Online retail fraud: Prevention and the role of PSPs
As the internet evolves and plays an even bigger part in people’s lives, it’s essential that high turnover companies find a payment solution which combats fraud and boosts confidence.
Updated June 17, 2026

AI Summary
Online retail fraud drains revenue, inflates chargebacks, and erodes the customer trust that established merchants work hard to build. As online transaction volumes climb, fraudsters automate their attacks and trade stolen payment data at scale, which puts pressure on every merchant accepting card payments across the UK and EEA.
This guide sets out what online retail fraud is, the main types merchants encounter, how to prevent it, and how a payment service provider strengthens that prevention. Fraud losses fall on the merchant far more often than the issuing bank, so the controls you put in place protect your margins and your reputation directly.
What is online retail fraud?
Online retail fraud is the use of stolen, falsified, or manipulated payment and identity data to obtain goods, services, or refunds from online merchants without legitimate payment.
It covers a broad range of tactics, from a fraudster checking out with stolen card details to a genuine customer disputing a charge they fully intended to pay. What links them is the outcome. The merchant ships the goods or issues the refund, then loses both the item and the transaction value when the payment is reversed.
That outcome is where many merchants underestimate their exposure. When a fraudulent card payment is disputed, the issuing bank recovers the funds from the merchant through a chargeback, so the merchant absorbs the loss rather than the bank. The merchant also forfeits the dispatched stock, pays the chargeback fee, and faces higher processing costs if dispute ratios climb.
5 main types of online retail fraud
Online retail fraud takes several distinct forms, and each one calls for a different detection approach. These are the five types merchants encounter most often.
- Identity theft: A fraudster uses stolen personal or card data to place orders in someone else's name.
- Friendly fraud: A genuine customer disputes a legitimate charge to win a refund while keeping the goods.
- Clean fraud: A fraudster pays with valid stolen card data and passes basic checks, which makes the transaction difficult to flag.
- Affiliate fraud: Fabricated or inflated traffic and transactions generate illegitimate affiliate commissions.
- Triangulation fraud: A fake storefront harvests customer card data while fulfilling orders with separately stolen cards.
How to prevent online retail fraud
No single control stops every type of online retail fraud. Effective online retail fraud prevention works in layers, combining authentication that confirms the shopper, screening that validates the payment, and monitoring that catches the patterns the first two miss. UK and EEA merchants also operate within a defined regulatory baseline, so part of this layering is a legal requirement rather than a discretionary choice.
Strong Customer Authentication
Strong Customer Authentication (SCA) requires shoppers to verify electronic card payments using at least two independent factors, such as something they know, something they have, and something they are.
EEA merchants must apply SCA under PSD2, and UK merchants must apply it under the Payment Services Regulations 2017 and the FCA's rules. For online card payments, 3D Secure 2 is the protocol that delivers SCA at the checkout, and it shifts much of the fraud liability for authenticated transactions away from the merchant and onto the issuing bank.
Layered transaction controls
Beyond authentication, several controls screen each transaction and limit the value of any data a fraudster manages to steal.
- Address Verification Service: Matches the billing address the shopper enters against the address the card issuer holds.
- CVV verification: Confirms the shopper has the physical card security code, which a database breach alone rarely exposes.
- Tokenisation: Replaces stored card numbers with tokens, so a breach of your systems yields no usable card data.
- Machine-learning fraud scoring: Scores each transaction in real time across hundreds of signals, clearing routine orders automatically and holding suspicious ones for review.
- Velocity and device checks: Flag abnormal transaction frequency and recognise the device fingerprints fraudsters reuse across attempts.
Manual review and chargeback management
Automated controls handle the bulk of screening, but borderline orders still need human judgement. A manual review step lets a risk analyst examine flagged transactions before dispatch. When a dispute does arrive, structured chargeback management—gathering evidence, representing the transaction, and tracking dispute ratios—recovers revenue on illegitimate claims and keeps your ratios within scheme thresholds.
How payment service providers support fraud prevention
A payment service provider gives merchants the infrastructure to run these controls without building fraud tooling in-house. The PSP sits in the transaction flow, which lets it detect, monitor, and report suspicious activity as it happens, then feed those patterns back into the rules that screen future payments.
The practical value shows up in the merchant risks a PSP helps contain:
- Financial loss: Detection and screening reduce the fraudulent transactions that turn into chargebacks and lost stock.
- Compliance and AML exposure: A PSP supports your KYC and anti-money-laundering obligations and keeps your processing aligned with current scheme and regulatory rules.
- Reputational damage: Fewer successful attacks mean fewer affected customers and less public fallout.
- Loss of customer trust: Visible security at the checkout reassures legitimate shoppers and protects repeat custom.
These outcomes are measurable. Effective fraud tooling and expert guidance lower your chargeback-to-sales and fraud-to-sales ratios, which protects your margins and keeps you below the thresholds card schemes use to place merchants into monitoring programmes. A capable PSP pairs the tooling with risk management support, advising on the controls that fit your transaction profile rather than leaving you to configure them alone.
» Learn how to reduce chargeback risks
How Fibonatix helps you prevent online retail fraud
Online retail fraud is a permanent cost of trading online, but it is a manageable one. Merchants who layer authentication, transaction screening, and ongoing monitoring, and who work with a PSP that runs those controls for them, keep fraud losses contained while still approving the legitimate orders that drive revenue.
Fibonatix gives UK and EEA merchants that combination: fraud detection and risk management tooling through the Paragon payment gateway, backed by a team that tunes the controls to your transaction profile. We work with online retailers across specialist and regulated categories, so we understand the fraud patterns those sectors attract.
Fibonatix (UK) Limited, company number 09738892, is authorised and regulated by the UK Financial Conduct Authority (FCA) as a Payment Institution (FRN 768776).
FAQs
What is online retail fraud?
Online retail fraud is the use of stolen, falsified, or manipulated payment and identity data to obtain goods, services, or refunds from online merchants without legitimate payment. The merchant usually absorbs the loss through chargebacks and lost stock.
What are the most common types of online retail fraud?
The most common types are identity theft, friendly fraud, clean fraud, affiliate fraud, and triangulation fraud. Each exploits a different weakness, so no single control catches them all.
How can merchants prevent online retail fraud?
Merchants prevent it by layering controls: Strong Customer Authentication, address and CVV checks, tokenisation, machine-learning fraud scoring, and ongoing monitoring. Combining these catches more fraud than any single measure on its own.
Are UK and EEA merchants required to use Strong Customer Authentication?
Yes. EEA merchants must apply Strong Customer Authentication under PSD2, and UK merchants must apply it under the UK Payment Services Regulations 2017.
What is the difference between friendly fraud and clean fraud?
Friendly fraud involves a genuine customer disputing a legitimate charge to win a refund while keeping the goods. Clean fraud involves a fraudster paying with valid stolen card data and passing standard checks, which makes it harder to detect.
How does a payment service provider help reduce online retail fraud?
A PSP runs detection, screening, and monitoring inside the transaction flow, then feeds fraud patterns back into the rules that screen future payments. This lowers your chargeback-to-sales and fraud-to-sales ratios and keeps you within card scheme thresholds.



