# Nine fraud types in payments and their legitimate twin

Nine fraud types in payments, each one next to the honest customer who leaves the same trace: card testing, velocity, first big purchase, identity rings, social engineering, the patient one, the sleeper, synthetic identity and bad-faith disputes.

2026-08-09 · https://frauddi.com/en/blog/tipos-de-fraude/

---
Lists of fraud types describe what the attacker does. This one adds who else, inside your own customer base, leaves exactly the same trace.

That customer always exists, and they are the one who pays the bill when you block a pattern blindly. We call them the legitimate twin of the fraud type: the honest behaviour that produces the same signal as the attack.

This series covers nine fraud types. There are many more, and new variants show up all the time. These nine are the ones that come up daily in payments and lending, and the ones that most often end up hitting an honest customer by mistake.

Each one comes in three parts: how it attacks, who looks the same and is honest, and how the attacker mutates once you start detecting them. They run from the loudest to the most invisible.

- Card testing

- Velocity

- First big purchase

- Identity rings

- Social engineering

- The patient one

- The sleeper

- Synthetic identity

- Bad-faith dispute


## 1. Card testing

Attacks by: running through a batch of stolen cards with minimum charges to see which ones are still alive, dropping the ones that decline.

Legitimate twin: the student who always buys the cheapest thing, the customer with no money left retrying for less each time, and the new user who types the CVV wrong.

Read part one →


## 2. Velocity

Attacks by: squeezing a single stolen card for everything it has before the cardholder reports it.

Legitimate twin: the shop owner running all the business purchases in two hours, and the person who pays every bill of the month in one sitting.

Read part two →


## 3. First big purchase

Attacks by: a freshly built identity, one large purchase, then gone.

Legitimate twin: the customer who barely uses your product and today is buying the appliance they had been putting off.

Read part three →


## 4. Identity rings

Attacks by: several fake identities run by the same person, with fewer devices than identities.

Legitimate twin: the family sharing one card across four phones, and the person rotating cards to optimise rewards.

Read part four →


## 5. Social engineering

Attacks by: holding every real detail of the victim, so the transaction looks flawless except for the device.

Legitimate twin: the customer travelling, and the family sharing a card across several devices.

Read part five →


## 6. The patient one

Attacks by: avoiding every obvious signal, watching their own risk level and pulling back the moment it rises.

Legitimate twin: any customer with a mid-range ticket and mid-range frequency.

Read part six →


## 7. The sleeper

Attacks by: weeks of boring, correct activity, and a single day where they take everything.

Legitimate twin: the freelancer who gets paid for a project, catches up on everything in three days, and goes quiet again.


## 8. Synthetic identity

Attacks by: fake details that look real, weeks of building trust with on-time payments, and one day draining the entire credit line.

Legitimate twin: the genuinely new customer, who also starts small and grows.


## 9. Bad-faith dispute

Attacks by: the real cardholder buying, receiving the product, and weeks later claiming they do not recognise the charge.

Legitimate twin: the teenager who used their parent's card, and the parent disputing in good faith.


## Why the twin matters

Risk teams know the fraud types. The problem shows up when the rule that cuts one of them also cuts its twin.

That is why the useful question is which of your customers looks like the fraud type hitting you.


### So how do you solve it?

Tuning this by hand takes days, and every day costs chargebacks and good sales. That is what we are solving at Frauddi. We will show you on your own data.

Written by Elio Rincón, founder of Frauddi. He writes about AI, security and fraud at e1i0.com.
