Marketplace Fraud Prevention: How to Stop Buyer Fraud, Seller Fraud, and Collusion

In your own store, fraud has a single face: somebody pays with another person's card, or lies about a parcel that never arrived. In a marketplace, you have two sides, so you have three kinds of fraud.
The third one, collusion between a buyer and a seller, most likely has nobody in your organization assigned to detect it.
Three different frauds need three different defenses, built in three different places in the system. The budget usually gets approved for the first of them only, because that one is familiar from 1P.
Marketplace fraud prevention has to cover three separate frauds: a buyer who pays with somebody else's card, a seller who ships nothing, and a buyer and seller who are the same person. Each one is caught at a different moment: at payment, at payout, and in the relationships between accounts.
Each therefore needs a defense built in a different place in the system. The budget usually covers the first one, because that is the fraud familiar from selling your own stock.
This article breaks down:
- Which 3 kinds of fraud does a marketplace face?
- Why does collusion never show up in your metrics?
- Which warning signals can only you see?
- Who carries the loss when a seller disappears?
Key insights
- Three frauds need three defenses in three places. Most anti-fraud budgets cover only the one carried over from selling your own stock.
- In collusion nobody is harmed enough to complain, so every complaint-based metric you run reports a model partner.
- A party whose payout depends on a status cannot be the source of that status. Take the fact of delivery from the carrier or the buyer.
- To earn back a single €1,000 loss at a 12% commission you have to push more than eight thousand euros of clean sales through the platform.
- Your payout policy decides how much you lose to seller fraud and collusion. A filter on the payment side cannot reach either of them.
Which 3 kinds of fraud does a marketplace face?

Take one order we will keep coming back to: a €1,000 cart at a 12% commission. You are owed €120 and the seller €880.
1. Buyer fraud
This is somebody who pays with another person's card, or with their own, and then claims the goods never arrived. The defense sits in the moment of payment and the proof of delivery.
2. Seller fraud
This is somebody who takes the money and ships nothing, or ships something else. The defense sits in the moment of payout.
3. Collusion
This is the case where the buyer and the seller are the same person, or two who have agreed in advance. The defense does not sit in any single event.
It sits in the relationships between accounts. Which is why it is usually missing.
The difference is structural. The first two frauds get reported to you by somebody who was harmed: the buyer calls, the bank sends a claim, the seller protests.
In collusion there is no injured party to speak up, because both sides of the transaction want the same thing. And every quality metric you run measures complaints: the incident rate, the return rate, response time, the rating.
A seller in collusion produces none of those. On your dashboard they look like a model partner.
On top of that comes an asymmetry worth knowing right away: to earn back a single €1,000 loss at a 12% commission, you have to push more than eight thousand euros of clean sales through the platform. In 1P you lose the margin on the product.
In 3P you lose the whole value of the cart and earn a fraction of it.
How does buyer fraud work on a marketplace?
The mechanics are the same as in 1P. A stolen card, an account opened today, expensive goods that are easy to resell, a delivery address different from the billing address.
Or a subtler variant: the genuine cardholder really does buy, receives the goods and reports that they never arrived. The industry calls that "friendly fraud," or first-party fraud, and it differs from theft in that there is no victim here other than you.
In a marketplace, two things change, and both work against you.
1. You do not control the evidence
Winning a dispute over "it never arrived" rests on confirmation of delivery. The seller shipped the parcel, with their own carrier, on their own account.
What you have is a number somebody typed into a form. If you are not pulling statuses straight from the carrier, your evidence is somebody else's declaration.
2. The money has already been paid out
The bank takes €1,000 back from you and €880 sits with the seller. With an honest seller that is a deduction from future sales and one phone call.
With a seller who is already gone, that is the full €1,000.
This article does not cover the mechanics of a chargeback. That has its own chapter.
Something else matters here: what you decide is whether, at the moment of the dispute, you still have anything to cover it from.
How does seller fraud work, and why is the payout cycle the defense?

The simplest seller fraud needs no technology at all. The seller posts an attractive offer, takes the orders, generates the labels, and ships nothing.
In the system the order carries the status "shipped," because a tracking number is what flips that status. Then the clock starts.
After a set time from shipping, most platforms mark an order as delivered on their own, because otherwise no settlement would ever close. The order matures, it enters the pool, the payout goes out.
The more expensive variant is the empty parcel: a shipment genuinely sent and delivered, except that what is inside is a weight. You then hold a complete set of delivery evidence and lose the dispute against a buyer who is telling the truth.
Work out the pace. A seller with a credible account and an aggressive price does 60 orders over a weekend: €52,800 of receivables due for payout, and 60 customers who will work it out on Monday or a week later.
If your payout cycle falls inside that window, the money leaves before anybody has had time to complain.
Two rules follow from that, and both are decisions somebody has to make:
- A party whose payout depends on a status cannot be the source of that status. Take the fact of delivery from the carrier or the buyer, never from the seller's declaration.
- A new seller is a different risk profile from a seller with history. A slower first payout cycle and a reserve are what handle that difference. The classic scheme is called the bust-out: a dozen or so honest small transactions, good ratings, then one jump in volume and a disappearance.
The same family covers frauds aimed at your business model: taking the customer off the platform and counterfeit goods. In practice, the first is caught only reactively.
What is collusion between a buyer and a seller?
This is where a marketplace stops resembling a store. The same person controls the buyer account and the seller account.
The order is genuine in every field of the database: there is an offer, there is a payment, there is a shipment, there is a delivery, there is no complaint. The only things missing are the goods and two independent parties.

Version one: moving money out of stolen cards. The buyer pays with another person's card.
The seller, who is that same person, collects €880 in the next payout. Your €120 of commission has been booked as revenue.
Weeks or months later a claim arrives from the bank, you hand back €1,000, and the seller's account is empty.
Version two is worse, because at no point does it look like fraud: fictitious turnover as money laundering. Nobody steals a card.
The buyer pays with their own dirty funds. The seller receives a payout into a company account, with your settlement report and your commission invoice as the paperwork.
The money leaves your platform as clean sales revenue, with documents that justify it. In that arrangement your commission is a cost of the operation.
Twelve percent is a price an outfit like that pays without blinking. Publications on anti-money laundering describe this family of schemes as "transaction laundering": a legitimate sales channel used to give the appearance of a transaction that never made economic sense.
The cheaper and more common variant of the same problem is artificial turnover on a seller's own offers. The point is to build a sales history, win visibility or pad the ratings.
There may be no financial loss at all, and the damage lands elsewhere: the algorithm that picks the winning offer starts promoting somebody who buys from themselves. Honest sellers notice that faster than you do.
That is the whole difference between a marketplace and a store. In a store you are always the counterparty, so there is no way to strike a transaction in which both sides want the same thing.
In a marketplace there is. Nothing in the default set of controls sees it.
How do the 3 frauds compare?
What does the setup decide? | Buyer | Seller | Collusion |
|---|---|---|---|
Who reports the problem | the buyer's bank | the buyer | nobody |
When you find out | weeks to months | days | by accident, or with a claim from a bank |
What you see in the quality metrics | a rise in disputes | a rise in incidents and returns | a model seller |
Where the defense sits | payment, identity verification, proof of delivery | the moment of payout: maturing, the reserve, the source of status | relationships between accounts |
Real loss on a €1,000 cart | €1,000, if you do not recover it from the seller | €1,000 plus the cost of handling it | €1,000, many times over, before you notice |
Does 1P know this problem | yes | partly | no |
Who usually has it in their job description | the risk team or the payment provider | seller operations | nobody |

Which warning signals can only the platform see?
None of the signals below is proof on its own. Their value is in the combination, and what they have in common is that they are relationships between accounts.
Your payment provider will not see them, because they do not have your order graph.
1. At registration
Watch for the same bank account, address, phone number, or device on the buyer side and on the seller side · a company registered recently alongside a high-value assortment · a seller who will not hand over documents but wants to sell immediately.
2. In the offer
Watch for a price significantly below market on goods that are easy to resell · sudden volume with no history · an assortment that changes from week to week.
3. In the orders
Watch for a buyer who buys only from one seller · repeating, round amounts · zero returns and zero contact with support at high volume · delivery recorded immediately after shipping · delivery addresses that repeat across different buyers.
4. At payout
Watch for a change of bank account just before the cycle · a payout request that does not match the age of the account · a jump in cart value after a period of quiet selling.
Treat the takeover of an honest seller's account separately. The attacker's first move is usually a quiet change of the payout account or of the notification email address.
The account then carries a real history and passes every reputation-based check. Changing payout details should be an event that triggers something.
What does marketplace fraud change about your other decisions?
1. Who carries the loss depends on the payment setup
If the payment provider splits the money on their side and you appear as the intermediary entity for your sellers, card scheme rules place responsibility for those sellers on you. "I do not touch the money" does not mean "I will not carry the loss." Check the exact split in your contract with the payment provider before you settle the model.
2. Seller verification is now an obligation
EU platform law requires you to collect and verify sellers' identification data, and to react when that verification fails. Confirm the scope with a lawyer.
That is the subject of the next article.
3. Money laundering stops being theoretical
The obligations follow from what your business formally does. That is a question for the lawyer at the first meeting.
4. Payout policy is your main anti-fraud instrument
That policy decides how much you lose to seller fraud and to collusion.
How do you check whether you are ready for marketplace fraud? 7 questions

Four questions for the platform vendor and three for yourself.
- Where does the system get the fact of delivery from? If the answer is "from the tracking number the seller typed in" or "automatically after X days," you do not have proof: you have a guess, and that guess is what you will defend yourself with in a dispute.
- Can you stop the payout to a single seller immediately, with no deployment? Ask for a live demonstration. That is the only button that genuinely stops a loss.
- What does the system know about relationships between accounts? Will it show that a buyer and a seller share a bank account, an address or a device? If not, detecting collusion will be manual work on your side. That is a line in the headcount budget.
- Which signals come as standard, and which have to be bought separately or built? "We have an integration with an anti-fraud tool" usually means the buyer side of the defense. Ask explicitly about the seller side and collusion.
And for yourself: who, by name, looks at this every week? Can that person block a payout without the sales team's approval?
What annual loss do we accept before we decide the controls cost too much? The last question is the one asked least often and the most important: a defense with no agreed risk appetite will always be either too expensive or too weak, and you will never know which.
Which mistakes do operators make about marketplace fraud?
1. The anti-fraud policy carried over from 1P unchanged
It protects one vector out of three, and the report looks good, because it measures only what it protects.
2. Treating the absence of complaints as evidence of quality
In collusion the absence of complaints is a warning signal. A return rate close to zero at rising volume deserves a second look.
3. A payout cycle set as a commercial promise
"We pay within 48 hours" can be a recruiting argument and an invitation at the same time. If you promise speed, you need a reserve and an instant block.
4. Assuming the payment provider will catch it
They see individual transactions, and the account graph is yours alone. A bank account shared by a buyer and a seller is visible only to you.
5. Changing payout details treated as an ordinary profile edit
The cheapest fix on this list, and the one most often skipped.
What do you still have to settle yourself about marketplace fraud?

This guide does not settle what kind of entity you are under money laundering rules, nor which identification obligations apply to you. That depends on the payment model, the country, and the scale, it changes faster than documents like this one, and it needs confirmation from a lawyer and from your payment provider.
That goes double if buyers' funds land in your account even for a moment.
This guide does not settle how much to spend on defense either. There simply is no credible market figure for "fraud losses as a percentage of marketplace turnover." The values in circulation measure different things, in different categories, under different return policies.
Calculate it on your own data after the first quarter. Until then, take a working assumption and design the system so that it can change without a rewrite.
You will not find the mechanics of chargebacks or of the seller verification process here. Both have their own chapters.
This article has one job: to show that there are three frauds and usually only one defense.
Summary: Where does each defense belong?
Buyer fraud is defended at payment and with proof of delivery you did not get from the seller. Seller fraud is defended at payout, with a slower first cycle and a reserve.
Collusion is defended in the account graph, and nobody else can see it for you.
Ask a vendor to demonstrate stopping a single seller's payout live, with no deployment. Talk to a marketplace expert if you want the seven questions sharpened before the demo.
Frequently asked questions on marketplace fraud prevention
What are the three types of marketplace fraud?
Buyer fraud, seller fraud, and collusion between the two. A buyer pays with a stolen card or claims a delivered parcel never arrived.
A seller takes orders and ships nothing, or ships a weight. In collusion one party controls both accounts, and the order is genuine in every database field except that no goods and no two independent parties exist.
How do you detect collusion on a marketplace?
By looking at relationships between accounts, because no single transaction looks wrong. A shared bank account, address, or device across a buyer and a seller, a buyer who buys only from one seller, repeating round amounts, and zero returns at rising volume.
Your payment provider cannot see any of it, because they do not hold your order graph.
Who carries the loss when a marketplace seller commits fraud?
Whoever the payment setup makes responsible, which is often the platform. Where the provider splits the money and you stand as the intermediary entity for your sellers, card scheme rules put those sellers' liability on you.
Not touching the money does not settle who absorbs the loss, so check the split in your provider contract.
Ready to build?
If you want to walk through these three scenarios on your own numbers and check which of them your current setup would even notice, let's talk.