Online Fraud Becomes Physical Theft Feature

How Online Fraud Becomes Physical Theft

A $50 BOPIS order for office supplies comes through. The card clears. Nobody at the pickup counter has a reason to look twice. That’s the point. The order was never really about the $50, it was a test of whether the counter would release merchandise without asking the question that mattered.

Once that test passes, the same crew moves to laptops, electronics, gift cards. The credential that placed the first order was stolen the same way the second and third were. The only thing that changed was the dollar amount the store was willing to hand over without friction.

What’s Actually Happening: BOPIS Closed One Gap and Opened Another

Buy Online, Pick Up In-Store solved a real retail problem: shipping cost, fulfillment speed, and the friction of waiting for a package. It also removed the one verification step traditional card-not-present fraud always had to get past, a shipping address that could be checked against the cardholder’s actual location.

Fraud teams already know the resulting numbers. BOPIS transactions show fraud roughly 7% of the time, a rate 2.4 points higher than other purchase methods, and BOPIS volume grew more than 500% during the pandemic and never fully receded. What’s less discussed is why the fraud rate stays elevated even after retailers added ID checks and card verification at pickup: those controls are applied inconsistently, and inconsistency is exactly what a low-value test order is designed to locate.

What the Losses Actually Look Like

This isn’t a marginal cost. Over a quarter of retailers surveyed report BOPIS-related losses between 3% and 10% of revenue, and 40.4% say BOPIS has measurably increased their fraud exposure. When a stolen credential funds the pickup, the cardholder eventually disputes the charge, leaving the retailer holding both the chargeback and an empty inventory line.

Some of the schemes are more elaborate than a straightforward pickup. A fraudulent BOPIS order gets placed, then the buyer races to a nearby store to return it for a gift card or cash refund before anyone reconciles the original transaction. It’s the same return-fraud playbook retailers have dealt with for years, now running through an e-commerce front end that gives it a head start.

The Actual Ops Gap: Nobody Owns the Handoff

Fraud prevention teams see the transaction. Loss prevention teams see the exit. Between those two vantage points sits the pickup counter, and it’s frequently staffed by whoever is on shift, not by someone trained to evaluate a flagged order.

Picture a new employee at that counter. A customer insists, with some edge in their voice, that the order is theirs. There’s no visible flag, no clear escalation path, and no confidence that a manager will back a hard “no” if the employee pushes back. Most employees release the order. That isn’t a training failure so much as a structural one: a system that generates a fraud signal upstream but gives the person facing the customer no way to see it.

Retailers are genuinely caught between two costs here. Harder verification at pickup risks frustrating the large majority of legitimate BOPIS customers who make the channel worth having in the first place. Looser verification hands the exploit to whoever tests it first. Neither side of that tradeoff gets easier without connecting the data both teams already have.

Why the Test Order Keeps Working

Organized retail crime groups didn’t invent this gap, they found it. Proxy pickup policies, partial ID matching, and orders that continue processing even after a cancellation request are documented soft points, not secrets. A crew tests a $50 order against a specific store’s actual practice, not its written policy, then scales up once the practice proves permissive.

The reason this keeps working isn’t a lack of data. Fraud systems flag the transaction. LP systems log the exit. The gap is that no one owns the space between those two records, so a coordinated test looks, to each team individually, like an isolated low-value incident rather than the first step of a pattern.

What Closing the Gap Actually Requires

Closing this isn’t primarily a technology purchase, it’s a decision about where fraud alerts go after they fire. An alert that stays in a fraud dashboard the store team never opens has no operational value at the pickup counter. It needs to reach the person standing at that counter, with enough context to justify a hold, before the merchandise leaves.

This is where a unified investigative environment earns its place. Hubstream is built to bring fraud, cyber, and LP signals into one case rather than three separate systems, then use link analysis to surface the overlaps: a proxy pickup pattern, a repeat address across supposedly unrelated orders, a name that keeps recurring across stores. Escalation can then move automatically, prompting a hold or an ID check before release rather than after a chargeback has already been filed.

Dynamic friction, applying scrutiny in proportion to actual risk rather than uniformly, lets that happen without turning every legitimate customer’s pickup into an interrogation. Most orders clear without incident. The ones that resemble a known pattern get a speed bump instead of a free pass.

Questions Worth Asking About Your Own Program

Who, specifically, is accountable for the space between a fraud alert firing and a pickup being released, is it fraud, is it LP, or does it belong to neither team today? If a pickup-counter employee faced the scenario above tomorrow, would they have any system-level signal to act on, or only their own judgment against an insistent customer? And when your team reviews a low-value BOPIS order that looked like a test, does anything connect it to the next, higher-value order from the same pattern, or does each one get evaluated on its own?

The Convergence Question That Matters More Than the Channel

BOPIS isn’t the vulnerability. The vulnerability is the assumption that online fraud and in-store loss are two different problems being handled by two different teams that rarely compare notes. As long as that assumption holds, a low-value test order will keep doing exactly what it’s designed to do: find the seam between two systems and walk a bag of merchandise through it.

The next question worth asking isn’t whether your defenses caught last month’s fraud. It’s whether they would have recognized it as a test, before the crew moved on to something worth more.

See it in action.

Request Demo