Low Chargebacks Do Not Prove a Good Merchant
Executive summary
The Federal Trade Commission’s September 4 settlement with Nuvei is easy to read as another payment-processor enforcement action: the company agreed to pay $4.85 million and accept merchant-screening and monitoring requirements after the agency alleged that Nuvei companies enabled deceptive merchants, including an offshore tech-support operation.
The more consequential lesson is about measurement. Chargeback rates are one of the payment industry’s most familiar merchant-risk signals, but they are not a reliable verdict on merchant quality. The FTC alleges that Reimage transactions were distributed across accounts, billing descriptors and processors in ways that reduced the chance that any one account would cross network monitoring thresholds. A merchant-level problem could therefore look acceptable at the account level.
The mainstream response will be to tighten chargeback thresholds and add more automated alerts. That is necessary and incomplete. The proposed order requires calculations both by individual account and in aggregate by client, but it also requires website reviews, complaint analysis, marketing-material review, internet searches and test calls. The control design recognizes that a clean ratio can coexist with evidence of deception elsewhere.
The contrarian thesis is that merchant risk cannot be reduced to a better transaction score. It is an entity-resolution and knowledge-governance problem. Processors must connect beneficial owners, domains, descriptors, merchant category codes, processing accounts, complaints, prior terminations and sales practices into one reviewable merchant record. The economic tradeoff is real: overly broad de-risking can exclude legitimate startups and high-variance businesses. The FTC’s own commissioners said the standard is knowledge, constructive knowledge or conscious avoidance, not strict liability for every bad merchant transaction.
This thesis would be weakened if aggregated chargebacks consistently identify deceptive merchants early enough to prevent material harm, or if non-transactional reviews add little incremental detection after controlling for false positives and review cost. The Nuvei record points in the opposite direction: the agency alleges that warnings accumulated across years while processing continued.
Market context
Payment processors control practical access to card acceptance for a large share of merchants. That position creates two incentives that can conflict. Processors earn revenue from approved volume, including merchants that are costly or difficult to underwrite. They also carry network, bank, regulatory and reputational exposure when merchant conduct produces fraud, disputes or consumer harm.
On September 4, the FTC announced a proposed settlement with Nuvei Corporation and several subsidiaries. According to the agency’s press release, Nuvei will pay $4.85 million for consumer redress and accept restrictions on serving certain tech-support sellers, avoiding risk controls, and screening and monitoring clients. The complaint and stipulated order were filed in federal court; the agency notes that a complaint states allegations and that the court will decide the case.
The FTC complaint alleges that Nuvei entities processed more than $30 million in consumer payments for Reimage from 2017 through 2023. It says the defendants opened multiple merchant accounts, used merchant-of-record channels and distributed sales and chargebacks in ways that obscured excessive dispute activity. Nuvei agreed to the settlement; the order is not a judicial finding that every allegation is true.
The case follows the FTC’s 2025 settlement with Paddle over alleged payment processing for the same tech-support operation and its 2024 action against BlueSnap. The common thread is not simply high chargebacks. It is the claim that intermediaries had or avoided knowledge of merchant misconduct while preserving access to payment rails.
Chart-ready table: alleged Reimage processing and risk signals
| Period / event | FTC allegation or disclosed measure | Why the signal matters |
|---|---|---|
| Feb.-Jul. 2016 | Monthly chargeback rates through SafeCharge Digital accounts exceeded 1% each month; one month reached 4.91% | Persistent excess disputes preceded later direct onboarding |
| Feb. 2017 review | Reimage rates reached 2.85% on Visa and 1.72% on Mastercard | Internal review identified the merchant as risky before migration |
| Jan. 2017-Jul. 2023 | More than 310,000 Reimage transactions and $28 million net sales through accounts in the names of Reimage and SafeCharge Digital | Shows the scale and duration of direct processing alleged |
| Sep. 2017-Jul. 2023 | An additional 89,000 Reimage transactions and $3.8 million net sales through Upclick accounts | Merchant-of-record routing created another processing channel |
| Sep. 2018 | Mastercard placed a Reimage-related descriptor into its Global Merchant Audit Program after six months of excessive chargebacks and high fraud-to-sales ratios | Network-level escalation supplied evidence beyond a single month |
| Jan. 2019 | Mastercard audit flagged 82 client accounts; alleged issues included 39 unregistered-payfac accounts, 18 suspected shell-company accounts and at least 20 suspected load-balancing accounts | Portfolio structure and identity anomalies were visible alongside disputes |
| Early-May 2020 | Visa warned of alleged Microsoft impersonation and later issued a EUR25,000 fine | A conduct-specific warning went beyond statistical inference |
| 2021 | Complaint cites an internal report showing 1,108 chargebacks on 12,934 sales, or more than 8.5%, for one Reimage account | Even after volume diversion, remaining activity showed severe dispute levels |
Source: FTC complaint filed September 3, 2026, paragraphs 65-85 and 108. Currency is nominal U.S. dollars except the Visa fine, which is euros. Transaction counts and sales are cumulative flows for the stated periods; chargeback rates are period ratios and are not additive. Values are allegations in a pending case, not independent measurements or judicial findings. The $3.8 million Upclick figure reflects net sales as presented in paragraph 69; a later paragraph cites approximately $4.1 million after refunds and chargebacks, so the table uses the earlier paired transaction-and-sales disclosure and does not reconcile the difference.
Findings
Finding 1
Account-level thresholds can be defeated by portfolio structure.
Card-network monitoring is built around ratios and counts because those measures scale. The complaint describes Visa programs that used both monthly chargeback counts and chargeback-to-sales ratios and cites a Mastercard threshold of more than 1.5% for two consecutive months. Those rules can identify a merchant generating disputes at a rate far outside the norm.
But a threshold only sees the unit being measured. If one underlying seller can use several merchant accounts, billing descriptors, merchant-of-record relationships or acquiring channels, volume and chargebacks can be distributed. The FTC alleges that Reimage activity was handled through direct accounts, SafeCharge Digital accounts and Upclick accounts. It also alleges that the defendants used or discussed other acquiring relationships as backup when network warnings approached.
This is why the stipulated Nuvei order requires monthly chargeback calculations for every individual processing account and in aggregate for each client. It also requires identifying all processing accounts during an investigation. The control is not just a stricter number; it changes the denominator from account to economic entity.
That principle extends beyond deliberate evasion. Legitimate global merchants often use multiple acquirers, local entities and descriptors for resilience, authorization performance, currency acceptance and regulatory reasons. Payment orchestration makes such routing easier. The same architecture that improves uptime can fragment risk visibility. Processors therefore need a canonical merchant identity that sits above terminals and routes without treating all multi-acquirer activity as suspicious.
Finding 2
Transaction telemetry is a lagging indicator of a merchant’s sales conduct.
A chargeback arrives after a customer has paid, noticed a problem, attempted or skipped merchant support, contacted an issuer and completed enough of the dispute process to enter the processor’s data. Some harmed customers do not dispute at all. Others accept a refund, fail to recognize their rights or write a complaint elsewhere. A merchant can consequently generate meaningful harm before the payment ratio becomes decisive.
The FTC’s allegations show why other evidence matters. They include allegedly misleading business descriptions and category codes, nominee directors, false locations, prior terminations by other providers, consumer complaint boards, websites flagged for content violations, marketing scripts and direct warnings from networks. None is perfect alone. Together they can establish what the processor knew or should have investigated.
The order operationalizes that broader view. For covered client categories, it requires reviews of websites from an IP address not associated with Nuvei, public and third-party complaints, transaction patterns, internet search results and representative marketing materials at least monthly. It calls for quarterly test calls, plus test shopping and validation of consumer authorizations during investigations.
This is costly, manual work. That is precisely why the merchant-risk operating model matters. Automation should assemble evidence and prioritize cases; it cannot declare sales practices lawful from transaction data alone. A model trained only on chargebacks will reproduce the blind spots created by missing disputes and fragmented accounts.
Finding 3
The enforcement standard is knowledge, not zero merchant fraud.
An aggressive reading of processor liability could produce a blunt response: reject young, unfamiliar or high-variance merchants because some will turn out to be bad. That would protect the processor by shrinking access to payments, but it would also harm legitimate businesses and competition.
The FTC commissioners addressed this concern directly in their joint statement. They said Section 5 should not create strict liability whenever a merchant commits fraud. In their view, liability requires that the processor knew, should have known or consciously avoided knowing that the merchant’s transactions involved unlawful conduct. They also warned that low chargebacks do not negate knowledge supplied by other facts.
That distinction turns compliance into a decision-record problem. A processor will sometimes onboard a merchant with unusual risk and still be acting in good faith. The defensible question is whether it collected the relevant evidence, tested inconsistencies, documented why the remaining risk was acceptable, set monitoring conditions and responded when facts changed.
Written policies are insufficient if commercial pressure can silently override them. The complaint alleges that internal policies barred merchants with excessive chargebacks, deceptive-practice flags or obscured ownership, yet exceptions were made. Operators should treat overrides as first-class risk events: named approver, evidence, time limit, exposure cap, review date and a record visible to compliance and sponsor banks.
Implications for operators
Build risk views at the merchant-family level. Link legal entities, owners, domains, customer-service numbers, IP addresses, descriptors, merchant category codes, terminals, processors and bank accounts. Calculate disputes and returns by account, route and aggregated family. Preserve the legitimate operating reason for each linkage and split so analysts can distinguish resilience from concealment.
Separate monitoring thresholds from closure decisions. A ratio can trigger review, but the review should weigh complaints, marketing claims, authorization evidence, refunds, prior provider actions and identity changes. Conversely, conduct-specific evidence can justify investigation even when the ratio remains below threshold.
Measure the commercial cost of exceptions. Report revenue, volume and margin from merchants with expired reviews, overridden declines, repeated warnings or unresolved identity discrepancies. This does not make revenue suspicious; it makes the incentive visible. Senior management and sponsor banks should see where risk decisions are economically hardest.
Create stop rules that survive organizational boundaries. The order gives Nuvei 60 days after commencing certain investigations to stop processing and close accounts unless a written report establishes by clear and convincing evidence that the relevant practices are not deceptive or unfair. Other processors need not copy that legal standard to benefit from an investigation clock, a documented burden of proof and an independent approver for continued processing.
Finally, test merchant-risk models against harm found outside the chargeback channel. Back-test whether complaint boards, regulator notices, test calls, refund patterns and website changes would have identified cases earlier. A lower chargeback rate is valuable only if it reflects fewer harmed customers, not better fragmentation or more refunds designed to prevent disputes.
Risks & open questions
The record is allegation-heavy. The court has not adjudicated the complaint, and public documents do not provide Nuvei’s full evidence, response history or portfolio-wide false-positive rates. The proposed settlement imposes company-specific obligations and should not be presented as a universal legal checklist.
Aggregation also creates its own errors. Common owners can operate genuinely different businesses, shared infrastructure can link unrelated sellers, and merchant-of-record platforms have legitimate models. Poor entity resolution can contaminate one merchant with another’s risk and exclude lawful businesses.
Manual reviews can become performative. Website screenshots and test calls matter only if findings change decisions. Processors need quality assurance that samples cover the actual customer journey, including localized pages, affiliates, post-purchase flows and scripts that may differ by channel.
The falsification tests are practical. Track how many material cases are found first by aggregate chargebacks versus complaints, identity links, marketing review or external warnings; measure time from first signal to restriction; and compare consumer loss, false positives and review cost. If account-level transaction controls catch problems early with low harm and broader evidence adds little, the thesis should be narrowed. If non-transactional signals lead, the industry is underinvesting in knowledge systems.
Appendix / methodology notes
This report uses the FTC’s September 3 complaint, September 4 proposed stipulated order, September 4 press release and September 4 joint commissioner statement as primary sources. The complaint contains allegations. The proposed order reflects agreed restrictions but does not by itself establish the truth of every allegation. The report avoids treating quoted internal communications as adjudicated fact.
Chargeback rate is defined in the order as monthly chargebacks divided by total credit- or debit-card transactions. For covered clients, the order calls for a reasonable investigation when, in any two of the prior six months, the monthly rate exceeds 1.0% and the count exceeds 75 for an individual account or the aggregated client. It sets a parallel ACH trigger above a 2.5% total return rate and more than 40 returned transactions. These are order-specific investigation triggers, not universal network standards.
The chart-ready table is a chronology rather than a continuous statistical series. Periods differ, figures overlap and the underlying data are not available at transaction level. It should not be plotted as a time series without the monthly source data. A useful future chart would show monthly sales, chargebacks, refunds and prevented chargebacks aggregated across all linked accounts and processors, with network warnings and review decisions annotated. That dataset is not public.