By NHI Mgmt Group Editorial TeamDomain: Identity Beyond IAMSource: SiftPublished August 10, 2026

TL;DR: Digital commerce brands lost an estimated $48 billion to fraud in 2025, while refund and policy abuse displaced payment fraud as the top merchant threat and every confirmed dollar now costs U.S. merchants $5.13, according to Sift and the Merchant Risk Council. Rules and manual review cannot keep pace with automated fraud rings that probe, adapt, and return at scale.


At a glance

What this is: Digital commerce fraud now centers on refund and policy abuse, with merchants reporting a shift away from payment fraud and toward more automated, lifecycle-wide abuse.

Why it matters: Fraud and identity teams need controls across account creation, login, checkout, and post-purchase actions because attack paths now span the full customer lifecycle, not just the payment page.

By the numbers:

👉 Read Sift's analysis of fraud prevention for digital commerce and retail ecommerce


Context

Refund and policy abuse is a governance problem, not just a loss-prevention problem. Once fraudsters can create accounts, age them, and exploit returns or loyalty flows later, the control surface expands beyond checkout into identity verification, account lifecycle monitoring, and post-purchase entitlement management. For fraud and identity teams, that means the old perimeter around payment fraud is no longer enough.

The article frames the same shift through operational reality: static rules and manual review queues are too slow for adaptive fraud rings. In identity terms, the real issue is that trust signals are being tested across the entire customer journey, while many programmes still treat onboarding, authentication, and refund handling as separate controls.


Key questions

Q: How should fraud teams handle account trust across the full customer journey?

A: Fraud teams should treat trust as a lifecycle property, not a one-time onboarding decision. That means linking account creation, login, checkout, refund behaviour, and exception handling into one scoring model so attackers cannot move into weaker control zones after initial verification passes. Continuous telemetry is more effective than isolated point checks.

Q: Why do synthetic identities and deepfakes make ecommerce fraud harder to stop?

A: They make weak verification signals less reliable. Synthetic profiles and AI-generated behaviour can look legitimate enough to pass basic proofing, especially when teams rely on email age, form completion, or single-factor checks. The answer is stronger identity assurance and behavioural monitoring throughout the account lifecycle.

Q: What do security teams get wrong about refund abuse?

A: They often treat refund abuse as a customer service issue rather than an identity and policy problem. Refund flows can be exploited through false non-receipt claims, manipulated tracking data, or repeated legitimate-account misuse. Strong controls require item-level evidence, clear refund terms, and identity-linked validation for high-risk returns.

Q: What should organisations measure if they want to know fraud controls are working?

A: Organisations should measure whether controls are increasing attacker cost, reducing campaign success rates, and forcing repeated abuse to become uneconomic. A control can reduce one attempt and still fail strategically if attackers can immediately retry at low cost. The right metric is not only detection, but deterrence.


Technical breakdown

Why refund abuse now outpaces payment-only controls

Refund and policy abuse works because it exploits trusted customer pathways after an account has already been accepted. Fraudsters often buy or create low-risk looking accounts, establish normal behaviour, then trigger refunds, returns, or policy exceptions where merchant scrutiny is weaker. This is not a card-present or card-not-present problem alone. It is a lifecycle governance problem that spans identity proofing, account age, behavioural signals, and entitlement checks. When those signals are disconnected, analysts see legitimate-looking sessions until the loss has already occurred.

Practical implication: connect refund decisions to account trust history, device behaviour, and prior lifecycle events, not just transaction value.

How AI changes fraud rings and verification pressure

Generative AI lowers the cost of creating plausible identities, synthetic profiles, and convincing account activity. That matters because fraud programmes often rely on shallow cues such as form completion, email age, or single-step verification. Deepfake-driven account creation and automated evasion techniques can imitate normal user behaviour well enough to pass weak checks. The result is a wider verification gap between who appears legitimate at onboarding and who actually deserves ongoing trust. In identity terms, the challenge is not only proving a user once, but maintaining trust over time.

Practical implication: strengthen step-up verification and behavioural monitoring for early lifecycle accounts and suspicious session patterns.

Why static rules and manual review fail at ecommerce scale

Static rules are retrospective. They encode yesterday’s fraud pattern, then age badly as fraud rings change device fingerprints, shipping patterns, payment instruments, and request timing. Manual review adds another bottleneck because it depends on human capacity that does not scale with seasonal spikes. The article’s core operational point is that fraud defence needs continuous scoring, prioritisation, and analyst triage across the full journey. Without that, teams end up choosing between conversion loss and fraud leakage, which is a false trade-off created by weak orchestration.

Practical implication: replace isolated decline rules with risk scoring and analyst queues that adapt as behaviour changes.


Threat narrative

Attacker objective: The attacker’s objective is to convert low-friction customer trust into repeated financial gain through refunds, rewards, and fraudulent purchases without triggering controls.

  1. Entry begins with account creation, credential stuffing, or synthetic identity activity that produces a trusted-looking customer profile.
  2. Escalation follows as the attacker ages the account, establishes benign behaviour, and builds enough trust to pass weaker fraud checks.
  3. Impact occurs when the account is used for refund abuse, promotion abuse, chargeback-related loss, or draining stored value and loyalty balances.

NHI Mgmt Group analysis

Refund abuse is a customer identity problem before it is a payment problem. Once an account is accepted, many merchants reduce scrutiny and assume the session remains trustworthy. That assumption breaks when attackers age accounts, imitate normal engagement, and cash out through returns or policy exceptions. The useful governance lesson is that trust must be dynamic across the lifecycle, not granted at onboarding and left untouched.

Deepfake-driven fraud creates a verification trust gap that traditional rule stacks cannot close. Identity verification and fraud teams are now facing synthetic signals that look operationally normal but are generated at scale. That makes proofing, authentication, and behavioural analysis part of the same control system. For programmes governed under NIST CSF and NIST SP 800-63, the practical conclusion is that trust signals must be evaluated as a chain, not as isolated checkpoints.

Fraud operations now need lifecycle telemetry, not just loss alerts. Chargeback counts tell you what happened, but they do not explain where trust was over-granted or where controls were bypassed. The better model is to measure account age, device reuse, refund frequency, and exception handling together. That creates a named governance concept we should sharpen here: lifecycle trust decay, meaning the gradual collapse of confidence in an account as behaviour diverges from its original proofing state. Teams that can detect lifecycle trust decay early will contain more abuse before payout.

Risk-based friction only works when identity signals are joined across the journey. A clean checkout alone is not a trustworthy outcome if the account was synthetic or the refund path is weak. Fraud and identity programmes should treat account creation, login, purchase, and post-purchase actions as one control surface. That aligns directly with modern identity governance practice: continuous assurance is more effective than static review when attackers adapt quickly.

Merchant loss figures are now large enough to change governance priorities. The scale described in the article justifies treating fraud prevention as a board-level resilience issue rather than a narrow operations task. That means identity, risk, and commerce teams need shared ownership of abuse pathways, shared metrics, and documented escalation rules. The practitioner conclusion is simple: if the lifecycle is fragmented, attackers will find the seams.

What this signals

Lifecycle trust decay is now a practical fraud governance concept. Once fraudsters can create believable accounts and wait for a later monetisation event, the important metric is not just whether verification passed, but how confidence changes after onboarding. Fraud teams should watch for account-age drift, refund concentration, and device reuse as indicators that trust is decaying across the customer journey.

For teams already aligning fraud operations with NIST Cybersecurity Framework 2.0, the implication is that fraud controls need to sit inside a broader detect-and-respond loop, not outside it. That means identity verification, trust scoring, and exception handling should be operationally linked to commerce workflows rather than reviewed in separate silos.

The market signal is clear: attackers are blending identity manipulation, automation, and post-purchase abuse into one exploit chain. Programmes that can correlate proofing, behaviour, and financial loss will be better positioned to spot abuse earlier, contain false positives, and justify control spend with defensible metrics.


For practitioners

  • Map controls across the full customer lifecycle Tie account creation, login, checkout, refund, and loyalty activity into one risk model so abuse cannot move between disconnected queues. Use shared telemetry for behavioural changes, device reputation, and exception handling.
  • Add step-up checks to early lifecycle accounts Require stronger verification for newly created accounts, unusual device changes, high-value first orders, and refund-heavy behaviour. Keep the friction targeted so legitimate customers are not penalised.
  • Track refund abuse as an identity signal Review refund frequency, timing, shipping anomalies, and account age together because return fraud often appears after initial verification has already passed. Feed those patterns back into trust scoring and analyst queues.
  • Replace static rules with adaptive scoring Use dynamic scoring and prioritised review queues to absorb changing fraud patterns instead of relying on fixed thresholds that age quickly. Measure false declines and manual review burden alongside confirmed loss.

Key takeaways

  • Refund and policy abuse now represents a lifecycle trust problem, not just a checkout fraud problem.
  • The evidence shows that AI-assisted identity fraud and account creation abuse are accelerating the shift toward more automated, harder-to-review attacks.
  • Teams that connect verification, behavioural telemetry, and post-purchase controls will be better placed to reduce loss without adding blanket friction.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while GDPR define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-63SP 800-63BAccount creation fraud and verification abuse map to digital authentication guidance.
NIST CSF 2.0PR.AA-01Fraud controls depend on identity assurance and access decisions across the customer journey.
GDPRArt.32Digital identity and fraud workflows process personal data and require security safeguards.
NIST SP 800-53 Rev 5IA-2Authentication strength matters when attackers reuse or manipulate accounts.

Document safeguards for fraud and identity data under Art.32 and limit exposure in verification flows.


Key terms

  • Refund Abuse: A monetisation tactic where an attacker uses a compromised account to request illegitimate refunds, credits, or reversals. It often follows successful takeover because the account has enough history to look trustworthy. In practice, refund abuse is a business-loss expression of identity compromise.
  • Lifecycle Trust Decay: Lifecycle trust decay is the gradual reduction in confidence that an account or customer is legitimate as its behaviour diverges from its original proofing or verification state. It is a useful fraud governance concept because it frames trust as something that changes over time and must be continuously reassessed.
  • Synthetic Identity: A synthetic identity is a software-based actor that can authenticate, request access, and execute actions without being a human user. In practice, this includes AI agents, bots, service accounts, tokens, and other machine identities that need clear ownership, scope, and revocation.
  • Risk-Based Friction: Risk-based friction is the practice of applying extra verification, inspection, or policy constraints only when signals indicate elevated abuse or loss exposure. It protects the merchant without forcing every customer through the same slow process, which is essential when trust and conversion must both be preserved.

What's in the full article

Sift's full article covers the operational detail this post intentionally leaves for the source:

  • A full breakdown of how the Sift Score is used across account creation, checkout, and post-purchase workflows.
  • Operational examples of Payment Protection, Account Defense, and Content Integrity in retail ecommerce environments.
  • Analyst workflow detail on how Queues and Insights support triage, reporting, and review prioritisation.
  • Specific guidance on balancing friction, false declines, and conversion loss during high-volume sales periods.

👉 The full Sift article covers scoring, queueing, and fraud signal handling across the customer journey.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and identity lifecycle controls. It helps security practitioners connect identity assurance to the broader governance work their programmes depend on.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 11, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org