Fraudsters target merchants for one of two payoffs: reselling stolen goods, or talking the merchant into a refund. Nearly every attack sorts into one of four categories — and each one calls for a different defense.
Four categories of merchant-facing fraud
- Identity theft: large purchases, bust-out activity (maxing out cards in a short window), multiple transactions, and personal data that looks clean on the surface
- Social engineering: manipulating a person into divulging information or changing account details — hijacking an order by altering shipping or billing info after the fact
- Convenience fraud: testing a stolen card's validity with small purchases at low-risk merchants like gas stations or digital services, before using it for something bigger
- Internal fraud: organized theft by employees, whether they share fraud methods with outsiders or steal directly themselves
The matching defense for each
Identity theft calls for watching multiple accounts and purchase patterns together, not one order at a time. Social engineering is countered by re-verifying any change through your own security protocol, not the channel the change request came in on. Convenience fraud is exactly what velocity checks are built for. Internal fraud needs strong hiring practices and real accountability measures — no fraud tool substitutes for that.
Recognizing which category an attack falls into is what actually lets a merchant identify and stop a recurring pattern, rather than reacting to each incident as if it were new.