By NHI Mgmt Group Editorial TeamPublished 2026-06-25Domain: AnnouncementsSource: Arkose Labs

TL;DR: E-commerce traffic that comes from bad bots is 65%, login attack rates at e-commerce sites jumped 216% in 2025, and annual e-commerce losses to online payment fraud reached $48B, according to Arkose Labs and LexisNexis. That combination shows fraud controls now have to govern machine-driven abuse, not just human attackers.


At a glance

What this is: This is Arkose Labs' retail fraud analysis, and its central finding is that bots, AI agents, and account abuse are already driving measurable risk across e-commerce.

Why it matters: IAM, fraud, and account security teams need to treat machine-driven abuse as an identity problem because account takeover, fake account creation, and API abuse all depend on controlling how access is granted and exercised.

By the numbers:

👉 Read Arkose Labs' analysis of bot-driven retail fraud and AI agent abuse


Context

Retail fraud is no longer just a checkout problem. It is an identity and access problem that starts with account creation, continues through login abuse, and ends in payment fraud, credential stuffing, or automated abuse of customer journeys.

Arkose Labs frames the issue around bad bots, AI agents, and fraudulent activity at scale, which means security leaders have to think beyond perimeter blocking. The operational question is how to distinguish legitimate customer behaviour from machine-driven abuse while preserving usable access for real users.


Key questions

Q: How should security teams reduce bot-driven account takeover in e-commerce?

A: They should combine device intelligence, behavioural analysis, and risk-based step-up checks at login and signup. The goal is not to block every automated request, but to identify when traffic patterns indicate scripted abuse, credential stuffing, or fake account creation. Controls work best when they are tied to live session risk rather than static rules alone.

Q: Why do bad bots create an identity governance problem for retailers?

A: Because bots can create accounts, test credentials, and complete sessions at scale while looking operationally similar to real users. That means authentication alone does not prove legitimacy. Retailers need governance that follows the full identity journey, including signup quality, session trust, and access abuse signals, not just the initial login event.

Q: What breaks when fraud controls are disconnected from IAM decisions?

A: Teams miss the link between identity behaviour and abuse patterns, so attackers can move from account creation to takeover to transaction fraud without triggering a coordinated response. Separate tools often see only one slice of the problem. A shared risk picture is needed so access, fraud, and customer-risk decisions reinforce one another.

Q: Which identity signals matter most for stopping retail automation abuse?

A: Look at account creation velocity, login repetition, device consistency, and session behaviour over time. Those signals help distinguish genuine customers from scripted activity. The strongest programmes use them together, because any single indicator can be spoofed, but consistent patterns across the journey are harder for automation to hide.


How it works in practice

How bot traffic distorts identity signals in e-commerce

Bad bots poison the signals IAM and fraud systems rely on, because they can mimic browsing, form submission, and login patterns at volume. Once that noise becomes common, reputation scoring and velocity checks lose precision unless they are paired with stronger device, session, and behavioural analysis. In retail environments, the challenge is not only blocking automation but also preserving enough signal quality to identify account takeover and fake account creation before downstream fraud occurs.

Practical implication: separate machine traffic detection from identity verification so abuse does not contaminate your access decisions.

Why adaptive challenges matter for account takeover and fake accounts

Adaptive challenges work by escalating friction only when risk rises, rather than forcing every user through the same control. That matters because fraud actors optimise for speed and scale, while legitimate customers need a low-friction path. In practice, this turns step-up friction into a decisioning layer, not a static gate. The value is highest when it is tied to current session context, device reputation, and attack patterns such as credential stuffing, account enumeration, and scripted sign-up abuse.

Practical implication: use risk-based challenge escalation at registration and login, not blanket friction across every customer journey.

How cross-industry risk intelligence improves fraud decisioning

Fraud patterns move across sectors, so isolated controls tend to lag the attacker. Cross-industry intelligence helps identify repeatable behaviours such as proxy use, synthetic identity patterns, and automation reuse across different sites. The technical advantage is that decisioning becomes informed by broader attacker infrastructure rather than only local incidents. For e-commerce teams, that means tuning controls to known abuse patterns instead of waiting for each pattern to appear first in their own environment.

Practical implication: enrich fraud controls with external intelligence so you can react to reused attacker infrastructure faster.


NHI Mgmt Group analysis

Retail fraud is now an identity governance problem, not just a transaction risk. The article shows that bad bots, AI agents, and login abuse sit upstream of payment loss, which means the control plane has shifted toward account lifecycle, session trust, and access decisioning. When machine traffic dominates customer journeys, fraud and IAM can no longer operate as separate disciplines. Practitioners should treat account abuse as a governed identity flow, not a point-in-time fraud event.

Machine-driven retail abuse exposes a governance gap between authentication and assurance. A login success or completed signup does not prove legitimate intent when automation can generate high-volume, human-like interaction. That gap is exactly where credential stuffing, fake accounts, and session abuse gain leverage. The practical conclusion is that assurance must follow behaviour across the full journey, not stop at initial authentication.

Behavioural friction is becoming the decisive control for e-commerce identity abuse. Static controls age badly against adversaries that can vary timing, device signals, and interaction patterns. Arkose Labs' framing points to a broader pattern: attackers win when teams optimise only for access acceptance rates and not for abuse resistance. The implication is that retail identity programmes need controls that adapt as quickly as the abuse they are meant to stop.

Named concept: identity-abuse decisioning. This article is really about the need to make fraud and access decisions from the same live risk picture, rather than bolting fraud checks onto the side of IAM. That concept matters because AI agents and bots can create legitimate-looking sessions at scale, and the old boundary between identity trust and fraud detection is already eroding. Practitioners should align fraud controls, IAM telemetry, and customer-risk response into one decision path.

From our research:

  • 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%), according to AI Agents: The New Attack Surface report.
  • Only 44% of organisations have implemented any policies to govern AI agents, which leaves most deployments operating without formal guardrails.
  • For the broader control picture, see OWASP Agentic AI Top 10 for the risk patterns that drive tool misuse and scope drift.

What this signals

Identity-abuse decisioning will become a standard requirement in retail and adjacent digital businesses because fraud, access, and customer trust are converging into one control problem. With 96% of technology professionals already identifying AI agents as a growing security threat in our research, the next failure mode is not only more automation but more ambiguity in who or what is acting.

Programme owners should expect stronger pressure to merge bot management, IAM telemetry, and customer-risk scoring into a single operational view. That shift also changes reporting: the question is no longer whether a login succeeded, but whether the surrounding identity behaviour was trustworthy enough to allow the transaction to proceed.

For teams building out this model, The 52 NHI breaches Report and the OWASP Agentic AI Top 10 help separate ordinary automation from behaviour that can materially change risk decisions.


For practitioners

  • Unify fraud and IAM telemetry Correlate login attempts, signup velocity, device reputation, and session behaviour so machine abuse is evaluated in one decision layer instead of separate tools.
  • Tune step-up controls to attack patterns Apply adaptive challenges when signals indicate credential stuffing, fake account creation, or scripted checkout activity, and avoid forcing the same friction on every customer.
  • Measure abuse at the identity edge Track account creation quality, login attack rates, and session anomalies together so you can see whether controls are reducing abuse or merely shifting it.
  • Use external intelligence to tune decisions Feed cross-industry risk intelligence into your bot and fraud controls so you can identify reused attacker infrastructure before it appears as a local incident.

Key takeaways

  • Retail fraud is increasingly an identity problem because bots and AI-driven automation can imitate legitimate customer journeys at scale.
  • The evidence points to large exposure, with bad bots, rising login attacks, and multi-billion-dollar fraud losses all reinforcing the same control gap.
  • Security teams should converge fraud telemetry, IAM decisioning, and adaptive challenges so abuse is assessed across the full customer journey.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01Bot and agent abuse maps to weak identity trust and unchecked non-human access.
NIST CSF 2.0PR.AA-01Identity proofing and authentication need to account for automated abuse patterns.
NIST Zero Trust (SP 800-207)AC-5Continuous verification aligns with adaptive challenges and session-level trust decisions.

Apply continuous, risk-based verification to customer journeys where automation can masquerade as legitimate use.


Key terms

  • Bad Bot: An automated client designed to imitate normal user behaviour while carrying out abuse at scale. In identity and fraud programmes, bad bots distort telemetry, inflate traffic, and can drive credential stuffing, fake account creation, and checkout abuse. Their impact is operational and governance related, not just volumetric.
  • Account Takeover: Unauthorized control of a user account after an attacker obtains valid credentials or exploits weak session controls. In retail environments, account takeover often begins with automated login abuse and ends in payment fraud, data exposure, or abuse of stored customer details.
  • Adaptive Challenge: A dynamic friction control that changes based on risk signals, such as device reputation, login behaviour, or traffic anomalies. Rather than forcing every user through the same step, it increases resistance when abuse is likely and stays light when trust is higher.

What's in the full announcement

Arkose Labs' full article covers the operational detail this post intentionally leaves for the source:

  • Detection and mitigation patterns for bot traffic using the vendor's 250-plus signal model
  • Examples of adaptive challenges for login, signup, and checkout abuse across retail journeys
  • Customer-story detail on fraudulent new account reduction versus incumbent controls
  • Decisioning and intelligence workflows used to tune fraud controls over time

👉 Arkose Labs' full article covers the detection, mitigation, and decisioning detail behind its retail fraud approach

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on 2026-06-25.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org