What Mastercard reason code 4840 means
The issuer files 4840 when the cardholder took part in at least one valid transaction at your business and then sees one or more further charges they did not agree to. Mastercard has folded 4840 into its main fraud code, 4837 No Cardholder Authorization, under its current rules. Some processors, acquirers and older reports still display 4840, so the label persists, and the defense works the same way under either number.
Typical triggers for a 4840 chargeback
-
A card on file was charged again for a new order the cardholder says they never placed.
-
An employee ran extra transactions on a card used for a real purchase.
-
A card present terminal captured the same card twice for different amounts.
-
Add on or upsell charges processed after checkout without clear consent.
Time limits for Mastercard 4840
The cardholder typically has 120 days from the settlement date of the disputed charge to file. Your response window is set by your processor and is often between 7 and 21 days. In Stripe the exact deadline is the evidence due date on the dispute, and a late response loses the case automatically.
Evidence that wins a 4840 dispute
-
Separate order records for each disputed charge, with items, timestamps and order numbers.
-
Authentication results for each charge, such as Mastercard Identity Check, AVS and CVC.
-
IP address, device and login data showing the same customer placed the later orders.
-
Signed consent or saved card terms that allow later charges, for card on file merchants.
-
Delivery or usage proof for every disputed order, not only the first one.
-
Staff access logs showing who processed each transaction, for card present businesses.
What to avoid when you respond
-
Do not defend only the first purchase. The cardholder already accepts it.
-
Do not ignore internal fraud risk. If an employee ran the charges, accept and fix it.
-
Do not refund after the chargeback posts, since the funds are already withdrawn.
How to prevent Mastercard 4840 chargebacks
-
Require clear consent for every charge to a stored card, and email a receipt each time.
-
Limit which staff accounts can run manual or keyed transactions, and log every one.
-
Use 3D Secure for new orders on saved cards when risk signals appear.
-
Use idempotency checks so a terminal or checkout cannot capture the same card twice.
-
Track your fraud count, because it affects your ratio under Mastercard ECM. See the chargeback ratio monitor.
How 4840 appears in Stripe
Stripe shows fraud claims like 4840 with the reason fraudulent, and the raw code, 4840 or 4837 depending on the issuer and acquirer, appears in the network reason code field on the dispute. NoChargeback reads that field, lists every charge on the same card and customer, and builds evidence that ties each disputed charge to its own order, device and delivery. See Stripe chargeback protection.
Rebuttal letter opening for Mastercard 4840
We are responding to the dispute filed under Mastercard reason code 4840. Each disputed transaction is a separate purchase placed and authorized by the cardholder, not an additional charge on an earlier order. The attached records show a distinct order number, authentication result, device and delivery confirmation for every charge.
What is the difference between 4840 and 4837?
4837 covers any transaction the cardholder says they did not authorize. 4840 is the narrower case where the cardholder made one real purchase and disputes extra charges on the same card. Mastercard now handles both under 4837.
Can I win a Mastercard 4840 chargeback?
Yes, when you show each disputed charge was its own authorized order, with authentication, device data and delivery or usage proof for every one.
Why do I still see 4840 on disputes?
Some processors and acquirers keep displaying the older code even though Mastercard folded it into 4837. Check the network reason code field and answer the claim described in the dispute.