# INC-2026-0912-07: customer refunded twice on one payment

Reporter: integrations@ateliernord.example (Atelier Nord, merchant `mer_B2X9L4M7`)
Opened: 2026-09-12 14:18 UTC, escalated to incident bridge 14:20 UTC
Priority: P1 (money movement)

## Merchant's message

> Our customer service just got a call from a customer who received two refunds of 89.00 CAD for one order. Payment `pay_2Fw6hT9jK3sR8vN1`. Our back office sent exactly one refund request at 14:03 UTC today, from our returns tool, for the full amount. Your API returned an error on it (our logs say "gateway timeout"), so the tool retried, as it always does, and the retry returned 201. Then we received two `refund.succeeded` webhooks, with two different refund ids: `re_A4kT7wQ2mL9sP8xN` and `re_C8pW3mK6tR2sL5qY`. Your API refunded twice. We need this reversed today and we need to know if any other customer is affected.

## Support first-line notes

- Dashboard: payment `pay_2Fw6hT9jK3sR8vN1`, captured 11 September, 8,900 CAD (minor units). Two refunds listed, both `succeeded`, 8,900 each.
- Merchant integration profile: REST client, webhooks verified, no `Idempotency-Key` usage recorded on any request this month.
- Incident bridge opened. Analyst assigned for timeline and blast radius. Review at 15:30 UTC.
