Ecommerce Fraud Statistics: What the Numbers Mean for Your Store

Ecommerce fraud costs are rising sharply, and the most useful merchant benchmark is the reason-code mix showing where disputes begin.

Ecommerce fraud statistics put the global cost in the tens of billions, and rising fast. Add the investigation time and the goods you never get back, and US merchants lose several dollars in total cost for every dollar of direct fraud loss.

I've run fraud reviews on my own stores, and sizing up these forecasts changed what I chased. The disputes I fought were rarely theft. They were customers who didn't recognize a charge, the same type these forecasts say is growing fastest.

Read the numbers by type and you can tell which two or three apply to your store.

Key takeaways

  1. 01Expect fraud losses to more than double, from $56 billion to $131 billion.
  2. 02Budget $5.13 of total US cost for every $1 of direct fraud loss.
  3. 03Treat friendly fraud as the growth driver behind that forecast.
  4. 04Check card-not-present disputes first, at 11.1% of our alerts.
  5. 05Watch subscription cancellations next, at 8.5% and 8.2% of alerts.

Rather see your own numbers? Size your dispute costs with our ROI calculator.

What is ecommerce fraud, and how big is the problem?

Ecommerce fraud is any online sale where you lose money because the charge was disputed, reversed, or never properly approved. Juniper Research expects those losses to rise from $56 billion in 2025 to $131 billion in 2030, which more than doubles the total in five years.

Friendly fraud is what grows fastest inside that number. Juniper ties the surge to real transactions that get disputed anyway, which is a customer problem needing a different fix. Screening catches a stranger using a stolen card, but misses your own buyer disputing three weeks after delivery.

Here is what that doubling means in 2026. Most of the growth comes from people who bought from you on purpose, then asked their bank for the money back.

That changes where your money should go. Better screening sharpens your defence against the part of the problem growing slowest, so put the first hours into what your buyers see after they pay.

One caveat before you benchmark against the total. That 2025 figure covers all of ecommerce, including digital goods, money transfer, and travel.

Your own rate will land somewhere else.

Say a store selling $30 snacks faces a different mix from one selling $2,000 laptops.

Read the forecast as a direction, then work from your own dispute mix. Your processor's dispute export lists a reason code on every case, and that column tells you which types below you actually have.

Types of ecommerce fraud, by the numbers

Card-not-present fraud, friendly fraud, account takeover, and return fraud cause most ecommerce losses. Four types, sorted by where each one reaches you, from your checkout through to your returns desk:

  1. Card-not-present fraud, committed with stolen card details at checkout
  2. Friendly fraud, disputes filed by buyers who bought from you on purpose
  3. Account takeover, where the attacker uses your customer's own login
  4. Return and refund fraud, which arrives through your returns desk

Each needs a different control, starting with the one that fills the most dispute files.

1. Card-not-present fraud

Card-not-present fraud is a purchase made with card details rather than the card itself, by someone with no right to use them. Across the alerts our platform processed, Visa reason code 10.4 covers these disputes, and it's the largest single code we see.

Chargeback fraud is the separate umbrella term for disputes where the purchase was real.

Our true fraud breakdown covers why that code's share overstates real criminal fraud.

You fix this before you ship. Turn on 3D Secure for card-not-present orders, and require address verification and CVV at checkout. Once the issuer authenticates a buyer through 3D Secure, liability for a fraud dispute generally shifts to the issuer.

In our dataset, only about 9.9% of the disputed transactions had 3D Secure switched on.

On Shopify, Stripe, or Adyen, you switch 3D Secure on in the dashboard, where your processor keeps its rules engine. By default it fires only when the issuer asks for it.

Change that rule so it also fires on the orders you consider risky. A first order well above your average size, or a shipping address that doesn't match billing, both qualify.

Then set address verification and CVV to decline on a mismatch, since plenty of stores collect both fields and approve the order anyway. Pull last month's disputed orders and read the address-verification response on each. The same result code usually sits on most of them.

2. Friendly fraud and first-party misuse

Friendly fraud is your real customer disputing a charge they actually made. Visa puts it at around 20% of fraudulent disputes globally, and up to 30% for high-volume online merchants.

Our friendly fraud guide covers the causes and the warning signs in full.

The cheapest action on this list is free. Fix the billing descriptor so the statement name matches your storefront name, because customers dispute charges they don't recognize. Most providers also let you set a soft descriptor per charge, so the product name travels with the brand name.

Test it the way your customer sees it. Buy from your own store on a personal card, then read the line in your banking app.

If you can't tell what you bought, neither can a customer three weeks later.

Then put a support email and a live chat link on the order confirmation itself, so the customer's first move is to contact you instead of their bank. Add the same links to every renewal email, because a renewal is when a charge surprises people.

Cancellation is the other half. Make a customer email you to stop a subscription and some will call the bank instead, which reaches you as a dispute. A self-serve cancel button saves you the dispute fee and the staff hour behind it.

3. Account takeover

Account takeover is fraud run through your customer's own login, which is why every card check on the order passes. Attackers collect the logins from phishing and credential-stuffing campaigns.

So the buyer arrives signed in, on a real account, using a card that account has used before.

Three controls stop most of it:

  1. Multi-factor sign-in, switched on in your storefront's customer-account settings
  2. A fresh sign-in check before a saved card ships to a new address
  3. Change alerts on every email, password, and shipping-address edit

The change alert matters more than it sounds. An attacker who gets in almost always edits the email first, so the real owner never sees the order. Send that alert to the old address too, and give it a one-click way to say no.

Rate limiting is the control most stores skip. Credential stuffing means thousands of login tries against real email addresses, so cap failed logins per account and per IP. Then watch your login logs for a spike in failed attempts, because they show the attack before your order queue does.

Our account takeover prevention guide covers each control and the gaps it leaves.

Adjacent terms blur into this one, and the account takeover glossary entry draws the lines between them.

4. Return and refund fraud

Return and refund fraud happens after the sale, at your returns desk, so fraud screening never sees it. The customer buys legitimately, then works the return policy to keep the goods, the money, or both. Our refund abuse guide covers the seven patterns it takes.

Track return rate per account and flag any customer returning at three times your store average.

Each single claim looks defensible, and only the pattern gives it away.

The practical version is a report you can build today. Export returns for the last six months, group them by customer email and shipping address, then sort by return rate. The accounts at the top are a short list, and a few will share an address under a different email.

Two settings in your returns platform cut most of the rest. Send every refund back to the original card, and hold it until the carrier scans the return. Both stop a customer from keeping your money and your goods at the same time.

What ecommerce fraud costs merchants

LexisNexis found that US merchants lose $5.13 for every $1 of direct fraud loss. That total counts investigation labor, fees, and replaced goods.

A $200 disputed order is closer to a $1,026 problem once your team has pulled evidence and written off stock.

The rest stays off the chargeback notice, and the largest piece is people. Someone has to find the order, pull the address-verification result and delivery scan, then write the rebuttal, which costs about an hour of salary per dispute.

Fees come next, since the card network charges a dispute fee whether you win or lose, and your processor often adds its own. The goods are usually gone, so you write off the stock and shipping.

You pay all of those costs after the chargeback arrives.

Three reason codes fill most of those files in our own data:

 
Largest specific dispute reason codes
 
10.4 Fraud, card-absent
11.1%
 
13.2 Cancelled recurring
8.5%
 
13.7 Cancelled merchandise
8.2%
 
Share of alerts with a recorded reason code, Chargeback.io platform data, 2026.

Those three codes cover more alerts than every other reason we record combined. A pre-dispute alert reaches you while the dispute is still with the issuer, so you can refund the order first and avoid the $4.13 behind it.

Use our ROI calculator to see what fraud like this is costing you. Two limits apply to the table above, since these are alerts across merchants our platform protects and describe our book of business.

In our dataset, they also exclude roughly 77% of alerts filed under an unspecified bucket, so each code's share of disputes is smaller than it looks.

Return and refund fraud

A denied return can come back to you as a chargeback, which moves the loss from your returns line into your dispute rate. That escalation is the part merchants who watch chargebacks closely still miss, because the original loss started somewhere they weren't looking.

Watch for it on the accounts your returns report already flagged. A customer who has been refused once and disputes the next order is telling you which pattern you have.

Our return and refund fraud guide covers the detection checks in full.

How we sourced our data

The reason-code figures here come from Chargeback.io's own alert dataset, anonymized and pooled across merchants on the platform. It covers the merchants who use us, and the payments industry as a whole runs on a wider population than that.

We counted total alerts in each reason-code category, then reported them as shares of alerts carrying a recorded code. We dropped the unlabeled bucket from the base.

These numbers describe alerts our own platform processed, so they describe the merchants we protect.

FAQ

What is the 10-80-10 rule in fraud?

The 10-80-10 rule splits people into three groups, always honest, always looking for a chance, and swayed by an easy opening. The last group is the majority, and that's the argument for closing those openings.

What is the most common online fraud?

In our dataset, fraud on card-not-present orders is the most common dispute reason, at 11.1% of alerts with a recorded code. The next two are both subscription cancellation disputes.

Are ecommerce fraud rates the same across every industry?

No. Rates vary by category, order value, and digital versus physical goods, so treat a global figure as context for your own numbers.

Why do fraud statistics vary between sources?

Sources measure different groups over different windows, so a retailer survey and a platform's dispute data measure different things. Check what each figure counts before you compare two numbers.

立即降低您的争议率

加入800多家企业,使用退单自动防止拒付——设置只需不到2分钟。