Fraud reporting figures released this month show a sharp rise in account takeover fraud targeting UK retail customers, with reports mentioning a major high street retailer alone topping over a thousand cases since the start of the year. The pattern is consistent: criminals use personal details harvested from other data breaches to log into genuine customer accounts, place orders using stored payment details or saved credit, and collect the goods in person from a store — leaving the actual account holder to discover it after the fact.

If your business runs an online store with click-and-collect, saved payment methods, or any kind of loyalty account, this isn’t just a large-retailer problem. The mechanics scale down to any SME e-commerce setup exactly the same way.

Why click-and-collect makes this worse

The reason this fraud pattern is spreading is that click-and-collect removes the one check that used to catch it: delivery address mismatch. When goods ship to a customer’s home address, a fraudulent order using someone else’s account often gets flagged because the delivery address doesn’t match anything on file. Click-and-collect skips that entirely — the fraudster just turns up with an order confirmation and a name. For smaller retailers who added click-and-collect as a convenience feature without revisiting fraud controls, this is the gap.

It’s also worth knowing this fraud rarely starts with your business. The stolen credentials usually come from an unrelated breach elsewhere — a password reused across sites, a data leak from a completely different company. Your systems don’t need to be compromised for your customers to be victimised through them, which is precisely why it can feel unfair when the reputational damage still lands on your brand rather than the original breached site.

That reputational cost is the part smaller retailers tend to underestimate. A customer who discovers a fraudulent order on their account doesn’t distinguish between “your platform was hacked” and “someone reused my Netflix password” — they experience it as your business failing to protect them, and the refund, chargeback and support time all land on you regardless of where the credentials actually leaked from.

Practical checks for this week

If you run click-and-collect or in-store pickup for online orders, add a basic identity check at collection — asking for the card used, a confirmation code sent separately, or ID matching the name on the order. It’s a small friction point that closes most of the gap.

It’s also worth reviewing whether your platform flags unusual account activity: a login from a new device followed immediately by a large order, or multiple orders placed in quick succession on an account with no recent history, are both classic signals. Many e-commerce platforms have these fraud rules available but switched off by default — check your settings rather than assuming they’re active.

Finally, encourage customers towards unique passwords and, where your platform supports it, offer two-factor login. It’s also worth setting a low-cost internal policy now: if a customer reports a fraudulent order, treat it as a priority ticket rather than routing it through standard returns — the faster you can freeze the account and reverse the order, the less exposure everyone has, including you.

This is exactly the kind of gap between “we have an online store” and “we have a secure online store” that a technical partner like CoolCoding can help audit — often a short review of checkout and account settings surfaces fixes that take an afternoon, not a redesign.

The takeaway

Account takeover fraud is rising specifically through the convenience features — click-and-collect, saved payment details — that many SME retailers added without a parallel review of fraud controls. If you offer in-store collection for online orders, add an identity check at the counter this week, and check whether your platform’s fraud detection settings are actually switched on.