There Are Two Kinds of Retail Fraud, and Your Tools Only Cover One

Retail Cache·Fraud Intelligence··9 min read
Illustration of a store in cross-section: a bright well-guarded checkout at the front, a dim unguarded returns area at the back
The front door is guarded. The threat moved to the back. · Illustration: Retail Cache

Most retailers have fraud protection. Most of it is pointed at the wrong place. It guards the front door, the checkout, while the threat has quietly moved to the back of the shop, where returns are processed and claims are paid. Those are two different kinds of fraud, and a tool built for one is largely blind to the other.

The evidence that the threat moved is not subtle. For the first time in 25 years, the Merchant Risk Council found refund and policy abuse had become the leading fraud threat for merchants in North America and Europe, overtaking phishing. The fraud is now happening after the sale. The tooling, mostly, is still standing at the till.

What Are the Two Kinds of Retail Fraud?

They split cleanly by when they happen. Pre-purchase fraud occurs at the checkout: stolen cards, account takeover, fraudulent payments, the classic problem of someone paying with money or an identity that is not theirs. Post-purchase fraud occurs after a perfectly legitimate sale: a real customer, paying with their own card, who then abuses the returns or claims process.

That second category is the one climbing. It includes false item-not-received claims, wardrobing, faked damage, empty-box returns and disputed-but-genuine charges. Crucially, the customer at the centre of it did nothing wrong at the checkout. The payment was real. The fraud comes later, which is exactly why the tools watching the payment never see it.

Why Did Everyone Build for the Checkout First?

Because for two decades, that is where the money was being lost. The entire fraud-prevention industry grew up around the moment of payment: is this card stolen, is this account taken over, is this transaction risky. Whole businesses were built on the chargeback guarantee, absorbing the cost of fraudulent payments in exchange for a fee. It was a sensible place to concentrate, because pre-purchase fraud was the dominant threat.

So the maps, the models and the muscle memory all point at the checkout. When a retailer says it has "fraud protection," it almost always means protection at the point of sale. That was the right investment for the problem of ten years ago. The problem has since changed address.

What Actually Changed?

The fraud moved past the sale, and the numbers followed it. Beyond the MRC finding that refund and policy abuse now leads, the 2026 Chargebacks911 report found friendly fraud rising for 83% of enterprise merchants. The growth is all on the post-purchase side: the returns desk, the claims queue, the delivery dispute.

There is a reason for the shift. As checkout defences got stronger, the easy money at the point of sale dried up, and abuse migrated to the softest remaining target: the generous, lightly-monitored returns and claims process that retailers built to compete on customer experience. Free returns and fast refunds are great for genuine customers and a gift to abusers, and almost nobody was watching that door.

Why Don't Checkout Tools Catch Post-Purchase Fraud?

Because they are built to answer a different question. A payment-fraud tool asks, at the moment of sale, "is this transaction legitimate?" Post-purchase fraud sails straight through that check, because the transaction genuinely is legitimate. The abuse happens days or weeks later, at a different moment, through a different process, and it turns on completely different information.

Here is the split in practice:

Pre-purchase layerPost-purchase layer
WhenAt the checkoutAfter the sale
The questionIs this payment legitimate?Is this claim or return legitimate?
The customerMay be a stranger or stolen identityA real, paying customer
The signalCard, device, account riskBehaviour over time and across retailers
Built for it?Yes, heavilyRarely

A tool tuned for the left column has almost nothing useful to say about the right one. It is not a weaker version of the same defence. It is watching a different door.

What Does Covering the Second Layer Take?

Visibility where the fraud now lives, which means the claims, returns and delivery process rather than the checkout. And because post-purchase abuse turns on behaviour rather than a single risky transaction, it means seeing that behaviour over time and, above all, across retailers.

That last part is what a single business cannot do alone. A serial refund abuser looks like an ordinary customer at any one retailer, because the payment was real and the individual claim looks plausible. Only their pattern across many retailers gives them away, which is the blind spot we cover in The Serial Returner No Single Shop Can See. The same is true for the delivery layer, where the proof of what happened sits with the carrier rather than the retailer, as we described in The Carrier Knows What Happened to Your Parcel.

Cover that second layer well and the genuine customer never notices, while the abuser meets friction aimed squarely at them. That is the outcome we build for, described in Fewer False Positives, Faster Claims.

The Gap Is Where the Money Now Goes

None of this means checkout fraud protection was a mistake. It works, and it is still needed. The point is narrower and more uncomfortable: it was only ever half the job, and the other half went unbuilt while the threat quietly relocated into it.

Refund and policy abuse is now the leading fraud threat, and most retailers are meeting it with tools designed for a problem at a different door. The fraud has moved to the back of the shop. Sooner or later, the defences have to follow it there.

Frequently asked questions

What are the two kinds of retail fraud?

Pre-purchase fraud happens at the checkout: stolen cards, account takeover, and fraudulent payments. Post-purchase fraud happens after the sale: false refund claims, item-not-received disputes, wardrobing and returns abuse. They occur at different moments and need different signals to detect.

What is post-purchase fraud?

Post-purchase fraud is abuse that occurs after a legitimate-looking purchase: claiming a delivered parcel never arrived, returning worn items, faking damage, or disputing a genuine charge. The Merchant Risk Council found refund and policy abuse became the leading merchant fraud threat in 2024, ahead of phishing.

Why don't payment-fraud tools stop refund fraud?

Because they were built to answer a different question. A checkout tool asks whether a payment is legitimate at the moment of sale. Refund fraud involves a real customer who paid with a real card, then abuses the returns or claims process later, which a payment-focused check is not designed to see.

How do retailers cover post-purchase fraud?

By adding visibility to the layer where it happens: the claims, returns and delivery process, and by seeing claimant behaviour across retailers rather than one. That combination separates a genuine customer from a serial abuser after the sale, where checkout tools cannot look.

Retail Cache · Fraud Intelligence

Retail Cache builds the shared fraud-intelligence network for retailers, carriers and 3PLs. We write about first-party, refund and delivery fraud, and how the industry can stop treating it as a cost of doing business.

Want to turn the tide on fraud, together?

See how Retail Cache helps retailers and carriers detect, prevent and stop fraud in real time.