The fraud hitting jewelry stores right now doesn't look like fraud. That's the problem.
The old red flags — sketchy email addresses, addresses that don't match, a caller who doesn't know basic details — don't work anymore. Today's scammers do their homework, and AI has made convincing fakes fast and cheap to produce. We're hearing about it more and more from the retailers we work with, and the patterns are worth sharing.
What we're seeing from our own customers
An increasing number of the jewelers we work with are reporting fraud attempts, and a pattern keeps repeating:
- The order is often a tennis bracelet or necklace — high value, easy to resell, nothing custom about it.
- The shipping address is real. It passes address verification because it's a legitimate residential address. The working theory: the scammer watches the tracking and steals the package off the porch of a real house.
- It's always a rush. The order “needs” to be overnighted — “my anniversary is Friday” — which conveniently leaves no time for extra checks.
- We're seeing a lot of it out of Texas — though the pattern travels.
Nothing about that order looks wrong in your system. Real name, real address, payment that appears to clear. The fraud only becomes visible when the chargeback lands weeks later — and in high-ticket retail, one fraudulent transaction can erase a month's margin on that category.
The industry is seeing the same escalation. The Jewelers' Security Alliance has documented a widespread scam in which callers know employee names, shipping procedures, inventory, even SKU numbers — then work to divert a shipped package to an address of their choosing.
What one of these looked like up close
This summer the same buyer scamed two of our customers about a month apart. Both charges went through. Together they came to over $19,000.
Both times he sent documents when asked. A driver's license, front and back. Photos of his credit card, front and back. To an associate glancing at a phone screen, they looked fine.
The card was the sloppy part. It was branded Visa, but the account number started with a 5. Visa numbers begin with 4, and numbers starting 51 through 55 belong to Mastercard. No genuine card carries Visa branding on a Mastercard number. The bank logo sat on a white rectangle that did not match the card art beneath it, pasted on.

The back gave it away twice more. The customer service line started 0845, a United Kingdom prefix, printed on a card for a bank headquartered in Ohio. The expiration was labeled “EXPIRES END,” a British convention. And the signature panel carried a repeating Mastercard watermark, on a card branded Visa.

And the card in the photo was not the card that paid. Both stores were charged on entirely different numbers.
The clearest signal never required looking at a document at all. It was sitting in the payment record. At the first store, four attempts failed across a Sunday night and the following morning before one cleared for $11,200. At the second, three failed inside ninety minutes before one cleared for $7,900.

That is card testing. He was cycling numbers until one worked.
And that is how the loss actually lands. The charge clears, the merchandise ships, and weeks later the real cardholder reports the transaction. The payment gets reversed. The store is out the money and the goods, and the person who took them is long gone.
A run of declines followed by a success, on a high-value order from someone with no history, is not a customer fumbling an expired card. It is someone finding out which stolen number is still live. If the tool you collect payments through shows you failed attempts, that is a fraud signal, and it arrives while you can still stop the sale.
Verification has to get harder, because faking got easier
Here's the uncomfortable part: the checks that used to feel thorough are now beatable.
A photo of an ID? Fakeable. An ID held next to a handwritten note with today's date? Also fakeable — AI image tools produce those in seconds.
For a high-value order from someone you don't know, get on a live video call. A real-time conversation is still meaningfully harder to fake than any image, and a legitimate buyer spending five figures will not object to five minutes on camera. On that call, don't settle for a static ID shown to the lens — ask them to move it, tilt it, hold it beside their face while they talk with you.

Just don't treat the call itself as proof. The FBI warns that live video and audio can be deepfaked too, and its advice is to watch for the inconsistencies: blurry or distorted facial features, blinking that's too frequent or too rare, hair or teeth that don't look quite real, audio out of sync with the video, a flat or unnatural voice, or odd shadows and lighting. Any one of those is reason to slow down and verify another way.
The store playbook
Practical habits, drawn from what's working for retailers and from JSA's guidance:

- Slow down the rush. Urgency is manufactured on purpose — it's why nearly every one of these orders “has” to ship overnight. The FBI counts fear, pressure, and unexpected urgent requests among the top red flags of an AI-enabled scam. Urgency isn't just inconvenient — it's a fraud signal in its own right. The more pressure to skip steps, the more reason to take them.
- Treat repeated declines as a red flag, not a technical hiccup. Several failed payment attempts followed by one that clears is the signature of someone testing stolen card numbers. Stop the order and verify by another channel.
- Lock down change-of-address with your shipper. Tell FedEx/UPS that address changes on your packages are refused or require one named person's authorization.
- When it feels wrong but you can't prove it, change the terms, not the payment method. Cancel the payment link and keep the order alive as in-person pickup, or hold it at a carrier facility for ID pickup, paid with the physical card in hand. A real buyer spending five figures will show up. Whoever is running the scam needs that package to reach an address they control, and will usually just stop responding.
- Train everyone, not just managers. JSA's documented scam works by phone-farming details from whoever answers. Staff should know what not to share about personnel, procedures, and inventory.
- Set an escalation rule. New client + high value + shipping + urgency = automatic second-person review. No exceptions, no matter how legitimate it feels.
And when an attempt does surface, don't just dodge it. Preserve the messages, phone numbers, payment information, and shipping details, and report it to the FBI's Internet Crime Complaint Center at IC3.gov — then loop in your bank or payment processor, the carrier, and local law enforcement when appropriate.
Your best fraud tool is knowing your clients
There's a reason scammers target stores where they can pose as a stranger with a credit card: strangers are easy to impersonate. Clients with history are not.
A real client profile — purchase history, past conversations, preferences, the associate who knows them — gives your team something no fake ID can beat: context. When “a longtime customer” calls and nothing about the request matches the actual relationship in front of you, that's your alarm.
Which is an argument for capturing more of them. Every walk-in who leaves anonymous is someone you will not be able to tell apart from a stranger six months from now, and the history already sitting in your client list is what makes that distinction possible.
Some stores go a step further with their highest-value clients and trusted trade partners and agree on a simple verification phrase or procedure in advance — a business version of the codewords the FBI suggests families set up with each other.
Clienteling was never designed as a security tool. But in 2026, knowing exactly who your customers are might be the most underrated fraud defense a jewelry store has.



