Skip to main content
Refund Abuse Overtakes Payment FraudChargebacks and Disputes
3 min readFor Fraud Risk Managers

Refund Abuse Overtakes Payment Fraud

Refund and policy abuse have overtaken payment fraud as the top threat in digital commerce, according to the Merchant Risk Council's 2026 Global eCommerce Payments & Suspicious Activity Report (SAR). This shift requires fraud analysts to adopt a new defensive strategy.

Digital commerce brands lost an estimated $48 billion to fraud in 2025. For every dollar of confirmed fraud, U.S. merchants incur $5.13 in total costs, including chargeback fees, labor, and lost merchandise. This is up from $4.61 in 2025. The National Retail Federation's 2025 Retail Returns Landscape report estimates returns and refund fraud at $76 billion in losses, with about 9% of all retail returns being fraudulent.

What Changed

Fraud rings have adapted their tactics. TransUnion's H1 2026 Top Fraud Trends Report found that 8.3% of digital account creation attempts in 2025 were suspected of fraud, marking the highest-risk stage in the consumer lifecycle. Nearly 7% of global fraud activity now involves deepfake AI to fabricate identities or bypass verification during account creation.

On the other end, tactics like empty-box returns and wardrobing are becoming more organized. Fraudsters create fraudulent accounts, age them to appear legitimate, and exploit refund channels when defenses are focused on checkout.

Key Findings

Refund and policy abuse are now major threats. These, along with account takeover and promotion abuse, require as much attention as card testing and synthetic payment credentials. A fraud prevention program focused only on payment-level signals will miss significant threats.

Static rules are ineffective against automated fraud. Fraud rings test defenses with low-value transactions to identify gaps. Once found, they return with automated scripts to exploit these gaps. Rules based on past attack patterns are ineffective against fraud rings that frequently change tactics.

Manual review is limited. Order volumes spike during major sales events, and a review queue designed for normal days can't handle this without delays or increased headcount. Analysts often rely on gut instincts under pressure, which fraud rings exploit.

Generous return policies are vulnerable. Policies designed to build customer loyalty have become targets for digital criminals who exploit lenient rules. First-party misuse is increasing, with many merchants reporting a rise in such incidents.

What This Means for Your Team

Your fraud prevention strategy needs visibility across the entire customer journey, not just the payment page. This includes account creation, login behavior, browsing patterns, checkout, and post-purchase actions like refund requests. Fraud rings often test multiple attack vectors simultaneously.

Risk-based friction balances fraud prevention with checkout conversion. A returning customer on a recognized device with a clean history checks out smoothly. A new account with a high-risk profile faces additional authentication before order shipment. The goal is to apply the right friction at the right time.

Action Items by Priority

Monitor account creation and login for fraud. With 8.3% of account creation attempts carrying fraud risk, start scoring at registration. Use device fingerprinting, behavioral signals, and velocity checks. Flag accounts that quickly move from creation to high-value orders.

Integrate refund and return abuse detection. Track refund patterns by account, device, and shipping address. Flag accounts with abnormal return rates, especially for high-value items. Cross-reference refund requests with original orders to identify empty-box schemes.

Adopt machine learning models for fraud detection. Models trained on thousands of signals across the user journey can catch fraud rings that change tactics. Use platforms that share network-level data anonymously across merchants to benefit from observed attack patterns.

Measure false decline rates alongside chargeback rates. Every wrongly blocked order is lost revenue. A fraud analyst who shows rising fraud detection accuracy and falling manual review rates demonstrates effective fraud prevention.

Apply Multi-Factor Authentication (MFA) selectively. Use MFA based on risk scores, not universally. Apply it where account behavior, device signals, or order characteristics suggest additional confirmation is needed. This protects high-risk transactions without affecting the entire customer base.

You Might Also Like