Retail fraud prevention starts with understanding how fraud targets businesses’ payment and returns systems, from checkout to refund. Return policies help build customer trust, and dispute rights protect cardholders. Fraud exploits both. But in 2025, 44% of institutions in the US and Canada relied mostly or entirely on manual processes to address fraud. This can make it difficult to catch sophisticated and emerging types of fraud.
Below, we’ll discuss the fraud categories that affect retail businesses most, how businesses identify fraud in transaction data, and which controls reduce exposure across online and in-store channels.
Key takeaways
Retail fraud spans card-not-present (CNP) fraud, return abuse, and friendly fraud. Each type has distinct patterns that require different detection approaches.
Effective retail fraud detection combines order behaviour, device data, and transaction history. No single signal is reliable on its own.
Omnichannel retailers face unique exposure. Fraud patterns that originate online often appear in physical stores.
What is retail fraud?
Retail fraud is theft that happens through the payment and returns systems businesses depend on. That fraud encompasses a range of methods, in-store and online, that fraudulent actors use to obtain goods, services, or funds from a retail business.
What are the common types of fraud in retail?
Retail fraud shows up in different parts of the purchase lifecycle. Each type involves different actors and requires a different response:
CNP fraud: Using stolen payment credentials to complete a purchase without the physical card. Stolen card data is obtained through breaches, phishing, or dark web marketplaces, then used to place orders before the legitimate cardholder notices.
Bank Identification Number (BIN) attacks: Testing thousands of card number combinations against a business’s checkout with an automated script to look for valid numbers. The business absorbs authorisation fees for every attempt, and a successful hit results in a fraudulent order that often triggers a chargeback.
Wardrobing: Purchasing items (typically apparel, electronics, or tools) with the intention of using them briefly and returning them for a full refund. This often leaves the business with merchandise that can’t be resold at full price.
Receipt fraud: Returning merchandise with a fraudulent or altered receipt to claim a refund that’s larger than the purchase price.
Refund-without-return schemes: Claiming an item never arrived or arrived damaged to obtain a refund while keeping the merchandise.
Friendly fraud: Disputing a legitimate charge with the card issuer and claiming the transaction was unauthorised or the item never arrived. This triggers a chargeback despite the order being genuine.
How do retailers detect fraud patterns?
Retail fraud detection involves cross-referencing several signals. Individually, these signals might be explained away, but collectively, they point to elevated risk.
These inputs matter most:
Order speed: Multiple orders placed in quick succession from the same device or Internet Protocol (IP) address or to the same shipping address.
Shipping and billing mismatch: An order in which the billing and shipping addresses are in different states or countries. This warrants closer review when the shipping address is a freight forwarder or reshipping service that obscures the final destination.
Device signals: Browser type, operating system, and device fingerprint reveal whether an order is coming from a known device associated with the account or an unfamiliar environment. Orders placed through virtual private networks (VPNs) appear in geographic locations inconsistent with a cardholder’s history.
Email and account age: A first-time customer with an account created minutes before that places a high-value order, or an account created with a throwaway email address (random character strings or addresses from disposable email services).
Return history: A customer with an unusually high return rate, particularly across the same product categories. This signal is especially relevant for return fraud and refund-without-return schemes.
What retail fraud prevention strategies should businesses use?
Effective retail fraud prevention operates at three layers: before authorisation, after the order is placed, and at the returns counter. No single control covers all three, but using these methods together can create a protective layer:
Address verification service (AVS): AVS checks compare the billing address provided at checkout against the address on file with the card issuer. Neither AVS nor card verification value (CVV) checks are foolproof—stolen card data often includes billing addresses and CVV numbers—but both raise the cost and complexity of CNP fraud.
3D Secure (3DS): 3DS adds an authentication layer for CNP transactions. When a transaction is flagged as high risk, 3DS routes the cardholder through a verification step with their bank. It typically shifts liability for fraudulent transactions from the business to the card issuer.
Post-order review queues: High-risk orders should route to a manual review queue before fulfilment, not after. Define the criteria clearly (e.g., orders above a specific value, first-time customers who order multiple units of the same high-value item, mismatched shipping and billing addresses), and staff the queue with people who understand what fraud looks like in your product category.
Return policy enforcement: Requiring a receipt, limiting the return window, and flagging accounts with high return rates are all effective controls. Tracking returns at the customer level across channels matters for high-volume abuse; a customer who has returned 15 of their past 20 purchases has a different risk profile from a customer who is returning for the first time.
How does fraud risk change in omnichannel retail?
Omnichannel retailers face fraud exposure that purely online and purely in-store businesses don’t. When you operate across both channels, fraud patterns that start in one environment often resolve in another.
Here are some examples:
Buy online, return in store (BORIS): A fraudulent actor places an online order using stolen credentials, then returns the merchandise in-store for cash or store credit. The in-store associate sees a transaction record and a return request, but the original purchase was fraudulent. If your online and in-store systems don’t share data in real time, the return will likely get processed before the fraud is flagged.
Buy online, pick up in store (BOPIS): Fraudulent orders placed online for in-store pickup might let fraudulent actors collect merchandise before fraud reviews can flag the order. High-value, same-day BOPIS orders warrant the same scrutiny as online orders with expedited shipping.
Fragmented customer data: Consistent fraud controls across channels require unified customer data. If your point-of-sale and e-commerce platforms don’t share account-level purchase and return history, you’re running two separate fraud prevention systems with a gap that allows fraud in.
How do fraud prevention tools help retail businesses?
Rather than review every order against a checklist, a fraud detection system scores transactions in real time based on hundreds of signals. The system uses a machine learning model trained on transaction data across businesses to score each payment. So a card that has appeared in fraudulent transactions at other businesses will carry an elevated risk score before it reaches your checkout. The fraud prevention tool routes high-risk orders for review or declines them automatically.
Custom rules for retail-specific risk can be created on top of a machine learning model’s baseline. A business that sells consumer electronics can flag orders that ship to freight forwarders, orders above a certain value from accounts created within the past 24 hours, or orders in which the same card has been used across multiple accounts. The business can update those rules as fraud patterns shift.
How Stripe Radar can help
Stripe Radar uses AI models to detect and prevent fraud, trained on data from Stripe's global network. It continuously updates these models based on the latest fraud trends, protecting your business as fraud evolves.
Stripe also offers Radar for Fraud Teams, which allows users to add custom rules addressing fraud scenarios specific to their businesses and access advanced fraud insight.
Radar can help your business:
Prevent fraud losses: Stripe processes over $1 trillion in payments annually. This scale uniquely enables Radar to accurately detect and prevent fraud, saving you money.
Increase revenue: Radar's AI models are trained on actual dispute data, customer information, browsing data and more. This enables Radar to identify risky transactions and reduce false positives, boosting your revenue.
Save time: Radar is built into Stripe and requires zero lines of code to set up. You can also monitor your fraud performance, write rules and more in a single platform, increasing efficiency.
Learn more about Stripe Radar or get started today.
The content in this article is for general information and education purposes only and should not be construed as legal or tax advice. Stripe does not warrant or guarantee the accuracy, completeness, adequacy, or currency of the information in the article. You should seek the advice of a competent lawyer or accountant licensed to practise in your jurisdiction for advice on your particular situation.