What is refund fraud?
Refund fraud is a widespread and increasingly sophisticated form of cybercrime where threat actors manipulate return policies to obtain illegitimate refunds, replacements, or store credits. While the direct impact is felt by retailers, the ripple effects extend across supply chains, logistics partners, and B2B enterprises, leading to inventory distortion, revenue loss, and reputational damage.
This type of fraud is particularly challenging to detect because it often mimics legitimate consumer behavior, making it ideal for low-risk, high-reward exploitation. In some cases, organized cybercriminal groups scale these attacks using bots, fake identities, and compromised accounts to operate across multiple retail platforms undetected.
How does refund fraud happen?
Refund fraud has a simple set of Tactics, Techniques, and Procedures (TTPs) that allow the attacker to earn a nice payout.
Receipt fraud
Cybercriminals generate or alter receipts using stolen data, phishing kits, or dark web templates. These fake receipts are used to return goods that were never purchased. This is often facilitated through social engineering or insider collusion.
Wardrobing
A form of "friendly fraud" where individuals purchase items (e.g., clothing, electronics) with the intent to use them temporarily and return them. This abuse thrives under lenient return windows and no-questions-asked refund policies.
Switch fraud
In this scheme, a fraudster buys a new product, removes it from its packaging, and replaces it with a used or defective version—returning the swapped item as if it were new. This tactic is common with electronics and small appliances.
Return abuse
Fraudsters exploit generous or poorly enforced return policies by repeatedly returning items, often using multiple identities or retail locations. Automation and synthetic identities have made it easier to scale this tactic across online and physical stores.
Examples of refund and return scams
Kohl’s Cash Refund Exploit
- A scammer exploited Kohl’s loyalty system (“Kohl’s Cash”) across multiple stores, repeatedly returning items purchased with coupons or bonuses to gain store credit or cash.
- Total losses reportedly reached $200,000.
- So what? Loyalty and store credit systems are increasingly targeted, often with automated or serial fraud tactics.
Airline Refund Scam via Forged Documents (India)
- A fake travel agency booked real flights for clients, then canceled them using fraudulent death or medical certificates to claim refunds from airlines.
- The fraudster pocketed most or all of the refund while the customer was left stranded or misled.
- So what? Return fraud is not limited to goods — services like travel or events are highly vulnerable to document-based deception.
Social Engineering + “Over-Refund” Scam (USA)
- A victim was tricked by a fake Norton antivirus email claiming she had been overcharged. When she called the listed number, the scammer “mistakenly” refunded her $49,500 and pressured her to return it in cash.
- She made multiple payments before realizing it was a scam.
- So what? Refund scams can include psychological manipulation and money laundering, not just product returns. These are hard to detect without user awareness or transaction analysis.
Amazon Insider Refund Fraud (USA)
- A fraud ring involving former Amazon employees orchestrated a scheme where customers received both the products and fraudulent refunds.
- The ringleader and accomplices were ordered to repay $2.4 million in damages.
- So what? Insider threats are real and can bypass even well-controlled systems when refund permissions aren’t tightly monitored.
Refund fraud & Retailers
On the cyber underground, threat actors seek to profit fraudulently from the e-commerce boom. In particular, this refunding tactic is growing in popularity. The underground discourse of threat actors peddling their refunding services and threat actors refunding exchanging tips and best practices reveals that certain e-commerce vendors more frequently attract the attention of threat actors. Recently, Amazon attracted the most threat actor attention, followed by Apple, Target, and eBay. This attention inevitably relates to the size and popularity of these retailers, but a study of underground refunding manuals reveals that social engineers are acutely attuned to the unique weaknesses and protocols of different retailers, sharing advice on which retailers to target by which methods - and for how much.
4 Common refunding methods
Generally, most refund scams use social engineering. The underground is rife with guides and manuals on refunding methods and social engineering techniques - some for sale, but many published freely and often anonymously. This section briefly overviews threat actors' most common methods and lays them out in their "how to" guides.
1. “Did Not Arrive”/”DNA”
The simplest refund fraud method involves claiming that the package has not arrived. Underground manuals suggest that customer support will likely press you on whether “you checked with your neighbors/garage/porch,” but that after enough strenuous denial, they will offer you a replacement or refund. An anonymous guide (figure 1) recommends that if the customer service representative says they want to launch an investigation with the courier service, simply hang up and try again.
2. “Empty Box”
This method claims that the shipment arrived empty. The leading vendor that suffers from this refund scam is Apple due to the high value of their items in price. For example, a successful return fraud for a new laptop could net $3,200. Moreover, this method works much better when reporting on small items such as apple’s AirPods, iPhones, etc. In one example, a threat actor shares a guide for refunding Apple in different countries using the ‘empty box’ method.
3. “Wrong Item Arrived”/"Wrong Item In the Box"
Here, the social engineer claims the retailer has sent the incorrect item, then returns a similar, but much cheaper, object that the retailer stocks in their inventory. Social engineering guides emphasize the psychological components of pulling off this method. According to the actor, it doesn't matter who the company is, as they all have a warehouse with an inventory of stock ready to be picked, packaged, and dispatched to their customers. As such, human error is inevitable when picking & packing an order. Thus threat actors can use social engineering for just about any item they like.
4. “Boxing”
This method entails contacting the retailer’s customer support to claim an item is defective, returning the box without the purchased item, and claiming the item got stolen during delivery. Since packages are weighed during shipment, social engineers generally place dry ice of equivalent weight, then tamper with the box to give the impression that the container had been tampered with during transit.
In addition to these guides, threat actors also share their experiences in refunding different retailers, which shed light on what to expect and how to succeed. In one example, an actor sells refunding guides for various retailers such as Best Buy, Amazon, and Sephora, at prices ranging from $600 to $3,000.
How to protect your business
1. Threat intelligence on fraud markets
Bitsight’s Threat Intelligence capabilities include robust deep and dark web monitoring, enabling visibility into online marketplaces and fraud communities where refund scams are openly discussed, bought, and sold. Analysts can uncover emerging TTPs (Tactics, Techniques, and Procedures), such as "box swap" schemes or refund-as-a-service operations, and track threat actor chatter to identify trends or campaigns targeting specific retailers or industries.
2. Actor and botnet attribution
Bitsight delivers on-demand threat actor profiles and supports ongoing tracking of known fraud groups. By correlating refund scam activity with identified actors or automation frameworks (e.g., bots exploiting return APIs), organizations gain vital context to understand who is behind the fraud, what tools they're using, and how widespread the campaign is. This helps prioritize response and enhances fraud detection rules.
3. Brand and retailer monitoring
With Brand Intelligence and Takedown Services, Bitsight monitors for impersonation of your company’s brand or abuse of its return systems across both surface and underground sources. Whether it’s phishing pages mimicking return portals or leaked return label templates, Bitsight helps quickly identify and remove these risks before they result in fraud or customer trust erosion.
4. Supply chain risk management
Refund fraud often targets weaknesses in fulfillment, logistics, or third-party vendor return policies. Bitsight provides supply chain cyber risk visibility, allowing you to identify partners with weak controls or exposure to abuse. This proactive approach helps you secure your extended retail and logistics ecosystem and prevents fraudulent returns from slipping through the cracks via trusted partners.