The shape of ecommerce fraud has changed. For years, the dominant story was stolen card numbers — someone buys a list of leaked credentials and runs fraudulent transactions until the card gets flagged. That threat hasn't gone away, but it's no longer the biggest problem on most merchants' plates. In 2026, the Merchant Risk Council's Global eCommerce Payments and Fraud Report ranks refund and policy abuse as the top fraud threat in ecommerce — displacing traditional payment fraud for the first time. More than 80% of retailers now report increasing friendly fraud, and friendly fraud drives roughly 75% of all ecommerce disputes.
That shift matters because friendly fraud is a genuinely harder problem than stolen-card fraud. A stolen card is a clear-cut case: the transaction was never authorized by the real cardholder, and once you catch the pattern, the fix is straightforward. Friendly fraud is murkier — a real customer makes a real purchase, receives the item, and then disputes the charge anyway, either because they've forgotten making it, because they're deliberately gaming a "your money back, guaranteed" policy, or because disputing a charge through their bank is simply less effort than requesting a refund through the merchant. First-party fraud — where the account holder themselves is the source of the fraudulent activity — is now the single leading fraud category globally, accounting for about 36% of all reported fraud.
What's driving the shift
Two forces are compounding here. First, chargebacks are genuinely expensive and getting more so: the 2026 LexisNexis True Cost of Fraud study puts the all-in cost of every $1 lost to chargebacks at $5.13 for merchants once you count processing fees, lost merchandise, and operational overhead — and global chargeback volume is projected to climb from $33.79 billion in 2025 to $41.69 billion by 2028. Second, the tooling available to bad actors has gotten sharper. Generative AI has moved from a novelty into a genuine operational tool for organized fraud rings, and automated "agentic" bot traffic — scripted, semi-autonomous purchasing and account-testing activity — surged an estimated 450% in 2025 alone.
AI is fighting on both sides
The same AI capability curve cuts both ways. On the defense side, AI-driven dispute management is now delivering measurably better outcomes than manual review: win rates on disputed chargebacks up to 80% higher, and average savings around $315 per dispute when AI tooling handles evidence compilation and submission instead of a human doing it manually. Roughly 40–50% of merchants globally now rank the accuracy of their AI/ML fraud tools, and fraud orchestration generally, as a top operational priority — which tells you this has moved from "nice to have" to core infrastructure for anyone running meaningful transaction volume.
Behavioral signals are the newer frontier
As fraud rings get better at mimicking legitimate-looking transaction data — right shipping address, plausible order size, a real-seeming account — merchants are increasingly leaning on signals that are much harder to fake: keystroke dynamics, touch pressure on mobile devices, scroll velocity, mouse movement patterns. These behavioral biometrics don't ask "does this transaction look legitimate on paper" — they ask "does this person's interaction with the page look like how a real human shops," which is a much harder thing for even a sophisticated bot or fraud ring to convincingly fake at scale.
Practical layers for a merchant building fraud defense in 2026
Separate friendly fraud from theft in your metrics. If your dashboard only tracks "chargeback rate," you're conflating two problems that need different fixes. Stolen-card fraud needs better authentication and device fingerprinting at checkout. Friendly fraud needs better evidence trails (delivery confirmation, usage logs, clear policy communication) and, honestly, sometimes a policy rethink — a return window that's too generous relative to your margin invites abuse regardless of how good your fraud tooling is.
Invest in dispute evidence automation before you invest in more blocking. A lot of merchants overweight prevention (blocking transactions before they happen) and underweight the dispute-response side, but the data above suggests the ROI on better dispute handling — higher win rates, lower per-dispute cost — is substantial and often cheaper to implement than a new fraud-scoring engine.
Treat refund/policy abuse as a distinct threat category, not a subset of "fraud" generally. Policies around returns, refunds, and promotional abuse need their own monitoring — repeat return patterns, accounts that consistently claim "item never arrived," coordinated abuse of a specific promo code — separate from payment fraud detection.
Watch for agentic bot traffic specifically. The 450% surge in automated purchasing/account-testing traffic means bot detection that was tuned for older, simpler bot patterns may be missing newer AI-driven traffic that behaves more convincingly human at a surface level. This is exactly where behavioral signals (not just IP reputation or request rate) earn their keep.
Don't treat fraud tooling as a set-and-forget purchase. Fraud patterns shift fast enough now — new bot capabilities, new social-engineering scripts, new refund-abuse tactics — that fraud rules and models need regular review, not an annual audit.
A note for smaller merchants
Most of the tooling discussed above — behavioral biometrics, AI dispute automation, fraud orchestration platforms — is built and priced for larger merchants with meaningful transaction volume. Smaller ecommerce businesses without that budget still have real, low-cost levers: clear, specific return policies that reduce ambiguity abuse can exploit; delivery confirmation and photo evidence at fulfillment; basic velocity checks (same card, multiple accounts, short time window); and honestly, a support channel — whether human or an AI-powered support widget — that resolves legitimate customer confusion before it turns into a dispute, since a meaningful share of "fraud" chargebacks start as a customer who couldn't get a straight answer about their order and defaulted to disputing the charge instead.
Fraud prevention in 2026 isn't primarily about stopping stolen credit cards anymore — that fight continues, but it's a mature, well-tooled problem. The harder, newer fight is against fraud that looks, on paper, exactly like a legitimate transaction gone wrong, and winning it increasingly depends on behavioral signal and smart dispute handling rather than blocking transactions at the door.
Sources: Merchant Fraud Journal: eCommerce Fraud Trends 2026, Digital Commerce 360: Friendly Fraud Rising, AI Mitigation, Chargeflow: Chargeback Statistics 2026
Get new posts as they publish
No spam — just the next post, straight to your inbox.