A New Taxonomy for Fighting Omnichannel Retail Fraud

Fraud carries a steep price tag for both merchants and consumers. The National Retail Federation (NRF) has updated its retail fraud taxonomy to combat it. Account takeover fraud cost consumers $15.6 billion in 2024, up from $12.7 billion the year before, according to Javelin research. The Federal Trade Commission reported at least $212 million in gift card fraud losses in 2024, though actual losses are likely far higher since many victims never report the crime. Returns fraud added another $76.5 billion in losses last year, based on NRF data showing 9% of the $849.9 billion in retail returns were fraudulent.

Fraud in retail no longer looks like isolated theft or opportunistic scams. Today’s fraud actors operate across digital and physical environments with the specialization and technical sophistication of organized crime and cybercrime groups. They evolve tactics, operate at scale and move fluidly across ecommerce platforms, in-store checkouts, payment systems and customer service channels. Countering that level of coordination depends on a shared language and knowledgebases for describing how these attacks unfold and what to do about them.

That was the focus when Evan Gaustad (Target), Gianni D’Aprile (BJ’s Wholesale and Chair of the NRF IT Security Council) and The Chertoff Group’s Adam Isles and Jon Tran unveiled Version 2.0 of the NRF Retail Fraud Taxonomy at the Association of Certified Fraud Examiners (ACFE) Global Fraud Conference earlier this month in Boston. The taxonomy was developed collaboratively by NRF, Target, the Retail & Hospitality Information Sharing and Analysis Center (RH-ISAC), and retail industry partners. The Chertoff Group serves as technical advisor and project manager. It standardizes how fraud teams, cybersecurity organizations, asset protection professionals and law enforcement can work together to identify fraud techniques, map fraudster behavior and prioritize prevention and detection strategies.

Version 2.0 expands significantly on the original framework. It adds a new returns and refund abuse scheme, reflecting the rise of organized “Refund-as-a-Service” operations that let low-skill actors pay experienced operators to run the fraud on their behalf. It introduces a Defense Evasion tactic that captures how fraudsters adapt to prevention and detection efforts. It also tags each technique by “channel” – “analog”, “digital” or “social engineering” – giving organizations a clearer view of where their exposure sits across physical and digital operations.

These additions are important because modern fraud rarely stays confined to one channel or one stage of an attack. A single fraud ring might combine a compromised account, a social engineering call to customer service and a manipulated return at checkout to extract resources from a retailer. A common vocabulary for these techniques enables organizations to share intelligence, spot emerging patterns and coordinate a response across in-store and digital teams.

The taxonomy organizes fraud activity into a structured lifecycle, from reconnaissance and resource development through monetization, and links each fraud technique to specific mitigations and detection opportunities. That structure helps security and fraud teams move past reactive, transaction-by-transaction responses toward a coordinated defense built on shared signals and shared terminology.

As fraud operations continue to evolve, the industry’s response must match the fraudsters’ sophistication. This common taxonomy gives defenders the foundation they need to act together instead of in isolation.

Download the Retail Fraud Taxonomy Version 2.0 full report here.

An interactive version is available here, courtesy of the Target Corporation.

Learn more about retail fraud and Target’s response here.

Our goal is to provide a solution tailored to your needs. Contact us today for a consultation. 

How can we help?

Fill out the information below. Provide as much detail and a team member will respond as soon as possible.