TL;DR: Fraud rarely appears as a single bad transaction; it emerges as a network pattern, and Sift’s Q2 2026 Digital Trust Index webinar shows how card testing, account takeover, and post-incident response create different control demands across merchants. Small signals like repeated card attempts, email changes, and unusual basket values matter most when seen across a broader fraud network. The governance lesson is that isolated merchant controls cannot see ring behaviour soon enough to stop it.
NHIMG editorial — based on content published by Sift: the Connected Threat webinar on fraud rings, ATO patterns, and payment fraud benchmarks
By the numbers:
- Transaction volume across Sift's network grew more than 15% this year, expanding the attack surface for fraudsters.
- The ATO ring targeted more than 90 businesses and generated nearly 13,000 attempted transactions.
- Roughly 80% of surveyed consumers said a quick, proactive resolution improved their perception of a business.
Questions worth separating out
Q: How should fraud teams distinguish card testing from account takeover?
A: Treat card testing as a high-volume validation pattern and account takeover as an identity integrity problem.
Q: Why do fraud rings require network-level visibility?
A: Because the same abuse pattern often spans multiple merchants, devices, and accounts before any one business sees enough volume to act.
Q: What do security and fraud teams get wrong about post-incident response?
A: They often treat resolution as a support issue rather than a control outcome.
Practitioner guidance
- Separate card testing from account takeover rules Use low-value transaction thresholds, repeated card-use caps, and velocity checks for card testing, but reserve step-up authentication and account review for ATO indicators such as email changes or unusual login patterns.
- Correlate fraud signals across channels and merchants Combine device, card, email, login, and transaction data so one merchant's small anomaly can contribute to a broader ring pattern instead of being dismissed as noise.
- Treat identity changes as high-risk events Flag changes to account email, recovery details, and receipt destinations as trust-boundary shifts that should trigger stronger verification before a purchase or payout is allowed.
What's in the full article
Sift's full post covers the operational detail this analysis intentionally leaves for the source:
- The webinar's side-by-side fraud ring breakdowns, including the exact signal combinations that distinguished card testing from ATO.
- The live poll results showing how consumers actually discovered account takeover, which helps benchmark response expectations.
- The discussion of merchant response patterns and why friction, not hard blocking, is the preferred control path for some ATO cases.
- The full Q2 2026 Digital Trust Index findings on how response speed and transparency affect trust after an incident.
👉 Read Sift's analysis of fraud rings, ATO patterns, and trust recovery →
Fraud rings and ATO patterns: what should fraud teams do next?
Explore further
Card testing is a visibility problem disguised as a payment problem. The article shows that a single merchant may only see a few suspicious attempts, while the real ring is distributed across many businesses. That pattern means local controls are necessary but insufficient, because the attacker is relying on the organisation's narrow view. For fraud and identity teams, the governance gap is cross-merchant correlation, not merely stricter blocking.
A question worth separating out:
Q: How do identity teams reduce account takeover risk without blocking normal users?
A: By focusing friction on trust-boundary changes and unusual behaviour instead of every login or purchase. ATO defence works best when teams revalidate sensitive changes, apply step-up checks to risky sessions, and keep routine flows low-friction for known-good users. The aim is selective verification, not blanket suspicion.
👉 Read our full editorial: Fraud rings and ATO patterns expose the limits of single-site fraud