Fraud rarely shows up as a single flagged transaction. It shows up as a pattern, one that’s often invisible to any single business but obvious once you can see across a network. That was the throughline of Sift’s recent webinar unpacking the Q2 2026 Digital Trust Index, featuring Brent Sleeper, Senior Product Marketing Manager, and Jeremy Cannon, Trust and Safety Architect.
The conversation moved past the headline numbers and into what the data actually reveals: the anatomy of two real fraud rings pulled from Sift’s Global Data Network, why account takeover (ATO) fraud requires a different playbook than card testing, and how a business’s response after an incident can do more damage to customer trust than the fraud itself.
Growth Brings a Bigger Attack Surface
Transaction volume across Sift’s network grew more than 15% this year, and that growth cuts both ways. More e-commerce means more revenue, but it also means a larger attack surface for fraudsters to work. As Cannon summed it up, “Fraud’s growing because the landscape is growing.”
Fraud rings aren’t isolated incidents either. They’re patterns that only become visible with enough breadth across industries and geographies, what Sleeper called strength in numbers.
What a Card Testing Ring Actually Looks Like
The report’s first example centered on a card testing ring, and the details were telling. One email address cycled through 94 different cards. “No one has 94 cards,” Cannon said, pointing to it as a clear signal for setting thresholds on how many cards a single person should be able to try at once.
The average transaction value was just $4, small enough to stay under the radar of both the cardholder’s alerts and the merchant’s fraud thresholds. Cannon described one customer who kept receiving orders for single cans of soda picked up in-store: cheap, no prep required, and easy to miss. “Is someone really ordering from your sandwich shop a single soda to be picked up?” he asked. But the soda was never the point. It was validating which of the 94 stolen cards would go through, so they could be resold or used for larger fraud later.
This particular ring hit five different food and delivery businesses with fraudulent chargebacks, none of which saw the full 94-card pattern on their own. Only a network view exposed the scale.
The response here should be aggressive. “With card testing, it’s pretty easy to block,” Cannon said, adding that businesses “can be aggressive” here since the cost of inconveniencing a rare legitimate edge case is minimal compared to letting a testing ring establish which cards are live.
Why ATO Requires a Different Kind of Scrutiny
The second ring told a messier story. This one targeted more than 90 businesses and generated nearly 13,000 attempted transactions, all tied to account takeover. Unlike card testing, ATO doesn’t look uniformly bad, “because the accounts are good,” Cannon explained. Legitimate accepts and fraudulent blocks can show up in the same cluster, because the sessions are attached to real customers with real histories.
Two signals are worth watching closely. Average transaction values in this ring ran higher than typical, since the goal is extracting maximum value rather than testing small purchases. A loyalty account email change also surfaced as a leading indicator of takeover, since redirecting an account’s email and receipts is often the first step toward full control.
Card testing and ATO frequently connect. “We generally see that the people testing the cards are not the people using the cards,” Cannon said. A tested card often resurfaces later on a compromised account, because a good account with an established purchase history draws far less scrutiny than a brand-new signup with a stolen card and a synthetic identity.
The recommended response here is friction rather than a hard block: step-up authentication, revalidating a card’s security code, or an alert on an unusual login. A 3% block rate at one merchant might be the tail end of an attack that started somewhere else entirely, and the merchant that absorbed the first wave had no way of knowing it. Network intelligence helps teams detect fraud faster because it expands what they’re able to see in the first place.
What Consumers Actually Experience After an ATO
The webinar’s live polls added a consumer lens to the data, and one result stood out immediately: no one in the audience said they first learned about an account takeover from the company or platform itself. Responses split evenly between noticing suspicious activity on their own and hearing about it from a friend or family member.
That gap matters. Finding out about a takeover on your own is often the worst version of the experience, since customers want to feel like a business already has their back.
Response Quality is a Retention Lever
The data on what happens after an incident was just as clear. Roughly 80% of surveyed consumers said a quick, proactive resolution improved their perception of a business, while a slow or opaque response worsened it for nearly half.
For fraud teams, the strategy doesn’t end with the block or the step-up challenge. It extends into how customer experience, communications, and support teams talk to affected customers afterward. “You want to make friends with them in peace time,” Cannon said, so the right people across the business are already aligned when a real attack surfaces.
The Bigger Picture
Card testing and ATO look different in the data, and they call for different responses. But both point to the same underlying lesson: fraud signals rarely make sense in isolation. As Cannon put it, the goal is to “use all the signals around you, use everything, but also use all the people around you.” A single merchant’s block rate, one email change, one unusually large order: none of these tell the full story alone. It’s the combination, seen across a broad enough network, that turns noise into a detectable pattern.
Want the full data behind these rings, plus more on how consumer trust shifts after a fraud incident? Read the complete Q2 2026 Digital Trust Index report or watch the webinar.





