TL;DR: North American ecommerce sales rose 8.35% in H1 2026 while fraud pressure climbed 38.6%, with AI-assisted search GMV up 815.91% and SNAD claims up 48% year over year, according to Signifyd’s 2026 State of Fraud data. Fraud is now tracking opportunity and channel change, not just sales growth, which forces merchants to treat fraud governance as a journey-wide control problem rather than a checkout-only one.
At a glance
What this is: This analysis shows fraud is decoupling from ecommerce growth, with Signifyd reporting that fraud pressure is rising much faster than sales while AI-assisted search is becoming a major purchase path.
Why it matters: For identity and fraud practitioners, the shift matters because trust decisions now have to span customer identity, account behaviour, payment signals, and fulfilment workflows rather than a single transaction step.
By the numbers:
- North American ecommerce sales across all verticals grew 8.35% year over year in H1 2026.
- Overall North American fraud pressure increased 38.6% during the same period.
- AI-assisted search GMV increased 815.91% year over year in the first half of 2026.
- Significantly not as described claims rose 48% year over year.
👉 Read Signifyd's analysis of why ecommerce fraud is breaking away from growth
Context
Fraud governance fails when teams assume it scales in step with revenue. In ecommerce, attackers and abusive customers look for friction points in search, checkout, fulfilment, refunds, and returns, so risk can rise even when sales growth looks healthy. The primary keyword here is ecommerce fraud, and this article argues that behaviour change, not just transaction volume, is now driving exposure.
That matters to IAM, fraud, and identity verification teams because the trust boundary is no longer the login or the payment event alone. Customer identity, device and behavioural signals, account history, and post-purchase workflows all shape whether a transaction is legitimate. Where identity controls intersect with fraud prevention, lifecycle governance and step-up verification become part of revenue protection rather than just security hygiene.
The pattern is typical for modern commerce environments: growth opens new paths for abuse faster than merchants can re-tune controls. AI-assisted discovery, larger baskets, BOPIS, and credit-based purchasing all widen the attack surface.
Key questions
Q: How should retailers adapt fraud controls when AI-assisted search becomes a major purchase path?
A: Retailers should treat AI-assisted discovery as a distinct acquisition channel and test whether current fraud models still score it accurately. The main risk is not just more traffic, but changed behaviour that weakens legacy signals. Controls should be tuned by channel, category, and fulfilment path so legitimate buyers are not overblocked while abuse still stands out.
Q: Why do ecommerce fraud losses sometimes rise faster than sales growth?
A: Fraud can outpace sales when attackers concentrate on categories, workflows, or fulfilment models that offer the easiest return. Growth alone does not create fraud, but it can open new abuse paths. Merchants that rely only on topline revenue trends miss category-level risk shifts, post-purchase abuse, and behaviour changes that fraudsters exploit.
Q: What do security and fraud teams get wrong about post-purchase abuse?
A: They often stop identity assurance at payment approval and assume the transaction is done. In reality, returns, refunds, pickup authorisation, and account recovery are where abuse frequently surfaces. If those workflows lack identity confidence and evidence linkage, fraud moves downstream instead of disappearing.
Q: Who is accountable when fraud shifts into fulfilment, returns, or dispute workflows?
A: Accountability should sit with the owners of the entire customer journey, not only the checkout team. Fraud, IAM, customer operations, and fulfilment all influence whether a transaction remains trustworthy after purchase. Governance needs shared ownership, because abuse often appears where teams hand off responsibility and lose visibility.
Technical breakdown
Why fraud decouples from ecommerce growth
Fraud does not need to rise with sales volume if criminals can concentrate on higher-yield categories, weaker fulfilment models, or easier abuse points. That is why a fast-growing market can still see fraud outpace revenue. The mechanism is opportunity selection: attackers optimise for friction, refundability, and ambiguity in goods or customer intent. In practice, this means fraud teams need to track category-level and journey-level variance, not just aggregate loss rates.
Practical implication: build fraud monitoring around product, channel, and fulfilment mix rather than only overall conversion and loss metrics.
How AI-assisted search changes identity and fraud signals
AI-assisted search changes the path to purchase by compressing discovery, comparison, and intent formation into a smaller set of interactions. That can improve conversion, but it also obscures traditional behavioural signals that fraud models use to separate legitimate shoppers from abuse. When AI referrals become a meaningful source of GMV, merchants need to understand how much trust is being delegated to the discovery layer and how that affects downstream identity confidence.
Practical implication: treat AI referral traffic as a distinct risk segment and test whether existing fraud models still score it accurately.
Why lifecycle controls matter after the sale
Modern fraud is not confined to payment authorisation. Returns abuse, SNAD claims, BOPIS fraud, and account takeover all depend on whether merchants can maintain identity confidence after the initial transaction. The control problem therefore extends into account recovery, refund authorisation, store pickup workflows, and dispute handling. Identity verification becomes a lifecycle discipline, not a point-in-time checkpoint.
Practical implication: extend identity and access controls into post-purchase workflows where refunds, pickup, and account changes are approved.
Threat narrative
Attacker objective: The objective is to extract value from ecommerce workflows while appearing legitimate enough to bypass fraud controls and preserve repeatable abuse.
- Entry occurs when attackers exploit AI-assisted discovery, BOPIS processes, or friction-light checkout paths to blend into legitimate shopping behaviour.
- Escalation follows when weak customer identity signals, refund logic, or account controls allow abuse to move from a single purchase into repeat fraud, returns abuse, or SNAD claims.
- Impact is realised through revenue leakage, chargebacks, disputed fulfilment, and erosion of trust in customer-facing commerce workflows.
NHI Mgmt Group analysis
Ecommerce fraud is now a lifecycle governance problem, not a checkout problem. The article shows that abuse is moving across discovery, fulfilment, refunds, and returns rather than clustering only at payment. That shifts the control question from single-transaction review to identity confidence across the customer journey. Practitioners should treat fraud controls as part of broader identity governance.
AI-assisted search creates a new trust layer that merchants are not yet measuring well enough. When 815.91% GMV growth comes through AI-driven discovery, the risk is not just volume, but opacity in how intent is formed and how customers arrive at the transaction. That creates a verification trust gap between marketing analytics and fraud analytics. Teams should test whether AI referral traffic needs its own risk policy.
SNAD and returns abuse are the clearest signs that post-purchase identity controls are too weak. The article’s 48% rise in significantly not as described claims points to abuse after the order is placed, where customer identity, dispute evidence, and fulfilment records must stay aligned. This is where many programmes still separate fraud from identity management. Practitioners should close that gap with stronger post-purchase identity governance.
Fraud concentration, not fraud volume alone, is what exposes control debt. Business Supplies, Consumer Medical, and Auto, Parts & Tires show that risk concentrates where products, behaviours, or fulfilment models create easier abuse. That means teams need category-specific thresholds and exception handling rather than a single enterprise fraud posture. Practitioners should re-tune controls by business line, not just by channel.
The named concept here is ecommerce verification drift. It describes the gradual weakening of identity confidence as shopping, fulfilment, and dispute workflows diverge from the original transaction signal. Once that drift takes hold, fraud tools can appear effective while abuse moves into adjacent processes. Practitioners should measure where identity assurance fades after purchase.
What this signals
Ecommerce verification drift: as AI discovery, BOPIS, and refund-heavy journeys become normal, identity confidence weakens after the original transaction and fraud shifts into adjacent workflows. Teams should watch for rising exceptions in returns, pickup authorisation, and account recovery, because that is where control debt becomes visible.
Fraud programmes that only optimise checkout friction will miss the next risk wave. The better model is journey-wide governance that combines behavioural scoring, customer identity assurance, and category-specific thresholds. For practitioners, the operational question is where trust fades after purchase, not just where fraud starts.
For practitioners
- Segment fraud controls by channel and category Create separate risk thresholds for AI-assisted search, BOPIS, gift card, store credit, and high-abuse product categories so fraud scoring reflects how the business actually sells.
- Extend identity checks into post-purchase workflows Apply stronger verification to refunds, account recovery, pickup authorisation, and dispute handling so identity confidence does not end at checkout.
- Measure abuse by journey stage Track fraud pressure separately across discovery, checkout, fulfilment, and returns to identify where control drift is letting abuse concentrate.
- Re-test models against AI referral traffic Compare false positives and false negatives for AI-driven traffic against other acquisition channels so the fraud model is not overfitting to older shopper patterns.
Key takeaways
- Fraud is no longer merely tracking ecommerce growth, because merchants are seeing abuse concentrate in the workflows and categories that create the easiest path to value.
- AI-assisted search and post-purchase abuse are changing where identity confidence breaks down, which means fraud controls must follow the customer journey instead of ending at checkout.
- The practical response is category-aware, journey-aware governance that links identity assurance to fulfilment, refunds, returns, and dispute handling.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and NIST SP 800-63 set the technical controls, while GDPR define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 | Customer identity and access decisions shape fraud control across the transaction journey. |
| NIST SP 800-63 | SP 800-63B | Authenticator and session assurance matter when account recovery and checkout identity are abused. |
| GDPR | Art.32 | Identity and fraud workflows often process personal data that needs appropriate security controls. |
Map identity assurance and step-up checks to PR.AC-4 across purchase, refund, and recovery workflows.
Key terms
- Ecommerce Verification Drift: The gradual weakening of identity confidence as a customer journey moves beyond the initial transaction. It appears when checkout signals are treated as sufficient proof of legitimacy even though refunds, returns, pickup, and recovery require their own verification and evidence controls.
- SNAD: SNAD means Significantly Not As Described, a dispute claim used when a customer says the received product did not match the listing or promise. It can be genuine, but it is also a common route for abuse when product descriptions, photos, or expectations were unclear.
- AI-Assisted Search Traffic: Purchase traffic generated when shoppers discover or decide on products through AI-powered search or recommendation tools. For fraud teams, it is a distinct behavioural segment because it can compress discovery signals, change intent patterns, and require separate scoring from traditional organic or paid channels.
What's in the full report
Signifyd's full report covers the operational detail this post intentionally leaves for the source:
- Category-by-category fraud breakdowns across North American ecommerce verticals for teams that need implementation-level benchmarking.
- Regional and segment-specific case studies showing how fraud shifts with fulfilment models, product mix, and customer behaviour.
- Deeper analysis of AI-assisted search and other emerging acquisition paths that merchants need to test against their own fraud models.
- Additional detail on SNAD, returns abuse, and BOPIS patterns that can inform control tuning and operations planning.
Deepen your knowledge
NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It gives practitioners a shared control language for programmes that need stronger identity assurance across complex workflows.
Published by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org