Cloudflare’s retail analysis citing the National Retail Federation’s 2025 report puts the pressure in numbers retailers already feel: **ecommerce fraud up 55%**, and **71%** of retailers seeing a sign
Retail “shrink” used to mean missing stock in a stockroom. Online, it looks like emptied carts that never checkout, scraped catalogues feeding rivals and LLMs, credential stuffing against customer accounts, and loyalty points drained by automation. The common thread is business-logic abuse, not only perimeter hacking.
Cloudflare’s retail analysis citing the National Retail Federation’s 2025 report puts the pressure in numbers retailers already feel: ecommerce fraud up 55%, and 71% of retailers seeing a significant rise in fraudulent returns. Separately, 85% of retailers say they are looking to AI to detect or prevent fraud — which raises a practical question for UK SMEs: where should that intelligence sit, and how do you avoid turning every checkout into a CAPTCHA obstacle course?
The new shape of automated threat
OWASP’s Automated Threats catalogue calls out denial of inventory (OAT-021): bots add high-demand SKUs to thousands of carts and never pay. Legitimate customers see “out of stock”; physical stock sits idle; peak demand passes; margin dies in markdowns. Cloudflare frames this as “phantom shrink” — loss that never shows as a chargeback but still destroys contribution.
Scraping has changed character too. In a September 2025 engineering post, Cloudflare reported that by mid-2025 nearly 80% of AI bot activity on its network was crawling for model training — a sharp rise year-on-year. Modern scrapers rotate residential proxies, mimic browsers, and follow plausible paths. A single request may look human against global traffic; against your store’s baseline, the behaviour is absurd: alphabetical product walks, zero cart interaction, sub-second dwell on every PDP.
Why one-size-fits-all bot scores are no longer enough
Classic signals (odd User-Agents, datacentre IPs) still catch lazy bots. They fail against residential-proxy fleets and AI-assisted agents. Cloudflare’s response has been twofold:
- Global fingerprinting — heuristics across HTTP/2 fingerprints, TLS Client Hello behaviour, and challenge-derived client signals; over a seven-day window their teams reported 11 billion requests linked to residential or commercial proxy networks in one snapshot they published.
- Per-customer behavioural models — baselines of normal for each zone, then anomaly detection. Early scraping detections flagged 138 million scraping requests in 24 hours across just five beta zones, with 34% of those requests not caught by prior bot-score logic alone.
Client-side and payment trust still matter
Not all shrink arrives as a bot swarm. Magecart-style skimmers and injected checkout scripts steal cards from the browser. Cloudflare cites Fossil’s use of Page Shield to monitor unauthorised script changes. Baymard’s abandonment research still finds 19% of users leaving because they did not trust a site with card details — trust UX and technical integrity are the same commercial problem.
UK Finance’s 2026 payments summary adds local colour: in 2025 online card spending grew 4% by volume but only 1% by value, with about 45.9 million adults (80% of UK adults) buying online. Wallets and one-click checkout are rising; so is the need for fraud controls that do not undo that convenience. IMRG’s 2026 outlook also flags AI-powered fraud growth as a margin risk for unprepared retailers.
A proportionate defence for UK SMEs
- Map critical journeys: login, account create, add-to-cart, apply voucher, checkout, returns portal.
- Rate-limit and score APIs as carefully as HTML — headless and mobile apps are soft targets.
- Separate verified bots (SEO, uptime) from scrapers and hoarders.
- Prefer invisible trust signals (Turnstile, device/session signals) over blanket CAPTCHAs.
- Monitor inventory hold patterns and voucher abuse, not only HTTP 403s.
- Keep human review for edge cases — false positives at checkout are self-inflicted shrink.
Why this matters for Clarity Growth
Clarity Growth designs ecommerce security as part of operations: Cloudflare bot and WAF policy, Shopify-compatible hardening, checkout integrity, and monitoring that protects margin without kneecapping paid traffic. For UK scale-ups heading into peak, bot management is stock and trust protection — not a bolt-on “IT ticket”.
Sources
- Cloudflare — Combating digital shrink with AI (theNET) — https://www.cloudflare.com/the-net/retail-digital-shrink-ai/
- Cloudflare Blog — Building unique, per-customer defenses against advanced bot threats in the AI era (23 Sep 2025) — https://blog.cloudflare.com/per-customer-bot-defenses/
- Cloudflare Docs — cf.bot_management.score — https://developers.cloudflare.com/ruleset-engine/rules-language/fields/reference/cf.bot_management.score/
- Cloudflare — Bot Management product overview — https://www.cloudflare.com/application-services/products/bot-management/
- Baymard Institute — 40+ UX Statistics (cart abandonment reasons) — https://baymard.com/learn/ux-statistics
- UK Finance — UK Payment Markets 2026 Summary — https://www.ukfinance.org.uk/system/files/2026-08/PaymentMarketsReport_2026Summary.pdf
- IMRG — Expectations for online trading in 2026 — https://www.imrg.org/blog/expectations-for-online-trading-in-2026/
Start with the friction. Build the capability.
Clarity Growth helps organisations identify, design and implement practical automation opportunities across existing systems and workflows.