Countering Cyber Threats, Digital Fraud and Theft in the Retail Sector
RSA Conference 2024 · Track Session
Overview
This talk, presented at RSAC 2024 by leaders from the Retail & Hospitality Information Sharing and Analysis Center (RH-ISAC), Target Corporation, and the National Retail Federation (NRF), addresses the escalating and increasingly sophisticated landscape of cyber threats, digital fraud, and theft impacting the retail sector. The session highlights a critical shift in the threat paradigm, where traditionally separate domains of cybersecurity and fraud are converging, demanding integrated strategies and capabilities from retailers. Speakers emphasize that this convergence is not only driven by the digital transformation of retail operations but also by the evolving tactics of threat actors who exploit legitimate business processes for illicit gains.

Key moments
- 1:15 Retail fraud's rise to #2 persistent threat
- 2:00 Introducing Target and NRF cyber security experts
- 4:00 Examining the blurred lines between cybercrime and fraud
- 4:40 How omni-channel retail created new fraud opportunities
- 5:00 Examples of advanced return fraud, like 'box of potatoes'
- 6:00 Fraudsters developing better tooling, capabilities, and visibility
Countering Cyber Threats, Digital Fraud and Theft in the Retail Sector
Speakers: Suzy Squire, President, Retail & Hospitality Information Sharing and Analysis Center (RH-ISAC); Ryan Miller, Senior Director of Threat Intelligence, Target Corporation; Christian Beckner, Vice President of Retail Tech and Cyber Security, National Retail Federation
Conference: RSAC 2024
YouTube: https://www.youtube.com/watch?v=6IsaTvtqb_o
Overview
This talk, presented at RSAC 2024 by leaders from the Retail & Hospitality Information Sharing and Analysis Center (RH-ISAC), Target Corporation, and the National Retail Federation (NRF), addresses the escalating and increasingly sophisticated landscape of cyber threats, digital fraud, and theft impacting the retail sector. The session highlights a critical shift in the threat paradigm, where traditionally separate domains of cybersecurity and fraud are converging, demanding integrated strategies and capabilities from retailers. Speakers emphasize that this convergence is not only driven by the digital transformation of retail operations but also by the evolving tactics of threat actors who exploit legitimate business processes for illicit gains.
The discussion underscores the urgent need for retailers to dismantle internal silos between cyber security, fraud prevention, and loss prevention teams. It reveals that fraud-related threats have surged from being the tenth most prevalent concern to the second, trailing only phishing, according to a recent RH-ISAC Intel summary report. This alarming trend signifies that the financial and reputational impact of digital fraud is no longer a peripheral issue but a core challenge that demands a proactive, intelligence-driven, and collaborative response across the industry and with law enforcement partners.
The panel delves into specific examples of sophisticated fraud, such as Account Takeover (ATO) and gift card tampering, demonstrating how organized criminal groups are leveraging digital platforms and exploiting retail processes at an unprecedented scale. The insights provided are crucial for any organization grappling with the complexities of securing their digital storefronts and protecting their customers and assets against a highly adaptable and financially motivated adversary.
Background
▶ Watch: Retail fraud's rise to #2 persistent threat (1:15)
The retail sector has undergone significant cybersecurity maturation over the past decade, yet the persistent nature of threats continues to challenge organizations. Historically, cybersecurity teams primarily focused on protecting networks and data from external breaches and cyberattacks, while fraud teams dealt with more traditional forms of financial deceit, often reactive to observed incidents. This created a clear, albeit artificial, delineation between "cyber criminals" and "fraudsters" within many organizations. However, as retailers embraced the omnichannel approach, enabling customers to shop, return, and manage accounts seamlessly across online and physical channels, the attack surface expanded dramatically. This digital transformation, while enhancing customer experience, inadvertently provided new avenues for exploitation.
The RH-ISAC, an information sharing organization with over 270 international member companies, has been instrumental in facilitating threat intelligence exchange within the retail, hospitality, travel, and consumer-facing sectors for 10 years. Their recent Intel summary report starkly illustrates the shift: fraud-related threats have climbed from number 10 to number 2 in the top 10 trends, highlighting their growing prevalence and impact. This rise is attributed to the fact that bad actors do not differentiate between "cyber" and "fraud"; they simply exploit any vulnerability or legitimate workflow to achieve their objectives. The National Retail Federation (NRF), the largest trade association for the US retail sector, also actively engages with its IT Security Council of retail CISOs, acknowledging and working on this convergence, particularly with the RH-ISAC, to address these evolving risks. The need for a unified strategy has become paramount as the lines between cyber-enabled fraud and traditional cybercrime continue to blur.
Key Findings
▶ Watch: Examining the blurred lines between cybercrime and fraud (4:00)
The talk highlights several critical findings regarding the evolving threat landscape in retail:
- Convergence of Cyber and Fraud: The traditional distinction between cybercrime and fraud is largely arbitrary from the perspective of threat actors. Bad actors, whether developing banking Trojans or sophisticated bots, operate without internal boundaries, blurring the lines that organizations often draw. This necessitates a unified approach to security that integrates cyber threat intelligence with fraud intelligence.
- Exploitation of Omnichannel Operations: The shift to an omnichannel retail experience, designed for customer convenience, has been mirrored by fraudsters. They meticulously learn retail operations and legitimate workflows to identify and exploit vulnerabilities, moving beyond traditional in-store theft to sophisticated online schemes.
- Sophistication of Digital Fraud: Fraud tactics have become significantly more advanced. Examples include manipulating shipping labels for fake returns (e.g., sending boxes of potatoes or rocks), and leveraging compromised accounts for a host of secondary fraudulent activities, not just direct credit card theft.
- Account Takeover (ATO) as an Enabler: While ATO has existed for a long time, its utility for fraudsters has evolved. Instead of merely stealing credit or gift card details, compromised "good standing aged accounts" are now used to bypass existing fraud controls and facilitate other complex fraud schemes, such as return fraud or gift card transfers between accounts.
- Rise of Organized Retail Crime (ORC) with Digital Ties: ORC, traditionally focused on physical theft for resale, is increasingly converging with digital fraud and cybercrime. These are often transnational organized criminal groups using sophisticated tactics and global networks for resale, money laundering, and other illicit activities.
- Importance of Proactive Intelligence and Data Centralization: Effective defense requires moving beyond reactive fraud detection. This involves proactive external threat intelligence, centralizing all relevant data (external intelligence, internal fraud observations, customer behavior) for a holistic view, and developing engineering capabilities to adapt and close exploited workflows.
- Policy and Law Enforcement Engagement: There is growing recognition at federal and state levels, with agencies like Homeland Security Investigations (HSI) partnering with the retail sector to build complex cases against ORC and fraud groups. Legislation like the INFORM Consumers Act aims to deter the resale of stolen goods online by increasing transparency on marketplaces.
- Need for Standardized Taxonomy: A significant challenge is the lack of a standardized lexicon for different types of fraud, similar to indicators of compromise (IoCs) or MITRE ATT&CK in cybersecurity. Developing a common language is crucial for effective collaboration and comparison of fraud instances across organizations.
Technical Deep Dive
▶ Watch: How omni-channel retail created new fraud opportunities (4:40)
The core of the challenge discussed in the talk lies in the sophisticated ways that fraudsters are exploiting legitimate retail processes, often leveraging cyber capabilities to amplify their impact. This section provides a deeper look into the technical aspects of these threats.
At its foundation, digital fraud often involves Account Takeover (ATO). While the concept of compromising online accounts for credentials has existed as long as online accounts themselves, the utility of these compromised accounts has evolved significantly. Fraudsters are no longer solely focused on immediate credit card theft. Instead, they seek "good standing aged accounts" that appear legitimate to an organization's internal fraud controls. These trusted accounts can then be used to facilitate a variety of other fraud types, flying under the radar. For instance, a compromised account might be used to initiate a return fraud scheme, transfer gift card balances, or make purchases that would otherwise trigger suspicious activity flags if attempted from a newly created or clearly fraudulent account. This demonstrates a shift from direct financial theft to using ATO as a foundational step for more complex, multi-stage attacks.
One of the most prevalent and technically interesting fraud types highlighted is return fraud. With the rise of omnichannel retail, customers can initiate returns online without ever stepping foot in a physical store. Fraudsters exploit this convenience by:
- Purchasing with Stolen Credentials/Cards: They often acquire products using stolen credit card information, meaning they never legitimately pay for the item.
- Fake Returns: They then initiate a return, often receiving a pre-paid shipping label. Instead of sending back the actual product, they might send an empty box, a box of rocks, or even potatoes, as explicitly mentioned in the talk.
- Shipping Label Manipulation: Another tactic involves manipulating the shipping label itself, causing the package to get "lost in transit." This shifts responsibility from the fraudster to the shipping company or the retailer, while the fraudster still receives a refund for an item they never returned.
These return fraud schemes are successful because they leverage the trust inherent in established return policies and the automated nature of online logistics. Fraudsters meticulously learn the specific return flows of individual retailers, as these processes can vary significantly between, for example, Target, Walmart, or Kohl's. They identify minor deviations or control gaps that allow them to bypass security checks, such as a missing step-up authentication or a control designed for physical returns that doesn't translate well to digital. The talk emphasizes that fraud is "intimate" to the organization, meaning a method that works for one retailer might not work for another, leading fraudsters to constantly pivot their tactics based on specific organizational vulnerabilities.
Perhaps the most alarming technical deep dive revolved around gift card tampering, which has become incredibly lucrative and is now the "number one" hot topic in retail fraud. This is a highly organized, multi-stage attack orchestrated by transnational organized criminal groups, often with ties to money laundering. The attack chain involves:
- Physical Theft/Acquisition: Individuals, often recruited through platforms like Telegram, WhatsApp, or Facebook, are hired to physically steal gift cards off store shelves. These "runners" are typically unaware of the broader operation.
- Tampering: The stolen cards are then handed off to another party who performs the actual tampering. This might involve carefully peeling back packaging, recording card numbers and PINs, or even replacing the magnetic strip or barcode with one linked to a different account. The packaging is then meticulously resealed to appear untouched.
- Reshelving: The tampered gift cards are placed back on store shelves.
- Activation and Draining: When an unsuspecting customer purchases and activates one of these tampered cards, the fraudsters, who already have the card's details, immediately drain the funds.
- Anonymity and Scale: A key technical aspect of this operation is the compartmentalization. Individual participants ("some guy Dave" as an example from the talk) have no knowledge of the full chain or the identities of others involved, making it incredibly difficult for law enforcement to track and dismantle the entire network. This allows these groups to operate at an enormous scale, leading to hundreds of millions of dollars in losses, not just from the stolen funds but also from the cost of the cards, security measures, and damage to brand reputation.
The technical sophistication of these attacks is not in developing zero-day exploits but in understanding and manipulating business logic and human processes at scale. Fraudsters leverage readily available digital communication tools for coordination and exploit the perceived anonymity of online transactions and the physical world's vulnerabilities (like easily accessible gift card displays). Countermeasures, therefore, must involve not only traditional cybersecurity controls but also a deep understanding of retail business processes, customer behavior analytics, and robust intelligence gathering from external underground communities to anticipate and prevent these abuses.
Demo / Proof of Concept
▶ Watch: Examples of advanced return fraud, like 'box of potatoes' (5:00)
The discussion primarily focused on strategic insights, threat landscape analysis, and organizational challenges rather than a live demonstration of specific tools or proof-of-concept exploits. The speakers detailed various fraud methodologies and the organizational responses required, drawing on real-world examples and the experiences of Target and the retail sector at large.
Defensive Implications
▶ Watch: Fraudsters developing better tooling, capabilities, and visibility (6:00)
The insights from this talk provide critical guidance for defenders in the retail sector and beyond, emphasizing a paradigm shift in how fraud and cyber threats are approached.
- Break Down Silos: The most crucial defensive implication is the necessity to dismantle organizational silos between cybersecurity, fraud prevention, and loss prevention teams. As threat actors do not differentiate between "cyber" and "fraud," organizations must adopt a unified "collective risk function." This requires fostering direct communication, collaboration, and shared objectives across these historically separate departments. Target's journey of integrating fraud capabilities under cyber security serves as a strong model, though it took years to achieve.
- Centralize Data and Intelligence: Effective defense relies on a holistic view of the threat landscape. This means centralizing data from various sources: external threat intelligence (e.g., underground forums, dark web monitoring), internal fraud engine data, customer account behaviors, and transactional records. A unified data lake allows security teams to identify normal vs. abnormal patterns, detect bot activity, and understand how legitimate workflows are being abused.
- Proactive Threat Intelligence for Fraud: Moving beyond reactive fraud detection, organizations must develop proactive cyber fraud intelligence capabilities. This involves actively monitoring external sources for discussions about specific retail attack methods, tools being built, or accounts being sold that target their organization. This intelligence can then inform preventative measures before widespread losses occur.
- Engineer Out Abused Workflows: Since many fraud schemes exploit legitimate business processes (e.g., return flows, gift card activation), a key defensive strategy is to re-engineer or add controls to these vulnerable workflows. This might involve implementing stronger multi-factor authentication for sensitive actions, changing return procedures, or enhancing checks during gift card activation. This requires close collaboration between security teams and product owners of digital platforms.
- Develop a Common Fraud Taxonomy: To facilitate effective information sharing and benchmarking, the industry needs a standardized lexicon for defining and categorizing different types of fraud. Similar to how MITRE ATT&CK provides a common framework for cyber threats, a standardized fraud taxonomy would allow organizations to compare "like instances to like instances," enabling better collective defense strategies and shared best practices.
- Strengthen Third-Party Partnerships: Many retail operations, particularly in areas like payments, last-mile delivery, and gift card issuance, involve third-party companies. Defenders must build strong partnerships with these vendors, understanding their security controls and processes, and collaborating to address vulnerabilities that span the entire ecosystem.
- Engage with Law Enforcement and Policy Makers: Organizations should actively engage with federal and state law enforcement agencies (e.g., Homeland Security Investigations) and support legislative efforts (e.g., INFORM Consumers Act) that aim to combat organized retail crime and digital fraud. These partnerships are crucial for building complex cases against transnational criminal groups and creating a more deterrent environment.
- Scale Solutions for Smaller Businesses: While large retailers like Target have significant resources, the principles of collaboration, data centralization, and proactive intelligence need to be scaled and adapted for small and medium-sized businesses with fewer resources. Industry associations like RH-ISAC and NRF play a vital role in disseminating best practices and facilitating collective defense for these members.
Key Takeaways
- The distinction between cybercrime and digital fraud is increasingly blurred; organizations must adopt a unified, integrated approach to security.
- Fraud-related threats have escalated dramatically in the retail sector, becoming a top priority alongside traditional cyberattacks.
- Sophisticated fraudsters exploit legitimate retail omnichannel processes and leverage Account Takeover (ATO) to facilitate complex, multi-stage schemes like sophisticated return fraud.
- Gift card tampering represents a highly organized, transnational criminal operation causing hundreds of millions in losses, demanding a concerted effort from retailers, third parties, and law enforcement.
- Effective defense requires breaking down internal silos, centralizing data for holistic threat visibility, and developing proactive intelligence capabilities to anticipate and engineer out vulnerabilities in business workflows.
- Collaboration with law enforcement, industry peers, and third-party partners, alongside supporting policy initiatives, is crucial for combating organized retail crime and its digital manifestations.
About the Speaker(s)
Suzy Squire is the President of the Retail and Hospitality Information Sharing and Analysis Center (RH-ISAC), an organization that represents retail, hospitality, travel, and consumer-facing companies, facilitating information sharing among their information security teams. The RH-ISAC has about 270 member companies internationally and is celebrating its 10th year.
Ryan Miller is a Senior Director in the Cyber Defense organization at Target Corporation. He leads the Cyber Threat Intelligence, Cyber Fraud Intelligence, and reverse engineering capabilities within Target's fusion center. With about 15 years of experience in cyber threat intelligence, Ryan emphasizes the evolving nature of threats and the necessity for organizations to blur the lines between traditional cyber and fraud intelligence.
Christian Beckner is the Vice President of Retail Tech and Cyber Security at the National Retail Federation (NRF), the largest trade association in the US for the retail sector. His role involves working on technology and cybersecurity-related policy and engagement, including leading the NRF's IT Security Council, which consists of retail CISOs and senior cyber professionals. Christian's background includes experience in policy, having previously worked as a Senate staffer and at several think tanks focused on cybersecurity.