Threat Report: Refund Fraud-as-a-Service

20/09/22

Article Contents

    Refund fraud is becoming increasingly detrimental to eCommerce stores. Last December, a man pleaded guilty to defrauding a retailer for more than $300,000 by performing refund fraud over the course of three years.

    With cybercrime’s continued shift to a service-driven economy, interested parties can outsource the process of refund fraud to groups of professional social engineers offering Refund-as-a-Service. This poses a significant challenge to retailers, as previously legitimate customers can enlist highly experienced fraudsters to perpetrate this fraud on their behalf, making it difficult to identify fraudulent activity.

    Our team of threat researchers have used cyber threat intelligence techniques to infiltrate deep into the rapidly maturing Refund-as-a-Service ecosystem.

    In this report, you’ll learn:

    • The current structure of the underground Refund-as-a-Service market
    • The changing tactics and methods used by adversarial groups to perform refund fraud
    • How threat intelligence and fraud teams can work collaboratively to effectively combat refund fraud

    Block Bots Effortlessly with Netacea

    Book a demo and see how Netacea autonomously prevents sophisticated automated attacks.
    Book

    Related Research & Reports

    28/05/26

    Agent Trust Management: The Business Case

    Research & Reports
    Research & Reports
    28/05/26
    This executive briefing sets out seven reasons the C-suite should act now on agent trust management, covering revenue capture, fraud reduction, competitive protection, data integrity, and regulatory compliance. It introduces the Netacea Agent Trust framework and the emerging standards (Visa TAP, Google AP2) already in production. Built for CISOs, CTOs, digital commerce leads, and fraud and risk stakeholders.
    22/05/26

    The Governance Gap – Why Your Platform Policies Were Not Written for AI Agents

    Research & Reports
    Research & Reports
    22/05/26
    This executive briefing sets out where the governance gap sits, why the distinction between beneficial and extractive automation matters commercially, and what a deliberate response looks like. It covers the emerging standards (Visa TAP, Google AP2, MCP) and introduces the Agent Trust governance layer.
    26/03/26

    The Rise of the Agentic Internet: What Every CISO Needs to Know About Governing Non-Human Web Traffic

    Research & Reports
    Research & Reports
    26/03/26
    What Every CISO Needs to Know About Governing Non-Human Web Traffic. This ebook introduces the Agentic Traffic Composition Model, a practical framework for classifying the machine actors hitting your platform and making governance decisions based on economic impact, not guesswork.

    Block Bots Effortlessly with Netacea

    Demo Netacea and see how our bot protection software autonomously prevents the most sophisticated and dynamic automated attacks across websites, apps and APIs.
    • Agentless, self managing spots up to 33x more threats
    • Automated, trusted defensive AI. Real-time detection and response
    • Invisible to attackers. Operates at the edge, deters persistent threats

    Book a Demo