A New Era of Fraud: What Role Can Cyber Play?
RSA Conference 2024 · Track Session
Overview
This talk, presented at RSAC 2024 by Rich and Jodie from Target, addresses the evolving and increasingly sophisticated landscape of Organized Retail Crime (ORC) and fraud. Far from the simplistic image of individual shoplifters, ORC has transformed into a complex, enterprise-level operation mirroring the intricate supply chains and service economies seen in cybercrime. The core message of the presentation is a powerful call to action: cyber security teams, with their expertise in understanding adversaries, advanced detection, and resilient defense, must play a significantly larger and more integrated role in combating this pervasive threat.

Key moments
- 0:00 Introduction: Agenda and ORC overview
- 1:00 Introductory video: The reality of organized retail crime
- 4:00 Perception vs. Reality: ORC beyond the hoodie
- 5:10 ORC's true complexity: Not just smash-and-grab
- 6:00 Blurred attack surfaces: Physical and digital fraud
- 7:00 Hypothetical scenario: Tracing a missing iPad's journey
A New Era of Fraud: What Role Can Cyber Play?
Speakers: Rich, Jodie (Target)
Conference: RSAC 2024
YouTube: https://www.youtube.com/watch?v=nYoPcEUmGoQ
Overview
This talk, presented at RSAC 2024 by Rich and Jodie from Target, addresses the evolving and increasingly sophisticated landscape of Organized Retail Crime (ORC) and fraud. Far from the simplistic image of individual shoplifters, ORC has transformed into a complex, enterprise-level operation mirroring the intricate supply chains and service economies seen in cybercrime. The core message of the presentation is a powerful call to action: cyber security teams, with their expertise in understanding adversaries, advanced detection, and resilient defense, must play a significantly larger and more integrated role in combating this pervasive threat.
The speakers aim to demystify ORC, illustrating its true scope and the blurring lines between physical and digital attack vectors. They argue that traditional approaches, which often compartmentalize physical theft from online fraud, are no longer effective against these highly coordinated, multi-faceted criminal organizations. Through detailed examples and insights from their work at Target, Rich and Jodie demonstrate how cyber defense capabilities can be adapted and applied to disrupt these fraudulent activities, ultimately protecting consumers and retailers alike. The talk underscores the critical need for a paradigm shift in how ORC is perceived and defended against, advocating for a collaborative, intelligence-driven strategy that leverages the full spectrum of cyber security expertise.
Background
▶ Watch: Introduction: Agenda and ORC overview (0:00)
The presentation begins by drawing a compelling analogy between the public's historical perception of hackers and the current misunderstanding of Organized Retail Crime. For many years, the image of a "hacker in a hoodie" dominated public consciousness, suggesting an isolated individual operating from a basement. However, as the cyber security community and the general public have learned, modern cybercrime is characterized by highly organized groups operating much like businesses, complete with sophisticated supply chains for services, tools, and expertise. This understanding has led to the development of advanced threat intelligence teams, multi-layered defenses, and robust incident response capabilities in the cyber domain.
Rich and Jodie contend that the public and, in many cases, even parts of the retail industry, are still in an "immature state" when it comes to understanding ORC. The prevailing image often remains that of simple shoplifting or "smash-and-grab" incidents, leading to proposed solutions focused primarily on increased law enforcement and physical security measures like locking up inventory. While these are components of a solution, they only address the "tip of the iceberg." The reality of modern ORC is far more intricate, characterized by a complete blurring of the lines between physical and digital attack surfaces. Consumers now shop seamlessly across online platforms, in-store pickups, and same-day delivery, making the traditional distinctions between "theft" and "fraud" obsolete from an attacker's perspective. Moreover, like cybercrime, ORC is fueled by an entire supply chain economy of service providers, operating across state and international borders, making it a globally coordinated problem that demands a similarly sophisticated and interconnected defense.
Key Findings
▶ Watch: Perception vs. Reality: ORC beyond the hoodie (4:00)
The talk reveals several critical findings about the nature and scale of modern Organized Retail Crime, highlighting its alarming growth and sophistication:
- ORC as an Enterprise-Level Operation: The most significant finding is the transformation of ORC from individual acts of theft into highly organized, often international, criminal enterprises. These groups operate with business-like structures, leveraging specialized services and a clear division of labor, much like advanced persistent threats (APTs) or ransomware gangs in the cyber world.
- The Commoditization of Fraud Services: A key driver of ORC's exponential growth is the easy availability and commoditization of fraud services. The speakers highlight "account shops" where criminals can purchase accounts with established transaction histories to bypass fraud detection, and "refunder services" that specialize in scamming retailers out of refunds, splitting the profits with the primary perpetrator. This lowers the barrier to entry for individuals looking to engage in fraud.
- Educational Resources for Fraudsters: The existence of explicit "education" for committing fraud, such as "Bob's refund handbook," a 50+ page guide teaching methods to defraud retailers through returns and refunds, underscores the organized nature of these activities. The fact that such resources are publicly marketed, often on platforms like TikTok, demonstrates the brazenness and accessibility of these illicit services.
- Blurring Physical and Digital Attack Vectors: The talk emphasizes that the clear distinction between "physical theft" and "e-commerce fraud" is no longer valid. Attackers exploit the seamless, omnichannel retail experience, combining online purchases with in-store pickups, gift card redemptions in physical stores for online transactions, or using stolen digital identities to facilitate physical theft, making traditional siloed defenses ineffective.
- Massive Financial Impact: The cumulative effect of these organized schemes is staggering. The National Retail Federation (NRF) reported that over 13% of all returns are fraudulent, amounting to over $101 billion in a single year. Gift card scams, like the hypothetical example shared, account for over $200 million reported to the FTC annually, a number that is likely significantly higher given that only an estimated 5-10% of victims report these scams. Even seemingly low-value targets like loyalty programs and employee discounts are exploited by these groups to maximize profits within larger, complex schemes.
- Publicity as a Scaling Mechanism: Unlike traditional clandestine criminal operations, many ORC services thrive on publicity. They actively advertise their offerings on public platforms, including social media, to attract participants and scale their operations. This public visibility paradoxically makes them more difficult to combat with traditional law enforcement methods alone, but offers unique opportunities for threat intelligence gathering.
Technical Deep Dive
▶ Watch: ORC's true complexity: Not just smash-and-grab (5:10)
The core of the technical deep dive in this talk is the detailed hypothetical scenario illustrating the complex, multi-stage nature of modern Organized Retail Crime, far beyond simple shoplifting. This example highlights how cyber-enabled tactics merge with physical actions to exploit vulnerabilities across the retail ecosystem.
The scenario begins with a seemingly simple problem: a retailer's inventory count shows a missing iPad, indicating a shortage or shrink. At face value, this might suggest a direct physical theft. However, the speakers unravel a much more intricate chain of events:
- Initial Victimization (Social Engineering): An international call center targets a vulnerable individual, such as a grandmother in New York. The scam involves a classic social engineering tactic, coercing the victim into purchasing a
$500 gift cardunder duress (e.g., claiming a grandchild is in trouble with the IRS). The victim sends a screenshot of the gift card details to the criminal, transferring the funds. - Account Acquisition and Laundering: Instead of directly using the gift card for an easy-to-trace e-commerce purchase, the criminals opt for a more sophisticated approach to obscure their tracks. They leverage an account shop, a service where they can purchase an existing retail customer account with a "couple years of good transaction history." This established account provides a veneer of legitimacy, making it harder for fraud detection systems to flag suspicious activity. The stolen
$500 gift cardfunds are then loaded into this compromised account, effectively laundering the proceeds through a legitimate customer profile and its associated digital wallet. - Physical Theft Facilitation: The compromised account and its loaded funds are then passed to an accomplice, perhaps in California. This individual enters a physical store, selects an iPad, and proceeds to the register. The payment is made using the funds from the compromised digital wallet. To further maximize profit and complicate tracing, the criminal might even use a stolen employee discount number, reducing the purchase price from
$500to$450. At this point, from the retailer's perspective, no shortage exists; the iPad was legitimately purchased. - Refund Fraud and Profit Splitting: The final and perhaps most insidious step involves leveraging a specialized refunder service. The criminal provides the details of the "legitimate" iPad purchase to this service. The refunder, using their expertise, exploits retailer return policies and systems to "figure out how to get the money back from the retailer." This could involve various tactics, such as claiming the item was never received, was damaged, or using fake return labels. The profits from this fraudulent refund are then split between the original criminal and the refunder service.
This hypothetical example illustrates several key technical and operational elements:
- Multi-Jurisdictional Coordination: The scam spans international borders (call center), multiple states (New York victim, California accomplice), and different retail channels (physical store, online account).
- Service-Oriented Architecture of Crime: The reliance on "account shops" and "refunder services" highlights the modular, specialized nature of modern ORC, where different criminal entities provide distinct services.
- Exploitation of Legitimate Systems: The criminals don't "hack" in the traditional sense; instead, they manipulate legitimate retail processes (gift cards, customer accounts, employee discounts, return policies) to their advantage.
- Obfuscation and Layering: Each step in the process adds a layer of obfuscation, making it difficult for investigators to trace the initial act of fraud back to the final financial gain. The presence of a "legitimate" transaction initially masks the theft.
- Cyber Defense Mapping: To combat such a complex scheme, cyber defense capabilities are crucial. This includes threat intelligence to understand the services and tactics used by ORC groups (like "Bob's refund handbook"), advanced fraud detection systems capable of correlating seemingly disparate physical and digital activities, account compromise detection, and robust identity and access management for employee discounts and customer accounts. The ability to track digital footprints across various platforms and link them to physical events is paramount.
Demo / Proof of Concept
▶ Watch: Blurred attack surfaces: Physical and digital fraud (6:00)
While the talk did not feature a live, interactive "demo" in the traditional software sense, Rich and Jodie effectively demonstrated the problem of Organized Retail Crime and Target's approach to combating it through compelling real-world examples and internal strategies. These served as practical "proofs of concept" for their cyber-driven defense methodology.
One significant demonstration involved showcasing how ORC groups openly advertise their illicit services and educate potential fraudsters. They presented footage from the notorious "Bob's refund handbook" video, featuring a rapper promoting his 50+ page guide on how to scam retailers out of returns and refunds. This visual evidence underscored the public and commoditized nature of fraud education. Furthermore, Jodie showed examples of TikTok videos where individuals openly discuss and demonstrate methods for committing refund fraud. These examples, though containing uncensored language, were critical in illustrating how accessible and widely promoted these fraudulent techniques are, emphasizing the need for retailers to conduct threat intelligence by actively monitoring these public channels.
The speakers then transitioned to demonstrating how Target applies cyber defense principles to disrupt these activities, using the example of Limited Time Offerings (LTOs), specifically mentioning the popular Stanley mugs.
- Adversary Research: Target's strategy begins with researching the adversary – understanding their tools, techniques, and tactics (TTPs). This involves consuming the same content fraudsters do, like "Bob's book," to anticipate their moves.
- Multi-Layered Disruption: For LTOs, the goal is to ensure legitimate customers receive the products, not resellers. They employ a multi-pronged approach:
- Bot Blocking: Automated activity, often used by resellers to quickly buy up limited stock, is actively blocked using sophisticated bot detection and prevention mechanisms.
- Activity Disruption/Step-Up: For more "graceful, less automated activity," they implement measures to slow down or disrupt the process. This includes step-up authentication or temporary account locking for suspicious user behavior, forcing fraudsters to abandon attempts or reveal more information.
- Order Blocking: If the initial layers of defense are bypassed, Target resorts to blocking orders from known or suspected fraudsters. Jodie likened this to preventing a customer from buying ten Stanley mugs in a physical store, ensuring fairness for legitimate buyers.
These examples vividly illustrate that combating ORC isn't just about technical exploits; it's about understanding human behavior, social engineering, and the "business" of crime, then applying cyber security's analytical rigor and defensive capabilities to disrupt these operations at various stages. The "demo" effectively showcased how threat intelligence, prevention, and detection, traditionally cyber security domains, are directly transferable and highly effective in the fight against ORC.
Defensive Implications
▶ Watch: Hypothetical scenario: Tracing a missing iPad's journey (7:00)
The insights presented in this talk carry profound defensive implications for organizations grappling with Organized Retail Crime and fraud, urging a fundamental shift in strategy:
- Cyber's Indispensable Role: The most critical implication is the absolute necessity for cyber security teams to integrate deeply into ORC and fraud prevention efforts. Historically, ORC has been seen as a loss prevention or law enforcement issue. However, given the blurring of physical and digital attack surfaces and the sophisticated, cyber-enabled nature of modern fraud, cyber professionals possess the unique skills (e.g., threat intelligence, data analytics, anomaly detection, incident response) to connect the dots and build effective defenses that traditional teams cannot.
- Unified Threat Intelligence: Defenders must adopt a unified threat intelligence approach that encompasses both traditional cyber threats and ORC. This means actively monitoring public forums, social media (like TikTok), and underground markets where fraud services are advertised and taught (e.g., "Bob's refund handbook"). Understanding the adversary's TTPs, tools, and motivations in the ORC space is as crucial as understanding ransomware groups.
- Holistic Prevention and Detection: Security strategies must move beyond siloed prevention (e.g., physical security for stores, fraud detection for e-commerce). A holistic approach is required, building preventive controls that span both physical and digital channels and detection mechanisms capable of correlating anomalous behavior across the entire customer journey, from online browsing to in-store pickup and returns. This includes advanced bot blocking, step-up authentication, and intelligent order blocking.
- Data Correlation and Analytics: The complexity of ORC schemes (like the iPad example) necessitates sophisticated data correlation and analytics. Defenders need to be able to link seemingly disparate events—a suspicious gift card purchase, an account login from an unusual location, a physical store transaction, and a subsequent refund request—to uncover organized fraudulent patterns. This requires robust logging, aggregation, and analytical capabilities.
- Secure Identity and Access Management: Loyalty programs, employee discounts, and customer accounts are all targets. Organizations must implement strong identity and access management (IAM) controls, including multi-factor authentication (MFA), monitoring for compromised credentials, and detecting unusual access patterns to prevent account takeovers and abuse.
- Industry Collaboration: The speakers strongly advocate for enhanced industry collaboration. Just as Information Sharing and Analysis Centers (ISACs) and other sharing groups have matured in the cyber security space, similar platforms are needed for ORC. Retailers and other affected industries must overcome competitive concerns to share intelligence on ORC groups, TTPs, and successful countermeasures to collectively keep pace with the rapid evolution of these criminal enterprises.
- Educating Talent: There is a need to educate the next generation of cyber talent about the role they can play in combating ORC. Expanding the scope of cyber security education to include fraud and physical-digital convergence will be vital for future defense.
Key Takeaways
- ORC is a Sophisticated, Enterprise-Level Threat: Organized Retail Crime has evolved far beyond simple shoplifting, operating as complex, multi-jurisdictional enterprises with sophisticated supply chains for fraud services, mirroring advanced cybercrime.
- Cyber Security Expertise is Critical: Cyber teams possess unique skills in threat intelligence, advanced detection, and building resilient defenses that are essential for combating the cyber-enabled and interconnected nature of modern ORC.
- The Physical and Digital Divide is Gone: Attackers exploit the seamless, omnichannel retail experience, blurring the lines between physical theft and online fraud. Defenses must adapt to this convergence, correlating data and activity across all channels.
- Threat Intelligence Must Expand to ORC: Organizations must actively conduct threat intelligence on ORC groups, monitoring public platforms and "underground" services (like "Bob's refund handbook") to understand adversary TTPs and proactively build defenses.
- Collaboration is Key to Collective Defense: To effectively counter the rapidly evolving and globally coordinated ORC threat, industries must enhance information sharing and collaboration, much like the mature sharing networks in the traditional cyber security space.
- Every Area of Value is a Target: Even seemingly low-value targets like loyalty programs and employee discounts are exploited within larger, complex ORC schemes to maximize profits, underscoring the need for comprehensive security across all assets.
About the Speaker(s)
The talk was delivered by Rich and Jodie from Target. While specific full names and titles were not provided in the transcript or metadata, both speakers are evidently deeply involved in applying advanced cyber security principles and practices to combat Organized Retail Crime and fraud within their organization. Their presentation demonstrated a profound understanding of both the evolving threat landscape in retail and the sophisticated defensive capabilities required to counter it, drawing from their practical experience at Target in disrupting these criminal enterprises. They emphasized the importance of understanding the adversary, leveraging cyber defense capabilities, and fostering industry collaboration.