Skip to content

Do You Need Fraud Prevention? What the 2026 Primary Data Actually Says

MRC surveyed 1,278 merchants. LexisNexis priced every fraud pound at $4.61. Here's what the primary data says about buying fraud tooling, and when not to.

The Sellarix team · 22 Jul 2026 · 16 min read

Every pound of fraud you take costs you $4.61 by the time it's finished. Not $1. That's the all-in figure from LexisNexis Risk Solutions, across 569 fraud and risk executives in the US and Canada, and it's up 28% since 2021 and 47% since 2019[1].

That multiplier is the whole reason fraud tooling gets bought. It's also the number every vendor quotes at you, and there's a decent argument that it's the wrong number to make a decision on. Let's do this properly, with the primary sources, including the ones that undercut the sales pitch.

What the 2026 data actually says

The Merchant Risk Council published its 2026 Global eCommerce Payments and Fraud Report on 18 March 2026, built with Visa Acceptance Solutions and Verifi, from 1,278 merchant professionals across 37 countries[2]. It's the closest thing this industry has to a census, and it's worth reading rather than reading about.

Some findings from it, straight:

64% of merchants report increasing rates of first-party misuse, and a quarter of those report increases of 25% or more[2]. First-party misuse is the polite term for a real customer disputing a real order they really received.

Merchants reported an average of 3.7 different fraud attack types in 2025, down from 4.2 the year before[2]. Fewer attack types, more concentrated attacks.

And 63% of merchants are actively exploring or planning agentic AI payments, while 72% already use some form of tokenization[2]. Those two facts sit awkwardly together and I'll come back to why.

Worth saying who paid for the research. The report is co-sponsored by Visa Acceptance Solutions and Verifi, both of whom sell into this problem[18]. The methodology is disclosed and the sample is large, which is more than can be said for most numbers in this category. Read it with that in mind and it's still the best dataset available.

The number nobody in this category likes

MRC's segmented data shows the gap between merchants with weak fraud tooling and strong fraud tooling: roughly 3.9% of revenue lost to fraud versus 0.6%, and 5.2% of good orders wrongly rejected versus 2.8%[3].

MRC 2026: merchants with weak fraud tooling lose 3.9% of revenue to fraud versus 0.6% with strong tooling, and reject 5.2% of good orders versus 2.8%

Read the second pair again. Even merchants with strong tooling reject 2.8% of good orders. That's the cost side of fraud prevention that never appears in an ROI calculator, and at scale it's often larger than the fraud.

Does this actually affect you?

Most stores under about £2M in revenue do not have a fraud problem. They have a chargeback problem, which is different, and buying fraud software to fix chargebacks is one of the more expensive category errors available.

Pull your last twelve months of chargebacks and sort them by reason code. Genuinely do this before reading further, because the split determines everything.

If most are fraudulent or unrecognised transaction, you have a fraud problem and tooling helps.

If most are item not received, you have a logistics and tracking problem. No fraud vendor fixes that. Better delivery confirmation and proactive shipping comms fixes it.

If most are not as described, you have a product data problem. Fix your photography and your size guides.

If most are subscription cancelled, you have a billing UX problem and probably a retention one.

I've seen a store spend £14,000 a year on fraud tooling to address a chargeback rate that was 70% "item not received" caused by a courier marking parcels delivered when they'd been left with a neighbour. The tooling did nothing. It couldn't. That was the wrong tool for the actual problem, and nobody in the sales process asked to see the reason codes.

The stakes, quantified honestly

Three costs, and only one of them is the fraud itself.

The chargeback. You lose the goods, the payment, and a fee that's typically £15 to £25 per dispute. That's the visible one.

The all-in multiplier. LexisNexis puts it at $4.61 per $1 of fraud for US merchants and $4.52 for Canada, covering the goods, the fees, the labour to investigate, and the replacement cost[1]. Mobile channels drive a disproportionate share, at 33% of US costs[1].

The false decline. The one nobody prices. At 2.8% of good orders rejected even with strong tooling[3], a £5M store is turning away £140,000 of legitimate revenue a year, plus the lifetime value of every customer who was told no and went elsewhere.

You'll see figures like "$443 billion lost to false declines" quoted around this. Don't use them. That number is Riskified marketing, and Nuvei publishes $308 billion for the same claim. Two vendors, 44% apart, on a number that's foundational to their pitch. The MRC's segmented rejection rates are measured, disclosed and boring, which is exactly why they're better.

What we found: the guarantee is the product, and the margin proves it

Here's the analysis that changed how I think about this category.

Riskified reported non-GAAP gross margin of 52% for the year ended 31 December 2025, against 53% the year before[4]. Normal SaaS runs 75% to 85%.

That 25-point gap is not inefficiency. It's the cost of underwriting. When a vendor guarantees your chargebacks, they're not selling you software, they're selling you insurance with a machine-learning underwriter, and the payouts sit in cost of revenue. Riskified's Q4 improved to 58% and they hit their first GAAP-profitable quarter on revenue near $100 million, ending the year with about $297.6 million in cash and no debt[4], so this isn't a distressed business. It's a differently-shaped one.

Why that matters to you as a buyer

An insurer's incentive is to minimise claims. That is the entire job. So when merchant reviews of guarantee-based fraud vendors cluster around denied claims, it isn't a customer service failure, it's the business model working as designed.

The guarantee is sold as certainty and experienced as a claims process. Both descriptions are accurate. If you buy one, read the claim exclusions before you read the marketing, and specifically look for what happens on orders you manually approved after a decline, on orders shipped to a reshipper, and on anything the vendor classifies as first-party misuse rather than third-party fraud.

Signifyd is at least clear about the shape: they charge a percentage of order total on approved orders, nothing on orders declined for fraud, and the guarantee is configurable from fraud-only to a full chargeback liability shift[5]. The percentage itself isn't published, and varies by vertical, volume and average order value[5].

The vendors, and who each one is actually for

Signifyd, Riskified, Forter

Liability-shifting vendors. They approve or decline, they take the chargeback risk on what they approve, and you pay a percentage of approved GMV. Realistic entry is around $5M GMV for Signifyd and Riskified, higher for Forter.

Buy one if fraud is genuinely material, your team is spending real hours on manual review, and you'd rather convert a variable loss into a fixed percentage. Don't buy one expecting explanations: the decision comes back as approve or decline, not as a reason you can act on.

Sift and SEON

Scoring vendors. No liability shift, but you get signals you can inspect and rules you can change. SEON publishes $699/month for Starter with Premium on quote[6], which makes it one of the very few self-serve options in the category with a real price on the page.

SEON's approach is worth understanding even if you don't buy it, because it solves the cold-start problem honestly. Email age, phone reputation, IP and proxy checks, device fingerprint and social footprint give you day-one signal without any transaction history at all. That's why they can sell self-serve. A model needs your data; enrichment doesn't.

Shopify Protect

Free, and much narrower than merchants assume. It covers eligible orders paid through Shop Pay, reimbursing the chargeback amount and the fee on fraudulent and unrecognised chargebacks[7].

The exclusions matter more than the coverage. Shop Pay only. Physical items requiring shipping only. All non-refunded line items must be Fulfilled. Only the first order in a subscription. US merchants only. And it doesn't cover "item not received" or "not as described"[14]. Shopify's separate guidance on handling a dispute under Protect is worth reading before you need it rather than during[13].

Which, if you did the reason-code exercise above, is precisely where most of your chargebacks probably are. Free is good. Read the boundary.

Doing nothing, deliberately

Still correct for a lot of stores, and nobody writes this article. If your chargeback rate is under 0.3% of transactions, your reason codes are mostly service issues, and your average order value is low, the rational move is better delivery evidence and a manual review rule on your top 1% of orders by value.

Card scheme thresholds are the thing that changes the answer. Visa and Mastercard both run dispute monitoring programmes with escalating fees and remediation requirements once you cross their ratios. Once you're near one of those, the decision stops being economic and starts being existential, because losing card acceptance ends the business.

How each platform changes the job

Shopify

The most support and the most false comfort. Shopify's built-in fraud analysis flags risky orders, Shopify Protect covers a narrow slice for free[7], and every major vendor has a first-party app.

Two Shopify-specific things worth doing regardless of vendor. Turn on a Flow rule that holds fulfilment on high-risk orders rather than cancelling them, because cancelling a good order costs you more than a day's delay. And check whether Shopify Protect's Fulfilled-status requirement is actually being met by your fulfilment flow, because partially-fulfilled orders quietly fall out of coverage[7].

WooCommerce

You have almost nothing native, and that's genuinely a gap rather than a criticism. Woo core does not ship fraud scoring. What you do get is complete control: every order, every IP, every payment attempt sits in a database you can query.

The highest-value free thing on Woo is velocity rules. Same card across multiple accounts in an hour. Same IP with different billing names. Order value more than 4x your average from a first-time customer. Three rules, a scheduled query, a Slack alert. That'll catch more than most merchants expect, and it costs a morning. Woo's order and product data model is documented well enough to write those queries against without guessing[17].

Beyond that, SEON, Sift and the enterprise vendors all reach Woo over API, though the depth of integration is usually shallower than the Shopify version. Ask specifically whether the vendor can act on the order (hold, cancel, refund) or only score it.

Magento and Adobe Commerce

Native fraud handling is thin, and Magento merchants are typically large enough that a real vendor is the answer. This is the platform where liability-shift vendors genuinely earn their keep, because order values are higher and the manual review burden is real.

The Magento-specific trap is the admin. A store with fifteen admin users and no 2FA is a bigger fraud risk than anything happening at checkout, and account takeover on the admin side doesn't show up in any chargeback report until it's very late.

BigCommerce

Sits between. Native fraud tools are basic, integrations exist for the main vendors, and the commercially relevant detail is that BigCommerce charges an Open Payment Provider Fee of 2.0% on Core down to 0.6% on Scale for transactions through non-integrated payment providers[8]. If you're considering moving processors to get better fraud tooling, price that fee in first.

Custom and headless

The decision is where the check runs. Score at authorisation and you can decline cleanly but you have less context. Score after authorisation and before fulfilment and you have the full order, but you're now managing a void or refund flow.

Almost everyone should do the second. The exception is digital goods, where there's no fulfilment gap to use.

The decision table

SituationDo thisCostWhy
Chargebacks under 0.3%, mostly service reason codesNothing. Fix delivery evidence£0Fraud tooling can't fix "item not received"
Shopify, US, Shop Pay volumeShopify Protect, and read the exclusionsFreeNarrow but genuinely free[7]
Under £2M, some genuine fraud, want to understand itEnrichment plus rules (SEON tier)~$699/mo published[6]Day-one signal without transaction history
£5M+, real manual review burdenA liability-shift vendor% of approved GMV[5]Converts variable loss to fixed cost
Near a card scheme monitoring thresholdBuy immediately, negotiate laterWhatever it costsLosing acceptance ends the business
High false-decline suspicionMeasure it before buying anything£02.8% of good orders rejected even with strong tooling[3]
On Woo or Magento, nothing nativeVelocity rules first, vendor secondA morningCatches more than expected, costs nothing

First-party misuse is the actual 2026 story

The fastest-growing category isn't criminals. It's customers. 64% of merchants in the MRC survey report first-party misuse rising, with a quarter seeing increases above 25%[2].

This breaks most fraud tooling, because the order is genuine. Real card, real address, real customer, real delivery. Every signal says approve, and it should. The dispute comes later.

The parallel data from returns says the same thing. Appriss Retail's 2026 benchmark splits returns loss into fraud at 2% and abuse at 12%, meaning $86 billion of abuse against $14 billion of outright fraud[9]. Abuse is six times larger. Vendors conflate the two because "fraud" sells better and "your customers are taking liberties" doesn't.

Before any of that, be clear what you are permitted to do about it: our guide to the legal ceiling on returns and abuse enforcement covers the statutory rights you cannot refuse and the automated decisions you cannot make alone. The fixes for first-party misuse are unglamorous and none of them are a fraud model. Delivery photo evidence. Signature on high-value orders. Clear order descriptors on the card statement so people recognise the charge. Representment with actual evidence rather than a template. And a policy, applied consistently, for the small number of accounts that dispute repeatedly.

The consumer-scoring line you should not cross

There's a legal boundary here that most vendors won't raise. The Retail Equation, owned by Appriss, is listed by the Consumer Financial Protection Bureau as a consumer reporting company[10]. Which means scoring individual consumers and acting on that score pulls you toward FCRA territory in the US, and GDPR automated-decision territory in the UK and EU.

The CFPB's full list is public and worth a look, because several companies on it sell products that merchants think of as ordinary risk tooling[15].

Appriss's own data is the argument for the softer approach anyway: 90% of flagged consumers purchase again after a warning[9]. Nudge and explain beats block and deny, on both the economics and the legal exposure. That's a design constraint I'd treat as binding, not a preference.

The scale argument helps here too. US returns were $849.9 billion in 2025, 15.8% of sales, and roughly 19.3% of online sales specifically[16]. At that volume, a policy that wrongly flags even 1% of returners is a lot of angry people who bought from you in good faith.

What agentic checkout does to fraud

Here's the awkward pair of facts from the same survey. 63% of merchants are exploring or planning agentic AI payments. And first-party misuse is up at 64% of merchants[2].

Agentic checkout removes exactly the signals fraud models lean on. There's no device fingerprint worth having when the device is a datacentre. Behavioural biometrics are meaningless when nothing types. Session velocity is whatever the agent's rate limit is.

The protocols anticipate this to a degree. The Agentic Commerce Protocol, maintained by OpenAI and Stripe at spec version 2026-04-17, has the agent hand the merchant a narrowly-scoped payment token rather than raw card details, keeping the merchant as merchant of record[11]. Google's Universal Commerce Protocol, launched 11 January 2026 with Shopify, Etsy, Wayfair, Target and Walmart[12], takes a similar line.

What nobody has solved is liability. If an agent buys the wrong thing and the human disputes it, whose fraud is that? The specs don't say. Ask any fraud vendor how their model handles agent-originated traffic and watch the answer. I've not heard a convincing one yet.

What to do this week

  1. Export twelve months of chargebacks with reason codes. Sort by count. This one report decides whether you have a fraud problem at all.
  2. Calculate your chargeback rate two ways: as a percentage of transactions and as a percentage of revenue. Card schemes care about the first.
  3. Measure your false declines. Count orders your current rules or gateway rejected, then sample twenty and check whether they look real. Most merchants have never done this.
  4. If you're on Shopify with Shop Pay, verify Protect eligibility on real orders. Especially the all-line-items-Fulfilled condition[7].
  5. Write three velocity rules and run them against last month's orders retroactively. See what they'd have caught, and what good orders they'd have blocked.
  6. Fix your card statement descriptor. Genuinely. "SP * MERCH LTD" causes disputes. Your brand name doesn't.
  7. If you're evaluating a guarantee vendor, read the claim exclusions first. The margin data says that's where the product actually lives[4].

The takeaway

The honest position, and one plenty of people in this industry would argue with: most stores buying fraud prevention are buying it for the wrong reason, at the wrong time, against a chargeback profile they've never examined.

The measured data supports a narrower use case than the marketing does. Strong tooling cuts fraud from around 3.9% of revenue to 0.6%, which is a real and large improvement, and it still rejects 2.8% of good orders[3]. Meanwhile the fastest-growing loss category is customers disputing orders they actually received[2], and no fraud model catches that, because there's nothing to catch.

Go and pull the reason codes. What's actually in there?

Sources

  1. Fraud Costs Surge as North America's Ecommerce and Retail Businesses Face Mounting Financial and Operational Challenges. LexisNexis Risk Solutions True Cost of Fraud Study, 2 April 2025. n=569 executives.
  2. MRC Releases 2026 Global eCommerce Payments and Fraud Report. Merchant Risk Council, 18 March 2026. 1,278 merchants, 37 countries.
  3. 2026 Global eCommerce Payments and Fraud Report. Merchant Risk Council. Accessed 22 July 2026.
  4. Riskified Reports Fourth Quarter and Full Year 2025 Results. Riskified investor relations, 4 March 2026. Full release also carried at Seeking Alpha.
  5. Signifyd Pricing. Signifyd. Accessed 22 July 2026. Vendor page; no rate published.
  6. SEON Pricing. SEON. Accessed 22 July 2026.
  7. Shopify Protect for Shop Pay. Shopify Help Center. Accessed 22 July 2026.
  8. BigCommerce Pricing. BigCommerce. Accessed 22 July 2026.
  9. The 2026 Total Retail Loss Benchmark Report. Appriss Retail, February 2026. Vendor-published; Appriss sells the analytics that address this loss.
  10. The Retail Equation. Consumer Financial Protection Bureau, list of consumer reporting companies. Accessed 22 July 2026.
  11. Agentic Commerce Protocol specification. Maintained by OpenAI and Stripe. Spec version 2026-04-17.
  12. Under the Hood: Universal Commerce Protocol (UCP). Google Developers Blog, January 2026.
  13. Addressing chargebacks with Shopify Protect. Shopify Help Center. Accessed 22 July 2026.
  14. Protecting an order with Shopify Protect. Shopify Help Center. Accessed 22 July 2026.
  15. List of Consumer Reporting Companies. Consumer Financial Protection Bureau, 2025 edition (PDF).
  16. Consumers Expected to Return Nearly $850 Billion in Merchandise in 2025. NRF with Happy Returns, 15 October 2025.
  17. Managing Products. WooCommerce documentation. Accessed 22 July 2026.
  18. 2026 Global eCommerce Payments & Fraud Report. Cybersource (Visa Acceptance Solutions), report co-sponsor. Accessed 22 July 2026.