A clear-eyed look at why well-funded fraud programs still leak revenue, and what the current data says separates the merchants and fraud prevention software who get it right.
Most ecommerce businesses that struggle with fraud prevention software aren’t struggling because they lack tools. They’re struggling because the tools answer the wrong question. Traditional fraud prevention software asks “is this transaction risky?” when the losses that actually move the P&L now come from somewhere else: good customers blocked at checkout, abuse that happens after the payment clears, and review queues that consume analyst hours faster than they return value.
The short answer, for anyone who wants it up front: ecommerce businesses struggle with fraud prevention software for five connected reasons. The software optimizes for blocking fraud rather than recognizing customer intent, so it declines legitimate orders alongside bad ones. Fraud has shifted post-purchase into returns, claims, and disputes, where transaction-level tools can’t see. Point solutions have multiplied into fragmented stacks with gaps between them. Manual review persists as a hidden cost center. And static rules age out quietly while fraud tactics evolve in the open.
Each of those problems is measurable, and each has a fix. This post walks through the data behind all five.
Why Fraud Prevention Software Falls Short of Its Promise
The core design assumption behind most fraud prevention software is that risk lives in the transaction. Score the order, set a threshold, block what scores badly. That model worked reasonably well when fraud meant stolen credit cards used at checkout.
It works far less well now, because the assumption no longer holds. The Merchant Risk Council’s 2026 Global eCommerce Payments and Fraud Report names refund and policy abuse, not payment fraud, the number one fraud threat across ecommerce. 64% of merchants report rising first-party misuse, meaning disputes and claims filed by real customers against their own legitimate purchases. A transaction score can’t catch a customer who pays with their own card, receives the product, and then files a false “item not received” claim. There was never a risky transaction to block.
That mismatch between what the software watches and where the losses happen is the struggle, condensed to a sentence. The rest of this post unpacks how it shows up.
The False Decline Problem: Blocking Isn’t the Same as Deciding
When software is tuned to block fraud, the easiest way to hit the target is to decline more orders. The cost of that instinct lands on legitimate customers.
According to PYMNTS Intelligence’s 2026 fraud prevention research, nearly half of merchants estimate that up to 5% of legitimate orders are incorrectly declined as fraudulent, an estimated $50 billion in lost revenue industrywide. The same research found 85% of merchants say their top fraud challenge is preventing fraud without degrading the customer experience.
The arithmetic on a false decline is worse than it looks. The merchant loses the order, the marketing spend that produced it, and often the customer relationship, since a shopper declined at checkout rarely tries twice. A first order declined in error is a lifetime value written off at the moment it was created.
This is where the distinction between blocking and deciding matters. A system built to recognize intent asks a different question: not “does this order match a risk pattern?” but “does the evidence suggest a real customer trying to buy?” Two orders can carry the same surface risk score, a mismatched billing address, a brand new account, an unusually large basket, and deserve opposite decisions once intent signals are weighed. Software that can’t make that distinction will keep converting good customers into lost revenue.
Fraud Moved Post-Purchase, and Most Software Didn’t Follow
The growth categories in ecommerce fraud now sit after the payment, not at it. Juniper Research projects global ecommerce fraud losses will rise from $56 billion in 2025 to $131 billion by 2030, a 133% increase, and names rising friendly fraud, where the customer themselves disputes a legitimate charge or abuses a refund policy, as a primary driver.
The MRC data tells the same story from the merchant side: refund and policy abuse displaced payment fraud at the top of the threat list, and more than one in four merchants report first-party misuse growing by 25% or more.
Fraud prevention software scoped to the checkout moment is structurally blind to all of it. Wardrobing, serial returns, empty box claims, promo code exploitation across alias accounts, support channel manipulation: none of these produce a transaction to decline. Catching them requires connected signal across the journey, noticing that an account’s return pattern, claim history, or dispute behavior doesn’t fit a real customer, and acting on that pattern before it becomes a write-off or a chargeback.
Too Many Tools, Not Enough Signal
The instinctive response to new fraud types has been to buy new tools, and the result is fragmentation. The PYMNTS research describes merchants managing five or more payment integrations alongside multiple fraud vendors, each with its own risk signals and blind spots. Fraudsters exploit the seams: the returns tool doesn’t know what the payment tool saw, the support desk can’t see either, and an abuser who fails at one surface simply moves to the next.
Fragmentation also has a quieter cost. Every additional dashboard is another place a signal can die unread. Risk intelligence that doesn’t reach the person making the decision, the CX agent processing the refund, the ops lead setting the return policy, the analyst clearing the queue, isn’t intelligence yet. It’s data.
The Manual Review Trap
The gap between what the software decides and what it merely flags gets filled by people. LexisNexis Risk Solutions’ 2025 True Cost of Fraud Study found 41% of North American merchants still depend on manual processes to prevent fraud, and that every $1 of direct fraud loss costs US merchants $4.61 once labor, investigation, and downstream costs are counted.
Manual review isn’t inherently the problem. Human judgment on genuinely ambiguous orders is one of the highest-value activities in a fraud program. The trap is what most software does with it: flagging high volumes of routine orders into a queue where expensive analyst time clears cases a well-tuned model should have decided in milliseconds, while the genuinely ambiguous cases wait behind them. The review queue becomes a tax on every order instead of a scalpel for the hard ones.
What the Merchants Getting It Right Do Differently
The same industry data that documents the struggle also shows it isn’t universal. The MRC report found average fraud rates by order fell from 3.4% to 3.0% in 2025 among surveyed merchants, evidence that well-deployed, well-tuned programs are pulling ahead. The common threads:
- They evaluate intent, not just risk. Decisions weigh the evidence that a real customer is trying to buy, which protects approval rates while still catching bad actors.
- They watch the whole journey. Checkout, returns, claims, support interactions, and chargebacks feed one connected picture, so post-purchase abuse patterns surface early.
- They consolidate signal instead of stacking tools. Fewer seams for abuse to slip through, and one decisioning layer instead of five dashboards.
- They spend human judgment where it pays. Analysts review the ambiguous minority; the model decides the routine majority in real time.
- They tune to their own business. A generic score trained on someone else’s order patterns makes someone else’s decisions. Merchant-specific context is what makes borderline calls accurate.
How Wyllo Helps
Wyllo, the risk intelligence platform for commerce, was built around the gaps this post describes: intent-aware decisioning instead of blunt blocking, connected signal across the full customer journey instead of a checkout-only view, and human fraud experts applied where context genuinely matters.
- Wyllo Payment Fraud Protection pairs AI-driven decisioning with expert analysts to approve more legitimate orders while catching payment fraud, directly addressing the false decline problem.
- Wyllo Return Fraud and Abuse Prevention catches wardrobing, serial returns, and false claims that transaction-level tools never see.
- Wyllo Claim and Policy Abuse Prevention identifies friendly fraud and policy exploitation before it becomes a chargeback.
- Wyllo CX Support delivers risk scores and next-best actions inside the tools CX teams already use, so intelligence reaches the decision instead of dying in a dashboard.
Judgment over rules. Precision over paranoia.
Frequently Asked Questions
Why do ecommerce businesses struggle with fraud prevention software?
Because most fraud prevention software optimizes for blocking risky transactions rather than recognizing customer intent, which produces false declines on legitimate orders; because fraud has shifted post-purchase into returns, claims, and friendly fraud where transaction-level tools can’t see; and because fragmented tool stacks and heavy manual review add cost without adding accuracy. MRC’s 2026 report now ranks refund and policy abuse, not payment fraud, as the top ecommerce threat.
How much do false declines cost ecommerce merchants?
PYMNTS Intelligence research from 2026 found nearly half of merchants estimate up to 5% of legitimate orders are wrongly declined as fraudulent, representing an estimated $50 billion in lost revenue industrywide. The full cost is higher than the lost order alone, since declined customers rarely return and the acquisition spend that produced the order is written off with it.
What is friendly fraud and why is it hard to stop?
Friendly fraud occurs when a real customer disputes a legitimate charge or abuses a refund or claims policy, for example filing a false “item not received” claim after delivery. It’s hard to stop because there is no fraudulent transaction to decline: the payment was genuine. Catching it requires journey-level signal, patterns in an account’s return, claim, and dispute history, rather than a checkout risk score. Juniper Research names rising friendly fraud a primary driver of ecommerce fraud growth through 2030.
Is manual review of orders still necessary?
Yes, but narrowly. Human judgment is valuable on genuinely ambiguous orders where merchant-specific context matters. The problem is over-reliance: LexisNexis Risk Solutions’ 2025 study found 41% of North American merchants still depend on manual processes, which drives the true cost of fraud to $4.61 for every $1 of direct loss in the US. The strongest programs let models decide the routine majority in real time and reserve analysts for the hard cases.
What should merchants look for instead of traditional fraud prevention software?
Look for intent-aware decisioning that evaluates whether a real customer is trying to buy, not just whether an order matches a risk pattern; connected signal across checkout, returns, claims, support, and chargebacks; consolidation into one decisioning layer rather than a stack of point tools; human expert review reserved for ambiguous cases; and tuning to your specific business rather than a generic score. Together those capabilities describe risk intelligence rather than transaction screening.
Bringing It Together
The struggle with fraud prevention software isn’t a tooling failure so much as a framing failure. Software built to block risky transactions is answering a question ecommerce stopped asking. The losses that matter now come from good customers turned away, from abuse that begins after the payment clears, and from operational drag across fragmented tools and swollen review queues. The merchants pulling ahead, and the industry data shows a widening gap, are the ones who reframed the job: understand the intent behind every interaction, across the whole journey, and decide accordingly.
That shift is already underway. Refund and policy abuse now tops the industry threat list, friendly fraud is projected to drive losses through the decade, and the balance between fraud catch and customer experience has become the defining challenge for 85% of merchants. The question for any brand evaluating its stack is whether the software can see what’s actually costing money.
Curious how intent-aware decisioning would change the math on your approval rates and post-purchase losses? Start with Wyllo Payment Fraud Protection for the AI-plus-human-experts model, or explore the broader Wyllo platform for connected intelligence across the full customer journey.