Full Breakdown
Tap-to-Pay Fraud Schemes Undermine U.S. Retail Security
7/17/2026, 8:39:53 PM
The Scheme in Action
In the spring of 2025, a man wearing a black Air Jordan T-shirt approached a self-checkout kiosk at a Lowe’s in Hammond, Louisiana. Over roughly seven minutes he entered a series of $95 gift-card purchases, tapping his phone to pay while a red-vested associate stood nearby. Surveillance captured the suspect receiving step-by-step instructions through wireless headphones. After leaving, he repeated the process at other retailers and returned to the same Lowe’s later that day. A similar incident was documented at a Target self-checkout in Tennessee, where police linked the fraudster to a Chinese organized-crime ring.
Background & Context
Tap-to-pay fraud—loading stolen credit-card data into a digital wallet and using it to buy gift cards or merchandise—has surged since the COVID-19 pandemic. Crime groups exploit the convenience of contactless payments and the comparatively lax security of retail apps. AI tools enable rapid scaling of phishing texts that masquerade as alerts about unpaid tolls or expiring registrations, prompting victims to surrender credentials. Once obtained, the data are used to load cards on devices controlled by the ring, allowing purchases that can be resold in the United States or shipped to China.
Key Figures & Groups
- Adam Parks, Assistant Special Agent in Charge, U.S. Homeland Security Investigations (HSI) – leads the federal probe into the Lowe’s case.
- Scott Glenn, Vice President of Asset Protection, The Home Depot – provides industry perspective on risk.
- Jeff Otto, Chief Marketing Officer, Riskified – explains how credential theft fuels the schemes.
- Capt. Matt Lawson, Knox County Sheriff’s Office, Tennessee – oversees local investigations of related rings.
- Walmart – issued a corporate statement on its security posture.
Data & Statistics
- Each recorded transaction involved a $95 gift card; hundreds of individuals are reportedly active nationwide.
- Law-enforcement estimates Chinese gangs earn as much as $1 billion annually from such schemes.
- CNBC identified roughly a dozen criminal cases across varied retailers.
- Login credentials for Walmart’s app and website have been observed for sale on Telegram at $1.50–$2 per set, often tied to accounts older than ten years.
Why It Matters
Retail platforms store credit-card numbers, personal data, and sometimes store-branded card credentials, yet they prioritize convenience and conversion over “bank-grade” security. This creates a lucrative target for organized crime, allowing low-risk conversion of stolen funds into cash or high-value goods that can be exported. The resulting losses are difficult for local authorities to quantify, leaving many retailers vulnerable.
Official Statements & Responses
HSI officials emphasize the scale of the problem, noting the coordination between foot soldiers in stores and overseas networks that funnel profits back to China. The Home Depot characterizes the method as “very low risk for the bad actors,” contrasting it with traditional, visible shoplifting. Riskified highlights that older, long-standing accounts often bypass basic fraud checks, and that retail apps lack the stringent safeguards of banking applications. Walmart asserts that customer privacy is a top priority and that its systems continuously evolve to detect and block unauthorized access.
Criticism & Opposition
Local law-enforcement officers observe that unless a fraud case reaches a federal threshold, perpetrators “get away with it almost,” underscoring gaps in prosecutorial resources and the need for stronger retail security standards.
Conflicting Reports & Gaps
No definitive nationwide loss figure exists; estimates rely on case studies and law-enforcement assessments rather than comprehensive industry data.
Verbatim Quotes
- “We know that there are hundreds of individuals at any one time doing this across the country,” — Adam Parks, Assistant Special Agent in Charge, U.S. Homeland Security Investigations
- “It's very low risk for the bad actors,” — Scott Glenn, Vice President of Asset Protection, The Home Depot
- “Once a fraudster has a person's email password and credit card, they can load that credit card into a device that they control,” — Jeff Otto, Chief Marketing Officer, Riskified
- “They have Yahoo addresses that are 10 years old, Gmails that are 10 years old,” — Jeff Otto, Chief Marketing Officer, Riskified
- “it's kind of like they get away with it almost,” — Capt. Matt Lawson, Knox County Sheriff’s Office
