or driving away the second.
Keeping the categories separate
A governance point worth stating explicitly, because conflation causes real harm.
Payment fraud is a security matter. It is investigated with evidence, actioned through account restriction or closure, and reported where obligations apply.
Bonus abuse is a commercial matter, best addressed through promotional design that cannot be exploited profitably rather than through payment controls applied after the fact.
Money laundering concern is a regulatory matter with defined reporting obligations, restrictions on what the customer may be told, and handling by a specific function. In Britain, the tipping-off offence is aimed at people working for remote and non-remote casino operators, while anyone can commit the separate offence of prejudicing an investigation.
Responsible gambling concern is entirely separate and must not be handled through any of the above. A customer depositing repeatedly from multiple sources may be laundering money, may be experiencing serious gambling harm, or may be doing something entirely ordinary. Those require different responses, and treating a harm indicator as a fraud signal, or vice versa, produces the wrong outcome in both directions.
Operations that route all unusual activity into a single risk queue reliably mishandle some of it. The categories need distinct criteria, distinct owners and distinct escalation paths, and the people assessing each need to be able to refer cases across.
Measuring the right things
The metrics that matter in this area are more varied than a single fraud loss figure.
Chargeback ratio by method, market and provider, tracked against scheme thresholds with enough headroom to react before a breach.
Chargeback reason distribution, since disputes citing non-recognition point at descriptors while disputes citing unauthorised use point at verification.
Representment win rate, which indicates whether the evidence being submitted is adequate.
Fraud loss as a proportion of deposit volume.
False decline estimate, however approximate, so that the invisible cost has a number attached.
Review queue volume and outcome, since a manual review process declining almost nothing is imposing delay for no benefit, and one declining a great deal may be set too tight.
The recurring finding when operators assemble these is that the largest opportunity is rarely in catching more fraud. It is usually in preventing disputes through better descriptors and verification, and in relaxing controls on populations where the risk never justified them.
Representment in practice
Contesting a chargeback is a documentation exercise, and success depends almost entirely on what the operator can produce.
The evidence that carries weight includes identity verification records showing the account holder was verified and how; login and device data demonstrating consistent access from the customer's usual devices and locations; session activity showing the deposit was followed by genuine play rather than immediate withdrawal; terms acceptance records with timestamps; communication history showing the customer engaged with the operator normally; and previous transaction history establishing a pattern of legitimate activity. Visa's Compelling Evidence 3.0 rule, in force since April 2023, formalises that last point for card-not-present fraud claims: a merchant that shows two earlier undisputed transactions on the same card with the same merchant, 120 to 365 days old, sharing at least two of user ID, IP address, device ID and delivery address with the disputed one, one of them the IP address or device ID, shifts liability back to the issuer. Consistent merchant descriptors help Visa match those earlier transactions.
The practical requirement is that this evidence must be retrievable quickly, in a presentable form, within the response window the scheme allows, which at a typical payment provider is 7 to 21 days depending on the card network. Operators that hold the data across several systems with no assembly process routinely miss deadlines and lose disputes they would have won.
Some disputes should not be contested. Where a transaction genuinely was unauthorised, where a minor accessed a household card, or where the operator's own records show something went wrong, representment wastes effort and, in the underage case, risks compounding a serious problem by defending it. Deciding which disputes to contest is itself a discipline, and contesting indiscriminately produces a poor win rate that provides no useful signal.
Third party claims services
A development worth understanding, because a claim over gambling losses is not always brought by the player who made them.
Services exist that offer to help consumers reclaim gambling losses, typically by pursuing chargebacks or by arguing that the operator failed in its regulatory obligations. Their quality and legitimacy vary widely.
Where the underlying claim has merit, for example where an operator permitted a self-excluded person to gamble or failed to act on clear harm indicators, the claim is legitimate regardless of who is bringing it, and the operator's exposure is real. The same applies to claims based on illegality: in April 2026 the Court of Justice of the EU ruled that EU law does not prevent a player from reclaiming stakes lost to an operator licensed in another member state where those games were prohibited in the player's own country, in a case where the claim of a player resident in Germany had been assigned to a company that pursued it before a Maltese court.
Where it does not, these services can generate substantial volumes of formulaic disputes that must nonetheless be handled individually.
The defensible position for an operator is the same in both cases: maintain the records that establish what happened, apply obligations properly so that meritorious claims do not arise, and handle disputes consistently on their merits. Operators whose compliance is sound find these claims manageable. Operators whose compliance was not find that the claims are the mechanism by which that becomes expensive.
Building the control framework
To close, a summary of how the controls described in this lesson fit together.
Controls apply at registration, through identity verification, device and email intelligence, and duplicate detection. At deposit, through transaction risk scoring, instrument verification and velocity limits. During play, through behavioural monitoring for patterns inconsistent with genuine gambling. At withdrawal, through payout instrument verification, closed loop routing and value-based review. And continuously, through screening and pattern analysis across the account base.
The design principles that matter are that controls should be proportionate to the segment rather than uniform; that they should be measured for false positives as well as for catches; that they should be layered, so no single control failure is catastrophic; that they should be reviewed as fraud patterns change, since static rules degrade; and that they should be separated by category, so that fraud, financial crime, bonus abuse and responsible gambling concerns each reach the function equipped to handle them.
The underage case
One dispute category requires separate treatment because it is not primarily a payment matter.
Where a chargeback arises because a person under the legal age used a household card to gamble, the operator has a problem considerably more serious than a disputed transaction. It has permitted underage gambling, which is among the most severely treated failures in this sector. In Britain, inviting, causing or permitting a child or young person to gamble is a criminal offence under section 46 of the Gambling Act 2005.
The correct handling is therefore not to contest the dispute. It is to refund, to close the account, to investigate how age verification was passed, and to treat the case as a compliance incident with the reporting that entails. Defending such a chargeback to protect a ratio would be a serious misjudgement, and the records of that defence would read very badly in any subsequent review.
The preventive control is robust age verification at registration rather than anything in the payment layer. Where an operator finds underage cases arriving through chargebacks, the verification process has already failed, and the payment symptom is the least important part of the finding.
Signals worth monitoring
A consolidated list of the indicators that generally warrant investigation, drawn from the categories above.
Deposit followed immediately by withdrawal with minimal or no wagering, which is the classic laundering and stolen instrument pattern.
Multiple payment instruments added to one account in a short period, particularly where names do not match.
Payout details changed shortly before a withdrawal request, which is the standard account takeover signature.
Login from an unexpected location or device followed by financial activity.
Clustering across accounts, where device fingerprints, addresses, instruments or behavioural patterns coincide between nominally unrelated customers.
Activity confined to promotional qualification, with play stopping once conditions are met.
Wagering-to-deposit ratios far below normal, indicating the account is being used to move money rather than to gamble.
Repeated failed deposit attempts across several instruments, which may indicate stolen card testing and may equally indicate a customer whose funds are exhausted, which is why this signal must be assessed against both fraud and responsible gambling frameworks rather than either alone.
That last example illustrates the governance point made earlier. The same observable behaviour can indicate criminality or distress, and a control framework that routes it automatically to one conclusion will regularly reach the wrong one.
Where the effort actually pays
To close, an ordering of interventions by return, since fraud and chargeback work can absorb unlimited effort.
Clear merchant descriptors prevent a common and avoidable category of chargeback at essentially no ongoing cost. This is the highest-return action available and is frequently deferred for privacy reasons that deserve examination rather than assumption.
Robust identity verification at registration prevents multiple fraud types simultaneously and supports representment on everything else. In Britain it is also a regulatory requirement, since online licensees must verify a customer's name, address and date of birth before the customer is permitted to gamble, which means the work is being done anyway and the question is only whether it is being done well.
Evidence assembly for representment converts disputes the operator would win into disputes it does win, and the constraint is usually retrievability rather than the existence of the data.
Segmented controls release acceptance on low-risk populations while maintaining protection where it matters, which improves both sides of the trade-off simultaneously.
Responsive complaint handling intercepts disputes before they become chargebacks, which is cheaper than contesting them.
Behavioural monitoring catches laundering and collusion patterns that transaction-level controls miss, and is where the more sophisticated work sits.
Tightening deposit controls comes last, because it is the intervention most likely to cost more in declined legitimate customers than it saves in prevented fraud, and because operators reach for it first precisely because its benefits are visible and its costs are not.