The landscape of retail crime has been gradually changing over the past few years. Threats have grown beyond shoplifting, and now contain external threats such as phone fraud and supply chain theft, and internal threats such as employee collusion in organised crime and employee theft.
In this article, Titan Security Global focuses on key rising issues contributing to the shift in retail crime and offers advice to retailers on how to tackle the growing threats, focusing specifically on the US and Europe.
Phone Fraud – Vishing
How Does It Work?
Voice phishing, also known as “vishing”, is sharply increasing in both the US and Europe. Fraudsters use AI to generate voices – even to the extent of impersonating the voice of real people from within a company after studying tone and speech pattern – to call retail stores and ask for sensitive information regarding data or delivery times, or to request payments or transfers.
Retail staff, believing that they are talking to someone from within their company – even the CEO in some instances – can gladly pass over this information, unaware that they are passing information or money onto malicious individuals.
In The US
- 70% of retailers have reported an increase in phone fraud in the past year according to a survey carried out by the National Retail Federation.
In Europe
- According to the UK’s 2025 Phishing Trends Report, voice phishing attacks have seen a staggering 449% increase in “vishing” attacks compared with the last year.
What Can Retailers Do?
Steps that retailers can take to lower the fallout of vishing attacks include:
- Authentication Policies: Establish strict policies that state that internal staff, such as IT, administrative staff, or higher-ups will never ask for sensitive information over an audio call.
- Simulated Vishing Exercises: Training exercises should be carried out in which staff are subjected to a simulation of a vishing attack without being forewarned. Any staff who fail the simulation can then undergo further training in how to identify vishing attacks and what to do if they occur.
- Call Filtering: The implementation of call filtering applications or mechanisms filter out known malicious numbers and identified spam calls, greatly decreasing the number of false calls that can come through to retailers.
Supply Chain Theft
How Does It Work?
When targeting the supply chain, criminals attack warehouses, transit vehicles and even storefronts to steal large amounts of stock before it can even reach the stores. Stores are left with gaps in their deliveries, leading to loss of potential sales.
Supply chain theft is often carried out by organised groups, but in up to 40% of cases, drivers and those in charge of the delivery processes can be involved in the thefts themselves – making supply chain theft both an external and internal concern.
In The US
- 50% of retailers reported an increase in theft during the supply chain process according to the NRF.
- 48% reported an increase in delivery theft, including deliveries to stores and deliveries to customers.
- It is estimated that supply chain and delivery theft costs US retailers up to $35 billion annually.
In Europe
- Supply chain theft is much less prevalent in Europe than it is in the USA, but it still costs retailers across Europe around €8.2 billion annually.
- Germany has the largest rates of supply chain theft, with Spain, the UK and France following.
What Can Retailers Do?
To combat supply chain theft, retailers could consider the following:
- RFID: Radio Frequency Identification uses wireless radio waves to track and identify assets as they are in transit, allowing retailers to track their assets at every stage of the supply chain so they can identify when or where an attempted theft happens.
- Tamper-Evident Packaging: This provides visible proof that a package has been accessed during transit, deterring theft. Utilising tamper-evident packaging can reduce supply chain shrinkage by up to 40%.
- Access Control for Warehouses: Preventing access to warehouses without access to a key card, biometric systems such as fingerprinting, or PIN codes that change monthly and are only known by staff can rapidly decrease the number of thefts from the warehouse stage of the supply chain.
Employee Collusion and Theft
How Does It Work?
The threats against the retail industry are not only external thefts. Internal threats, such as employee theft and collusion with organised crime, are also a glaring concern. Employees can steal merchandise from the shop floor, stockroom, or while unboxing deliveries.
They can also work alongside organised crime groups targeting their store in order to get a share of the profits. This can include intentionally mis-scanning items for accomplices posing as customers, informing accomplices of delivery times and sizes, or utilising internal systems to falsify returns and gift card payments.
In The US
- 21% of retailers in the US have reported an increase in employee collusion with organised crime groups, with 64% reporting that there has been no improvement in the matter.
- Employee theft costs the US retail industry approximately $50 billion annually, accounting for 30% of total retail shrinkage
In Europe
- Estimates indicate that employee theft makes up roughly 40% of retail shrinkage in Europe, costing the sector roughly €10.2 billion per year.
What Can Retailers Do?
- Register Controls: Giving employees their own individual codes to log into registers with ensures that all activity is tied to each individual, making it far easier to track who processed a potentially problematic transaction. Combining this with restricting ability to process refunds, discounts and the like to managers only further prevents potential issues.
- Blindspot CCTV Placement: By placing CCTV in usual blindspots, such as stockrooms and behind tills, employee movement can be tracked even in areas that are often missed. This can be clearly signposted as a deterrent.
- POS Integration: Real-time analytics tracking inventory against sales, entered discounts and employee purchases can identify inconsistences that could be a red flag for employee theft – especially when combined with the above.
Conclusion
The landscape of retail crime across the US and Europe has been changing rapidly over the last few years, with shoplifting no longer the main or only concern. A growth in AI usage for vishing attacks, organised crime groups targeting the supply chain, and internal workers aiding in thefts during the supply chain or in-store means a much wider scope of crime that retailers need to look out for.
Retailers in the US should be more focused on supply chain theft, as this is their prevalent concern. In Europe, internal staff theft is the larger concern. Phone scams, or vishing attacks, are growing exponentially across both regions.
By training staff, implementing new features such as end-to-end asset tracking and tweaking existing security measures, such as ensuring CCTV covers blindspots, retailers in both the US and Europe can create security systems that can combat the changing face of retail crime.
