Fraud Temperature Gauge: August 2026

Merchants are talking about agentic AI in commerce, but they’re not the only ones. Fraudsters are already planning for the day when consumers start using and expecting agentic transactions… and merchants aren’t yet protected from agent-enabled fraud. 

The criminal excitement is so great that they’re calling it a “golden age” for fraud.

The Fraud Temperature Gauge is tracking the month by month evolution of ecommerce fraud trends, drawing on and adding more context to the constantly updating data from https://intelligence.forter.com/

August’s data shows that fraud attacks are continuing to increase, carried out by a growing number of fraud rings. 

Identities are under pressure. Sophisticated Account Takeover (ATO), which would once have required real technical expertise and an investment of time and resources, is rising. Reputation takeover is easier than it has ever been, with AI able to piece a profile together out of open source information and add convincing details as necessary. 

Fraudsters have a greater level of automation at their fingertips than could have been imagined three years ago. Every quarter they dig a little deeper into what that means for fraud.

August’s data shows that fraud attacks are continuing to increase, carried out by a growing number of fraud rings. 

Identities are under pressure. Sophisticated Account Takeover (ATO), which would once have required real technical expertise and an investment of time and resources, is rising. Reputation takeover is easier than it has ever been, with AI able to piece a profile together out of open source information and add convincing details as necessary. 

Fraudsters have a greater level of automation at their fingertips than could have been imagined three years ago. Every quarter they dig a little deeper into what that means for fraud.

2.4 million attacks in August, 84% of which were perpetuated by coordinated fraud rings

According to a report from the World Economic Forum, cyber-enabled fraud and phishing are the ecommerce fraud trends most concerning to CEOs this year, followed by AI vulnerabilities. The growth of attacks is an important data point for fraud leaders providing context for leadership on why investment in fraud prevention is vital today. 

3.3K large, coordinated fraud rings detected across the network

This clear pattern demonstrates the importance of connecting the dots to identify returning fraud rings. Doing that effectively means pattern-matching attackers on your own site, and working as part of a network of other sites so that a ring that’s attacked any network member can be identified by all the other members as well.

Desktop interactions carry 54% of detected fraud, despite lower traffic

Mobile accounts for well over half of traffic. However, it’s powerfully protected by in-built biometric authentication, which makes ecommerce fraud trends more difficult to perpetuate. Make sure you’re measuring channels by fraud attacks, not just traffic, and allocating resources accordingly.

12% rise in sophisticated ATO patterns

Package rerouting used to involve quite a bit of manual effort, like setting up accounts with carriers in the victim’s name, and tricking customer support agents into changing addresses for package delivery. With AI, fraudsters can effortlessly expand their attack surface area. ATO detection needs to draw on as many data points and as much context as checkout protection.

18% year-over-year increase in reputation takeover

AI agents can find an abundance of open-source information about real people, and piece it together to create detailed profiles. That makes it easy for fraudsters to adopt an identity convincingly. Merchants must have a detailed, rich understanding of real users on their sites, and an ability to distinguish real people and fraudsters pretending to be them. 

Airline accounts that are part of loyalty programs have a stored value that make them attractive to fraudsters. They’re 3.5x more likely to be targeted, according to Arkose Labs.

Fraudsters use automated credential stuffing tools like OpenBullet, SilverBullet, or Sentry MBA, loaded with custom configuration scripts (“configs”) tailored to a specific brand’s login API. When a valid login occurs, these tools execute data scraping directives and telemetry directly from the HTTP response payload. The fraudsters then sort the results by points, so accounts with high point balances or elite tiers are prioritized for immediate redemption or premium resale, while zero-balance accounts are discarded or sold in bulk batches.

If your company offers a loyalty program, it’s worth building in extra protections for those accounts. You have more information than average about that user and their typical behavior, because they’re a loyal customer. Make sure your systems check whether a new login, or new attempted action, reflects known and expected behaviors. 

Beauty merchants have seen a ~25% YoY increase in return abuse and return fraud. These ecommerce fraud trends are growing in large part because of AI-altered images used to manipulate return and refund flows.

Merchants must take return abuse into account when measuring a customer’s lifetime value, and personalize their experience accordingly. Some customers may be told at checkout that they don’t get the privilege of returns. Others may be restricted only at certain times of the year, or when buying particular products.

Food delivery customers are also increasingly treat cheating as part of the ordinary ordering process. They use the same AI tactics to alter images of their delivery so they can get their refund and eat their cake, too. 

Fraud Ring Deep Dive: Chrome Soles

Every month there’s a fraud ring that encapsulates key trends we’re seeing across multiple rings and bad actors. This month, it’s the Chrome Soles: a North American fraud ring that launched a coordinated attack against footwear merchants. Given the focus on kids’ shoes, we hypothesize a connection to back to school shopping, which occurs during the period in which the ring was most active.

Rather than racing through the site, Chrome Soles used bots designed to mimic human browsing behavior with slow- and medium-paced browsing patterns, exploiting guest checkout. The fraud ring leveraged proxy routing. IP activity was concentrated in two metro areas — one in the Northeastern U.S. and one in Canada — but 54% of shipments were directed to California.

The stats:

  • 333 transactions
  • 5 attack attempts per minute, at the peak 
  • $71,561.71 attempted (and blocked)

The Chrome Soles didn’t show the signals of an experienced group. They used 0-day accounts and 88% used standard shipping, pointing to coordinated account creation backed by automated infrastructure. Their consistency with Microsoft’s OS and the Chrome browser made it easy to spot the pattern. Their proxies were easy to pierce, with no attempt made to cover the mismatch between shipping and billing.

Get real-time fraud data

This month’s ecommerce fraud trends are a snapshot. The fraud landscape moves faster than any monthly recap can capture. For a real-time view of attacks blocked, ATO patterns, and fraud trends across industries and regions, explore Forter’s Fraud & Abuse dashboard.

You can filter by vertical or region to see what’s happening right now, and sign up for reports and alerts to stay ahead of the next Chrome Soles before it hits your site.