Article

Four in-person fraud trends reshaping retail

In-person fraud is evolving. Discover four emerging fraud trends impacting retailers today and practical steps to reduce risk across your unified commerce operations.

July 15th, 2026
 ·  7 minutes

When it comes to fraud, in-person payments have long been considered a secure baseline. But as the payments landscape evolves, so do fraudsters’ methods. The interconnectedness of online and in-store payment ecosystems has opened new vulnerabilities within omnichannel merchant environments. Learn more about the future of fraud in our 2026 fraud report

This evolution can lead to significant financial losses and operational friction for retailers. Yet in our conversations with retail merchants, many say they currently lack the tools required to tackle omnichannel fraud effectively. 

By partnering with merchants through technology and shared intelligence, Adyen stays at the forefront of identifying these emerging threats. Here are four fraud trends we see currently impacting the retail sector, along with insights on how to proactively mitigate them.

1. Unreferenced refund exploitation: Social engineering and policy abuse

Unreferenced refunds — refunds processed without being linked to an original, verified transaction record — remain one of the most lucrative targets for bad actors. Fraudsters primarily exploit unreferenced refunds in two ways: 

  • Social engineering. Fraudsters call store cashiers directly, posing as the merchant’s internal corporate IT department or help desk. They manipulate the cashier into processing a test transaction, then instruct them to issue an unreferenced refund to a card controlled by the fraudster.

  • Policy abuse. Fraudsters exploit lenient store return policies or high-volume environments by requesting refunds without proof of purchase, often using stolen merchandise or items brought from outside the store. In severe cases, fraudsters collude with employees who abuse point-of-sale (POS) system access to cre

    dit money directly to their own cards.

The bottom line

These tactics are heavily used across retail environments both small and large. Because such refunds lack an auditable trail to an initial purchase, they are incredibly difficult to trace.

Adyen insight & merchant action

Given that social engineering relies on human deception, technology alone can’t prevent it. Merchants must train store staff to never accept phone instructions for test transactions or refunds.

From a policy and system perspective, retailers should require linked refunds whenever possible with tools like Adyen's refundWithData or tokenized refunds. If you must allow unreferenced refunds, ensure your POS mandates unique staff ID logging to detect insider patterns. More information around the risks of unreferenced refunds can be found in our Adyen Docs.

Adyen team members presenting at a conference or event

2. Contactless wallet fraud: Offline and issuer exploits

Fraudsters increasingly manipulate how payment terminals communicate with card issuers by loading fabricated card credentials into third-party digital wallets. Their goal is to force a transaction to be approved locally at the terminal without receiving a valid, real-time authorization from the card issuer. They typically try two methods:

  • Forced offline EMV approval. The fraudulent digital card profile is configured to manipulate the terminal during an EMV transaction, falsely returning an offline approval response code like Y1. This code tricks the terminal into accepting the payment without it ever attempting to dial out online.

  • Issuer exploit (aka store and forward abuse). The card profile triggers an online authorization request designed to purposefully fail with a specific issuer unavailable response. The fraudster hopes the terminal will misinterpret this response as a genuine network outage, activate its store-and-forward mode, and approve the purchase locally.

The bottom line

This tactic results in fraudulent transactions that ultimately default to costly chargebacks. Bad actors frequently use this approach in the retail and hospitality sectors.

Adyen insight & merchant action

Adyen proactively protects merchants against these vulnerabilities through both integrated terminal  and network level defense layers:

  • Terminal level security. Adyen payment terminals strictly adhere to advanced EMV security kernels. Our hardware and applications mandate online authorization checks in these exact scenarios, thwarting fake forced offline approvals.

  • Network level action. To neutralize issuer-side exploits, Adyen blocks issuer unavailable responses from erroneously triggering store-and-forward mode across our platform, preventing terminals from incorrectly approving bad transactions.

3. "Ghost tap" NFC relay attacks

A highly sophisticated form of proximity fraud, the so-called “ghost tap" relies on an NFC relay attack. A fraudster uses a physical accomplice (sometimes called a mule) inside the store to tap a device at the point of sale. The actual payment credentials are streamed and authorized remotely from a completely different device loaded with stolen card details. To the cashier and the terminal, however, the transaction appears to be a legitimate contactless tap.

The bottom line

This tactic is increasingly frequent among luxury retail merchants in particular, where high ticket values make the coordinated effort profitable for fraud syndicates.

Adyen insight & merchant action

Because ghost tap attacks use real card tokens in real time, they bypass standard terminal checks. While Adyen continues to monitor this trend globally, merchants can reduce risk immediately with a few simple steps:

  • Train staff on suspicious behavior. Watch for customers who appear to be coordinating with another device or person during the transaction.

  • Add friction for high-value purchases. Require customers to insert their physical card chip instead of simply tapping for expensive transactions.

  • Watch for repeated device switching. Stop the transaction if someone tries multiple phones or digital wallets after failed tap attempts.

4. Cross-channel gift card fraud

This tactic is a high-speed race involving two coordinated individuals. One fraudster attempts an in-store purchase using a gift card. The moment the card is presented, they share the card details with a remote accomplice, who immediately executes a rapid online purchase using the same gift card. Before the store associate can finalize or potentially void the in-store transaction due to secondary suspicions, the balance has already been completely drained online.

The bottom line

This pattern is primarily observed within large format retail environments where online and in-store inventory systems may not sync instantly with gift card ledgers.

Adyen insight & merchant action

Since Adyen operates as a unified platform, we track a gift card’s end-to-end lifecycle across all sales channels, all at once. Our platform can recognize a pending in-store action and halt simultaneous online use of that same gift card number, effectively closing the real-time processing loophole.

Staying ahead of emerging fraud

A proactive approach to risk

Adyen is committed to helping retailers navigate the complexities of modern, omnichannel fraud. Through our unified platform, rich ecosystem data, and ever-evolving, AI-powered risk management capabilities, we provide a holistic view of your transactions — along with the tools you need to stop fraud before it impacts your bottom line.

Beyond our current features, we’re continually innovating to address the kinds of policy abuse unified commerce merchants face. This includes our Policy Abuse Management solution, launched in 2025, to tackle refund abuse. The solution leverages cross-channel data and shopper recognition to seamlessly validate good shoppers while aggressively curbing malicious behavior.

What next?

Many of these fraud patterns rely heavily on operational gaps and social engineering that fall outside the realm of traditional payment security. Mitigating them requires a combination of staff awareness, strict store policies, and robust technology.

Every retailer's risk profile is different. If you're looking to strengthen your fraud strategy, speak with your Adyen Account Manager to assess your current risk posture, discuss tailored fraud prevention strategies, and explore the capabilities available across Adyen's risk and optimization solutions, including Uplift Protect.

Authors:

Priyanka Agrawal, Global retail lead

Emily Dymond, Head of performance & risk optimization

Suzanne Gendelman, Head of account management, unified commerce

Fresh insights, straight to your inbox

Subscribe to email alerts