Fraud targeting merchant businesses is changing—not just in volume, but in how it presents itself. Many of today’s most damaging incidents don’t resemble cyberattacks or system breaches. Instead, they show up as everyday business activities, such as a new customer placing a large order, a phone call to the order desk, a payment that appears valid and clears successfully, and inventory shipped as scheduled—all seemingly routine events that can quietly conceal fraudulent activity.
By the time the problem surfaces, the damage is already done.
Across industries—including construction materials, lumber, fencing, and specialty supply—fraudsters are exploiting routine merchant workflows. They combine social engineering, card not present fraud, and operational pressure to move goods or redirect funds before red flags are noticed. Understanding how these schemes unfold is the first step to reducing exposure—without slowing down legitimate business.
How merchant fraud typically unfolds
Most merchant fraud doesn’t happen all at once. It progresses through a sequence that feels familiar to anyone running a business with inventory, payment acceptance, and customer fulfillment.
Fraudsters rely on normalcy—requests that don’t feel out of place, customers who don’t raise immediate suspicion, and payments that appear to process successfully. The risk emerges not from a single step, but from how these steps combine.
A typical sequence looks like this:
1. Initial contact A fraudster reaches out as a new customer, contractor, or vendor—by phone, email, or eCommerce.
2. A request that seems credible The order is large but plausible. The timing is urgent but reasonable. The customer sounds professional.
3. Payment manipulation Payment occurs without the card being physically present, or a payment change is requested. Multiple cards may be tried until one authorizes (enumeration).
4. Pressure to release inventory or process payment quickly Pickup, delivery, or payment processing is rushed to avoid scrutiny.
5. Loss realization Days later, the charge is disputed, the payment is reversed, or a check is returned—leaving the merchant with lost inventory, unrecoverable funds, and operational disruption.
At no point does the interaction feel overtly fraudulent.
The five fraud patterns hitting merchants hardest
1. Social engineering at the point of sale
Fraudsters increasingly rely on conversation rather than code. Social engineering schemes are designed to blend into normal sales and service interactions—especially in fast moving merchant environments where the staff is focused on fulfilling orders and helping customers.
Instead of exploiting technical vulnerabilities, criminals exploit trust, urgency, and routine behavior. This makes social engineering particularly effective at counters, call centers, order desks, and pickup locations.
Common signals include urgent requests, unfamiliar buyers placing large orders, and pressure to bypass standard steps “just this once.”
2. “New customer” large order fraud
One of the fastest growing patterns for middle market merchants involves fraudsters posing as legitimate new customers. These scams are especially common in project based industries where large, one time purchases are typical.
The order itself rarely looks suspicious. The risk comes from how payment is handled—often over the phone or through a card not present channel—and how quickly inventory is released once an authorization appears to succeed.
When the charge is later disputed, the merchant is left with both inventory loss and chargeback exposure.
3. Enumeration attacks (not just bots)
Card testing is often associated with automated online attacks, but merchants are increasingly seeing manual enumeration over the phone. Fraudsters test stolen card numbers verbally, relying on staff to continue attempting payment until a card is approved.
Because this happens through normal customer interactions, it can be difficult to distinguish from legitimate payment issues—until the chargeback arrives.
Enumeration increases operational strain and heightens down-stream risk with processors and card networks.
4. Vendor impersonation and payment redirection
Business Email Compromise hasn’t disappeared—it’s adapted to merchant environments. Fraudsters impersonate suppliers and request changes to payment instructions for inventory, materials, or equipment.
These requests often arrive at busy times, reference real invoices, and appear routine. If accepted, a single diverted payment can result in a significant loss tied to a normal accounts payable cycle.
5. In store fraud: checks, refunds, and skimming
Despite the shift toward digital payments, traditional fraud methods remain active—and increasingly sophisticated.
Merchants are seeing:
- Counterfeit or altered checks
- Refund abuse using manipulated receipts
- Skimming devices placed on lightly monitored terminals
- Internal misuse of access or permissions
These incidents often go unnoticed until reconciliation, when recovery options are limited.
What fraud looks like in practice
Fraud rarely announces itself.
A merchant receives a call from a new customer needing a large order for an upcoming project. The request sounds legitimate and time sensitive. Payment is taken over the phone. Several cards are declined before one is approved. The order is released for pickup. A week later, the transaction is disputed. The merchant loses the inventory and the payment.
This scenario is becoming increasingly common across industries that historically had little exposure to fraud.
Why merchants are being targeted now
Fraudsters are deliberately expanding into industries and business models where controls may be lighter or inconsistently applied.
Key drivers include:
- High value goods that can be resold quickly
- Increased use of card not present and phone based payments
- Inconsistent procedures across locations or shifts
- Pressure to move inventory quickly to meet customer expectations
In most cases, the issue isn’t a lack of effort—it’s a lack of visibility into how modern fraud actually works.
What high performing merchants do differently
Fraud prevention is not a single control — it’s an operating discipline.
Merchants that consistently reduce losses tend to:
- Apply the same payment and pickup rules across locations
- Train staff on fraud patterns, not just procedures
- Use dual controls for refunds, checks, and payment changes
- Reconcile transactions and exceptions daily
- Treat fraud awareness as part of operations, not IT
Final takeaway
Merchant fraud in 2026 doesn’t look like a breach. It looks like business as usual—until it isn’t.
Organizations that understand how fraud blends into everyday operations—and empower staff with practical, consistent guidance—are far better positioned to protect inventory, cash flow, and customer relationships.
How to safely turn down suspect fraud (without harming customer experience)
Reducing fraud losses doesn’t require being overly restrictive. It requires slowing down the right transactions.
High performing merchants apply consistent, defensible practices that protect the business while maintaining service quality:
- Pause on urgency Fraud relies on speed. Legitimate customers can typically accommodate reasonable verification.
- Know your customer Treat large, first time orders differently from established relationships.
- Limit phone based card payments for large purchases Especially when inventory release is immediate.
- Apply stronger authentication for unfamiliar orders Use modern, risk based checkout authentication tools for online transactions.
- Delay inventory release when patterns don’t align Authorization alone doesn’t guarantee legitimacy.
- Standardize escalation paths Give staff clear guidance on when and how to raise concerns.
- Avoid acting as an intermediary in payment transactions Do not forward or transfer funds to another business on behalf of a customer or cardholder within a payment transaction.
These steps protect inventory, reduce chargebacks, and create consistency across locations.