Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM Why can fraud attempts rise during a sales…
Identity Beyond IAM

Why can fraud attempts rise during a sales boom even when the fraud share falls?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 19, 2026 Domain: Identity Beyond IAM

Fraud attempts often rise because fraudsters mimic normal shopping patterns and follow the same demand surge as legitimate customers. When overall transaction volume expands faster than suspicious activity, fraud can increase in absolute terms while shrinking as a percentage of total orders. That is why teams should monitor both fraud volume and fraud rate before changing approval policy.

Why the denominator matters during a boom

A sales surge changes the denominator. If legitimate orders grow faster than suspicious orders, the fraud rate can fall even while the absolute number of fraud attempts rises. For operations teams, that means a clean-looking percentage can hide more total cases, more review workload, and more exposure if controls are tuned only to ratio-based thresholds.

That pattern is easiest to miss when teams look at one dashboard metric in isolation. During a demand spike, fraudsters often blend into the same seasonality, channel mix, and geography that legitimate buyers follow, so the operational question becomes whether volume is rising in step with demand or outpacing it.

When transaction growth is the dominant force, the right comparison is not “fraud up or down”, but “fraud growth versus sales growth”. A lower fraud share can still coincide with more manual reviews, more chargeback exposure later, and more pressure on approval queues if policy changes are based on the percentage alone.

How fraudsters exploit normal shopping behaviour

Fraud attempts often rise because bad actors track the same commercial conditions that drive legitimate demand. Promotions, product launches, restocks, and holiday traffic create a larger pool of transactions that can mask testing, account takeover, carding, and abuse of weak approval logic.

That matters because fraud activity is rarely uniform. Some attempts are opportunistic and scale with traffic; others are targeted at high-value items or high-throughput periods when defenders are busy and more likely to loosen controls. The result is a pattern where the fraud count expands alongside the business, even if the proportion of suspicious orders declines.

The practical implication is that a falling rate should not be treated as proof that fraud pressure is easing. It may simply mean the business grew faster than the attacker set, or that the same attack volume is being diluted by a larger legitimate order base. The control question is whether the organisation can still distinguish normal lift from disguised abuse.

What teams should monitor before changing approval policy

Fraud decisions should be driven by both volume and rate, plus the business context behind the spike. A team should look at absolute fraud attempts, fraud as a share of orders, approval latency, chargeback trends, false positives, and which products or channels are attracting the change. That gives a fuller picture than rate alone.

What to verify: Check whether the fraud increase is concentrated in a specific channel, payment method, geography, or product class. If the spike mirrors legitimate demand, keep the tighter policy under review rather than immediately relaxing it. If fraud is growing faster than sales in a specific slice, investigate whether an attack pattern is being masked by overall growth.

Decision rule: If fraud attempts are rising in absolute terms, do not widen approval criteria just because the percentage falls. Treat the lower rate as one input, not the deciding signal, and compare it with backlog pressure, customer friction, and downstream loss indicators before changing thresholds.

Practitioner takeaway: The safest interpretation of a falling fraud share is “context changed”, not “risk disappeared”. In a boom period, control decisions should be anchored to both absolute fraud activity and relative fraud rate so that growth does not hide emerging abuse.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS 8 — Audit Log ManagementFraud spike analysis depends on logging and trend visibility across transaction activity.
CIS 15 — Service Provider ManagementSales booms often involve external processors and channels that can change fraud exposure.
Recommendation — Correlate order, approval, and chargeback telemetry to spot fraud growth hidden by overall sales growth. Review third-party payment and channel controls when transaction volume changes materially.
NIST CSF 2.0DE.CM — Continuous MonitoringMonitoring both rate and absolute volume is a detection problem requiring continuous measurement.
RS.AN — AnalysisFraud growth during a boom needs analysis of whether attackers are scaling with demand or hiding in it.
Recommendation — Track absolute fraud attempts alongside fraud rate so control tuning reflects the true trend. Analyse whether fraud is rising faster than legitimate sales before changing approval policy.
MITRE ATT&CKT1110 — Brute ForceTraffic surges can conceal bulk testing and repeated abuse patterns consistent with credential attacks.
Recommendation — Hunt for repeated failed attempts and other bulk abuse patterns when sales volume spikes.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 19, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org