The Biggest Fraud Risk May Already Be Inside the Business - Travel And Tour World

The Biggest Fraud Risk May Already Be Inside the Business

Tuhin Sarkar Written by Tuhin Sarkar

Published

9 mins to read
Donald-kossmann-chargebacks911

Internal fraud is emerging as a critical but often overlooked threat for merchants, particularly across travel, hospitality and retail businesses where refunds, customer accounts and payment systems involve multiple employees and processes.

Chargebacks911 warns that nearly one in four merchants has experienced employee-initiated fraud or internal collusion, yet fewer than four in ten actively monitor for such activity. Unlike conventional external fraud, internal abuse can involve legitimate credentials, authorised system access and familiar workflows, making suspicious behaviour difficult to identify.

Refund manipulation, misuse of customer information, inappropriate account changes and employee-customer collusion can eventually generate chargebacks that appear indistinguishable from ordinary disputes.

In a Travel & Tour World written interview, Monica Eaton, Founder and CEO of Chargebacks911, and Donald Kossmann, Chief Technology Officer, explain why businesses must look beyond traditional fraud controls, connect operational and dispute data, strengthen access governance and use AI-driven monitoring to uncover hidden patterns before financial losses become entrenched.

Advertisement

Advertisement

1.     Your research finds that nearly one in four merchants has experienced employee-initiated fraud or in-house collusion. What are the most common forms of internal fraud currently affecting merchants?

Monica Eaton: “Internal fraud can take many forms, from deliberate refund manipulation and misuse of customer data to collusion between employees and customers. In travel and hospitality, that could mean manipulating a refund following a booking cancellation, directing a customer towards a chargeback instead of the correct refund process, or exploiting access to customer or payment information. What makes these cases difficult is that they do not necessarily resemble the fraud merchants have been trained to look for. The employee may be using legitimate access and following a familiar process, but manipulating it for an illegitimate purpose. That is the real blind spot – the loss is originating inside a process the business already trusts.”

Advertisement

Advertisement

2.     Why do you believe many merchants have spent years investing heavily in external fraud prevention while overlooking threats that may already exist inside their organizations?

Monica Eaton: “Most fraud prevention is built facing outward: businesses look for stolen credentials, suspicious transactions, account takeover and other signs that somebody outside the organization is trying to get in. However, internal fraud reverses that assumption. The person may already have legitimate access to the systems and information they need, so many of the barriers designed to stop an external attacker are no longer the barriers that matter.”

“There is also an ownership challenge, as internal risk can cross payments, operations, security, finance and HR, while fraud controls are often designed around much clearer responsibilities. When a threat sits between those functions, important signals can sit between them too.”

“Merchants have become very good at building higher walls. Internal fraud is a reminder that the threat does not always need to climb them.”

3.     The report shows that fewer than four in ten merchants actively monitor for internal fraud. Why is internal fraud still so difficult for businesses to track and detect?

Donald Kossmann: “Because the activity may not look fraudulent at the point it happens. An employee can sign in with valid credentials, use a familiar system and perform an action they are authorized to perform. A conventional fraud control may see nothing unusual. The signal often appears in what happens around that activity. Imagine a travel business seeing repeated refund failures associated with a particular workflow, followed by an unusual concentration of disputes. Neither event necessarily proves anything on its own but the relationship between them is what deserves investigation.”

Advertisement

Advertisement

“That is the technical challenge. Transaction data may sit in one system, refund activity in another, employee access somewhere else and disputes in another. Detecting internal fraud means connecting those events well enough to identify when apparently legitimate activity is producing an abnormal outcome.”

4.     How can an employee’s actions within refund processes, customer accounts or payment systems ultimately trigger a chargeback that appears identical to external fraud?

Monica Eaton: “A chargeback tells a merchant that a transaction has been disputed but it doesn’t necessarily tell them what originally went wrong inside their business.”

“If a customer is promised a refund and that refund is deliberately not processed, for example, the customer may eventually go to their bank. The resulting dispute may give the merchant little indication that the underlying problem originated internally. The business investigates what appears to be another customer dispute while the behaviour that caused it can remain hidden. That distinction matters because responding to the chargeback does not necessarily solve the underlying problem. If merchants cannot connect what happens in the dispute environment with what happened earlier in their own operations, they can end up repeatedly treating the symptom while missing the cause.”

5.     What specific warning signs or unusual patterns should merchants monitor across the dispute lifecycle to identify potential internal fraud or employee collusion earlier?

Donald Kossmann: “Do not look for one smoking gun but look for relationships that should not normally exist.”

Advertisement

Advertisement

“A refund failure on its own could be an error. Repeated refund failures around the same workflow followed by a concentration of disputes are more interesting. So are unusual concentrations of refunds, account changes or customer interactions connected to the same access patterns. For a hotel group, airline or travel platform processing large volumes of bookings and cancellations, those relationships can disappear into ordinary transaction noise very quickly. But the important thing is to connect dispute outcomes back to the activity that preceded them. That means looking across transactions, refunds, customer service interactions and access records over time.”

“Individual events can look perfectly legitimate but it’s often the pattern between those events that tells you something is wrong.”

Monica

6.     Why does the back-to-school and seasonal hiring period create greater pressure on internal fraud controls, particularly when retailers rapidly onboard large numbers of temporary employees?

Monica Eaton: “The risk is not that temporary employees are inherently less trustworthy but the nature of rapid operational change. Travel, hospitality and retail businesses can add large numbers of people around seasonal peaks while simultaneously handling more transactions, more customer enquiries, more cancellations and more refunds. Training is compressed, managers are under greater pressure and access may need to be granted quickly. All of that changes what normal activity looks like. That matters because unusual behaviour is harder to identify when the entire operating environment is unusually busy. Controls designed around an established team and predictable transaction patterns can become less effective when both change at once. Seasonal hiring should therefore be treated as a change in the business’s risk environment.”

7.     What role do weak onboarding procedures, expanded system access and limited oversight play in increasing the risk of internally generated disputes and financial losses?

Donald Kossmann: “Permission and legitimacy are not the same thing and that is a fundamental distinction. An employee may legitimately need access to a booking, refund or customer account system. The fact that they were authorized to use it does not mean every action performed through that access was appropriate.”

Advertisement

Advertisement

“Good onboarding therefore needs to establish more than whether somebody can access a system. Businesses need to understand what normal use of that access should look like, keep permissions proportionate to the role and review temporary access when it is no longer required.”

“Access controls only solve part of the problem. You also need an audit trail that shows how legitimate access was actually used and enough context to identify when that behaviour stops matching the role, process or circumstances for which the access was granted.”

8.     How can AI, machine learning and continuous dispute monitoring help merchants distinguish between genuine external fraud, consumer abuse, internal process failures and deliberate employee collusion?

Donald Kossmann: “The difficulty is that external fraud, consumer abuse, process failure and deliberate collusion can all eventually produce something that looks like another dispute, but looking at the dispute alone may not tell you which one occurred.”

“That is where AI and machine learning can be genuinely useful. Their value is in analysing volumes of behavioural, transaction and dispute data to identify relationships and changes that would be extremely difficult for people to find case by case.”

“Continuous monitoring matters for the same reason. Merchants need to understand whether a pattern is isolated or recurring, whether it is changing over time and whether an intervention actually changes the outcome. The objective is to understand the underlying source of losses well enough to respond to the right problem.”

Advertisement

Advertisement

9.     What immediate steps should merchants take before and during major seasonal hiring periods to strengthen internal controls and prevent unexplained chargeback losses from becoming an accepted cost of doing business?

Monica Eaton: “Start by removing the organizational boundaries around the issue. Internal fraud cannot belong exclusively to security, HR, operations or payments if the eventual financial loss crosses all four. Dispute data should be considered alongside refund activity, customer service information and internal operational records and not treated a completely separate issue.”

“For businesses preparing for a seasonal peak, that conversation needs to happen before volumes increase. Establish who owns the risk, what information they can see and how concerns move between teams when something unusual appears.”

Donald Kossmann: “From a systems perspective, establish what normal activity looks like before the peak begins. Keep access proportionate to each role, review temporary permissions when they are no longer required and maintain audit trails around processes involving refunds, customer accounts and payment systems.”

“Most importantly, connect downstream dispute outcomes with upstream operational activity. What appears later in the dispute environment can reveal something that was difficult to identify when the original activity occurred.”

Monica Eaton: “By the time a business can see the loss clearly, the behavior that caused it may have been happening for months.”

Advertisement

Share On:
Share on: X in w
Download the TTW app