Sellers are targeted from two directions
Fraud aimed at marketplace sellers generally comes from two different directions that require different defenses: buyer-side fraud (return fraud, chargebacks on legitimately-received goods, fake damage claims) that costs you money order by order, and account-side fraud (phishing, credential theft, account takeover) that can cost you the entire account, including funds in transit and future sales. Treating both with the same level of seriousness matters — sellers often over-invest in preventing the buyer-side fraud they've personally experienced while under-investing in account security until after a takeover has already happened.
Return fraud patterns
Empty box / wrong item returns: a buyer returns an empty box, a different (often cheaper) item, or a used substitute claiming it's the original. Photograph and, ideally, weigh every returned package before opening it — this is the single most effective proactive defense, since it creates evidence at the moment of receipt rather than after the fact when it's your word against the buyer's.
Wardrobing: buying an item, using it once (for an event, a photoshoot, a short-term need), then returning it as if unused. Harder to prevent outright, but inspecting returned items for signs of use before processing a refund, and having a documented condition-on-return policy, gives you grounds to push back on obviously-used returns.
Serial returners: a small number of accounts responsible for a disproportionate share of return volume. Most marketplaces provide some visibility into return patterns at the buyer level, or allow flagging/blocking repeat abusive buyers — check what your specific marketplace exposes for this.
Switch fraud: buying a genuine item and a counterfeit/inferior look-alike separately, then returning the fake as if it were your product to keep the genuine item at no cost. Careful serial-number or unique-marking checks on higher-value returned items can catch this.
Account takeover and phishing
Credential phishing: an email or message impersonating the marketplace, asking you to "verify" your account by logging in through a link. These frequently spike around policy-update periods or tax-document season, when a request to "update your information" seems plausible. Never log in through a link in an email — navigate to the seller dashboard directly through your browser or bookmark instead.
Fake support impersonation: a message claiming to be marketplace support, asking for your password, two-factor code, or remote access to "help fix an account issue." No legitimate marketplace support process asks for your password or your two-factor authentication code — treat any request for either as a certain sign of fraud, regardless of how official the message looks.
Account takeover consequences: once an account is compromised, an attacker can redirect payout bank details, change contact information to lock you out further, and post fraudulent listings using your account's established seller history (which sell more readily than a brand-new scam account would) — potentially triggering account health and policy violations in your name that you'll then have to appeal.
The account-security baseline every seller should have
- Two-factor authentication turned on, using an authenticator app rather than SMS where the platform supports it (SMS-based codes are more vulnerable to interception).
- Unique, non-reused password for each marketplace seller account, stored in a password manager rather than memorized or reused across sites.
- Regularly reviewed authorized users and connected apps/API access — a former employee's still-active access or an old, unused third-party app integration is a common overlooked entry point.
- Payout bank details double-checked periodically, especially after any account alert, since an unnoticed change here is one of the more financially damaging outcomes of a takeover.
- A designated, bookmarked login URL for each marketplace, so you never rely on clicking a link from an email or search result to reach the login page.
What to do if you suspect a takeover
Change your password immediately from a device you're confident is not compromised, revoke active sessions/API tokens if the platform allows it, verify payout bank details haven't changed, and contact the marketplace's seller support through their official channel to flag a suspected takeover — most marketplaces have a dedicated account-security escalation path that reviews faster than general support.
Best practices
- Photograph and weigh every returned package before opening, as standard process, not just for suspicious-looking returns.
- Treat any request for your password or two-factor code as certain fraud, no exceptions.
- Use an authenticator app for two-factor authentication rather than SMS where supported.
- Periodically audit authorized users, connected apps, and payout bank details, not just after an alert.
- Bookmark your login URL rather than navigating via email links or search results.
Troubleshooting
I received a login alert for a location I don't recognize. Change your password immediately and check active sessions/devices in your account settings; don't assume it's a false alarm without verifying.
A "support" message is asking me to share my screen or install remote-access software to fix an account issue. This is a well-documented takeover pattern — do not comply, and report the message through the marketplace's official fraud-reporting channel.
I suspect a specific buyer is committing serial return fraud but have no proof for any single case. Check whether your marketplace exposes buyer-level return-history data or a flagging mechanism; even without individual-case proof, a documented pattern across multiple orders is often enough grounds to escalate to the platform.
FAQs
Does the marketplace ever compensate sellers for confirmed return fraud? Some platforms offer limited reimbursement or protection programs for specific documented fraud patterns (particularly on marketplace-fulfilled programs) — check your specific platform's seller protection policies, since coverage varies significantly.
Is SMS two-factor authentication good enough, or do I need an authenticator app? SMS is better than no two-factor authentication at all, but an authenticator app (or a hardware security key, where supported) is meaningfully more resistant to interception-based attacks and is worth the small extra setup effort.
How often should I audit connected apps and authorized users? A quarterly review is a reasonable baseline for most sellers, with an immediate review triggered any time a team member's role changes or a third-party integration is no longer in active use.