Identity theft is the unauthorized use of another person’s identifying information, such as their name, payment credentials, account logins, or government ID numbers, to commit fraud. In ecommerce it most often appears as purchases on stolen payment credentials, account takeovers, and new accounts opened in a victim’s name.
How Identity Theft Reaches Your Store
Merchants rarely face the original theft; they face its downstream use. Credentials harvested through phishing, data breaches, and card skimming are packaged and sold on the dark web, then deployed against stores as card not present fraud, account takeover, and credential stuffing attacks. Consumer reports aggregated through the Federal Trade Commission’s fraud reporting portal consistently rank identity misuse and unauthorized charges among the most common fraud complaints.
Impact on Commerce Brands
When stolen identity data is used at checkout, the real cardholder disputes the charge and the merchant absorbs the chargeback, the merchandise loss, and the fees. When an existing customer’s account is taken over, the damage extends further: stored payment methods get drained, loyalty balances get spent, and the legitimate customer’s trust in the brand takes the hit even though the brand was also a victim.
How to Protect Shoppers and the Business
Layered controls matter on both sides of the login: screen transactions for signals that the buyer is not the cardholder (device, network, behavioral, and historical patterns rather than address matching alone), protect accounts with multi-factor authentication and anomaly detection, and monitor for credential stuffing against the login page. Speed matters: identity-driven attacks are increasingly automated, so defenses need to decide in real time.
How Wyllo Helps
Stolen identity data passes identity checks by definition. What it fails is intent: the behavior around the order doesn’t match the customer it claims to be. Wyllo Payment Fraud Protection screens every order against device, network, and behavioral signals backed by human fraud experts, and Wyllo Claim and Policy Abuse Prevention catches account takeover before it becomes refunds, claims, and disputes.
Frequently Asked Questions
Who is liable when identity theft leads to fraudulent purchases?
For card not present transactions, liability generally falls on the merchant, not the card issuer. The cardholder is made whole through the chargeback; the merchant loses the goods, the revenue, and pays the dispute fee.
How can merchants tell identity theft from friendly fraud?
Identity theft involves a third party using stolen data, so signals typically show a buyer inconsistent with the account or cardholder history. In friendly fraud, the real customer transacted and later disputed. Distinguishing the two determines whether to fight the chargeback.
What should a merchant do after detecting identity theft activity?
Block the transaction or freeze the affected account, notify the legitimate customer through verified contact channels, preserve evidence, and feed the identifiers back into screening so related attempts are caught. Victims can report at reportfraud.ftc.gov and identitytheft.gov.