Article
Four in-person fraud trends reshaping retail
In-person fraud is evolving. Discover four emerging fraud trends impacting retailers today and practical steps to reduce risk across your unified commerce operations.
In-person fraud in retail environments is shifting fast. As defence mechanisms across online checkout channels strengthen, bad actors are redirecting their efforts back into physical store spaces. High-volume point-of-sale (POS) environments across Australia, from busy shopping centres to large multi-outlet stores, present unique operational vulnerabilities that fraudsters actively target. Learn more about the future of fraud in our 2026 fraud report →
Understanding these emerging vectors is critical for retail operations, risk managers, and finance leads. By tracking payment data and threat vectors across global network signals, Adyen identifies emerging terminal-level exploits before they scale. Here are four in-person fraud trends currently impacting the retail sector, along with technical and operational controls to proactively mitigate them.
1. Unreferenced refund exploitation: Social engineering and policy abuse
Unreferenced refunds, refunds processed without being linked to an original, verified transaction record, remain one of the most lucrative targets for bad actors. Fraudsters primarily exploit unreferenced refunds in two ways:
Social engineering.
Fraudsters call store cashiers directly, posing as the merchant’s internal corporate IT department or help desk. They manipulate the cashier into processing a test transaction, then instruct them to issue an unreferenced refund to a card controlled by the fraudster.
Policy abuse.
Fraudsters exploit lenient store return policies or high-volume environments by requesting refunds without proof of purchase, often using stolen merchandise or items brought from outside the store. In severe cases, fraudsters collude with employees who abuse point-of-sale (POS) system access to credit money directly to their own cards.
The bottom line
These tactics are heavily used across retail environments both small and large. Because such refunds lack an auditable trail to an initial purchase, they are incredibly difficult to trace.
Adyen insight & merchant action
Given that social engineering relies on human deception, technology alone can’t prevent it. Merchants must train store staff to never accept phone instructions for test transactions or refunds.
From a policy and system perspective, retailers should require linked refunds whenever possible with tools like Adyen's refundWithData or tokenized refunds. Because card network rules and AML regulations strictly restrict unreferenced credits, merchants should disable standalone refunds at the POS whenever possible. Where contractually permitted by your acquirer, limit this functionality to elevated manager permissions with mandated unique staff ID logging.
More information around the risks of unreferenced refunds can be found in our Adyen Docs.

2. Contactless wallet fraud: Offline and issuer exploits
As contactless and digital wallet usage continues to grow across Australia's retail landscape, bad actors are manipulating how payment terminals communicate with card issuing banks. By loading fake card credentials into digital wallet applications, fraudsters attempt to force the payment terminal to approve transactions locally without reaching out to the card issuer for real-time online authorisation.
This manipulation typically relies on two terminal interaction exploits:
Forced offline EMV approval:
The altered card profile tampers with the terminal during the EMV transaction exchange. It sends back a fake offline approval response code (such as Y1), tricking the payment device into accepting the transaction locally without dialing out for authorisation.
.
Issuer exploit (store-and-forward abuse):
The digital wallet profile triggers an online authorisation request designed to return a specific "issuer unavailable" error response. The fraudster relies on the terminal misinterpreting this message as a network failure, causing it to default to store-and-forward mode and approve the transaction locally.
These exploits bypass live verification, eventually leaving the retailer exposed to chargebacks and unrecoverable inventory losses.
Adyen insight and merchant action
Adyen protects store operations by enforcing defence controls across both payment terminal hardware and network routing layers:
Terminal-level security:
Adyen POS terminals strictly execute hardened EMV security kernels. The terminal architecture mandates mandatory online authorisation checks during these specific payment flows, neutralising fake forced offline responses.
Network-level defence:
Adyen platform routing prevents "issuer unavailable" signals from mistakenly triggering store-and-forward behaviour, ensuring bad transactions are declined immediately rather than accepted locally.
3. "Ghost tap" NFC relay attacks
A highly sophisticated form of proximity fraud, the so-called "ghost tap" relies on an NFC relay attack. A fraudster uses a physical accomplice (sometimes called a mule) inside the store to tap a device at the point of sale. The actual payment credentials are streamed and authorised remotely from a completely different device loaded with stolen card details. To the cashier and the terminal, however, the transaction appears to be a legitimate contactless tap.
The bottom line
This tactic is increasingly frequent among luxury retail merchants in particular, where high ticket values make the coordinated effort profitable for fraud syndicates. In a highly contactless market like Australia, where shoppers are accustomed to quick tap-and-go interactions, cashiers are naturally accustomed to rapid contactless checkouts, making physical vigilance even more critical.
Adyen insight & merchant action
Because ghost tap attacks use real card tokens in real time, they bypass standard terminal checks. While Adyen continues to monitor this trend globally, merchants can reduce risk immediately with a few simple steps:
Train staff on suspicious behaviour:
Watch for customers who appear to be coordinating with another device or person during the transaction.
Add friction for high-value purchases:
Configure payment terminals to automatically trigger Cardholder Verification Methods (CVM) such as requiring a PIN or dynamic verification for transactions exceeding high-value thresholds, ensuring card scheme compliance while protecting against tap fraud.
Watch for repeated device switching:
Stop the transaction if someone tries multiple phones or digital wallets after failed tap attempts.
4. Cross-channel gift card fraud
This tactic is a high-speed race involving two coordinated individuals. One fraudster attempts an in-store purchase using a gift card. The moment the card is presented, they share the card details with a remote accomplice, who immediately executes a rapid online purchase using the same gift card. Before the store associate can finalise or potentially void the in-store transaction due to secondary suspicions, the balance has already been completely drained online.
The bottom line
This pattern is primarily observed within large format retail environments where online and in-store inventory systems may not sync instantly with gift card ledgers.
Adyen insight & merchant action
Since Adyen operates as a unified platform, we track a gift card’s end-to-end lifecycle across all sales channels, all at once. Our platform can recognise a pending in-store action and halt simultaneous online use of that same gift card number, effectively closing the real-time processing loophole.
Staying ahead of emerging fraud
Adyen is committed to helping retailers navigate the complexities of modern, omnichannel fraud. Through our unified platform, rich ecosystem data, and ever-evolving, AI-powered risk management capabilities, we provide a holistic view of your transactions, along with the tools you need to stop fraud before it impacts your bottom line.
Beyond our current features, we’re continually innovating to address the kinds of policy abuse unified commerce merchants face. This includes our Policy Abuse Management solution, launched in 2025, to tackle refund abuse. The solution leverages cross-channel data and shopper recognition to seamlessly validate good shoppers while aggressively curbing malicious behaviour.
What next?
Many of these fraud patterns rely heavily on operational gaps and social engineering that fall outside the realm of traditional payment security. Mitigating them requires a combination of staff awareness, strict store policies, and robust technology.
Every retailer's risk profile is different. If you're looking to strengthen your fraud strategy, speak with your Adyen Account Manager to assess your current risk posture, discuss tailored fraud prevention strategies, and explore the capabilities available across Adyen's risk and optimisation solutions, including Uplift Protect.
