The food left your kitchen. It was made, packed and handed over. Six weeks later you find a deduction on a statement for an order the customer says never arrived, and nobody can tell you which one of the four people who touched it is wrong.
Restaurant delivery fraud is the loss category that behaves least like everything else on the loss prevention list. There is no drawer to count and no camera angle that settles it. The money disappears after the point where your controls end, and it usually disappears through a platform whose dispute process you did not design. This guide covers each scheme, who ends up paying for it, and the controls that actually reduce it. For the other six places a restaurant loses money, see our guide to restaurant loss prevention.
Key Takeaways
- About 20% of food delivery accounts face takeover attempts, against roughly 2.5% across other industries, and takeover attacks in quick service rose 72% year over year in 2025 (Sift, retrieved 2026-09-29).
- First-party fraud, meaning customers who dispute orders they actually received, cost businesses an estimated $103 billion in 2024.
- Restaurants carry a low chargeback rate by industry standards, but a high share of the disputes they do get are refund abuse rather than real fraud.
- Proof of delivery is the single control that changes the outcome of a dispute. Almost everything else is prevention; this is evidence.
- Most schemes are recognisable at order time. Training staff to spot them beats fighting refunds after the fact.
Boost customer satisfaction with just a few clicks
Most-Loved Features:
- On-demand drivers
- Real-time GPS tracking
- Delivery confirmation photos
- Over 50% of customers report a smoother delivery experience
How restaurant delivery fraud works
Six distinct schemes account for most off-premise losses, and they are worth separating because the party who ends up paying differs in each one.
| Scheme | What happens | Who absorbs the loss | The control |
|---|---|---|---|
| False “never arrived” claim | Customer receives the order, reports non-delivery, gets refunded | Usually the restaurant | Photo proof of delivery, handoff timestamp |
| Chargeback / friendly fraud | Customer disputes the card charge after the fact | Restaurant, plus a dispute fee | Clear descriptor, receipts, fast evidence filing |
| Stolen card orders | Order placed on a card that is not the buyer’s | Restaurant, once the real cardholder disputes | Address verification, order-value limits |
| Promo and refund abuse | Bulk fake accounts farm first-order discounts and refunds | Split between platform and restaurant | Platform fraud tooling, promo caps |
| Account takeover | Someone takes over your ordering or platform account | Restaurant directly | Unique passwords, 2FA, access review |
| Support impersonation | Scammer poses as platform support to extract credentials or payment | Restaurant directly | Verify through the app, never a callback number |
Two things follow from this table. First, the losses are not one problem with one fix. Second, the controls split cleanly into prevention at order time and evidence at dispute time, and most restaurants have neither.
Chargebacks and false never-arrived claims
This is the biggest and most frustrating slice, because the orders are real, the food was made, and the customer is not a criminal in any sense they would recognise.
Industry data puts the scale of it plainly: first-party fraud, meaning disputes filed over orders the customer actually received, was estimated to cost businesses around $103 billion in 2024, and it sits among the top threats reported by the overwhelming majority of providers (Sift, retrieved 2026-09-29). Restaurants have one of the lowest raw chargeback rates of any industry, in the range of 0.12% of transactions, but the composition is unfavourable: a large share of what does come through is refund abuse rather than card fraud proper.
What makes it stick to restaurants rather than platforms is the default. On most third-party apps, a “missing item” or “never arrived” report triggers an automatic customer refund, and the cost is charged back to the merchant unless the merchant disputes it inside a window that is frequently seven days or less. Nobody sends you a reminder.
The practical response has three parts.
- Capture proof at handoff. A photo at drop-off, a timestamp, a signature or a PIN. Which one depends on your platform, but something that exists after the fact.
- Check the deduction report weekly. Not monthly. The dispute window closes before a monthly review would even notice the charge.
- Dispute everything with evidence attached. Restaurants that file consistently see far fewer repeat claims from the same accounts, because repeat abuse is usually targeted at merchants who never push back.
Track your refund and chargeback count as a line item. If you cannot say what it was last month, it is not being managed.
Promo abuse and fake account fraud
Promotional abuse is the volume scheme. Fraud operations create fake accounts in bulk, farm the first-order discount on each, and in many cases resell the accounts to people looking for a permanent discount. Reported fast-food fraud rose by close to 50% in 2024.
You cannot fix this at the restaurant level, because the account creation happens on the platform. What you can control is exposure: cap the value of promotional offers, avoid open-ended first-order discounts on high-ticket items, and check which of your promotions produce orders that never repeat. A promo where every redeeming account is a first and only order is not a marketing channel.
Account takeover on restaurant ordering platforms
This one is direct theft and it is growing fastest. Sift’s benchmarking found roughly 20% of food delivery accounts facing takeover attempts, compared with about 2.5% across other industries, with attacks in the quick-service segment up 72% year over year in 2025 (Sift, retrieved 2026-09-29).
For a restaurant the exposure is your own merchant accounts, the portals where you set menus, prices and bank details. A takeover there can redirect payouts, issue refunds, or simply run up promotions at your cost.
The controls are unglamorous and they work:
- Unique passwords per platform, never shared across the management team
- Two-factor authentication on every merchant portal that offers it
- A named list of who has access to which platform, reviewed quarterly
- Access removed the day someone leaves, not at the end of the month
- Bank detail changes treated as a security event that requires a second person to confirm
Delivery support impersonation scams
A scheme worth naming specifically because it targets restaurants directly rather than customers. Someone calls claiming to be support from a delivery platform, reports a problem with an order or the account, and walks a manager into handing over login credentials, a verification code, or a payment to “release” funds. The FTC has published a consumer alert on scammers impersonating delivery service support to defraud drivers and restaurants (Federal Trade Commission, retrieved 2026-09-29).
The FTC alert describes two recurring hooks. One is a free tablet or printer for handling delivery orders, which the caller needs to “verify” your login, Social Security number and bank details to ship. The other is a problem with an order, or a refund owed on a cancelled one. In both cases the real target is usually the email verification code that arrives next.
The rule to teach is short: platform support does not need your password or a one-time code, and you never resolve an account issue through a number someone gave you on a call. You hang up and open the app.
Losses at the handoff
Not every off-premise loss is fraud in the criminal sense. A meaningful share is a handoff that went wrong: the wrong bag given to the wrong driver, a missing item that was in fact missing, an order sat on a shelf for twenty minutes and arrived cold enough to justify a refund request.
These matter because they feed the fraud problem. Operations with unreliable handoffs generate real complaints, real refunds, and a customer base that learns the complaint works. Sealed bags, order-number labels, a designated pickup shelf with driver verification, and a packing check against the ticket remove most of it. They also make your dispute evidence far stronger, because “we seal and label every bag” is a claim you can actually support.
Where the driver relationship is yours rather than a platform’s, you have more control than most restaurants realise: named drivers, tracked routes and delivery confirmation close the evidence gap that third-party apps leave open.
Turning this into staff procedure
Everything above is a procedure before it is a policy, which means it lives or dies on whether the team knows it. Fraudulent orders are usually recognisable at the point of order: unusual value, a rush on a first-time account, a delivery address that does not match the card, a caller pressing for urgency. Staff who have been shown those patterns catch them; staff who have not, process them.
Build these into the same cycle as the rest of your program rather than treating them as a separate memo. Our guide to restaurant loss prevention training covers how to structure that, how often to repeat it, and how to measure whether it changed anything.
Frequently asked questions
Who pays when a delivery order is reported as never arrived?
On most third-party platforms the customer is refunded automatically and the cost is charged back to the restaurant, unless the restaurant disputes it within the platform’s window. That window is often a week or less, which is why weekly review of deduction reports matters more than the dispute process itself.
What is friendly fraud in food delivery?
Friendly fraud, also called first-party fraud, is a customer disputing a charge or claiming non-delivery for an order they actually received. It is the largest category of delivery disputes and the hardest to contest without proof of delivery.
Can a restaurant win a delivery chargeback?
Yes, with evidence and speed. Proof of delivery, an order receipt, the handoff timestamp and a clear billing descriptor are what decide it. The most common reason restaurants lose is not weak evidence but a missed filing window.
How do I stop fake orders placed with stolen cards?
Enable address verification where your ordering system supports it, set a review threshold on unusually high-value orders, and train staff on the pattern: a large first-time order, urgency, a delivery address that does not match the card. Orders that trip two of those are worth a confirmation call.
Is delivery fraud worse on third-party apps than on direct orders?
The schemes differ. Third-party apps carry more promo abuse and automatic refunds you do not control; direct ordering carries more stolen-card exposure but leaves you owning the evidence and the dispute. Direct orders are generally easier to defend, which is one of the underrated arguments for running your own delivery channel.
Where to start
Pull your last three months of refunds and chargebacks on off-premise orders and add them up. Most operators have never done this, and the number is usually larger than the shrink figure they worry about instead.
Then fix the two cheapest things: proof of delivery at handoff, and a weekly look at the deduction report. Those two changes decide most disputes, and neither of them costs anything.