The Serial Returner No Single Shop Can See

Refund fraud is now the leading fraud threat facing online merchants, and the reason it keeps winning is not clever technology. It is a blind spot built into how every retailer looks at its own data.
Picture one person filing a false claim at ten different retailers in a month. At each one, they are a single anomaly: one disputed delivery, one refund request that does not quite add up, one return that arrives lighter than it left. Ten quiet cases, spread across ten businesses that never compare notes. To each retailer, this looks like bad luck. To the person doing it, it looks like a business model.
Why Is Refund Fraud the Top Threat Now?
Because the fraud moved after the sale, and the numbers followed it. In 2024, for the first time in 25 years, the Merchant Risk Council found refund and policy abuse and first-party misuse had become the leading fraud threats in North America and Europe, ahead of phishing, with 48% of merchants naming refund and policy abuse a top fraud type.
For most of the last two decades, fraud in retail meant the moment of payment: stolen cards, account takeover, bad transactions stopped at checkout. That is not where the pressure is anymore. The 2026 Chargebacks911 report found friendly fraud rising for 83% of enterprise merchants and 27.1% of returns attributed to refund abuse. The tooling, mostly built for the checkout, has been slow to follow the threat into the returns and delivery layer.
What Makes One Fraudster Invisible to Ten Retailers?
Scale, deliberately kept small. Fraud detection at a single retailer is a search for the abnormal: it compares a customer against that retailer's own baseline and flags what stands out. That works against someone who does something extreme in one place, and badly against someone who does something small in many places.
A serial claimant understands this instinctively. Keep the behaviour at any one retailer modest and it never rises above that retailer's normal noise. One claim is not a pattern. It is a Tuesday. The pattern only exists when you stack all ten claims together, and the one place they are never stacked together is inside any single retailer's data. The detection is not failing because it is weak. It is failing because it is pointed at the wrong scope.
Do Better In-House Tools Solve It?
No, because the ceiling is the data, not the model. More data science, tighter rules and smarter scoring all help at the edges, but they train on the same limited view: this business, and only this business. You can see the strain in how merchants cope, with only 34% running a dedicated chargeback team and nearly a quarter juggling five or more separate tools (Chargebacks911, 2026).
This is the uncomfortable part for anyone who has spent money on the problem. A better keyhole is still a keyhole. The information that would resolve the ten-claim pattern does not exist anywhere inside the business being defrauded. It exists across the businesses, in aggregate, and nowhere else.
What Does Guessing Actually Cost?
It costs a victim on every decision. Because the pattern is invisible, retailers make calls on incomplete information, and each call lands on someone.
Refuse a claim and you might deny a genuine customer whose parcel really was lost, turning a loyal shopper into a public one-star review. Approve it and you might be paying a serial abuser to come back next week. Tighten the policy for everyone and you tax the honest majority to deter a dishonest few. Raise prices to cover the leakage and, as we wrote in Honest Shoppers Are Already Paying for Friendly Fraud, the honest customer ends up paying for fraud they never committed. Every move is a guess, because the retailer cannot tell the repeat offender from the unlucky first-timer.
Is This a Technology Problem or a Coordination Problem?
It is a coordination problem wearing a technology problem's clothes. Refund fraud is not a modelling gap that a sufficiently clever algorithm will close. It is a structural gap in visibility, and the UK has closed exactly this kind of gap before.
Bodies like CIFAS exist because identity and application fraud were unsolvable one bank at a time. A fraudster rejected at one bank simply walked to the next, until the banks agreed to share signals about fraudulent applications. The individual institution did not get smarter. The network did, and the fraud that relied on institutions not talking to each other stopped working. Delivery and refund fraud sits where identity fraud sat before that network existed.
What Does a Shared View Change?
It changes who looks suspicious. When a claimant's behaviour is visible across many retailers instead of one, the serial abuser and the genuine customer stop looking identical, and that single change ripples outward.
Here is the difference in practice:
| Decision | Single-retailer view | Shared-network view |
|---|---|---|
| A first-ever claim | Looks identical to an abuser's first hit | Seen in context of behaviour elsewhere |
| A serial abuser | Below the radar at every shop | Visible as one pattern across shops |
| Genuine customers | Taxed by blanket policy tightening | Left alone, refunded fast |
| The default response | Price defensively, slow every refund | Firm with the few, generous with the many |
None of this asks the genuine customer to do anything differently. They do not prove their innocence, pass verification, or notice anything at all. The friction lands only where the pattern is, on the behaviour that earned it. That is the difference between fighting fraud with blunt instruments and fighting it with information, and it is the outcome we describe in Fewer False Positives, Faster Claims.
Where Is the Industry Heading?
Toward the network, whether any single vendor pushes it or not. Regulators are leaning on shared intelligence, merchants have named refund and first-party abuse their top threat, and the economics of guessing get worse every year friendly fraud climbs.
The serial returner has had a good run precisely because the industry treated fraud as something each business fixes alone. The moment retailers, carriers and logistics providers start treating it as the network problem it has always been, the math that hides that fraudster stops working. Ten small claims across ten retailers stop being ten Tuesdays and become what they always were: one pattern, finally visible.
The keyhole was never going to be enough. The interesting question for the next few years is how quickly the industry decides to open the door.
Frequently asked questions
What is refund fraud?
Refund fraud, a form of first-party or policy abuse, is when a customer exploits a returns or delivery-claim process to get money or goods they are not entitled to, for example claiming an item never arrived. The Merchant Risk Council found 48% of merchants rank it a top fraud type.
Why is refund fraud so hard to detect?
Single-retailer detection looks for behaviour that is abnormal against that retailer's own baseline. A serial fraudster keeps each claim small and unremarkable, so it never stands out at any one shop. The pattern only exists across retailers, where no single business can see it.
Is refund fraud bigger than payment fraud now?
In North America and Europe, yes. In 2024 the Merchant Risk Council reported that refund and policy abuse and first-party misuse overtook phishing as the leading fraud threats for the first time in 25 years. LexisNexis data puts first-party fraud ahead of scams globally.
How does shared intelligence reduce refund fraud?
Shared intelligence lets retailers see a claimant's behaviour across many businesses, not just their own. That makes a repeat abuser who is invisible at any single shop visible across the network, so genuine customers and serial abusers stop looking identical and can be treated differently.
Retail Cache · Fraud Intelligence
Retail Cache builds the shared fraud-intelligence network for retailers, carriers and 3PLs. We write about first-party, refund and delivery fraud, and how the industry can stop treating it as a cost of doing business.
Want to turn the tide on fraud, together?
See how Retail Cache helps retailers and carriers detect, prevent and stop fraud in real time.