Skip to main content
$48 Billion Lost: What Retail Fraud Data RevealsChargebacks and Disputes
4 min readFor Fraud Risk Managers

$48 Billion Lost: What Retail Fraud Data Reveals

Digital commerce brands lost an estimated $48 billion to fraud in 2025, according to the Merchant Risk Council’s 2026 Global eCommerce Payments & Suspicious Activity Report (SAR). More revealing: refund and policy abuse just displaced payment fraud as the top threat merchants report. This shift shows where fraud rings find the easiest path through your defenses.

For every dollar of confirmed fraud, U.S. merchants now absorb $5.13 in total cost once chargeback fees, labor, and lost merchandise are counted. This is up from $4.61 in 2025. If you're still measuring fraud prevention success by gross fraud loss alone, you're missing 80% of what fraud actually costs your business.

Key Fraud Insights

Recent fraud reports highlight where retail ecommerce brands are losing ground:

Account creation is the highest-risk stage. TransUnion's H1 2026 Top Fraud Trends Report found that 8.3% of digital account creation attempts in 2025 were suspected of fraud. Fraudsters aren't waiting until checkout. They're building fraudulent accounts early, aging them to look legitimate, and cashing out later when your defenses focus on payment transactions.

Deepfake AI accelerates identity fabrication. Nearly 7% of global fraud activity now involves deepfake AI, used to fabricate identities or bypass verification checks during account creation. The barrier to creating convincing synthetic identities has dropped to near zero, and your static verification rules weren't built to detect machine-generated documents or video.

Returns fraud is organized crime. The National Retail Federation's 2025 Retail Returns Landscape report puts returns fraud at roughly $76 billion in losses for the year, with about 9% of all retail returns now fraudulent. Empty-box returns, wardrobing, and overstated quantities are increasingly organized rather than opportunistic. These aren't individual shoppers gaming your return policy; they're fraud rings running the same playbook across dozens of merchants.

Implications for Your Team

If your fraud prevention program focuses primarily on payment fraud, you're defending the wrong perimeter. Payment fraud still matters, but fraud rings have moved to softer targets: account creation, loyalty programs, and post-purchase processes where verification is weaker and automation is harder to deploy.

Static rules can't keep pace with this shift. A rule built around last quarter's attack pattern does little against a fraud ring that changes its device fingerprints, shipping addresses, or card testing cadence weekly. Every new rule also risks catching legitimate customers, driving them away before they complete checkout.

Manual review has its own ceiling. Retail ecommerce brands see order volume spike around major sales events, and a review queue sized for an average Tuesday cannot scale to Black Friday without either massive headcount or unacceptable delays. Analysts end up triaging by gut feel under time pressure, which is exactly the condition fraud rings exploit.

Your fraud prevention program needs to cover the full customer journey with everything connected in one risk picture. That means visibility into account creation, login behavior, browsing patterns, checkout, and post-purchase actions like refund requests. Treating each stage as a separate silo lets fraud rings exploit the gaps between them.

Action Steps

1. Monitor account creation rigorously. Deploy device fingerprinting, behavioral analysis, and velocity checks at registration, not just payment. If 8.3% of account creation attempts are fraudulent, you can't afford to treat registration as a low-risk event. Flag accounts created with disposable email domains, VPN connections, or device profiles that match known fraud patterns.

2. Implement risk-based friction. A returning customer on a recognized device with a clean history should check out without interruption. A new account attempting a high-value order from a mismatched location and a risky payment method should get Multi-Factor Authentication before the order ships. Apply step-up verification only where risk warrants it, not as a blanket policy that frustrates every customer.

3. Connect payment fraud signals with post-purchase behavior. If an account shows clean payment activity but repeatedly files refund requests for high-value items, that pattern matters. Fraud rings test your payment defenses first, then exploit your returns process once they've established a pattern of legitimate-looking transactions. Your fraud prevention tools need to surface those cross-journey patterns, not just flag individual transactions in isolation.

4. Track false decline rate alongside gross fraud loss. Every wrongly blocked order is lost revenue your fraud team caused rather than prevented. If you're tightening rules to reduce fraud but driving away legitimate customers in the process, you're solving the wrong problem. Measure manual review rate and average review time to show whether analysts are spending their hours on genuine risk or repetitive noise.

5. Replace static rules with machine learning models. Fraud rings test defenses before committing to an attack. A small batch of low-value transactions probes which rules trigger a decline and which slip through without being flagged. Once a gap is found, the same ring returns days later with automated scripts running that pattern at volume. Your fraud prevention program needs to learn from those probe attempts and adjust defenses before the full attack arrives.

PCI DSS compliance

By taking these steps, your team can better protect against evolving fraud tactics and minimize false positives.

You Might Also Like