Site logo

The Automation of Theft: What AI-Powered Fraud Means for Every Customer Touchpoint in Retail

Retail fraud stopped being a crime of opportunity sometime in 2025. It became a manufacturing process.

The numbers surfacing in early 2026 are difficult to anchor to anything comparable. Fraud detection firm Pindrop, analyzing data from more than 50 major U.S. customers, found that AI-driven attacks against those organizations rose 1,210% over the course of 2025, with combined estimated losses reaching $1 billion. A separate study from payment fraud prevention firm Trustpair found that 71% of U.S. companies reported an increase in AI-powered fraud attempts last year. Nearly half of finance leaders ranked AI-generated fraud as one of their most pressing operational challenges. One in four companies reported six-figure losses from fraud in the past year alone.

These are not isolated findings from vendors with a commercial interest in alarming their markets. They are converging signals pointing toward the same conclusion: AI has handed fraudsters something the retail industry spent a decade building for legitimate customers, namely the ability to run thousands of simultaneous attempts across voice, video, chat, and email using identities that look and sound completely genuine.

Retail Was a Deliberate Target, Not a Casualty

Retail and CPG companies are not collateral damage in a broader fraud wave. The sector’s customer-service architecture, shaped by years of competitive pressure to make returns frictionless and refunds instant, created a purpose-built attack surface. Fraudsters identified it and built operations around it.

Pindrop’s analysis found that among its retail clients, AI-powered fraud attacks rose 330% over just two months in the fall of 2025, with a 56% month-over-month spike in November. The preferred method is not technically sophisticated. It is effective by volume. Automated bots initiate return requests on retail sites using scripted sequences, deliberately targeting refunds small enough to fall below review thresholds. A single fraudulent refund is noise. Thousands of them running continuously across multiple accounts become a material loss.

The underlying exposure is significant. Approximately $850 billion in merchandise was returned in 2025, equivalent to roughly 16% of total retail sales, according to research from Happy Returns and the National Retail Federation. Around 9% of those returns involved fraud, translating to an estimated $76.5 billion in annual industry losses. The global Merchant Risk Council has designated refund and return policy abuse as the most prevalent fraud type facing online retailers worldwide.

What changed in 2025 is not the category of fraud. It is the degree to which it has been automated, and the pace at which that automation is compounding.

The Contact Center Has Become a Primary Attack Vector

Return portals are one exposure. Retail contact centers are another, and in many ways the more consequential one.

Pindrop’s 2025 Voice Intelligence and Security Report, based on analysis of more than 1.2 billion calls, found deepfake voice fraud in contact centers rose 680% year over year. In retail specifically, the report documented an average of one fraudulent attempt for every 127 calls, a rate five times higher than in financial services. Axios reported in November 2025, citing Pindrop data directly, that at least one large retailer was fielding more than 1,000 AI-generated calls per day.

The mechanism deserves attention at an operational level. AI voice synthesis has advanced to where real-time caller impersonation requires minimal technical resources and is often indistinguishable to a human agent working under handle-time pressure. A 2025 survey of fraud and risk leaders across retail and financial services, conducted by voice security firm Modulate, found that 84% of organizations faced moderately to highly sophisticated voice attacks in the past year, and 45% identified keeping pace with evolving fraud techniques as their primary challenge.

This is where the problem moves well outside the IT department. The instincts that make a contact center agent effective, reading tone, resolving issues quickly, extending trust without demanding verification at every turn, are the same instincts fraud operations are built to exploit. These attacks are not trying to defeat authentication systems. They are trying to be convincing enough that a trained agent never thinks to question the call.

Executive Impersonation Is Documented Fact, Not Emerging Risk

Beyond customer-facing channels, AI fraud is escalating inside organizations themselves. Deepfake technology capable of cloning executive voices and video likenesses has moved from theoretical threat to a category of fraud with a paper trail.

In March 2025, a finance director at a Singapore multinational authorized a transfer of approximately $499,000 after joining what appeared to be a Zoom call with the company’s CFO and several senior leaders. Every participant was AI-generated, synthesized from publicly available footage of the real executives. Singapore’s Police Force, Monetary Authority, and Cyber Security Agency issued a joint advisory on the incident. Authorities recovered the initial transfer, but a follow-on request for $1.4 million, which the finance director grew suspicious of before acting, shows how close the outcome came to being considerably worse.

The Wall Street Journal, citing cybersecurity advisory firm Optiv, reported that losses from AI-generated executive impersonation schemes exceeded $200 million in the first quarter of 2025 alone. That figure was corroborated independently by Resemble AI’s Q1 2025 Deepfake Incident Report, which analyzed 163 documented incidents between January and April of that year.

Retail and CPG organizations carry specific exposure because of how their financial operations are structured. Urgent payment requests for vendor settlements, promotional co-op payments, and logistics contracts are a normal feature of the business calendar. Finance teams are conditioned to respond quickly to time-sensitive requests from senior leadership. Fraudsters do not need to manufacture urgency. They find the urgency that already exists inside the organization and use it.

The Infrastructure Built for Customers Created the Opening

The investments made over the past decade to reduce customer friction have, in parallel, expanded the attack surface for AI-powered fraud. That is not a comfortable thing to say, but it is the operational reality.

Self-service return portals, QR drop-offs, no-box and no-label returns, and instant refund credits were built to serve legitimate customers faster. They also removed natural verification points from the return process. In many cases today, a refund reaches a customer account before the returned item has been scanned at a processing hub, let alone inspected. Online return rates have reached approximately 24.5%, nearly three times the 8.7% rate for in-store purchases, and the infrastructure behind those returns was built for volume throughput, not for distinguishing systematic fraud from genuine customer behavior at scale.

The same problem runs through contact center self-service. IVR systems, chatbots, and automated account tools that allow customers to initiate refunds, update payment details, or reroute shipments without speaking to an agent are widely deployed and increasingly expected. They are also accessible to bots running continuous request sequences and to voice-cloned callers who have already cleared whatever authentication sits at the front of the call flow.

This is not an argument against the investments that made retail more convenient. It is an argument that those investments were designed around a threat model that no longer exists.

What the Defensive Response Looks Like, and Where It Falls Short

The response from retailers and their technology partners is underway. The gap between fraud sophistication and defensive capability is still wide.

Happy Returns, the UPS-owned reverse logistics company, began piloting an AI detection tool called Return Vision in late 2025 with Everlane, Revolve, and Under Armour. The system analyzes return timing, frequency, location patterns, and item imagery at drop-off points, comparing returned goods against catalog images before refunds are processed. It catches physical substitution fraud well: empty boxes, knockoff swaps, missing items. It is less effective against behavioral fraud such as wardrobing, where the item being returned is genuinely the one that was purchased.

On the contact center side, vendors including Pindrop and Modulate are building real-time voice authentication tools that treat fraud risk as a continuous assessment across the full duration of a call rather than a single check at the start. These systems evaluate voice characteristics, behavioral patterns, and contextual signals in combination, updating risk scores as the conversation develops.

The consistent finding across multiple research sources is that internal processes have not moved at the pace the threat demands. Trustpair’s CEO put it without qualification: the baseline of fraud has risen, but organizational controls have not kept up. The companies most exposed are those still relying on static verification methods, knowledge-based security questions and account credentials, that were already being bypassed routinely before generative AI made impersonation broadly accessible.

Fraud at This Scale Requires an Organizational Response, Not Just a Security One

The practical implication for retail and CPG executives is that AI fraud cannot be managed within the cybersecurity budget and the fraud operations function. It has become an enterprise risk with direct exposure across loss prevention, customer experience, supply chain, finance, and human resources.

The return policies that define the customer experience are the same policies that determine fraud exposure. The speed at which finance teams approve vendor payments is the same speed fraudsters depend on. The candidate who completed a video interview for a role with system access may not have been the person they appeared to be on screen. None of these belong to a single function, and none of them will be solved by a single technology deployment.

The organizations that manage this most effectively will be those that bring loss prevention, operations, technology, and finance into a shared conversation about where their decision points sit, both customer-facing and internal, and what verification logic governs each one. The hard part is not identifying the right tools. The hard part is building the organizational will to apply them across functions that have operated independently for a long time, against a threat that was not part of the original design brief for any of them.

Conversations On Retail

Conversations On Retail is a gathering place and resource center for retail and CPG executives, built to make it easier to stay current, discover the technologies and solutions shaping the industry, and connect with the people driving it forward.

We publish news, views, and reviews from staff editors, contributing experts, and trusted partners. Some articles are developed internally, while others are submitted by industry contributors or adapted from interviews and recorded conversations with industry leaders.

More Posts by This Contributor

Nearly six years ago Walmart sent 500 shelf-scanning robots home after concluding that workers picking online orders could see the
Conversations On Retail
July 20, 2026
n 2012, Dollar Shave Club spent $4,000 on the YouTube video that built the brand. This month, it spent a
Conversations On Retail
July 14, 2026
For two years, the marquee nuclear power deals have all read the same way: a tech giant buys a reactor's
Conversations On Retail
June 25, 2026

Comments

  • No comments yet.
  • Add a comment
    Please, select form to show

    Contact

    Sign Up For Our Newsletter

    Select options...

    Conversations On Retail is an independent platform. References to retailers, brands, technologies, or trademarks throughout our content are for informational and educational purposes only and do not imply any partnership, sponsorship, or commercial endorsement unless explicitly stated.

    The views and opinions expressed on this site are those of the individual authors and contributors and do not necessarily reflect the views of any company or organization discussed. All content is based on publicly available information, including but not limited to news reports, press releases, SEC filings, and publicly shared industry data. Nothing on this site should be construed as professional, legal, or financial advice.

    We are committed to accuracy and fairness. If you believe any content on this site contains an error or requires clarification, we welcome your feedback and will promptly review and address any concerns.

    ©2026 Conversations On Retail. All Rights Reserved.