Agilence Blog - Loss Prevention for Retail, Restaurant, and Grocery

Ecommerce Return Fraud and the Omnichannel Gap: Why Real-Time Alerts Only Catch Half the Problem

Written by Agilence Staff | Aug 4, 2026, 4:29:46 PM

A woman comes in store to return an online purchase; the receipt matches, tags are attached, and it is inside the return window. Your system approves it in seconds because it appears legitimate but it is her fourteenth return this quarter across 6 of your stores, and she is careful to keep every one of them clean to fly under the radar.

Your system did its job, but it was asked whether one transaction looked wrong rather than looking at her overall return trends and patterns.

Eighty-five percent of retailers now use AI to detect return fraud, according to the National Retail Federation, but only 45 percent believe it works. Against $849.9 billion in returns last year with 9 percent of those returns known to be fraudulent, that gap can be expensive.

Real-time monitoring catches the obvious and stops there

A real-time engine evaluates one return, at one location, in one moment, and it does that well. It stops the empty box and the reattached tags, takes the confrontation off your associates, and applies policy the same way in every store.

But it is scoped to a single transaction and that scope is the biggest limitation.

Here is what it cannot tell you:

  • Cross-channel history - Whether the person returning in-store has an open concern on the e-commerce side, or the reverse.
  • Cumulative velocity - How many returns this customer has made across every location and every channel over weeks or months.
  • Linked identities - Returns filed under different names that share an address, a phone number, or a payment instrument.
  • Employee association - Which associates are present for outsized shares of no-receipt refunds, overrides, and manual adjustments.
  • Item-level movement - Whether a single SKU is coming back at an abnormal rate, and where.
  • Location comparison - How one store or district performs against the rest of the chain on returns and refunds.
  • Refund tender patterns - Where the money actually went, including store credit and gift card issuance.

None of those signals exist inside a single transaction but rather they exist across multiple transactions and channels. Return fraud is a question about a pattern of abuse rather than about a single transaction.

The channel handoff is where the data breaks

Most retailers cannot see these patterns because their systems were never built to. Research from the ECR Retail Loss Group found retailers stuck partway through the move from multichannel to omnichannel, running store and online operations on platforms designed for one channel and forced to cover both. A returns director in that study put it plainly: the systems were built as a single channel and made to work across channels afterward.

The consequences show up in the data itself. The same research found that most retailers carried meaningful volumes of transactions where the sale, the return, and the refund could not be reconciled against one another. Worse were what finance teams called unallocated returns, where an item comes back with no order, no reason, and no customer identity attached.

Patterns need more than one level of view

Store reporting shows store performance. Ecommerce reporting shows ecommerce performance. Cross-channel behavior falls into the space between them, which is exactly where it is designed to sit. Closing that gap means pivoting the same return data across every level where a pattern can hide:

Level

What it surfaces

Customer

Repeat returners operating just inside policy, cross-channel return chains

Item

Return spikes tied to a specific product, promotion, or fulfillment path

Employee

Associates present for outsized shares of no-receipt refunds and overrides

Store

Locations absorbing disproportionate online returns, or applying policy loosely

District

Activity moving between locations to stay under any one store's radar

Together those views turn an undifferentiated flood of daily returns into a ranked list of where to look first.

What closing the gap looks like in practice

DSW covers more than 500 stores across the US and Canada with only a seven-person Asset Protection team. That ratio explains why pattern visibility is not a nice-to-have, but a necessity.

Using Agilence Analytics, DSW's team surfaced a return fraud scheme that no transaction-level check would ever have flagged. Associates with override capability were reprocessing returns to themselves, switching the return tender to their own personal cards and tapping phones and smartwatches to move fast without attracting attention. Every one of those returns was individually valid from the system’s point of view. The pattern was the crime.

What changed was how fast they saw it. Karen Walls, DSW's Manager of Investigations and AP Systems, described the first weeks on the platform as finding "a leaky bucket" of opportunity across the business. Before Agilence, that kind of activity could run three to five months before the team caught up to it. Now they catch it inside a few weeks. Fraudulent return activity dropped, partly from faster resolution and partly because stores knew the transactions were being watched.

 

Agilence Analytics with the Ecommerce Module pulls store transaction data and ecommerce transaction data into the same environment, which means a return does not become invisible when it crosses a channel boundary. A buy online, return in store transaction is legible as a single connected event rather than two disconnected records in two systems.

From there, you [AB1] can move from a chain-level view down to a single customer, item, employee, store, or district without leaving the data or waiting on a report request. When the same customer identity keeps appearing behind refunds in three states, that surfaces as one finding rather than three unrelated ones.

The other half of the work is tuning. Fraud and abuse behavior shifts, sometimes within a single quarter, and a threshold that was correct in February will generate noise by August. Agilence exception thresholds are adjustable on an ongoing basis, so the definition of what counts as an exception keeps pace with what your organization is actually seeing rather than being frozen at implementation.

If you are running real time monitoring on your returns today and still cannot answer who your top twenty repeat returners are across channels, that gap is worth a conversation. Our team can walk through how Agilence customers are using cross-channel return data to build those lists.

 

Read the full DSW case study, or talk to our team about what your own return data would surface in its first month.