Buy Now, Pay Later compresses application, credit decisions, checkout, and fulfillment into minutes. Fraudsters exploit that speed before providers, merchants, and victims spot the warning signs.
The fraud methods are familiar. BNPL gives them a fast new route to goods, credit, and cash-out opportunities.
How fraudsters exploit Buy Now, Pay Later:
🎭 Account takeover - Criminals use stolen credentials, phishing, or compromised email and phone accounts to enter established BNPL accounts. They change delivery details and spend the available limit before the real customer sees the purchase or the first repayment request.
🪪 Application and identity fraud - Stolen or synthetic identity data is used to obtain credit at account opening. A fabricated applicant builds purchasing history, increases available spending, and disappears with resalable goods.[ref]
💳 Stolen payment instruments - Criminals pair a hijacked identity or BNPL account with a compromised card or bank account for repayments. The merchant, lender, payment institution, and victim each see only one fragment while the criminal controls the full chain.
🔄 First-party fraud - Some applicants misrepresent information, manipulate disputes, or borrow without intending to repay. The first installment makes the transaction look legitimate; later payments fail after the goods are delivered and resold. Providers still need to distinguish deliberate abuse from genuine hardship.
⚡ Cross-provider velocity - Fraudsters apply and purchase across several firms before any one provider sees the accumulated exposure. In a 2022 U.S. dataset covering six pay-in-four providers, 63% of borrowers held simultaneous BNPL loans at some point, and 33% borrowed across multiple firms.[ref] These figures describe borrowing patterns, not fraud. Criminals exploit the same fragmentation as a visibility gap for rapid applications and purchases.
🏪 Merchant, refund, and fulfillment abuse - Fake or collusive merchants seek payment for non-existent goods, manipulate refunds, or disguise circular transactions. Fraud sits with the seller, buyer, delivery destination, or a combination of all three.
The CFPB found that five surveyed U.S. BNPL firms originated 180 million loans worth more than $24 billion in 2021.[ref] That is a lot of fast decisions, fragmented signals, and merchandise moving before the full risk is visible.
What can we do:
For BNPL providers:
- Use layered, risk-based verification at onboarding and step up authentication when devices, contact details, delivery addresses, or behavior change.
- Combine identity, device, behavioral, payment, merchant, fulfillment, and cross-account signals. Where lawful and proportionate, use consortium or credit data to identify cross-provider velocity.
- Separate deliberate abuse from affordability problems and genuine hardship so fraud controls target the right behavior.
- Monitor merchants, refunds, disputes, and delivery patterns as closely as customer applications.
For consumers:
- Monitor BNPL accounts and linked cards or bank accounts, enable purchase and account-change alerts, and use unique passwords with MFA where available.
- Treat BNPL as credit: check the repayment schedule, fees, reporting, return process, and dispute protections before accepting it.
- Report an unfamiliar account or purchase immediately to the BNPL provider, merchant, and linked payment provider. If identity theft is involved, follow the reporting and credit-protection process available in your country.
- Be skeptical of unusually good deals from unfamiliar stores.
Buy now. Resell now. Disappear before the second payment.