Mail Max

Your provider in email marketing

Chargeback Codes Cluster 9 Days After a First Deposit

· 2 min read
Chargeback Codes Cluster 9 Days After a First Deposit

Fraud teams at mid-size operators have a name for the pattern: the nine-day window. Across a sample of first-deposit accounts at three European-facing sportsbooks in 2024, the median gap between a successful deposit and the first chargeback code landing was 9 days — with 61% of those codes arriving between day 7 and day 12. Not day 30, when the friendly-fraud crowd usually gets around to disputing. Day nine, like clockwork.

Why nine days is not a coincidence

A chargeback code isn't a random event. It's the acquirer's classification of why a cardholder or issuing bank reversed the transaction. Visa's 10.4 ("other fraud – card-absent environment") and Mastercard's 4837 ("no cardholder authorization") behave differently in timing terms, but both cluster around the point where a stolen card's real owner checks a statement.

That's the mechanism. A card gets compromised, the number circulates on a resale channel, a mule account opens at your casino, deposits arrive, the account plays low-variance slots or lays off bets on a heavy favourite, and the real cardholder notices the line item during their next statement review or a bank app push notification. Statement cycles vary, but the practical lag between "card used fraudulently" and "cardholder disputes" sits at roughly one to two weeks.

Nine days is the average of that lag, not a magic number.

What the cluster actually looks like operationally

If you pull the data, the shape is not a bell curve. It's bimodal.

  • Days 1–3: genuine mistakes — duplicate deposits, a customer who forgot they signed up, an accidental double-tap. These resolve cheaply and rarely escalate.
  • Days 7–14: the fraud cluster. Multiple codes, often from the same BIN range, often from accounts that share a device fingerprint or a payment instrument with one or two other accounts.
  • Day 30+: the "I lost and I'm trying it on" group. Lower success rate, but expensive to fight.

The middle band is where the money is lost. By the time the code lands, the funds have typically been withdrawn to a crypto rail or a second e-wallet, and the account has gone dormant. Recovery rates on 10.4 codes inside that window run under 20% in most operator datasets — the evidence trail is cold.

The signal you can act on before the code arrives

Chargeback codes are lagging indicators. The leading indicator is behavioural, and it shows up around day two or three:

  • Deposit velocity that doesn't match the KYC tier — a £20 initial deposit followed by £400 the next morning.
  • Play pattern that optimises for cashout speed rather than entertainment: minimum-wagering the bonus, then a single large bet on a 1.05 market.
  • Withdrawal attempt to a method that doesn't match the deposit method, especially a different name on the e-wallet.

None of these is proof. All three together, on an account that's under 14 days old, is worth a manual review. The cost of reviewing 100 accounts is trivial against a single successful 4837.

The uncomfortable part

Here's the tension nobody at the affiliate conferences wants to talk about: the friction that stops fraud is the same friction that stops legitimate first-time depositors. A 72-hour withdrawal hold, mandatory source-of-funds checks at low thresholds, and device fingerprinting at signup will cut your chargeback rate — and your conversion rate with it.

So the real question isn't whether operators can catch the nine-day cluster. Most can, with data they already hold. The question is whether the industry's current economics — where acquisition costs keep climbing and every extra verification step costs signups — will ever make that trade worth taking before a regulator forces it.