Because they prove that someone knows or controls a credential, not that the session is legitimate. Stolen passwords, relay attacks, SIM swapping, and AI-assisted social engineering make those signals easy to bypass. Retailers need context from the device, network, and behaviour behind the login before they assume the customer is genuine.
Why This Matters for Security Teams
Passwords and MFA are useful authentication signals, but they are weak as standalone fraud controls because they answer only one question: did the user present the expected factor? In retail, fraudsters increasingly work around that test with credential stuffing, phishing, session hijacking, SIM swap abuse, and support-channel manipulation. NIST SP 800-53 Rev 5 Security and Privacy Controls frames authentication as one part of a broader control environment, which is the right way to think about it when account takeover, refund fraud, and loyalty abuse are the real risks.
The operational mistake is treating successful login as evidence of trust. Retailers often discover that the account is compromised only after baskets, shipping addresses, delivery timing, or payment methods start to change in ways that look legitimate at the login screen. That creates a detection gap between authentication and transaction integrity, and it is where fraud losses accumulate.
In practice, many security teams encounter abuse only after a customer disputes the transaction, rather than through intentional session risk detection.
How It Works in Practice
Effective retail fraud control uses authentication as an input, not a verdict. Stronger programs combine login signals with device reputation, behavioural patterns, network intelligence, transaction history, and step-up challenges tied to risk. That allows the retailer to distinguish a normal customer session from an account under active manipulation, even when the password and MFA response are technically valid.
Common implementation patterns include:
- Risk scoring at login and at checkout, rather than only at account entry.
- Device binding or persistent device recognition for returning customers.
- Behavioural signals such as typing cadence, navigation flow, and purchase velocity.
- Step-up verification only when the session deviates from the user’s normal pattern.
- Correlation of identity events with delivery address changes, refund requests, and payment instrument reuse.
Retailers should also be explicit about what MFA can and cannot prove. Push approvals, one-time codes, and SMS-based factors can reduce opportunistic abuse, but they do not reliably stop real-time phishing proxies, social engineering of support staff, or adversary-in-the-middle attacks. Guidance from the NIST digital identity guidelines is useful here: assurance must be matched to the transaction risk, not assumed to be static across all customer actions.
Where retailers have mature controls, authentication events feed fraud engines and customer risk models in near real time. That lets analysts see the whole sequence, including login source, device change, velocity spikes, and unusual fulfilment behaviour, instead of relying on a single success event. This approach also matters for API-driven commerce and mobile apps, where the session may be legitimate but the subsequent action is automated or coerced. These controls tend to break down when legacy commerce platforms cannot share identity, device, and transaction telemetry because the fraud decision becomes blind to context.
Common Variations and Edge Cases
Tighter fraud controls often increase friction, so retailers must balance conversion, customer experience, and loss prevention. That tradeoff is especially sharp for high-value purchases, gift cards, digital goods, and loyalty redemption, where low-friction checkout is commercially important but also attractive to attackers.
Best practice is evolving for passwordless and passkey-based flows. These can improve phishing resistance, but they are not a complete fraud solution on their own. A valid passkey still does not prove that the device owner is acting voluntarily, that the session is free from malware, or that the transaction intent matches the customer’s normal behaviour. Retail fraud teams should therefore treat authentication strength and fraud confidence as related, but separate, decisions.
There is also no universal standard for when step-up checks should trigger. The right threshold depends on merchant risk appetite, chargeback exposure, geography, and regulatory obligations. For retailers handling payment data, PCI DSS v4.0 guidance remains relevant because it reinforces layered controls around account access and payment protection, not reliance on credentials alone. In high-abuse environments, the goal is to make compromised access less useful, not merely harder to obtain.
Identity assurance and fraud detection converge most clearly when a retailer can link login trust, device trust, and transaction trust into one decision model.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 address the attack surface, NIST CSF 2.0, NIST SP 800-63 and NIST AI RMF set the technical controls, and PCI DSS v4.0 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA-01 | Authentication must be joined with broader asset and access risk decisions. |
| NIST SP 800-63 | SP 800-63B | Digital identity assurance defines what credentials can and cannot prove. |
| PCI DSS v4.0 | 8 | Retail payment environments need layered access controls around account use. |
| NIST AI RMF | GOVERN | Fraud scoring increasingly uses AI, so governance and accountability matter. |
| OWASP Agentic AI Top 10 | AI-assisted social engineering and automated abuse can bypass weak user verification. |
Treat login success as one signal and correlate it with fraud telemetry before allowing high-risk actions.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 15, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org