Ecommerce fraud pressure rose 33% year over year in the first four months of 2026, according to Signifyd’s 2026 State of Fraud Report, which tracked transactions across a Commerce Network of thousands of merchants and more than 950 million digital wallets. The surge is driven largely by widely accessible AI attack tools, and refund and policy abuse has overtaken traditional stolen-card fraud as merchants’ most commonly cited threat. The numbers below cover what fraud costs merchants in 2026, which attack types are growing fastest, and where a clear refund policy fits into the defense.

If you run an online store, the direction of travel matters more than any single figure: losses are climbing, the attackers increasingly look like real customers, and the merchants with the lowest fraud rates are the ones running structured prevention programs rather than manual review alone.

How much is ecommerce fraud costing merchants in 2026?

Global ecommerce fraud losses are on pace to climb from $44.3 billion in 2024 to $107 billion by 2029, a 141% increase, according to Juniper Research’s Global Merchant Fraud Prevention Market report, which analyzed more than 25,000 data points across 60 countries. Separately, the Merchant Risk Council’s 2026 Global eCommerce Payments and Fraud Report found merchants lose an average of 3.2% of total annual ecommerce revenue to payment fraud globally, based on a survey of 1,278 merchant professionals across 37 countries, and both the share of orders proving fraudulent and the share of revenue lost to fraud rose compared to the 2025 edition of the same report.

Global eCommerce Fraud Value, 2024 vs 2029 Projection (Juniper Research) 0306090120B202420252026202720282029107B

Figure 1: Global ecommerce fraud value is projected to rise from $44.3 billion in 2024 to $107 billion by 2029. Source: Juniper Research, Global Merchant Fraud Prevention Market 2024-2029. Intermediate years are linearly interpolated between the two published data points, not independently reported figures.

The cost is not evenly distributed once a fraud event happens. LexisNexis Risk Solutions’ 2025 True Cost of Fraud study, a survey of 569 fraud and risk executives across the US and Canada, found US merchants now lose $4.61 for every $1 of fraud, once chargebacks, lost merchandise, and internal investigation labor are counted, up from $3.16 in 2022. Canadian merchants reported a close $4.52 multiplier in the same study.

A rising loss multiplier means the sticker price of a fraud incident understates the real damage by a wide margin, which is why prevention spending increasingly gets budgeted as a cost center of its own rather than an afterthought.

What is driving the surge in ecommerce fraud in 2026?

Fraud pressure climbed 33% year over year in the first four months of 2026 across Signifyd’s Commerce Network, and two specific attack types explain most of the acceleration: card-testing attacks surged 175% and account takeover attempts rose 78% over the same period. Both figures accelerated sharply from 2025, when card testing had already risen 65% between Q2 2024 and Q2 2025.

Signifyd’s report ties the jump directly to widely available AI tools that lower the cost and complexity of running an attack, letting fraud rings automate identity theft, checkout abuse, and returns fraud at a speed manual review teams cannot match. The result is fraud that increasingly spans a customer’s full journey, from account creation through checkout to the return, rather than a single stolen-card transaction.

Figure 2: Key ecommerce fraud cost and attack-growth milestones. Sources: LexisNexis True Cost of Fraud studies, Juniper Research, Signifyd 2026 State of Fraud Report.

The trend line points in one direction: fraud is getting cheaper to commit and more automated to scale, which is why attack-type mix, not just total loss, is now the more useful number for a merchant to track. A rising loss multiplier and a rising attack rate are compounding problems rather than separate ones, since each successful attack now costs more to absorb than it did even a year earlier, and there are simply more of them landing per merchant.

What fraud attack types do merchants report most in 2026?

Fraud is now close to universal: 98% of merchants surveyed by the Merchant Risk Council reported experiencing at least one type of fraud attack in the past 12 months, and both the share of orders proving fraudulent and the share of revenue lost to fraud rose compared with the 2025 edition of the same annual survey. That near-universal exposure makes attack-type ranking more useful than a single blended fraud rate, since it tells a merchant which specific defense to prioritize first rather than treating fraud as one undifferentiated threat.

Within that exposure, refund and policy abuse is the single most commonly cited attack type in 2026, named by 41% of merchants, ahead of real-time payment fraud at 38%, phishing/pharming/whaling at 37%, first-party misuse at 36%, and card testing at 33%, according to the same MRC report.

Top eCommerce Fraud Attack Types Cited by Merchants, 2026 (MRC) 012.52537.550%41Refund/policy abuse38Real-time paymentfraud37Phishing/pharming/whaling36First-party misuse33Card testing

Figure 3: Top five fraud attack types cited by merchants in 2026. Source: Merchant Risk Council, 2026 Global eCommerce Payments and Fraud Report, n=1,278 merchant professionals.

That refund abuse now outranks payment-specific attacks is a shift from prior years, when card-not-present fraud and real-time payment fraud typically topped merchant-reported threat lists. A store’s terms matter directly here: publishing a clear, current refund policy generator that states the return window, condition requirements, and dispute process up front closes off the vague-terms loophole that drives a meaningful share of policy-abuse claims. Merchants surveyed also ranked minimizing fraud-related operating costs as their top operational priority in 2026, cited by 29% of fraud professionals, up sharply from 20% in 2025 and just 10% in 2024, a sign that fraud has moved from a security line item to a budget-level concern.

Merchants who track attack type mix rather than a single blended fraud rate can target prevention spending at whichever category is growing fastest for their business, rather than defending uniformly against every threat at once.

How does refund and policy abuse factor into fraud losses?

Refund and policy abuse is not just the top-cited attack type, it is also getting more expensive to resolve. The MRC’s 2026 report found 61% of merchants experienced an increase in refund and policy abuse over the past year, with 20% reporting a jump of 25% or more, and the average cost to resolve a single disputed refund claim rose to $82, up from $74 in 2025. False “item not received” claims were cited as the primary abuse pattern by 52% of merchants surveyed.

Payment fraud rate as a share of ecommerce revenue, by merchant profile 0.6% 3.9% fraud rate as share ofrevenue: MRC membersversus non-member firms

Structured fraud-prevention membership correlates with meaningfully lower loss rates: MRC member merchants reported a fraud rate of just 0.6% of revenue and 0.3% by order count, compared to 3.9% of revenue and 4% by order count at non-member enterprises, a gap of nearly 7x on the revenue measure alone.

Whether that gap reflects the value of network membership itself, better baseline fraud tooling among merchants who join, or both, is not something the MRC’s survey design can separate, so treat the comparison as directional rather than a guaranteed causal return on membership dues.

The pattern still points the same direction as the refund-abuse data above: merchants running structured, documented fraud and returns processes report both lower attack volume and lower per-incident cost than merchants relying on ad hoc review. Real-time payment fraud is the closest runner-up threat behind refund abuse, cited by 45% of merchants as the attack type they expect to grow fastest next, which suggests the current top-five ranking is unlikely to hold steady through the rest of 2026.

Where do US ecommerce fraud costs originate?

Online and mobile channels together account for the overwhelming majority of US fraud costs. LexisNexis’s 2025 study found 53% of US fraud costs trace to online/ecommerce purchases and another 30% to mobile channels, including digital wallets, peer-to-peer transfers, and QR-code payments, leaving 17% spread across other channels including in-store. That leaves the physical point of sale as a small slice of the exposure for a typical merchant selling primarily online, which is worth knowing before allocating a fraud-prevention budget evenly across channels instead of weighting it toward where the losses concentrate.

Where US Fraud Costs Originate, by Channel (LexisNexis 2025) 53%30%17%Online/ecommerce purchases53%Mobile channels30%Other channels17%

Figure 4: Where US merchant fraud costs originate, by channel. Source: LexisNexis Risk Solutions, 2025 True Cost of Fraud Study, n=487 US risk and fraud executives.

Despite the scale of the problem, automation remains limited: LexisNexis found only 6% of US ecommerce businesses and 3% of Canadian ecommerce businesses have fully automated fraud prevention, while 41% of North American merchants still rely primarily on manual review. Fraud also has a conversion cost beyond direct losses: 64% of merchants told LexisNexis that fraud friction hurts checkout conversion, and 63% said it increases customer churn. Manual review catches some abuse, but it does not scale against attack volume that is itself growing at double- and triple-digit rates, which is part of why the loss multiplier keeps climbing even as fraud teams add headcount.

Card-not-present transactions carry a disproportionate share of this exposure, since there is no physical card to inspect and no signature to compare. Our related breakdown of card-not-present fraud data for 2026 covers how that specific category has grown to dominate overall card fraud, which compounds the online-channel share shown above.

How can merchants stop a refund dispute before it becomes a chargeback?

The MRC’s $82 average cost to resolve a disputed refund claim, and its finding that 52% of merchants cite false “item not received” claims as the primary refund-abuse pattern, both point to the same weak link: a claim that cannot be resolved quickly with clear evidence tends to escalate. A cardholder who is unsure whether a package arrived, or unsure what a store’s return terms allow, is far more likely to file a bank dispute than to wait on a support ticket. Chargeback-specific data backs this up. Our chargeback statistics for 2026 piece found that 76% of cardholders prefer resolving a disputed charge through their bank rather than the merchant, and nearly half go straight to their bank without contacting the merchant first, which is exactly the outcome a fast, documented refund process is meant to prevent.

The decision path below simplifies how a refund claim either gets resolved directly or escalates into a costlier dispute:

Figure 5: A simplified decision path for resolving a refund claim before it escalates to a chargeback. Source: synthesized from MRC 2026 refund-abuse findings and LexisNexis dispute-resolution data above.

Two data points from elsewhere in this cluster reinforce the pattern: our analysis of friendly fraud data for 2026 found first-party disputes now represent a growing share of total chargeback volume, and our return fraud statistics for 2026 piece found roughly 1 in 7 returns shows signs of abuse. A documented, easy-to-find refund policy will not eliminate either category, but it removes the ambiguity that turns a legitimate question into an adversarial bank dispute.

Fraud benchmarks at a glance

MetricPrior period2026 figure
Ecommerce fraud pressure (Signifyd, YoY)baseline (2025)up 33% (Jan-Apr 2026)
Revenue lost to payment fraud (MRC)lower in 2025 report3.2% globally
Refund/policy abuse cited as top threat (MRC)not the top-ranked category41% of merchants
Card-testing attack growth (Signifyd)up 65% (Q2 2024 to Q2 2025)up 175% (Jan-Apr 2026)

Source: Signifyd 2026 State of Fraud Report; Merchant Risk Council 2026 Global eCommerce Payments and Fraud Report.

The Bottom Line

The single most useful number for 2026 is not the dollar total, it is the 33% jump in fraud pressure driving everything else in this article, because it explains why a benchmark from even a year ago is already out of date. Refund and policy abuse has become the most commonly cited attack type at 41%, ahead of any payment-specific fraud category, which means the fastest lever most merchants have is not a new fraud tool but a clear, current refund policy that removes the ambiguity fraudsters and confused customers alike exploit. Merchants running structured prevention programs report fraud rates roughly 7x lower than those relying on manual review, so the gap between doing nothing and doing something specific is large and measurable.

Frequently Asked Questions

How much does ecommerce fraud cost merchants in 2026? Global ecommerce fraud losses are on pace to climb from $44.3 billion in 2024 to $107 billion by 2029, a 141% increase, according to Juniper Research. US merchants separately lose $4.61 for every $1 of fraud, per LexisNexis’s 2025 True Cost of Fraud study of 569 risk executives.

Why did ecommerce fraud pressure jump 33% in 2026? Signifyd’s 2026 State of Fraud Report found fraud pressure rose 33% year over year in the first four months of 2026, with card-testing attacks up 175% and account takeover up 78%, driven largely by widely accessible AI attack tools.

What is the most common type of ecommerce fraud in 2026? Refund and policy abuse is the top named fraud attack type, cited by 41% of merchants in the Merchant Risk Council’s 2026 Global eCommerce Payments and Fraud Report (n=1,278), ahead of real-time payment fraud at 38% and card testing at 33%.

Does joining a fraud-prevention network reduce ecommerce fraud losses? It appears to. MRC member merchants report a fraud rate of just 0.6% of revenue, versus 3.9% at non-member enterprises, a nearly 7x gap, according to the MRC’s 2026 report.

Sources and References

  1. Signifyd. (2026). “2026 State of Fraud Report.” Commerce Network data, thousands of merchants, 950M+ digital wallets.
  2. Juniper Research. (2024). “eCommerce Fraud to Exceed $107 Billion in 2029.” Global Merchant Fraud Prevention Market 2024-2029, 25,000+ data points, 60 countries.
  3. LexisNexis Risk Solutions. (2025). “Fraud Costs Surge as North America’s Ecommerce and Retail Businesses Face Mounting Financial and Operational Challenges.” True Cost of Fraud study, n=569 (487 US, 82 Canada), fielded by KS&R.
  4. Merchant Risk Council. (2026). “MRC Releases 2026 Global eCommerce Payments and Fraud Report.” Survey of 1,278 merchant professionals, 37 countries, with Visa Acceptance Solutions and Verifi.

Note: All figures verified as of August 2026. Fraud rates and attack-type mix shift quickly, so headline figures are refreshed at least twice a year. The Juniper Research 2025-2028 intermediate-year values are interpolated between two published data points and flagged as such in-text.