Signifyd’s 2026 State of Fraud Report shows North American fraud pressure rising 38.6% against 8.35% sales growth in the first half of 2026. For Shopify merchants, the most overlooked cost is good customers declined by cautious fraud settings; stores under roughly $10M can usually rely on Shopify’s native protection first.
Every chargeback arrives with a dollar amount attached. Every good customer you decline disappears without a trace. That asymmetry is why so many stores tune their fraud settings in the wrong direction.
Picture a Tuesday morning in November. Someone on your team opens the Shopify admin, sees a first-time customer flagged as high risk with a billing address in one state and shipping to another, and cancels the order to be safe. Nobody ever learns whether that customer was real. If the numbers in this year’s fraud data are anywhere close, there is a decent chance they were.
That scene is why the 2026 State of Fraud Report from Signifyd caught my attention. I learned about it while recording an episode of the eCommerce Fastlane podcast with Nicole Jass, SVP of enterprise strategy at Signifyd. Her career spans payments product leadership at Worldpay and FIS, and a stint as chief product officer at the identity company Prove, so she has looked at fraud from the processor side, the identity side, and now the merchant side.
What follows is my take, not a summary of the report. It combines what the data says, what Nicole shared on the show, and what I watched play out with brands during my six years inside Shopify. Where I think the data needs a caveat, I say so. Read the full report yourself as well; the true crime case studies alone are worth it.
The 2026 State of Fraud Report found that fraud pressure across Signifyd’s network rose 33% year over year in January through April 2026, with the steepest jumps in card testing (up 175%), account takeover (up 78%), and buy online, pick up in store fraud (up 65%). The data comes from transactions across Signifyd’s Commerce Network, which the company describes as thousands of online merchants and more than 950 million unique digital wallets, and it covers North America, Latin America, Europe, and the UK.
The post-purchase numbers are the ones I would present to an operations team. In North America, Signifyd’s regional breakdown of the report shows first-party fraud and abuse up 9% and “item not as described” claims up 49% over the same four months, which Signifyd links to generative AI tools that fake photos of damaged products. Europe and the UK saw account takeover attempts rise 67% and “item not received” claims rise 49%. Latin America saw consumer abuse jump 168%.
Now the caveat, because you deserve it. This is vendor data. Signifyd sells protection against exactly these problems, and “fraud pressure” is a measure of activity across its network, not a prediction of your store’s chargeback rate. A 175% rise in card testing attempts across thousands of merchants does not mean your losses rise 175%.
I still take the report seriously, for one reason: direction. When the same network shows attackers shifting effort toward accounts, pickup orders, and return claims all at once, that tells you where to look in your own store before the holiday rush. You plan around direction, and you verify magnitude with your own numbers.
Fraud is growing faster than sales because AI has cut the cost of running an attack, so a fraudster no longer needs to win often to get paid. Signifyd’s North American data for the first half of 2026 puts ecommerce sales growth at 8.35% while fraud pressure grew 38.6%, more than four times faster, according to Signifyd’s analysis of fraud breaking away from sales growth.
Nicole put the mechanics plainly on the show. AI does not have a mind of its own that wakes up and decides to rob your store. Fraudsters use it to scale up, putting techniques that once required an organized fraud ring into the hands of amateurs. When an attack is that cheap to run, getting one attempt in a thousand through still pays.
Card testing is the clearest example. A fraudster buys a list of stolen card numbers, often from a data breach sold on the dark web, and needs to know which cards are still valid. So they cycle the list through a low-value transaction somewhere. Nicole described a Signifyd customer whose $1 donation option became a target for card testing, and another pattern in which fraudsters take over a dormant customer account and try to save cards to its wallet, because many stores ping the bank to validate a card on save. A card that saves is a card worth using.
If you have ever seen a burst of tiny failed authorizations at 3am, that is what you were looking at. Our breakdown of the security mistakes that leave stores vulnerable to AI-powered bots and card testing covers Shopify’s native bot protection and when to enable it.
Signifyd’s data adds one more wrinkle worth knowing: fraud follows opportunity, not revenue. Categories like business supplies and consumer medical saw sharp increases in fraud despite modest sales growth, so a slow-growing category is not a safe one.
For many growing Shopify stores, the most expensive fraud mistake is not the chargeback; it is the legitimate order canceled out of caution and never heard from again. Nicole framed fraud as a two-sided problem. Rotate too hard toward stopping chargebacks, and you turn away good customers. Rotate too hard toward approving everyone, and you open the floodgates. Both sides have to be managed together.
Signifyd’s own figure is striking: on its Shopify chargeback protection page, the company states that 73% of declined orders are not fraud, and Nicole cited the same number on the show, noting it varies widely depending on which rules, platforms, or AI a merchant uses. Signifyd does not publish the methodology behind that number on the page, so treat it as their estimate rather than a benchmark for your store. The honest version is that nobody knows your false decline rate, including you, until you look for it.
Here is the pattern I saw over and over during my years at Shopify. A chargeback shows up in a report with a dollar sign and a reason code, so it gets attention. A canceled good order shows up nowhere. There is no report called “customers we insulted.” So teams tighten rules after every painful chargeback and never loosen them, and approval rates drift down for months without anyone noticing.
You can test this with data you already have. Pull the orders you canceled for risk in the last 90 days. Check how many of those customers later placed an order that went through, emailed support asking why their order was declined, or match an existing good customer by email or address. If the answer is more than a handful, your settings are working against your ad budget. Every good order you decline is a customer you already paid to acquire.
This matters most right now. Nicole’s point about the holidays stuck with me: shoppers try new stores in November and December, and new customers look riskier precisely because you have never seen them before.
Fraud now shows up before and after checkout: in customer accounts, loyalty balances, store pickup orders, and return claims. Signifyd co-founder and CEO Raj Ramanand made the same point in the press release announcing the report, arguing that treating fraud as a checkout problem no longer holds.
Up the funnel, account takeover is the growth story. A fraudster who logs into a trusted, long-standing account inherits its good history, saved cards, and loyalty points, which Nicole called a very valuable currency. If you run a points program, ask your team when someone last reviewed unusual redemptions.
Pickup orders are the newer one. The report describes schemes in which mules place large online orders for items that nobody scrutinizes, pick them up, return them for store credit, and then spend that clean credit on expensive, easy-to-resell goods. One example: a houseful of smoke detectors turned into power tools.
Then there are returns. Nicole listed the classics: rocks in the box and old jeans sent back in place of new ones, and the report adds the new one: AI-generated photos of damaged products used to claim refunds. I have a soft spot for this topic because I worked in retail for Best Buy before any of my e-commerce years. We had an unofficial “national return day” every January, and as a commissioned salesperson, you started that day in the negative, clawing back the holiday sales that walked back through the door. Online stores are heading into their own version of that day right now.
Nicole’s distinction is the useful one: fraud (rocks in the box) and abuse (gaming a generous policy) are different from normal returns, and good customers deserve a frictionless experience. Keep your policy generous for customers with clean histories, and add a gate for the rest, such as issuing refunds only after inspection for high-risk returns.
Shopify Protect reimburses fraudulent chargebacks, plus the chargeback fee, on eligible Shop Pay orders for merchants located in the United States with a US Shopify Payments account, at no extra cost. It is a genuinely good starting point, and Nicole agreed that stores doing less than roughly $10M a year are usually best served by Shopify Protect and the built-in rules before adding anything else.
The fine print matters, and it is all on Shopify’s eligibility page for Shopify Protect. Orders must contain only physical items that ship, be fulfilled with valid tracking from a supported carrier within 7 days, and be in transit within 10 days. Shop Pay Installments orders are excluded; only the first order of a subscription is covered; pickup orders are excluded; and changing the shipping address after checkout voids coverage. Managed Markets orders processed through Shopify Payments are protected automatically.
I need to correct myself here. On the episode, I said Shopify Protect does not cover international shipments. The more precise version is that the hard limits are where your business is located and how the customer paid, not where the parcel goes. If you are a Canadian merchant, like many of my readers, there is no Shopify Protect available to you at all. And because Protect covers fraud chargebacks, it does not help with “item not received” or “not as described” disputes.
That last gap is where my cross-border worry actually lives. The international disputes I saw in Shopify often involved shipments to P.O. boxes or addresses with a name but no street number, followed by a claim that nothing arrived. Those are hard to prove either way, and Protect was not built for them. For those, you need a clean evidence packet for item-not-received chargebacks, or a partner whose guarantee covers them.
AI shopping agents still account for a small share of orders, but they break the old rule that any bot on your site is a bad bot, so fraud systems now need signals to distinguish a trusted agent from an attacker. Nicole put agent volume at under a percentage point of traffic, or in the very low single digits. Signifyd separately reports that ecommerce sales originating from AI-assisted search grew by more than 815% in the first half of 2026, indicating a steep growth rate from a small base.
Nicole described three buckets. The first is discovery, which is happening now: she used Gemini to troubleshoot algae in a new fish tank, got a product recommendation, and bought it herself on the merchant’s site. The only difference the merchant sees is the referral source. The second is an agent that browses your site like a human and fills the cart, where header signals are starting to identify it as an authorized agent. The third, and the one she is most optimistic about, is agents buying through an API using protocols like the Universal Commerce Protocol, where the agent can pass the shopper’s identity, device signals, or a risk score along with the order.
My read, applying the 18-month test, is that the discovery shift matters today because it changes which new customers show up and how they arrive. Fully autonomous checkout at meaningful volume is still waiting on the protocol fight among the big platforms to settle. For most stores, the practical move now is to ensure your fraud rules do not auto-decline traffic simply because it looks automated, and to ask any fraud vendor you evaluate how they handle agent orders today.
Match fraud tooling to the size of the problem: native Shopify tools until fraud and manual review become a real line item, then a decisioning partner with a financial guarantee once you are around $10M or more and declines or chargebacks are measurably costing you. The table below is how I would sort it.
If you are between $500K and $2M, the trap I see most often is premature complexity: adding a fraud vendor to solve a problem nobody has measured. Pull four numbers first: approval rate, risk cancellations per month, chargeback count by reason, and hours spent on manual review. If none of them hurts, you do not need another app yet.
When the numbers do hurt, compare multiple options. Signifyd’s Shopify app installs from the App Store, and Nicole described pricing as a fraction of a percent, charged only on orders that are approved and shipped, with Signifyd covering the chargeback amount and the $15 to $25 fee she cited if an approved order is later deemed fraudulent.
For a sense of what good looks like, Signifyd’s case study with athleisure brand Carbon38 reports a 99% approval rate and a 3% revenue uplift after moving off manual review of every order. That is one brand on Shopify Plus, reported by the vendor, so use it as an example of what to ask for rather than a promise. Whichever partner you talk to, bring your own baseline to their ROI analysis. The vendor with the best answer to “how many of my declined orders would you have approved?” is usually the one worth testing.
Signifyd’s 2026 State of Fraud Report found that ecommerce fraud pressure across its network rose 33% year over year from January to April 2026, driven by AI tools that make attacks cheaper and faster. In North America, card testing attacks rose 175%, account takeover rose 78%, buy online, pick up in store fraud rose 65%, and “item not as described” claims rose 49%. A follow-up analysis of first-half 2026 data showed North American fraud pressure growing by 38.6% against 8.35% sales growth. The data comes from Signifyd’s merchant network, so read it as a directional signal about where attackers are focusing, then check your own chargeback and decline numbers before changing anything.
You find out by auditing the orders you canceled for fraud risk, because false declines never show up on their own in a report. Export the last 90 days of risk cancellations from your Shopify admin and check each customer for signs they were legitimate: a later successful order, a support email asking why they were declined, or an email or address that matches an existing good customer. Compare your payment approval rate month-over-month as well. If approval rates are declining while chargebacks remain flat, your rules have likely tightened past the point of usefulness, and you are paying to acquire customers you then turn away.
Shopify Protect only covers merchants located in the United States with a US Shopify Payments account, so Canadian and other non-US merchants get no Shopify Protect coverage at all. For US merchants, the limits are about payment method and fulfillment rather than destination: the order must be paid with Shop Pay, contain only shipped physical items, and be fulfilled with tracking from a supported carrier within 7 days. Managed Markets orders processed through Shopify Payments are automatically protected. Protect covers fraudulent chargebacks only, so “item not received” and “not as described” disputes, which are common on cross-border orders, still need your own evidence or a third-party guarantee.
A Shopify store should pay for a fraud prevention partner when fraud costs, manual review time, or declined good orders become a measurable line item, which, for many brands, happens around $10M in annual revenue. Before that point, Shop Pay, Shopify Protect, and native risk analysis cover most stores. The signals to watch for are someone reviewing orders by hand every day, an approval rate that keeps slipping, chargebacks arriving weekly, or significant sales outside Shopify Protect’s eligibility, such as Canadian stores or subscription renewals. Compare at least two providers, and ask each one to estimate how many of your recently declined orders they would have approved.
AI shopping agents are a small but growing share of traffic, and the main risk today is treating every automated visitor as a threat, which can lead to declining legitimate agent orders. Signifyd’s Nicole Jass estimated agent-driven purchases at under a percentage point of traffic in her conversation with me, even as Signifyd reported sales from AI-assisted search growing more than 815% in the first half of 2026 from a small base. Most AI influence right now is discovery, where the shopper still buys on your site. As agents start checking out using protocols like the Universal Commerce Protocol, they can pass identity and risk signals to the merchant, making trusted-agent orders easier to approve.