Advancing the NRF Fraud Taxonomy

July 14, 2026

Yash
Yashwantha Rao Bagare Nagaraja

Lead Engineer

A man with brown hair and beard in a blue suit, white a white collard shirt
Ryan Miller

Sr. Director - Tech - Threat Intelligence Operations

Jonathan Staples

Principal Cybersecurity Analyst

Erik Thoreson

Lead Engineer

Christopher De La Rosa

Lead Threat Intelligence Analyst

Retail fraud has become one of the fastest-growing threats facing merchants, with fraudsters increasingly operating like organized cybercriminal groups. Defending against these operations requires more than better detection — it requires a common language. Today, Target, in partnership with the National Retail Federation (NRF), Chertoff Group, the Retail & Hospitality Information Sharing and Analysis Center (RH-ISAC), and retail industry partners, is releasing Version 2 of the NRF Fraud Taxonomy.
 
This latest release significantly expands both industry participation and technical coverage by adding returns and refund abuse schemes, introducing new techniques across the fraud lifecycle, and enhancing the accompanying web application with new collaboration, customization, and operational capabilities.
 
Target and its partners introduced the NRF Fraud Taxonomy in December 2024 as a common framework for understanding and defending against modern retail fraud. Since its initial release, retailers, fraud practitioners, cybersecurity professionals, and industry partners have continued expanding the taxonomy to reflect the evolving retail fraud landscape. Their collaboration has broadened the framework, added new techniques, and strengthened its value as a practical resource for defenders.
 
The goal remains the same: to provide a practical, community-driven resource that helps retailers, anti-fraud teams, cybersecurity organizations, asset protection professionals, and law enforcement agencies understand attacker behavior, identify defensive opportunities, and coordinate around a common language for retail fraud.
 
 
Why a Shared Fraud Language Still Matters
 
Modern fraud operations rarely exist in isolation. Threat actors routinely combine multiple techniques, moving fluidly across ecommerce platforms, customer support channels, fulfillment workflows, payment systems, and in-store operations. This growing complexity reinforces the need for a shared industry language that enables retailers, fraud teams, cybersecurity organizations, asset protection professionals, and law enforcement agencies to coordinate more effectively.
 
Impact of Retail Fraud on Merchants and Consumers
  • Account takeover fraud cost consumers $15.6 billion in 2024, a sharp increase from $12.7 billion the year before, according to Javelin research analysis.
  • According to the Federal Trade Commission (FTC), at least $212 million was stolen through gift card fraud in 2024 (actual losses are likely far higher, since many victims don’t report these crimes), and a 2024 AARP survey found that more than a quarter of consumers have given or received a gift card with zero value.
  • According to National Retail Federation data, 9% of all returns are fraudulent ($849.9 billion returns in 2025 x 9% = $76.5 billion fraudulent returns)
 
The Taxonomy organizes fraud operations into a hierarchical structure:
 
What’s new in Version 2
 
The initial release of the NRF Fraud Taxonomy focused primarily on gift card scams and account takeover activity, providing defenders with a structured way to map fraud schemes, attacker behaviors, mitigations, and detection opportunities.
 
Version 2 significantly expands both industry participation and technical coverage. In addition to broader collaboration among retail peers, the taxonomy now includes returns and refund abuse schemes and nearly doubles the overall size of the framework.
The latest release also introduces a new Defense Evasion tactic, along with numerous new techniques spanning Pre-Compromise, Initial Access, Control, and Monetization. Together, these additions provide defenders with broader visibility across the retail fraud lifecycle while reflecting how modern fraud operations continue to evolve.
 
Alongside these taxonomy updates, Version 2 also introduces significant enhancements to the accompanying web application, making it easier for organizations to operationalize the framework within their own environments.
 
Exploring the Web Application
 
To help organizations operationalize the NRF Fraud taxonomy, the project includes an interactive web application. The platform allows organizations to visualize fraud techniques, explore associated mitigations and detection opportunities, score risks, track mitigation progress, and customize the framework based on their own operational environments.
 
The source code of the NRF Taxonomy Viewer is currently available through Target’s GitHub repository target/retail-fraud-taxonomy-viewer, along with simple installation instructions.
 
The latest release introduces several enhancements designed to improve usability, collaboration, and operational maturity.
 
Users can now add or edit tactics and techniques directly within the platform while also creating custom organizational content layered on top of the core NRF taxonomy. This allows retailers and industry partners to tailor the framework to their own fraud environments while still maintaining alignment with the broader industry model.
 
The functionality also introduces synchronization and sharing capabilities intended to improve collaboration across teams and organizations. Users can now synchronize custom content with newly released NRF taxonomy updates, helping organizations remain aligned with the latest framework revisions while preserving local enhancements. In addition, import and export functionality enables teams to share taxonomy content and configurations through simple JSON files, making collaboration across industry peers significantly easier.
 
Another key enhancement area focuses on operational tracking and defensive maturity. Organizations can now document implementation status for specific mitigations and detection opportunities directly within the platform, helping teams better understand defensive coverage, identify gaps, and prioritize investments. Enhanced filtering options — including filtering by detection type, channel, mitigation, and risk score — further support operational analysis and investigation workflows.
 
The latest release also improves visualization and administrative control capabilities. Newly added risk scoring and color-coding features make it easier to prioritize techniques based on organizational impact, while visibility controls allow administrators to hide or unhide techniques as needed for internal workflows or tailored use cases.
 
Collectively, these enhancements move the taxonomy beyond a static reference model and closer to an operational platform that organizations can integrate into broader fraud prevention, cybersecurity, and intelligence programs.
 
Returns Abuse: A New Addition to the Taxonomy
 
Returns abuse has become one of the most persistent and operationally challenging forms of fraud impacting the retail industry. Unlike traditional theft, returns abuse often occurs through seemingly legitimate customer interactions, making it difficult to identify, investigate, and prevent at scale.
 
Modern retail environments are intentionally designed to reduce friction for customers. Flexible return policies, rapid fulfillment, curbside pickup, same-day delivery, and streamlined customer service processes all improve convenience and customer satisfaction. However, these same capabilities also create opportunities for exploitation, as fraudsters increasingly manipulate operational gaps, policy thresholds, and customer service expectations in ways that allow fraudulent activity to blend into normal business operations.
How Returns Abuse has Evolved
 
What was once largely opportunistic behavior evolved into a more organized and professionalized ecosystem. Open-source intelligence collected from criminal communities, social platforms, and underground marketplaces shows sustained coordination around refund fraud methodologies. Over the past year alone, analysts identified more than 15,000 discussions tied to refund fraud techniques, much of it occurring on platforms such as Telegram and Discord. These communities operate more like organized networks than informal chat groups. Fraudsters openly collaborate to share playbooks, refine techniques, promote proven methods, and mentor less experienced actors. Many individuals specialize in distinct stages of the fraud lifecycle, including account acquisition, social engineering, refund execution, reshipping, and resale.
 
The growth of “Refund-as-a-Service” offerings has further accelerated the problem. Similar to other cybercrime service models, these operations allow individuals with minimal technical expertise to outsource fraud execution to experienced actors in exchange for a fee or percentage of proceeds. Many services now advertise pricing tiers, guarantees, customer support-style communication, and operational guidance designed to maximize success rates.
 
Fraudsters are also increasingly targeting modern fulfillment workflows — including curbside pickup, in-store pickup, and last-mile delivery — using schemes such as false non-delivery claims, damaged-item fraud, empty-box returns, partial returns, and serial number substitution. Combined with synthetic identities, compromised accounts, freight forwarders, and reshipping networks, these techniques enable coordinated fraud across multiple retailers.
 
Why a Taxonomy Matters
 
Returns abuse remains effective because it exploits trust-based systems and the challenge of balancing fraud prevention with customer experience. Fraud indicators often closely resemble legitimate customer issues, allowing threat actors to operate within that ambiguity.
 
Organizations need a consistent way to map fraud activity across the full fraud lifecycle — from account acquisition and social engineering to refund execution, reshipping, and monetization.
 
By establishing a shared fraud taxonomy, organizations can consistently categorize techniques, infrastructure, and actor behaviors, identify defensive gaps, implement layered controls, and improve intelligence sharing across trusted partners. Version 2 extends that shared framework to returns and refund abuse, giving organizations a consistent way to analyze these increasingly sophisticated schemes alongside the broader retail fraud landscape.
Detecting and Mitigating Returns Abuse
 
Defending against returns abuse requires a fundamentally different approach than traditional fraud prevention because fraudulent activity is often designed to closely mimic legitimate customer behavior. Damaged shipment claims, non-receipted returns, and requests for store credit may all appear consistent with normal customer issues, making simple binary controls ineffective. As a result, organizations are increasingly implementing layered defenses that combine policy enforcement, identity validation, transaction integrity, behavioral analytics, customer history, and operational context. These controls should be applied across multiple phases of the fraud lifecycle, with friction calibrated to the sensitivity and risk associated with each transaction or business process step.
 
The taxonomy’s returns scheme helps organizations map controls to specific stages of the fraud lifecycle. Preventative controls may include proof of purchase requirements, delayed reimbursement, delivery confirmation, restocking fees, return limits, and escalation workflows for suspicious activity. Identity-focused measures strengthen confidence in the individual initiating the return through account verification and tighter linkage between refund activity and customer profiles. Additional controls harden the physical workflow through item-condition inspections, packaging analysis, and verification of serial numbers, RFID tags, or other product identifiers.
 
Detection is similarly dependent on correlating signals across multiple systems. Transaction data can identify duplicate refund attempts, mismatched return records, and repeated return claims tied to the same order. Behavioral, device and identity signals help uncover coordinated abuse across accounts, payment methods and customer profiles and link ostensibly separate return attempts to the same actor or actors within the crime ring. While shipping and location indicators may reveal fraudulent addresses, delivery manipulation, or fulfillment related anomalies.
 
In practice, detecting returns abuse fraud is rarely tied to a single suspicious refund event. More often, success comes from correlating signals across multiple systems, channels, and customer interactions to identify broader patterns of coordinated abuse.
 
Looking Ahead
 
Retail fraud continues to evolve alongside advances in ecommerce, digital payments, fulfillment technology, and online fraud ecosystems. Fraudsters increasingly operate with the sophistication, specialization, and collaboration models traditionally associated with cybercrime operations. As fraud schemes become more interconnected across physical and digital channels, defenders should adopt a similarly collaborative approach. Shared intelligence, common terminology, and cross-industry coordination are becoming essential components of effective fraud defense.
 
The NRF Fraud Taxonomy was designed to support that mission by helping organizations better understand attacker behavior, identify defensive opportunities, and align operational teams around a common framework. This project will continue to evolve through ongoing partnership with retailers, cybersecurity organizations, fraud professionals, and industry stakeholders. We welcome continued collaboration and community contribution as the fraud threat landscape continues to rapidly develop.
 

RELATED POSTS

A Structured Approach to Tackling Theft, Fraud, and Abuse 

By Evan Gaustad, Keerthana B, and Yashwantha Rao Bagare Nagaraja, August 4, 2025
Developed with the NRF and industry leaders, a new taxonomy creates a shared framework to identify threat patterns and strengthen defenses.