Nearly six years ago Walmart sent 500 shelf-scanning robots home after concluding that workers picking online orders could see the
Conversations On Retail
July 20, 2026
Retail fraud stopped being a crime of opportunity sometime in 2025. It became a manufacturing process.
The numbers surfacing in early 2026 are difficult to anchor to anything comparable. Fraud detection firm Pindrop, analyzing data from more than 50 major U.S. customers, found that AI-driven attacks against those organizations rose 1,210% over the course of 2025, with combined estimated losses reaching $1 billion. A separate study from payment fraud prevention firm Trustpair found that 71% of U.S. companies reported an increase in AI-powered fraud attempts last year. Nearly half of finance leaders ranked AI-generated fraud as one of their most pressing operational challenges. One in four companies reported six-figure losses from fraud in the past year alone.
These are not isolated findings from vendors with a commercial interest in alarming their markets. They are converging signals pointing toward the same conclusion: AI has handed fraudsters something the retail industry spent a decade building for legitimate customers, namely the ability to run thousands of simultaneous attempts across voice, video, chat, and email using identities that look and sound completely genuine.
Retail and CPG companies are not collateral damage in a broader fraud wave. The sector’s customer-service architecture, shaped by years of competitive pressure to make returns frictionless and refunds instant, created a purpose-built attack surface. Fraudsters identified it and built operations around it.
Pindrop’s analysis found that among its retail clients, AI-powered fraud attacks rose 330% over just two months in the fall of 2025, with a 56% month-over-month spike in November. The preferred method is not technically sophisticated. It is effective by volume. Automated bots initiate return requests on retail sites using scripted sequences, deliberately targeting refunds small enough to fall below review thresholds. A single fraudulent refund is noise. Thousands of them running continuously across multiple accounts become a material loss.
The underlying exposure is significant. Approximately $850 billion in merchandise was returned in 2025, equivalent to roughly 16% of total retail sales, according to research from Happy Returns and the National Retail Federation. Around 9% of those returns involved fraud, translating to an estimated $76.5 billion in annual industry losses. The global Merchant Risk Council has designated refund and return policy abuse as the most prevalent fraud type facing online retailers worldwide.
What changed in 2025 is not the category of fraud. It is the degree to which it has been automated, and the pace at which that automation is compounding.
Return portals are one exposure. Retail contact centers are another, and in many ways the more consequential one.
Pindrop’s 2025 Voice Intelligence and Security Report, based on analysis of more than 1.2 billion calls, found deepfake voice fraud in contact centers rose 680% year over year. In retail specifically, the report documented an average of one fraudulent attempt for every 127 calls, a rate five times higher than in financial services. Axios reported in November 2025, citing Pindrop data directly, that at least one large retailer was fielding more than 1,000 AI-generated calls per day.
The mechanism deserves attention at an operational level. AI voice synthesis has advanced to where real-time caller impersonation requires minimal technical resources and is often indistinguishable to a human agent working under handle-time pressure. A 2025 survey of fraud and risk leaders across retail and financial services, conducted by voice security firm Modulate, found that 84% of organizations faced moderately to highly sophisticated voice attacks in the past year, and 45% identified keeping pace with evolving fraud techniques as their primary challenge.
This is where the problem moves well outside the IT department. The instincts that make a contact center agent effective, reading tone, resolving issues quickly, extending trust without demanding verification at every turn, are the same instincts fraud operations are built to exploit. These attacks are not trying to defeat authentication systems. They are trying to be convincing enough that a trained agent never thinks to question the call.
Beyond customer-facing channels, AI fraud is escalating inside organizations themselves. Deepfake technology capable of cloning executive voices and video likenesses has moved from theoretical threat to a category of fraud with a paper trail.
In March 2025, a finance director at a Singapore multinational authorized a transfer of approximately $499,000 after joining what appeared to be a Zoom call with the company’s CFO and several senior leaders. Every participant was AI-generated, synthesized from publicly available footage of the real executives. Singapore’s Police Force, Monetary Authority, and Cyber Security Agency issued a joint advisory on the incident. Authorities recovered the initial transfer, but a follow-on request for $1.4 million, which the finance director grew suspicious of before acting, shows how close the outcome came to being considerably worse.
The Wall Street Journal, citing cybersecurity advisory firm Optiv, reported that losses from AI-generated executive impersonation schemes exceeded $200 million in the first quarter of 2025 alone. That figure was corroborated independently by Resemble AI’s Q1 2025 Deepfake Incident Report, which analyzed 163 documented incidents between January and April of that year.
Retail and CPG organizations carry specific exposure because of how their financial operations are structured. Urgent payment requests for vendor settlements, promotional co-op payments, and logistics contracts are a normal feature of the business calendar. Finance teams are conditioned to respond quickly to time-sensitive requests from senior leadership. Fraudsters do not need to manufacture urgency. They find the urgency that already exists inside the organization and use it.
The investments made over the past decade to reduce customer friction have, in parallel, expanded the attack surface for AI-powered fraud. That is not a comfortable thing to say, but it is the operational reality.
Self-service return portals, QR drop-offs, no-box and no-label returns, and instant refund credits were built to serve legitimate customers faster. They also removed natural verification points from the return process. In many cases today, a refund reaches a customer account before the returned item has been scanned at a processing hub, let alone inspected. Online return rates have reached approximately 24.5%, nearly three times the 8.7% rate for in-store purchases, and the infrastructure behind those returns was built for volume throughput, not for distinguishing systematic fraud from genuine customer behavior at scale.
The same problem runs through contact center self-service. IVR systems, chatbots, and automated account tools that allow customers to initiate refunds, update payment details, or reroute shipments without speaking to an agent are widely deployed and increasingly expected. They are also accessible to bots running continuous request sequences and to voice-cloned callers who have already cleared whatever authentication sits at the front of the call flow.
This is not an argument against the investments that made retail more convenient. It is an argument that those investments were designed around a threat model that no longer exists.
The response from retailers and their technology partners is underway. The gap between fraud sophistication and defensive capability is still wide.
Happy Returns, the UPS-owned reverse logistics company, began piloting an AI detection tool called Return Vision in late 2025 with Everlane, Revolve, and Under Armour. The system analyzes return timing, frequency, location patterns, and item imagery at drop-off points, comparing returned goods against catalog images before refunds are processed. It catches physical substitution fraud well: empty boxes, knockoff swaps, missing items. It is less effective against behavioral fraud such as wardrobing, where the item being returned is genuinely the one that was purchased.
On the contact center side, vendors including Pindrop and Modulate are building real-time voice authentication tools that treat fraud risk as a continuous assessment across the full duration of a call rather than a single check at the start. These systems evaluate voice characteristics, behavioral patterns, and contextual signals in combination, updating risk scores as the conversation develops.
The consistent finding across multiple research sources is that internal processes have not moved at the pace the threat demands. Trustpair’s CEO put it without qualification: the baseline of fraud has risen, but organizational controls have not kept up. The companies most exposed are those still relying on static verification methods, knowledge-based security questions and account credentials, that were already being bypassed routinely before generative AI made impersonation broadly accessible.
The practical implication for retail and CPG executives is that AI fraud cannot be managed within the cybersecurity budget and the fraud operations function. It has become an enterprise risk with direct exposure across loss prevention, customer experience, supply chain, finance, and human resources.
The return policies that define the customer experience are the same policies that determine fraud exposure. The speed at which finance teams approve vendor payments is the same speed fraudsters depend on. The candidate who completed a video interview for a role with system access may not have been the person they appeared to be on screen. None of these belong to a single function, and none of them will be solved by a single technology deployment.
The organizations that manage this most effectively will be those that bring loss prevention, operations, technology, and finance into a shared conversation about where their decision points sit, both customer-facing and internal, and what verification logic governs each one. The hard part is not identifying the right tools. The hard part is building the organizational will to apply them across functions that have operated independently for a long time, against a threat that was not part of the original design brief for any of them.