TL;DR: Retail fraud losses reached $138 billion in 2025 and online payment fraud alone cost merchants $53 billion, according to Fingerprint’s analysis of how omnichannel shopping, BOPIS, and AI-driven credential abuse are outpacing passwords, OTPs, CAPTCHA, and static risk rules. The practical shift is toward persistent device-level signals that reduce false positives without adding friction that drives abandonment.
NHIMG editorial — based on content published by Fingerprint: retail fraud is shifting beyond login checks and one-time codes
By the numbers:
- Global ecommerce fraud losses exceeded $138 billion in 2025 and are projected to nearly double by 2029.
- $53 billion in 2025., cost merchants $53 billion in 2025.
- 58% of shoppers abandon their transaction when they encounter difficulties at the login or verification step.
Questions worth separating out
Q: How should retailers reduce fraud without making checkout too slow?
A: Use progressive verification.
Q: Why do passwords and MFA fail as primary fraud controls in retail?
A: Because they prove that someone knows or controls a credential, not that the session is legitimate.
Q: What breaks when BOPIS orders are trusted after login alone?
A: The entire fulfilment chain can inherit a false trust decision.
Practitioner guidance
- Concentrate step-up checks on high-value retail sessions Apply additional verification only to accounts with stored payment methods, large loyalty balances, or professional-tier purchasing patterns, while allowing recognised low-risk devices to pass without friction.
- Move fraud controls upstream of fulfilment Place device and session risk decisions at order placement and before BOPIS release, so suspicious activity is stopped before inventory is allocated or goods are handed over.
- Replace cookie reliance with persistent device signals Use device intelligence, browser attributes, and behavioural anomalies to recognise repeat abuse even when cookies are cleared, browsers change, or incognito mode is used.
What's in the full article
Fingerprint's full report covers the operational detail this post intentionally leaves for the source:
- Device-intelligence signal breakdowns showing which browser, network, and hardware attributes improve fraud discrimination.
- Practical guidance on where to place risk checks across login, checkout, BOPIS, and fulfilment workflows.
- Examples of how Smart Signals can be weighted to reduce false positives while preserving step-up decisions.
- The report's discussion of device fingerprint persistence across sessions and why that matters for repeat abuse detection.
👉 Read Fingerprint's analysis of retail fraud controls, BOPIS risk, and device intelligence →
Retail fraud controls are failing beyond login checks and MFA?
Explore further
Static authentication is no longer a sufficient trust boundary for retail fraud. Once passwords and one-time codes can be harvested or relayed, the security decision has to move to the session context and device history. Retail teams that still treat successful login as proof of legitimacy are defending the wrong boundary. The operational conclusion is to build trust decisions around persistent behavioural and device signals, not credential possession.
A question worth separating out:
Q: How do security and fraud teams know whether device intelligence is working?
A: Look for three signals: fewer false positives, lower abandonment at login and checkout, and earlier detection of repeated abuse from the same persistent device. If fraud loss drops while good customers move through without extra friction, the device layer is doing its job. If challenges increase but loss does not fall, the controls are too blunt.
👉 Read our full editorial: Retail fraud is shifting beyond login checks and one-time codes