What's actually changing across card networks and fraud tactics right now, summarized in plain English — for a merchant deciding what to act on, not a compliance department writing a policy.
Visa's Acquirer Monitoring Program (VAMP) — the framework that replaced the older Visa Dispute Monitoring and Visa Fraud Monitoring programs — moved to stricter enforcement in 2026. The merchant "Excessive" threshold dropped from 2.2% to 1.5% (combined fraud-plus-dispute ratio) effective April 1, 2026, and acquirers themselves now face their own tighter bands: 0.7% for "Excessive" and 0.5% for "Above Standard," with enforcement that began January 1, 2026.
The mechanics matter more than the headline number. VAMP counts fraud and disputes together — TC40 fraud reports plus TC15 dispute records, divided by total settled card-not-present transactions — and increasingly holds the acquirer's whole portfolio accountable, not just an individual merchant in isolation. That's part of why some payment processors have gotten more selective about onboarding higher-risk small merchants over the past year: a few problem accounts can now affect the acquirer's own standing.
For a small or mid-size merchant, the practical takeaway isn't the exact percentage — it's that ratio, not raw dispute count, is what determines risk classification, and a modest-volume business can cross that ratio faster than a much larger one. First violations do get a three-month grace period before formal enrollment, which is a reasonable window to fix root causes rather than just fight individual cases.
Source: Merchant Risk Council
Industry-wide dispute volume climbed from roughly 238 million to 337 million transactions between 2023 and 2026 — a 41% increase — and the true cost runs well past the disputed amount itself. Recent estimates put the effective multiplier at $4.61 in total cost for every $1 lost to fraud once chargeback fees, operational overhead, and lost merchandise are counted in, a 37% increase from five years earlier.
The more useful number for most small and mid-size merchants isn't the fraud figure — it's the friendly fraud figure. Merchants report that friendly fraud (a legitimate cardholder disputing a transaction they actually made) accounts for an average of 43.8% of their chargebacks, and several industry analysts believe the real rate is higher once undetected cases are factored in. Merchants who do represent disputes win close to that same 43.8% of cases on average, but the practical recovery rate — after accounting for second-cycle disputes and cases that are never contested at all — lands closer to 10.7%.
That gap between "win rate on cases fought" and "practical recovery rate" is the real story: most of the recoverable revenue is lost not because the evidence is weak, but because the case is never fought in the first place.
Source: Chargebacks911
Deepfake-related fraud attempts now account for roughly 11% of global fraudulent activity, and sophisticated, AI-assisted fraud overall grew an estimated 180% compared to 2024. A meaningful part of that growth is document forgery assisted by generative AI — a category that was close to negligible in prior years and is now a measurable share of fake documents submitted during onboarding and verification.
For chargeback and payment-risk purposes, the relevant shift isn't the deepfake headline itself — it's what sits alongside it. Account takeover remains the second most common type of third-party fraud (behind identity theft), and card testing continues to be a significant share of third-party payment fraud. Together, these point toward the same operational answer: verification quality at the point of account creation and checkout increasingly matters as much as dispute response after the fact, since a growing share of fraud is now designed specifically to pass basic identity checks.
None of this changes the fundamentals of good chargeback hygiene — it raises the bar on the fraud-prevention side that sits upstream of it.
Source: Sumsub
Mastercard consolidated its dispute categories back in 2016 around a smaller set of core reason codes — 4808 (authorization issues), 4834 (processing errors like double billing), 4837 (no cardholder authorization — the primary fraud code), 4849 (questionable merchant activity, tied to Mastercard's GMAP monitoring), 4853 (general cardholder disputes, including recurring billing and "not as described"), and 4854 (a US-only catch-all). What trips merchants up is that Mastercard never fully retired the legacy codes underneath this simplified structure, so older documentation and some processor dashboards still reference terminology that no longer maps cleanly to current practice.
Deadlines vary by code and shouldn't be assumed uniform: reason code 4849 disputes carry a 45-day response window, while 4854 has its own conditions (transactions over $50 occurring within 100 miles of the cardholder's billing address, in the US). The two most common merchant mistakes remain the same as they've always been — proceeding without proper authorization confirmation, and not resolving a customer's complaint directly before it escalates into a formal dispute. Both are avoidable with process, not new technology.
Source: Chargeflow