Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Refund abuse in ecommerce: what it means for fraud teams


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15374
Topic starter  

TL;DR: Digital commerce brands lost an estimated $48 billion to fraud in 2025, while refund and policy abuse displaced payment fraud as the top merchant threat and every confirmed dollar now costs U.S. merchants $5.13, according to Sift and the Merchant Risk Council. Rules and manual review cannot keep pace with automated fraud rings that probe, adapt, and return at scale.

NHIMG editorial — based on content published by Sift: fraud prevention for digital commerce and retail ecommerce brands

By the numbers:

Questions worth separating out

Q: How should fraud teams handle account trust across the full customer journey?

A: Fraud teams should treat trust as a lifecycle property, not a one-time onboarding decision.

Q: Why do synthetic identities and deepfakes make ecommerce fraud harder to stop?

A: They make weak verification signals less reliable.

Q: What do security teams get wrong about refund abuse?

A: They often treat refund abuse as a customer service issue rather than an identity and policy problem.

Practitioner guidance

  • Map controls across the full customer lifecycle Tie account creation, login, checkout, refund, and loyalty activity into one risk model so abuse cannot move between disconnected queues.
  • Add step-up checks to early lifecycle accounts Require stronger verification for newly created accounts, unusual device changes, high-value first orders, and refund-heavy behaviour.
  • Track refund abuse as an identity signal Review refund frequency, timing, shipping anomalies, and account age together because return fraud often appears after initial verification has already passed.

What's in the full article

Sift's full article covers the operational detail this post intentionally leaves for the source:

  • A full breakdown of how the Sift Score is used across account creation, checkout, and post-purchase workflows.
  • Operational examples of Payment Protection, Account Defense, and Content Integrity in retail ecommerce environments.
  • Analyst workflow detail on how Queues and Insights support triage, reporting, and review prioritisation.
  • Specific guidance on balancing friction, false declines, and conversion loss during high-volume sales periods.

👉 Read Sift's analysis of fraud prevention for digital commerce and retail ecommerce →

Refund abuse in ecommerce: what it means for fraud teams?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14958
 

Refund abuse is a customer identity problem before it is a payment problem. Once an account is accepted, many merchants reduce scrutiny and assume the session remains trustworthy. That assumption breaks when attackers age accounts, imitate normal engagement, and cash out through returns or policy exceptions. The useful governance lesson is that trust must be dynamic across the lifecycle, not granted at onboarding and left untouched.

A question worth separating out:

Q: What should organisations measure if they want to know fraud controls are working?

A: Organisations should measure whether controls are increasing attacker cost, reducing campaign success rates, and forcing repeated abuse to become uneconomic. A control can reduce one attempt and still fail strategically if attackers can immediately retry at low cost. The right metric is not only detection, but deterrence.

👉 Read our full editorial: Refund abuse is now the top digital commerce fraud threat



   
ReplyQuote
Share: