By NHI Mgmt Group Editorial TeamDomain: Identity Beyond IAMSource: FingerprintPublished June 9, 2026

TL;DR: Retail fraud losses reached $138 billion in 2025 and online payment fraud alone cost merchants $53 billion, according to Fingerprint’s analysis of how omnichannel shopping, BOPIS, and AI-driven credential abuse are outpacing passwords, OTPs, CAPTCHA, and static risk rules. The practical shift is toward persistent device-level signals that reduce false positives without adding friction that drives abandonment.


At a glance

What this is: This is Fingerprint’s analysis of why traditional retail fraud controls are losing effectiveness as omnichannel shopping, BOPIS, and AI-driven credential abuse expand the attack surface.

Why it matters: It matters because fraud teams now need detection that spans login, checkout, fulfilment, and chargeback defence without adding friction that damages conversion and loyalty.

By the numbers:

👉 Read Fingerprint's analysis of retail fraud controls, BOPIS risk, and device intelligence


Context

Retail fraud is no longer a single-login problem. Once credentials can be bought, phished, relayed, or replayed at scale, the control point has to move from the credential itself to the session, device, and fulfilment path that follows it. In retail, that is especially true where loyalty programmes and BOPIS blend digital access with physical product pickup.

The identity angle is real even though this is a fraud and device-intelligence article. Account takeover, stored payment methods, loyalty balances, and checkout verification all depend on trust in the account, but passwords and one-time codes are no longer enough to prove the person or device behind the session is legitimate.


Key questions

Q: How should retailers reduce fraud without making checkout too slow?

A: Use progressive verification. Keep low-risk browsing and sign-up flows fast, then increase assurance only when users request account recovery, payment enrolment, or other high-value actions. That approach preserves conversion while still creating a real control point where fraud risk is highest. Measure both fraud loss and abandonment so you can see whether the balance is working.

Q: Why do passwords and MFA fail as primary fraud controls in retail?

A: Because they prove that someone knows or controls a credential, not that the session is legitimate. Stolen passwords, relay attacks, SIM swapping, and AI-assisted social engineering make those signals easy to bypass. Retailers need context from the device, network, and behaviour behind the login before they assume the customer is genuine.

Q: What breaks when BOPIS orders are trusted after login alone?

A: The entire fulfilment chain can inherit a false trust decision. A compromised account can place an order, reserve inventory, and release goods for pickup before the real customer notices. That turns one authentication failure into merchandise loss, dispute labour, and chargeback exposure, especially when loyalty accounts and stored payment methods are involved.

Q: How do security and fraud teams know whether device intelligence is working?

A: Look for three signals: fewer false positives, lower abandonment at login and checkout, and earlier detection of repeated abuse from the same persistent device. If fraud loss drops while good customers move through without extra friction, the device layer is doing its job. If challenges increase but loss does not fall, the controls are too blunt.


Technical breakdown

Why passwords, OTPs, and CAPTCHA fail in retail fraud flows

Passwords, one-time codes, and CAPTCHA were designed for a simpler threat model in which proving possession of a secret was a useful proxy for legitimacy. That breaks down when credentials are harvested through phishing, SIM swapping, real-time relay attacks, and AI-generated lures. CAPTCHA can be scripted around, MFA prompts can be socially engineered, and a valid login still tells you nothing about the device, network, or behavioural context behind the session. In modern retail fraud, authentication often confirms account access without confirming customer intent.

Practical implication: treat successful authentication as one input, not the decision point for account trust.

How BOPIS and loyalty accounts expand the fraud blast radius

BOPIS creates a bridge between digital compromise and physical loss because the online order can be legitimate-looking even when the underlying account is stolen. Loyalty accounts intensify the problem by concentrating stored payment methods, points, and purchase history into a high-value target. Once the account is trusted, the order, pickup, refund, and chargeback paths often inherit that trust by default. That creates a cascading failure where a single compromised account can generate merchandise loss, dispute labour, customer service cost, and churn.

Practical implication: add risk controls at order placement and fulfilment, not only at login.

Device intelligence as a persistent signal for account fraud

Device intelligence uses many browser, network, and hardware attributes to build a persistent visitor identifier that survives cookie deletion, browser resets, and incognito mode. That makes it materially different from static signals like IP reputation or cookie-based recognition. When combined with behavioural and anomaly signals, it gives fraud engines a way to distinguish first-time legitimate shoppers from repeated abuse patterns and high-risk automation. The control value is not just detection. It is selective friction, where only the riskiest sessions are challenged or blocked.

Practical implication: use persistent device signals to tune step-up challenges and reduce false positives.


Threat narrative

Attacker objective: The attacker wants to monetise trusted retail accounts by converting valid login access into payment fraud, merchandise theft, and account abuse at scale.

  1. Entry occurs when attackers obtain valid retail account credentials through phishing, credential stuffing, AI-generated lures, or social engineering.
  2. Escalation follows when the authenticated session is treated as legitimate and the attacker reaches stored payment methods, loyalty balances, or order placement workflows.
  3. Impact lands in fraud loss, chargebacks, dispute labour, and in BOPIS cases, physical merchandise theft before the legitimate customer can react.

NHI Mgmt Group analysis

Static authentication is no longer a sufficient trust boundary for retail fraud. Once passwords and one-time codes can be harvested or relayed, the security decision has to move to the session context and device history. Retail teams that still treat successful login as proof of legitimacy are defending the wrong boundary. The operational conclusion is to build trust decisions around persistent behavioural and device signals, not credential possession.

BOPIS has turned account fraud into a cross-channel control problem. The issue is not only digital account takeover, but the way an authenticated online order can be converted into physical loss at pickup. That means fraud, e-commerce, and store operations all share responsibility for the same risk chain. Practitioners should align pickup controls, fulfilment verification, and account risk scoring as one programme, not separate workstreams.

Device-level intelligence is becoming the named concept that matters here: session trust without credential trust. The article’s core insight is that fraud detection now needs a durable signal that survives browser resets, VPN use, and AI-assisted automation. This does not replace authentication, but it changes what authentication is for. Teams should treat device intelligence as the signal that separates access from trust.

Retail fraud governance now depends on balancing friction against revenue leakage. Too much friction increases abandonment, while too little allows fraudulent sessions to flow through login, checkout, and pickup. That tradeoff makes fraud optimisation a governance discipline, not just a rules-engine problem. The practical conclusion is that fraud teams need measurable control objectives for both loss prevention and customer experience.

Friction-based controls must be judged against omnichannel economics, not generic security instinct. Static risk thresholds and broad challenge policies often create more customer harm than fraud reduction. The better model is risk concentration, where high-value accounts, suspicious devices, and vulnerable fulfilment steps receive stronger controls while ordinary shoppers move through with less interruption. Practitioners should re-tune controls around value at risk and session confidence.

What this signals

Retail fraud programmes are moving toward trust signals that survive session changes, device resets, and AI-assisted credential abuse. The practical signal for practitioners is that checkout, login, and fulfilment controls now have to be measured as one chain, not three separate events.

Session trust without credential trust: this is the governance pattern emerging in omnichannel retail. When the same account can be accessed from multiple devices, through VPNs, or via relay attacks, device intelligence becomes a decision layer rather than an investigative luxury. Teams should align risk scoring with value at risk and abandonment tolerance.

The identity intersection matters because retail accounts are increasingly repositories of payment methods, loyalty value, and personal data. That makes account takeover both a fraud problem and an access governance problem. For programmes that manage human identity alongside customer trust, this is a reminder that verification strength and user experience must be measured together.


For practitioners

  • Concentrate step-up checks on high-value retail sessions Apply additional verification only to accounts with stored payment methods, large loyalty balances, or professional-tier purchasing patterns, while allowing recognised low-risk devices to pass without friction.
  • Move fraud controls upstream of fulfilment Place device and session risk decisions at order placement and before BOPIS release, so suspicious activity is stopped before inventory is allocated or goods are handed over.
  • Replace cookie reliance with persistent device signals Use device intelligence, browser attributes, and behavioural anomalies to recognise repeat abuse even when cookies are cleared, browsers change, or incognito mode is used.
  • Tune challenge policies against abandonment data Measure how often login, reset, and verification prompts cause cart abandonment, then reduce friction where the business impact exceeds the fraud benefit.

Key takeaways

  • Retail fraud controls built around passwords, OTPs, and CAPTCHA are no longer enough to distinguish legitimate customers from attacker-controlled sessions.
  • The scale is already material, with $138 billion in global ecommerce fraud losses and $53 billion in online payment fraud in 2025.
  • Persistent device intelligence is the control lever that lets teams reduce fraud without turning every customer journey into a high-friction challenge.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST SP 800-63 set the technical controls, while GDPR define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-4Retail fraud decisions hinge on access and session trust, which maps to least-privilege access control.
NIST SP 800-53 Rev 5IA-5Authentication and authenticator management are directly challenged by stolen credentials and relay attacks.
GDPRArt.32Where customer identity data and behavioural signals are processed, security of processing is relevant.
NIST SP 800-63SP 800-63BThe article questions reliance on single-factor and MFA-based authentication assurance.

Document access controls and risk scoring under Art.32 when device intelligence processes personal data.


Key terms

  • Device Intelligence: Device intelligence is the practice of interpreting signals from a device to assess whether a session or transaction is likely legitimate. It goes beyond fingerprinting by combining device context with behavioural, identity, and payment evidence to support a risk decision.
  • Account Takeover: Account takeover is unauthorized use of a legitimate account after an attacker obtains valid access through stolen credentials, tokens, or trusted integrations. The key security problem is that the resulting activity often looks normal to logs and controls, which makes containment and attribution harder than in a forced-entry breach.
  • Buy Online, Pick Up In Store: Buy online, pick up in store is a fulfilment model where customers place orders digitally and collect goods at a physical location. It creates a fraud bridge because a compromised online account can be turned into physical product loss if pickup verification does not independently challenge the order.
  • False Positive: A false positive is a scanner result that looks like a secret but is not actually sensitive. In secret governance, false positives matter because they consume analyst time, weaken trust in alerts, and can delay response to the findings that truly change exposure and access risk.

What's in the full article

Fingerprint's full report covers the operational detail this post intentionally leaves for the source:

  • Device-intelligence signal breakdowns showing which browser, network, and hardware attributes improve fraud discrimination.
  • Practical guidance on where to place risk checks across login, checkout, BOPIS, and fulfilment workflows.
  • Examples of how Smart Signals can be weighted to reduce false positives while preserving step-up decisions.
  • The report's discussion of device fingerprint persistence across sessions and why that matters for repeat abuse detection.

👉 Fingerprint's full report covers the device signal strategy, conversion tradeoffs, and downstream fraud costs in more detail.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, secrets management, and access lifecycle fundamentals. It is designed for practitioners who need to connect identity control to broader security operations.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 15, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org