Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Retail fraud controls are failing beyond login checks and MFA


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 17031
Topic starter  

TL;DR: Retail fraud losses reached $138 billion in 2025 and online payment fraud alone cost merchants $53 billion, according to Fingerprint’s analysis of how omnichannel shopping, BOPIS, and AI-driven credential abuse are outpacing passwords, OTPs, CAPTCHA, and static risk rules. The practical shift is toward persistent device-level signals that reduce false positives without adding friction that drives abandonment.

NHIMG editorial — based on content published by Fingerprint: retail fraud is shifting beyond login checks and one-time codes

By the numbers:

Questions worth separating out

Q: How should retailers reduce fraud without making checkout too slow?

A: Use progressive verification.

Q: Why do passwords and MFA fail as primary fraud controls in retail?

A: Because they prove that someone knows or controls a credential, not that the session is legitimate.

Q: What breaks when BOPIS orders are trusted after login alone?

A: The entire fulfilment chain can inherit a false trust decision.

Practitioner guidance

  • Concentrate step-up checks on high-value retail sessions Apply additional verification only to accounts with stored payment methods, large loyalty balances, or professional-tier purchasing patterns, while allowing recognised low-risk devices to pass without friction.
  • Move fraud controls upstream of fulfilment Place device and session risk decisions at order placement and before BOPIS release, so suspicious activity is stopped before inventory is allocated or goods are handed over.
  • Replace cookie reliance with persistent device signals Use device intelligence, browser attributes, and behavioural anomalies to recognise repeat abuse even when cookies are cleared, browsers change, or incognito mode is used.

What's in the full article

Fingerprint's full report covers the operational detail this post intentionally leaves for the source:

  • Device-intelligence signal breakdowns showing which browser, network, and hardware attributes improve fraud discrimination.
  • Practical guidance on where to place risk checks across login, checkout, BOPIS, and fulfilment workflows.
  • Examples of how Smart Signals can be weighted to reduce false positives while preserving step-up decisions.
  • The report's discussion of device fingerprint persistence across sessions and why that matters for repeat abuse detection.

👉 Read Fingerprint's analysis of retail fraud controls, BOPIS risk, and device intelligence →

Retail fraud controls are failing beyond login checks and MFA?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 16618
 

Static authentication is no longer a sufficient trust boundary for retail fraud. Once passwords and one-time codes can be harvested or relayed, the security decision has to move to the session context and device history. Retail teams that still treat successful login as proof of legitimacy are defending the wrong boundary. The operational conclusion is to build trust decisions around persistent behavioural and device signals, not credential possession.

A question worth separating out:

Q: How do security and fraud teams know whether device intelligence is working?

A: Look for three signals: fewer false positives, lower abandonment at login and checkout, and earlier detection of repeated abuse from the same persistent device. If fraud loss drops while good customers move through without extra friction, the device layer is doing its job. If challenges increase but loss does not fall, the controls are too blunt.

👉 Read our full editorial: Retail fraud is shifting beyond login checks and one-time codes



   
ReplyQuote
Share: