The Maze: Ecommerce fraud is no longer waiting at checkout. Signifyd's Commerce Network data, summarized by SecurityBrief Asia, shows fraud pressure up 33% year over year in the first four months of 2026. Account takeover rose 78%, card testing 175%, store-pickup fraud 65%, and first-party fraud and consumer abuse 9%. These are changes in orders presumed risky inside a vendor network—not a universal loss rate. Still, the pattern is clear: identity, accounts, fulfillment and returns are now one attack surface.
AI changes the cost and speed of the attack. Generative tools make phishing pages, fake identities, altered photos and plausible return documents cheaper to produce. Automation tests credentials and cards at volume. Signifyd's findings describe criminals combining methods: collect identity data, test payment credentials, take over a trusted account, route goods through store pickup, then dispute or return the order. Card testing is infrastructure; it identifies which stolen credentials work before criminals move into higher-value purchases.
A trusted account is now a stored-value target. Account takeover gives a criminal access to a real customer's login, often through phishing, purchased credentials or password reuse. The account can hold saved cards, gift cards, loyalty points, store credit and a history that makes a new order look familiar. Signifyd's 2026 commerce analysis shows account takeover rose 45% in apparel and 31% in both grocery and electronics during 2025 in its network. Checkout screening arrives late. Operators need to notice new devices, unusual locations, failed logins, contact changes and sudden stored-value activity before payment.
Fulfillment and returns convert digital abuse into operating cost. Buy online, pick up in store combines a card-not-present purchase with physical collection. The merchant generally carries online-fraud liability, while staff must decide whether the collector is legitimate. After delivery, abuse can include false item-not-received, damaged-product or not-as-described claims. Signifyd's fraud guide separates those behaviors from stolen-card fraud, but both consume margin through refunds, chargebacks, inventory errors, customer service and review. AI adds polish to fake receipts, photos and claim narratives.
More blocking can protect losses while quietly killing sales. `Fraud pressure` measures orders with enough anomalies to be presumed fraudulent by Signifyd's models or analysts. It is not the share of completed orders proven fraudulent. Every defense has a conversion cost: blanket bot blocking can reject legitimate AI shopping agents, while rigid return rules punish loyal customers. The better model is risk-calibrated friction—approve known buyers quickly, request stronger verification when identity or behavior changes, and review high-risk pickup or return requests. Fraud prevention becomes revenue optimization, not a contest to reject the most orders.
Why it matters: The risk perimeter follows the customer journey, so the control system must follow it. Teams need shared signals across login, device, payment, fulfillment and returns—not isolated decisions. They also need cleaner measurement. A 33% rise in vendor-defined pressure is a warning, not proof that every merchant lost 33% more money. The useful question is narrower: where is suspicious behavior accelerating, what friction stops it, and how many good customers does that friction cost? Protecting revenue and preserving conversion are now the same job.


