
Are You Tracking Repeat Retail Offenders — or Repeatedly Rediscovering the Same Network?
A Georgia woman bought expensive area rugs at TJ Maxx using a debit card, then returned them within minutes under a change-of-mind policy. She kept the receipt. At a different TJX store — sometimes in a different state — she used that same receipt, or a duplicate, to return a cheap rug bought elsewhere and relabeled to look like the genuine product. Investigators eventually traced nine debit cards to 84 fraudulent refund transactions run this way from November 2020 to May 2021, netting as much as $300,000 across TJ Maxx, Marshalls, and HomeGoods locations.
No single store’s repeat-offender list ever had a chance of catching that. Eighty-four transactions, nine cards, three banners under one parent company, and a receipt trick specifically designed so that no individual location saw the same name twice.
A Repeat-Offender List Tracks a Person. The Operation Behind It Rarely Depends on Being One Person.
Loss prevention programs are generally built to flag identity: a name, a face on camera, a loyalty account, a card number tied to a prior incident. That works when the person actually is the unit of repetition — when the same individual walks back into the same store enough times to trip a threshold. It works less well against operations built around the opposite assumption: that rotating the identity, the card, or the store is cheap, and that no single location has the visibility to notice the rotation.
The Florida case is not unusual in this respect. In April 2025, the California Department of Justice announced felony charges against three people running what Attorney General Rob Bonta’s office called an identity theft mill — using 13 victims’ stolen identities to open store credit accounts and then purchasing merchandise with no intention of paying it back. The scheme ran from March to July 2023 across Los Angeles, Orange, San Bernardino, Riverside, Alameda, San Mateo, and Santa Clara counties, and touched retailers as different as Signet Jewelers and Harbor Freight, generating more than $100,000 in fraudulently obtained merchandise. The investigation only came together after a corporate fraud investigator at Signet flagged an anomaly and multiple agencies — including Homeland Security Investigations and four separate police departments — pieced the rest together.1
In both cases, the retailers involved had functioning loss prevention systems. Both were watching for repeat behavior. Neither was set up to notice that the “repeat” was happening across store names, card numbers, or counties rather than within one location’s own records.
The Industry Data Suggests This Is Not a Fringe Problem
The National Retail Federation’s 2025 Impact of Theft and Violence study, based on responses from 70 retail companies representing 168 brands and $1.3 trillion in annual sales, found that 67 percent of retailers reported involvement of a transnational organized retail crime group in thefts against their company over the prior year, and that the average number of shoplifting incidents rose 18 percent from 2023 to 2024. The same study found that 64 percent of retailers report less than half of their theft incidents to law enforcement at all, most commonly because they do not expect a response.2
Read together with the TJX and California cases, the picture is not that retailers lack loss prevention effort. It is that the effort is scoped to a boundary — one store, one banner, one jurisdiction — that the people committing the fraud have already priced in and designed around.
The Harder Question: Would More Cameras or Stricter Return Policies Have Caught This?
It is tempting to conclude that the fix is simply tighter controls: shorter return windows, mandatory ID for refunds, more aggressive fraud scoring on card numbers. Some of that would likely have helped at the margins. But the TJX scheme specifically exploited a legitimate customer convenience — the change-of-mind return — and the California scheme exploited legitimate credit application processes. Making every return or credit application maximally suspicious would also make the store worse for the overwhelming majority of customers who are not committing fraud. The honest answer is that policy tightening has a ceiling, and both of these operations were built with an understanding of where that ceiling is.
What neither operation appears to have accounted for is a retailer’s ability to notice that a receipt, a card, or a shipping address kept reappearing across locations that do not routinely compare notes. That is a narrower, more achievable target than “stop all fraud,” and it is the one loss prevention technology can actually move.
What Tracking the Operation Instead of the Identity Looks Like
The distinction worth building a program around is between tracking who someone claims to be and tracking what stays constant about how they operate. A name, a face, and a card number are all designed to be disposable in a sophisticated scheme. A device fingerprint, a vehicle, a shipping or return address, a receipt-duplication technique, or a pattern of transaction timing are much harder to rotate on the same schedule — because doing so costs the operation money and coordination.
This means the useful question for an LP program is not only “has this person shoplifted before,” but “does this transaction share any operational fingerprint with an incident already on file, regardless of what name or card is attached to it today.” Retailers that can ask that question across their own banners — and ideally in coordination with peers, the way Signet’s fraud team’s referral helped unravel the California case — catch the pattern at transaction 5 or 15 instead of transaction 84.
Questions Worth Asking About Your Own Program
- If the same debit card or receipt number appeared at three different store locations within your company in one month, would your current systems surface that automatically — or would it require someone to go looking?
- Does your repeat-offender tracking extend across sibling banners under the same parent company, or does each banner effectively start from zero?
- When your fraud team flags an anomaly, is there a clear path to share that signal with peer retailers or law enforcement — the way Signet’s referral helped unravel a scheme touching an unrelated retailer?
- Are your return and credit policies tuned only for individual risk, or do they also account for the possibility that a single legitimate-looking transaction is one instance of a repeated technique?
The Number That Should Worry You Is Not Incidents. It Is Distinct Identities Per Operation.
Eighty-four transactions. Nine cards. One operation. Thirteen stolen identities, several counties, two unrelated retail chains. One operation. The count of incidents on any single store’s log will always understate the scale of what is actually happening, because the identities are the part of the scheme built to be replaced.
The test worth applying to any repeat-offender program is not whether it catches people who use the same name twice. Almost every system does that already. It is whether it catches the ones who were counting on not doing that.
State of California Department of Justice, Office of the Attorney General, “Attorney General Bonta Dismantles Active Identity Theft Mill and Organized Retail Scheme Spanning Seven California Counties,” April 25, 2025. oag.ca.gov ↩︎
National Retail Federation, Loss Prevention Research Council, and Sensormatic Solutions, “New Study Finds Retailers Continue to Contend with Rising Levels of Theft & Violence,” October 28, 2025. nrf.com ↩︎