Ahead of the Curve: Fraud-Cyber Convergence in Retail/eCommerce is a vertical cut of The Convergence Dividend: Quantifying What Fraud-Cyber Convergence Actually Delivers (Accertify + Liminal, 2026), a study of 250 fraud and risk decision-makers across five verticals: Retail/eCommerce, Travel, Quick Service Restaurants (QSR), Entertainment & Media, and Marketplaces. This post looks at what the Retail/eCommerce respondents (n=50) are actually thinking about.
Because the 250 organizations in the study were performing similarly on fraud decisioning metrics such as approval rate on dollar volume (ranging from 97.5% to 98.2%) and on fraud chargeback rate on dollar volume (ranging from 15.9 basis points to 24.9 basis points), the study assessed the ROI of fraud-cyber convergence using a precision measure called the Precise Yes Score (PYS), calculated as the approval rate divided by fraud chargeback rate. The PYS answers the question: for every dollar lost to fraud chargebacks, how many dollars in legitimate volume is an organization approving? The higher the better. The PYS rewards saying yes precisely, not just saying yes often.
The study also grouped all 250 respondents into a five-tier convergence maturity framework, based on four specific behaviors: sharing responsibility for two or more fraud/cyber use cases, integrating or unifying data on a single pipeline or platform between fraud and cyber teams, putting fraud regularly on the Board agenda, and integrating fraud and cyber into a single organizational structure. Organizations with none of the four in place (“Siloed”) score a mean PYS of 456 (approving $456 per $1 of fraud chargeback); organizations with all four (“Elite”) score 1,540 (approving $1,540 per $1 of fraud chargeback). This is a 3.4x gap, driven almost entirely by reduction in fraud chargeback rate – meaning that as organizations mature in fraud-cyber convergence, their approval rates remain high, but they “get burned” less. The research also discovered that the sequence of convergence matters too:
- Share use cases first
- Integrate the data for fraud and cyber to look at and take results to the Board
- Structural integration last, used as a capstone. Interestingly, the study found that structure adopted prematurely underperforms doing nothing at all.Â
With this context, Retail/eCommerce presents a genuine paradox in our research. On the data, it’s the best-performing vertical in the study: highest approval rate, lowest fraud chargeback rate, lowest cost per fraud investigation, highest Precise Yes Score, and the highest concentration of organizations in the “Elite” tier of fraud-cyber convergence maturity of all the 5 verticals we studied. Yet, Retail/eCommerce is also the most vigilant vertical in the study. It’s the one most likely to say fraud risk is getting worse and the most concerned about AI-enabled and AI-agent fraud. That combination – performance strength paired with heightened attention, not complacency – is the real story here.
The Paradox at a Glance
| Performance (best-in-study) | Retail | Vigilance (also highest-in-study) | Retail |
|---|---|---|---|
| Approval rate | 98.2% (highest of 5) | Say fraud risk grew more important vs. 12mo ago | 92% (highest of 5) |
| Fraud chargeback rate | 15.9 bps (lowest of 5) | Say AI-fraud impact increased significantly | 36% (highest of 5) |
| Cost per investigation | $169 (lowest of 5) | “Very concerned” about AI-agent fraud risk | 30% (highest of any vertical) |
| Precise Yes Score | 874 (highest of 5) | Cite account takeover as a top threat | 56% (2x the other 4 verticals) |
| Organizations in “Elite” convergence tier | 24% (2x+ study avg of 9.6%) |
Source: Ahead of the Curve: Fraud-Cyber Convergence in Retail/eCommerce, Accertify + Liminal, 2026. Retail/eCommerce n=50.
1. The Pressure Is Real, and Retail Feels It Most
92% of Retail respondents say fraud risk has grown more important over the past 12 months, the highest rate of any of the five verticals (vs. 86% in QSR, 82% in Entertainment & Media, 80% in Marketplaces, and 72% in Travel), and not a single Retail respondent said it has decreased.
The AI dimension is sharper still. 88% of Retail respondents say AI-enabled fraud has increased in business impact over the past 12–24 months, and 36% say it’s increased significantly, the highest of any vertical. Agentic commerce adds another layer of concern: 30% of Retail respondents are “very concerned” about AI-agent fraud risk, also the highest of any vertical, while 88% of retailers still see meaningful commercial opportunity in agentic commerce, in line with the study average. Retail isn’t retreating from the technology; it’s leaning in while watching it more closely than any of its peers.
2. Account Takeover Is Retail’s Signature Threat
56% of Retail respondents cite account takeover (ATO) as a top discussed threat – twice the 28% rate across all other verticals combined. Promo, loyalty, and returns abuse rounds out the top threats at 50%, also above the study average. Together, these point to a threat surface that spans the full customer journey, from account creation to post-purchase exploitation. At the other end, malware (6%) and data theft (4%) barely register. Retail’s exposure is concentrated in transactional fraud, not infrastructure attacks.
ATO matters for a specific reason: it isn’t a fraud attack that merely resembles a cyber attack – it’s both simultaneously. The account compromise is the cyber event; the downstream purchase fraud is the fraud consequence. That dual nature is what’s driving where Retail invests next (see below).
3. The “Shift Left:” Where Retail Is Actually Investing
Today, 60% of Retail respondents identify checkout as their primary fraud/cyber control point, more than triple the 18% rate across non-Retail verticals. That focus is clearly working, because Retail’s approval and chargeback numbers lead the study.
But the investment direction is shifting “to the left:” 74% of Retail respondents say controls are actively expanding into account creation and 64% say they are also expanding into account login. The logic tracks directly back to ATO: the further left the control sits in the customer journey, the earlier the threat is intercepted and the less downstream damage (chargebacks, account compromise, fraud loss) it can do. Chargeback reduction is, in fact, the dominant lens Retail uses to evaluate any fraud/cyber investment: 68% cite it as a critical outcome, 20 points above other industries.
4. Performing Best, Yet Still the Most Vigilant
This is the part of the story that could read as contradictory but isn’t. Retail leads every vertical in the study on fraud decisioning precision and has the strongest fraud-cyber convergence-maturity profile of any vertical, with 24% of organizations at “Elite” status (more than double the 9.6% study average) and 34% in one of the top two tiers combined, against 17.2% study-wide.
Interestingly, that strength isn’t producing complacency – it’s producing the opposite. The same organizations posting the best fraud economics in the study are also the ones reporting the most concern about where the threat is heading next. Read together with Section 1, the honest interpretation isn’t “Retail is behind and worried.” It’s, “Retail has been fighting these threats longer and more effectively than anyone else in the study, which is exactly why it isn’t taking its foot off the gas.”
5. What Retail Could Be Doing Better
Two gaps stand out, and they’re gaps Retail respondents are naming themselves, not ones we’re inferring.
Distinguishing fraud from cyber, in the moment, is still hard. Only 22% of Retail respondents say they can tell a cyber attack from a fraud attack in real time, versus 40% across the other four verticals combined. 24% say they can’t distinguish the two at all, in real time or after the fact. Given that ATO – Retail’s signature threat – is a cyber event and a fraud event at the same time, this is a meaningful blind spot sitting directly on top of the vertical’s biggest exposure.
Fraud and cyber are still perceived very differently inside the same organizations. Only 18% of Retail respondents say fraud solutions are tightly aligned with primary business objectives, while 58% would say cybersecurity solutions are tightly aligned – a 40-point internal perception gap.
Both point toward the same underlying need, and Retail respondents say so directly: 72% believe a unified platform for account takeover would deliver a meaningful advantage. The signal in the data isn’t “add another point solution” – it’s “stop treating fraud and cyber signal for the same event as two separate problems.” That’s the gap between where Retail’s convergence maturity already sits and where the vertical’s own respondents say the next real advantage is.
The Bottom Line
Retail/eCommerce isn’t converging fraud and security teams in reaction to a crisis, because only 16% of retailers cite a major incident or breach as a driver, versus 35% across the other four verticals – it’s converging ahead of one. The vertical that has spent the longest fighting this threat is also the one that knows best how much is still unresolved: a real-time fraud/cyber distinction that isn’t there yet, an internal alignment gap between how the two functions are perceived, and a stated appetite for treating account takeover as one signal instead of two. For organizations further behind on that same path, the study’s own numbers show what full convergence is worth: Elite-tier organizations approve $1,540 for every dollar lost to fraud chargeback, or 3.4x the $456 recorded by organizations with none of the four convergence behaviors in place.
FAQ
What is the average fraud chargeback rate for the Retail/eCommerce industry?
15.9 basis points (0.159%) on dollars transacted, the lowest of the five verticals studied (Travel: 23.2 bps, QSR: 23.4 bps, Entertainment & Media: 23.7 bps, Marketplaces: 24.9 bps).
What is Retail’s Precise Yes Score?
874. Meaning Retail organizations approve $874 in transaction volume for every $1 lost to fraud chargeback, the highest of any vertical in the study.
What is retail’s top fraud threat?
Account takeover (ATO), cited by 56% of Retail respondents as a top discussed threat. nearly three times the 20% rate in QSR.
Can retailers tell fraud attacks apart from cyber attacks?
Not easily. Only 22% of Retail respondents say they can distinguish a cyber attack from a fraud attack in real time, versus 40% across the other four verticals combined; 24% say they can’t distinguish the two at all.
Where is Retail investing next in fraud prevention?
Upstream in the customer journey: account creation (74% expanding controls there) and account login (64%) – shifting left from today’s checkout-heavy focus (60%).
What is the ROI of fraud-cyber convergence maturity?Â
Organizations at the “Elite” tier of fraud-cyber convergence maturity achieve a Precise Yes Score of 1,540, compared to 456 for “Siloed” organizations — a 3.4x gap. The improvement is driven almost entirely by a lower fraud chargeback rate: Elite organizations say yes just as often, but get burned far less. Source: The Convergence Dividend, Accertify + Liminal, 2026 (n=250).
How concerned are retail fraud teams about AI-enabled fraud?Â
Very. 88% of Retail respondents say AI-enabled fraud has increased over the past 12 months — the highest of any vertical — and 36% say the impact has been significant, also the highest of any vertical. 30% say they are “very concerned” about AI-agent fraud specifically, the highest rate of any vertical studied.
What percentage of retail organizations have reached “Elite” fraud-cyber convergence maturity?Â
24% of Retail/eCommerce organizations in the study qualify as “Elite” — meaning they share fraud/cyber use case responsibility, have integrated data pipelines, put fraud on the Board agenda, and have unified their organizational structure. That is more than double the study-wide average of 9.6% across all five verticals.
What is the right order of steps to implement fraud-cyber convergence?Â
Sequence matters. The research identified a specific order that maximizes outcomes: (1) share responsibility for two or more fraud/cyber use cases first; (2) integrate data so both teams work from a unified pipeline and bring results to the Board; (3) unify organizational structure last, as a capstone. Organizations that adopt structural integration prematurely — before the use case sharing and data steps — actually underperform organizations that do nothing at all.
How does retail compare to other industries on cost per fraud investigation?Â
Retail has the lowest cost per fraud investigation of the five verticals studied: $169 per investigation, compared to higher costs across Travel, QSR, Entertainment & Media, and Marketplaces. This is consistent with Retail’s broader performance profile as the top-performing vertical on all four fraud decisioning metrics measured.
Sources: Retail/eCommerce figures from Ahead of the Curve: Fraud-Cyber Convergence in Retail/eCommerce, n=50. Study-wide convergence framework and headline findings from The Convergence Dividend: Quantifying What Fraud-Cyber Convergence Actually Delivers (Accertify + Liminal, 2026), n=250.
Accertify enables commerce by doing one thing extraordinarily well: pinpointing fraud. The company’s Predictive Yes Platform helps businesses say yes to more — more good customers, more revenue, and more growth — without getting burned. Learn more at accertify.com.