Join our Newsletter — 33% off our NHI Course

What should merchants do when new customer segments create both growth and fraud exposure at the same time?

Merchants should treat growth and fraud as the same operating problem, not separate ones. When a new segment enters quickly, teams need stronger account protection, clearer customer education, and fraud controls that can distinguish risky behavior from legitimate novelty. The right response is to preserve conversion while preventing scams, breaches, and downstream loss.

Why growth and fraud become the same operating problem

When a merchant enters a new customer segment, the useful question is not whether the segment is “good” or “risky”, it is how fast the business can learn normal behavior without opening the door to abuse. New segments often bring unfamiliar purchase patterns, device mixes, refund behavior, or channel expectations, so conversion and abuse prevention must be tuned together rather than owned by separate teams.

That matters because fraud controls are not just a loss-prevention layer, they are part of the customer experience. If controls are too strict, legitimate new customers abandon; if they are too loose, scammers, account takeover attempts, and synthetic activity can scale before the merchant understands the new baseline. The operating goal is to preserve trust while the segment is still being profiled.

For merchants working through this balance, it helps to use a broader controls view from NIST Cybersecurity Framework 2.0 and to keep transaction and account protections aligned with the core controls described in OWASP API Security Top 10 when new segment onboarding flows rely on exposed application or API paths.

How merchants should shape controls without killing conversion

The practical response is to segment risk gradually, not to hard-code a permanent high-friction policy on day one. Merchants should start with sharper signals around account creation, login, payment method changes, shipping changes, and refund requests, then relax or tighten controls based on observed behavior in that segment. That lets teams distinguish legitimate novelty from patterns that look new only because the segment itself is new.

A good operating model combines step-up verification, velocity checks, and review thresholds with customer education that explains why some actions trigger extra checks. The goal is to make security explainable enough that honest buyers keep transacting, while still forcing fraudsters to work harder and reveal more signal. This is especially important when the segment is valuable enough to attract opportunistic abuse quickly.

Where merchants expose checkout, account, or partner integration APIs, they should also verify that authorization boundaries are tight enough to prevent abuse through excessive trust or over-permissive tokens. If the new segment depends on a partner or platform integration, attack surface can grow faster than internal review cycles, so access controls and abuse monitoring need to move in parallel with marketing expansion.

Practical research on identity abuse supports that posture, especially where automation, stolen access, or reused credentials can accelerate fraud. NHIMG’s 52 NHI Breaches Analysis and Guide to the Secret Sprawl Challenge are useful reminders that insecure access material and overbroad trust tend to become business problems long before they become technical ones.

What breaks first when merchants ignore the overlap

The first failure is usually misclassification. Teams mistake legitimate new-segment behavior for fraud, or they treat early fraud as harmless noise because the segment is still growing. Both errors are expensive: the first suppresses revenue, while the second trains fraudsters on weak controls and creates a pattern that is harder to unwind later.

The second failure is operational drift. Marketing may optimize for acquisition, support may absorb the complaints, and fraud may only see delayed downstream loss. Without shared metrics, the organisation ends up with conflicting definitions of success, and the segment keeps expanding before the control baseline is stable. That is when chargebacks, account takeover, refund abuse, and merchant distrust start to feed each other.

Merchant teams should also watch for concentration effects. A new segment can look small in revenue terms but still produce outsized loss if a single payment method, device family, referral channel, or onboarding path becomes the preferred abuse route. When that happens, the issue is not just fraud volume, it is the fragility of the growth path itself.

Risk and Threat Considerations

New customer segments create a short period of weak signal, and that is exactly when abuse becomes attractive. Fraudsters exploit uncertainty in behavioral baselines, while legitimate customers can be caught by controls that have not yet learned the segment’s normal variation.

Failure mechanism: The merchant scales acquisition faster than its fraud models, review queues, and account protections can adapt, so the segment’s novelty suppresses detection quality and raises both false positives and missed fraud.

Impact: The result is avoidable loss through chargebacks, account takeover, refund abuse, and support burden, plus conversion damage if the merchant reacts by over-tightening controls after losses begin.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.OC-03 — Cybersecurity in Enterprise Context New segments change business exposure and control priorities.
PR.AA-01 — Identity Management, Authentication and Access Control Customer account protection is central when growth increases abuse pressure.
DE.CM-01 — Continuous Monitoring Early anomaly detection is needed to separate novelty from fraud.
Recommendation — Align fraud controls with segment expansion risk and shared operating metrics. Strengthen customer account protection and step-up verification for risky actions. Monitor new-segment behavior for velocity, reuse and transaction anomalies.
CIS Controls v8 6 — Access Control Management Account protection and least privilege reduce takeover and abuse risk.
8 — Audit Log Management Fraud detection depends on observable account and transaction activity.
Recommendation — Tighten access controls around customer, support and admin actions. Log signups, logins and payment changes so fraud patterns are detectable.
OWASP Non-Human Identity Top 10 NHI-01 — Secret Discovery and Inventory Merchant growth often depends on integrations whose credentials can be abused.
Recommendation — Inventory and protect integration secrets that could enable fraudulent access.

Practitioner Guidance

What to prioritise: Treat launch-day monitoring as a control design problem, not a campaign problem. The most useful early signals are account creation velocity, device and payment reuse, first-order anomalies, and refund or address-change spikes, because they tell you whether the segment is behaving like real demand or coordinated abuse.

What to verify: Confirm that step-up checks can be applied selectively, that review queues have capacity, and that support teams know which customer friction is expected versus suspicious. If fraud and growth report separately, ensure there is one shared threshold for action, otherwise each team will optimise against a different risk model.

Practitioner takeaway: The best outcome is not “more friction” or “more growth”, it is a controlled learning loop where the merchant can absorb novelty, preserve legitimate conversion, and stop abuse before the new segment defines the next fraud pattern.