By MFJ Staff | Sources: ZIGRAM, and FinTech Global
Key takeaway: Merchants, processors, and fintechs that still treat refunds and chargebacks purely as a fraud-operations cost risk missing the AML exposure building up underneath. Institutions running fraud and AML monitoring on separate systems may want to start with something simple: give both teams a shared view of refund and dispute activity.
Fraud teams and anti-money laundering (AML) investigators who monitor refunds and chargebacks in separate silos may be missing the money-laundering patterns hiding inside ordinary-looking payment reversals, according to RegTech provider ZIGRAM.
Taken alone, a disputed payment or a refund request rarely looks like anything more than routine customer activity, ZIGRAM’s analysis argues (cited by FinTech Global on October 2, 2026). But stack several behaviors from the same customer — purchases spread across different merchants, refunds routed through different channels, a bank dispute on top of that, and the resulting money shuttled between accounts, cards, or wallets — and a different picture starts to form.
Fraud teams are typically set up to judge a single transaction or dispute; AML investigators are built to spot patterns in money movement and the links between accounts and entities. Keep those two views apart, ZIGRAM says, and coordinated activity spanning several merchants or payment instruments can slip through undetected by either team.
ZIGRAM is pushing for a unified FRAML (fraud plus AML) model that folds payment fraud detection, transaction monitoring, and broader financial-crime analysis into a single view. Among the red flags it lists: high-frequency refunds from different merchants landing in one account; refunds sent to a different payment instrument than the one originally used; cross-border refunds routed to foreign cards or wallets in higher-risk jurisdictions; and refunded funds moved quickly into crypto exchanges or third-party accounts.
The firm also points to organized refund-as-a-service operations run on platforms like Telegram and Discord, where groups coordinate bulk “did not arrive” claims across accounts linked by shared devices or delivery addresses.
One case ZIGRAM cites in its analysis: a U.S. Department of Justice prosecution in which the defendant, who ran a merchant-account facilitator called CB Surety, pleaded guilty in August 2026 to conspiracy to commit bank fraud. According to DOJ’s own case filings, he and his co-conspirators pushed at least $111 million in transactions through accounts opened under sham companies and straw owners, using manipulated chargeback ratios to keep those accounts open at banks that would otherwise have shut them down.
Why it matters: Return fraud isn’t a new cost center — the National Retail Federation and Appriss Retail put 2023 losses at roughly $101 billion, or about 13.7% of all returns, with more recent Appriss Retail/Deloitte data putting the 2024 figure at $103 billion and 15.14% of returns.
What ZIGRAM’s analysis adds isn’t the size of that number but the argument for what to do with the data behind it: treat refund and chargeback activity as a compliance signal, not just a fraud-ops loss. For banks, processors, and fintechs, that means refund and dispute feeds that have traditionally stayed inside fraud operations may need to reach AML transaction-monitoring systems before a pattern turns into a Suspicious Activity Report problem instead of a chargeback one.
Sources: ZIGRAM; FinTech Global












