Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM How should merchants structure fraud-prevention programmes when account…
Identity Beyond IAM

How should merchants structure fraud-prevention programmes when account takeover, chargebacks, and returns abuse are all rising at once?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 16, 2026 Domain: Identity Beyond IAM

Merchants should treat these as connected abuse patterns, not separate problems. The strongest approach combines early detection, customer authentication, transaction risk scoring, and clear dispute handling. That lets teams reduce friction for legitimate buyers while interrupting repeated abuse paths, especially in high-pressure periods like holidays. The goal is to coordinate controls so one weak point does not become the easiest route for fraud.

Why This Matters for Security Teams

Merchants are dealing with three abuse patterns that often share the same operational roots: weak account controls, poor transaction-level detection, and inconsistent post-transaction handling. When those problems rise together, fraud teams can no longer optimise each channel in isolation. A control that reduces chargebacks but adds friction to legitimate buyers can push abuse into returns, while a lenient returns path can become a profitable fallback after account takeover. Coordinated programmes matter because they let teams see the full abuse chain, not just the individual loss event. Practically, this is a governance problem as much as a fraud problem. The team that owns login security, the team that reviews disputes, and the team that manages returns all see different symptoms of the same attacker or abuser behaviour. If they do not share signals, they will keep treating the same actor as a series of unrelated incidents. In practice, many merchants discover the pattern only after one abuse path has been squeezed and the volume simply shifts elsewhere.

How It Works in Practice

A useful programme starts by separating preventive, detective, and responsive controls, then linking them to the same customer and order risk view. Prevention should focus on reducing easy account reuse and fraudulent checkout activity. Detection should look for behavioural patterns that span channels, such as rapid credential resets followed by address changes, unusual purchase velocity, repeated low-value orders, or return requests that cluster around the same devices, payment instruments, or shipping destinations. Response should make it easy to step up review where risk is elevated, while preserving a smooth path for low-risk buyers.
  • Use account-risk signals before checkout, not only at login, so takeover attempts are assessed in context.
  • Combine transaction scoring with customer-history signals, because chargeback risk and returns abuse often emerge after the first successful purchase.
  • Align dispute rules with fraud outcomes, so teams do not approve one type of refund while ignoring the pattern that caused it.
  • Track repeat identities, repeat devices, and repeat fulfilment patterns across channels to identify serial abuse.
The most effective programmes also define what counts as a recoverable loss versus a blocked attack. That distinction helps analysts avoid over-blocking legitimate customers who simply look risky during holiday spikes, promo events, or inventory shortages. Strong process design reduces manual review load because the same evidence can support account protection, payment review, and returns decisions without creating three separate investigations. Controls tend to break down when merchants run separate tools for login fraud, payment fraud, and returns management, because the handoff gaps let the same actor move to the next weakest control.

Common Variations and Edge Cases

Tighter fraud controls often increase customer friction and manual review cost, so organisations need to balance loss reduction against conversion, retention, and support workload. That trade-off becomes sharper when chargeback pressure is high but legitimate return rates are also seasonal. One common variation is that returns abuse may look operational rather than malicious at first. Some merchants see it as customer service leakage until the pattern is large enough to distort inventory, margins, and staffing. Another edge case is account takeover without immediate fraudulent purchase. Attackers may first change delivery details, save payment methods, or build trust before monetising the account later. Best practice is evolving toward treating those pre-purchase changes as meaningful risk signals, not just harmless profile edits. Returns-heavy businesses also need different thresholds from digital goods or subscription merchants. A policy that works for low-return categories may fail where size, fit, or delivery uncertainty is normal. In those environments, the right answer is usually not harsher denial, but better segmentation: higher trust for stable customers, closer review for unusual behaviour, and clearer evidence capture for disputes and returns. The programme should be tuned to the business model rather than copied from another merchant category.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v86 — Access Control ManagementFraud programmes here depend on restricting account misuse and repeated abuse paths.
8 — Audit Log ManagementCross-channel fraud detection relies on log data from login, payment and returns events.
16 — Application Software SecurityCheckout and returns workflows need secure handling to reduce abuse-prone transaction logic.
Recommendation — Tighten account access and review abusive patterns that indicate takeover or repeated misuse. Correlate account, transaction and returns logs to identify linked abuse sequences. Harden customer-facing workflows so fraud checks are enforced consistently across channels.
NIST CSF 2.0PR.AA — Identity Management, Authentication and Access ControlAccount takeover risk makes authentication and access control central to the programme.
DE.CM — Continuous MonitoringThe programme needs monitoring across accounts, transactions and returns for linked abuse.
RS.MI — MitigationFraud response must interrupt abuse paths once coordinated patterns are detected.
Recommendation — Strengthen authentication and access controls to reduce account takeover opportunities. Monitor behavioural signals across fraud channels and trigger review on repeated patterns. Apply mitigations quickly when account takeover, chargebacks or returns abuse recur together.
MITRE ATT&CKT1078 — Valid AccountsAccount takeover commonly relies on stolen credentials and valid account access.
T1110 — Brute ForceCredential attacks are a common precursor to account takeover in retail fraud.
Recommendation — Hunt for valid-account abuse and correlate it with downstream fraud activity. Detect automated credential attacks before they become successful account takeovers.

Practitioner Guidance

What to prioritise: Build one shared fraud view across login, payment, and returns data. If teams only see their own slice, they will keep displacing abuse instead of reducing it.

Decision rule: If an account shows takeover indicators and then triggers a refund or return request soon after, treat the case as a linked abuse sequence and route it for stepped-up review rather than isolated handling.

What to measure: Track repeat actors across channels, false-positive friction on legitimate buyers, and the share of losses that move from chargebacks into returns. That shows whether controls are suppressing abuse or merely redirecting it.

Practitioner takeaway: The objective is not to make every channel harder; it is to make abuse expensive at every step while keeping legitimate customers moving through the path with the least resistance.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 16, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org