Buy-online-pickup-in-store turned convenience into a fraud shortcut. By collecting goods in person, a fraudster skips the one thing that usually gives them away in card-not-present fraud, the shipping address, and walks out with the merchandise before any chargeback signal exists.
This article explains why BOPIS and curbside flows carry unique risk, how the fraud plays out, and how device intelligence flags dangerous orders before release. It connects to the broader payment fraud detection pillar.
Why pickup flows are uniquely exposed
BOPIS removes the friction that also happened to slow fraudsters down.
- No shipping trail. There is no delivery address to verify against AVS, blocklist, or link to a reshipping network.
- Near-instant fulfillment. Goods are ready in minutes, collapsing the window in which fraud signals normally surface.
- Untrained judgment at the counter. Pickup staff verify an order number, not payment legitimacy, and cannot see risk scores.
- High-resale focus. Fraudsters target electronics and other liquid goods that resell instantly.
The order is approved, the card looks fine, and the merchandise is gone before the real cardholder even sees the charge.
How BOPIS fraud plays out
The scheme is fast by design.
- Order. Stolen card details or a taken-over account place a pickup order for high-value goods.
- Notification. The confirmation and pickup code go to an address or number the fraudster controls, or are pulled from the compromised account.
- Collection. An accomplice or the fraudster collects in person, sometimes via contactless curbside where identity is barely checked.
- Cash-out. Goods are resold, and the chargeback lands days later with nothing to recover.
Why traditional controls miss it
The tools that catch shipped-order fraud rely on signals BOPIS erases.
- Address verification is moot with no shipping address.
- Delivery-based velocity cannot trigger when there is no delivery.
- Manual review windows are too slow for minutes-to-pickup fulfillment.
- IP checks fall to VPNs that mask the fraudster’s origin.
What survives the shipping-address gap is the identity of the device that placed the order and whether it belongs to the account it used.
Device identity as the anchor
A stable visitor identifier evaluates the order at placement, before the goods are staged for pickup. When an order comes from a device the account has never used, or from a device linked to prior fraud, that signal arrives in time to flag the pickup for verification.
Prynt returns the visitorId with server-side Smart Signals so store systems can act during the fulfillment window:
- New-device-on-account flags catch takeover-driven pickup orders even with a valid saved card.
- Cross-account and cross-order linkage ties the placing device to other fraudulent orders.
- Bot and network signals surface automated bulk ordering and proxy origins.
- Reputation carry-over flags devices tied to fraud elsewhere through a cross-site reputation network.
Building the control
The goal is to slow risky pickups without frustrating the shopper grabbing groceries on the way home. A scoring flow works:
- Score at order placement, not at pickup, so a risk decision exists before staging.
- Require ID verification on flagged pickups only, keeping friction targeted.
- Delay staging for high-risk, high-value orders to reopen the review window BOPIS removed.
- Keep decisions explainable with reason codes so store staff understand why a pickup needs a check.
Measuring success without over-blocking
The trap is a fraud drop that also turns away legitimate pickup customers, the exact convenience-seekers BOPIS is meant to serve. Track both:
- Flagged-pickup rate versus verification pass rate; high pass rates mean you are flagging real shoppers.
- Chargeback rate on BOPIS orders, the direct target.
- Time-to-pickup on unflagged orders, protecting the convenience promise.
- Value of losses averted against counter friction and staff time.
BOPIS fraud wins by racing your controls to the counter. Anchoring order risk to a device identity you can score at placement puts a decision in staff hands before the goods walk out the door.
Frequently asked questions
What is BOPIS fraud?
BOPIS fraud exploits buy-online-pickup-in-store flows by ordering with stolen payment details and collecting the goods in person, avoiding the shipping address trail that normally exposes card-not-present fraud.
Why is BOPIS riskier than shipped orders?
There is no shipping address to verify or blocklist, fulfillment is near-instant, and pickup staff cannot judge payment legitimacy, so the goods leave before any chargeback signal appears.
How does device intelligence reduce BOPIS fraud?
It scores the order at placement for takeover and automation signals and links risky orders to known-bad devices, letting you flag pickups for verification before the goods are released.
BOPIS trades a shipping trail for speed, and fraudsters exploit both. Score orders at placement, flag only risky pickups, and measure convenience alongside loss. See device linkage in the playground, or plan a deployment on the pricing page.
Try it free
Prynt is device intelligence with a free tier — visitor IDs, bot & fraud Smart Signals, and behavioral biometrics, powered by a cross-site network. Start free.