What is AI-powered fraud?
AI-powered fraud is fraudulent activity that uses artificial intelligence to automate, scale or improve an attack. It can support traditional ecommerce fraud schemes as well as newer threats created by the rise of generative AI and autonomous agents.
How is AI-powered fraud different from traditional fraud?
Large fraud operations used to require teams with different specialties and significant manual trial and error. Today, AI can give individual fraudsters access to capabilities that once required more people, time and expertise.
AI-powered fraud often uses the same underlying schemes as traditional ecommerce fraud, but AI changes the way fraudsters can execute those attacks and can make them up to 4.5 times more profitable(opens in new tab).
The biggest differences between AI-powered and traditional fraud are:
- Efficiency: AI reduces the time, manual work and specialized expertise needed to execute sophisticated attacks.
- Scale: One operator can target more people, accounts and transactions at once.
- Quality: Generative AI can create more convincing messages, websites, images and documents.
- Iteration: AI lets fraudsters systematically test checkout limits, promotion rules, return policies and other controls, then refine tactics based on what works.
What are examples of AI-powered fraud in ecommerce?
AI can be applied to a wide range of ecommerce fraud schemes. Some of the most common and emerging examples include:
AI-powered phishing
AI-powered phishing uses artificial intelligence to create and scale convincing phishing content designed to steal credentials, payment information or other personal data.
How AI is used: Generative AI can produce thousands of personalized phishing emails, texts, voice messages or even deepfake videos far faster than a fraudster could create them manually.
AI-generated fake storefronts
AI-generated fake storefronts are fraudulent ecommerce sites created to impersonate legitimate retailers or pose as businesses that don’t actually exist.
How AI is used: To impersonate an existing retailer, fraudsters can use AI to recreate branding, product copy, page layouts and marketing content that closely resemble the legitimate site.
To create a new fake business, generative AI can quickly produce a brand identity, site copy, product descriptions, images, landing pages and supporting ads or messages. The copy-cat sites allow fraud rings to sell stolen goods via triangulation schemes and harvest payment credentials and personally identifiable information.
AI-powered account takeover
AI-powered account takeover (ATO) uses artificial intelligence to help fraudsters obtain, test or exploit credentials used to access legitimate customer accounts.
How AI is used: Fraudsters can use AI to create more convincing credential-stealing scams and analyze or test stolen credentials at scale. Once inside an account, they may target stored payment methods, gift cards, loyalty points or personal information.
AI-powered card testing
Card testing is a fraud technique used to determine which stolen payment credentials are successfully authorized before attempting larger fraudulent purchases — and AI is making it easier to run at scale. Signifyd found(opens in new tab) card-testing attacks increased 175% YoY during the first four months of 2026
How AI is used: AI and automation can help fraudsters test large batches of stolen cards, classify the results and quickly prioritize credentials that successfully authorize.
Return and refund fraud
Return and refund fraud occurs when a customer or bad actor makes a false or misleading claim to obtain a refund, replacement or other benefit from a merchant.
How AI is used: Generative AI can create or alter images, receipts and other evidence to make false claims appear legitimate, whether the claim comes from an individual customer performing first-party fraud (or “friendly fraud”) or an organized fraud operation. Similar tactics can also support types of chargeback fraud(opens in new tab) to make a false dispute appear more credible.
Agent / bot takeover
Bot takeover (BTO) occurs when a fraudster gains control of an AI agent that has been authorized to act on behalf of a legitimate customer.
How AI is used: A compromised agentic commerce shopping agent(opens in new tab) could use the customer’s delegated authority to make purchases, reroute orders to different addresses or take other actions in the customer’s name.
How can merchants identify AI-powered fraud?
Merchants usually cannot determine from a single signal whether fraud was created or executed with AI. Instead, fraud detection(opens in new tab) should focus on signs of manipulation and whether the identity, behavior and transaction are consistent with legitimate customer activity, whether human or automated.
When AI is used to generate or alter content, there may be clues in the content itself. Images or documents might contain visible watermarks, inconsistent details, unusual metadata or signs of digital manipulation. But those clues are not definitive: Watermarks can be absent or removed, metadata can be changed and increasingly realistic AI-generated content may have no obvious visual flaws.
For other forms of AI-powered fraud, the stronger signals often come from the activity surrounding the attack. That can include unusual account changes, high transaction velocity, unfamiliar devices, mismatched identity or payment information and connections among accounts, cards, devices or addresses associated with other suspicious activity.
How can ecommerce businesses prevent AI-powered fraud?
Preventing and protecting against AI-powered fraud schemes requires the same core controls used to stop other ecommerce fraud, but those controls need enough context to keep up with attacks that are faster, more scalable and more convincing.
It’s best to take a layered approach:
- Verify identity and payment information when risk is elevated, especially around login, account recovery and checkout.
- Create a unified view of each customer(opens in new tab) by connecting identity, account, device, payment and transaction history.
- Analyze behavior and velocity to catch unusual patterns across accounts, devices and transactions.
- Review suspicious orders using the full transaction context by connecting available order data(opens in new tab) rather than relying on one risk signal.
- Use machine learning alongside rules(opens in new tab) so detection is not limited to predefined fraud scenarios.
- Review post-purchase claims using multiple signals instead of relying on a single image, receipt or piece of evidence.
- Apply friction selectively so legitimate customers are not challenged unnecessarily.
- Work with a fraud protection provider that backs approved orders with a financial guarantee(opens in new tab) so if fraud does slip through, it doesn’t become a direct loss to your business.
AI may change the tools fraudsters use, but the fundamentals of ecommerce fraud prevention remain the same: Understand who you’re transacting with, evaluate behavior in context and adapt as new attack patterns emerge. Explore Signifyd’s Fraud 101 resources for practical guidance on ecommerce fraud detection and prevention.
FAQs
Is AI-powered fraud a new type of fraud?
No, not exactly. In many cases, AI is being layered onto familiar fraud tactics like payment fraud, account takeover, identity theft, phishing and chargeback abuse. What’s new is the level of automation and sophistication AI can add, from deepfake social engineering and synthetic identities to large-scale testing and decision-making.
Can AI also be used to prevent fraud?
Yes. AI and machine learning are widely used in fraud prevention to analyze risk in real time, identify suspicious patterns and help distinguish legitimate activity from fraud.
What does an AI-powered fraud detection tool do?
AI-powered fraud detection tools use machine learning to evaluate transactions in real time using signals like device data, behavior, velocity and historical outcomes.
Signifyd’s Commerce Protection Platform(opens in new tab), for example, also analyzes patterns across its Commerce Network of thousands of merchants to help identify fraud that may not be visible from a single merchant’s data alone. That gives merchants a clearer picture of what’s fraud vs. what’s a legitimate order, helping them stop more bad transactions without turning away good customers.