Law enforcement and retail loss-prevention teams say tap-to-pay scams, retail app account takeovers and gift-card laundering have become the preferred tactics of Chinese-organized crime, generating as much as $1 billion annually.
Federal investigators and retail security teams report a surge in digital retail fraud that replaces the visible “grab-and-run” theft model with low‑visibility schemes: stolen card data is loaded into digital wallets, used to buy gift cards or merchandise, then funneled through networks tied to Chinese crime rings. Authorities say the model can scale quickly, evade store staff, and convert stolen funds into goods resold overseas.
What happened — a common pattern
Surveillance reviewed by authorities shows individuals quietly using tap-to-pay at self-checkout or store registers to buy gift cards in modest increments — for example, $95 cards rung up repeatedly over minutes — while remote operators coach them through transactions via wireless headsets. Investigators say the individuals at registers are often low‑level foot soldiers instructed by overseas criminal networks that maintain scam “compounds” to manage operations.
How the scheme works
- Initial compromise: Fraudsters obtain cardholder credentials through phishing texts that warn of unpaid tolls, expiring registrations or fake enforcement actions. AI and scaled social engineering make those messages more convincing, authorities say.
- Account takeover: With email or retail-account credentials, criminals add stolen cards to digital wallets or retail apps. They can intercept one-time codes by accessing victims’ email accounts before banks detect suspicious activity.
- Monetization: Stolen cards are used to buy gift cards or high-value consumer electronics. Gift cards are resold at a discount or used to buy goods — such as smartphones configured for foreign markets — which are then shipped and resold abroad, enabling money laundering and value extraction while avoiding direct bank transfers.
Retailers and platforms targeted
Investigations reviewed by CNBC span multiple retailers, including Lowe’s, Target, Walmart, The Home Depot and TJX Companies. Industry and law enforcement sources say fraudsters target retailers because shopping apps and e-commerce platforms store credit-card details and personal data but often lack the bank-grade security designed to prevent account-takeover fraud.
Scale and structure of criminal operations
U.S. Homeland Security Investigations (HSI) and local law enforcement describe a broad ecosystem: opportunistic solo actors buy and resell gift cards locally, while organized rings coordinate logistics, recruit people to perform in-store transactions, and move proceeds back to China. HSI estimates some Chinese gangs generate as much as $1 billion annually from these digital retail crimes. Project Red Hook, HSI’s gift-card fraud initiative, has produced at least 239 arrests since January 2024, officials said.
Case examples from police investigations
- A Lowe’s incident: Surveillance at a Louisiana Lowe’s showed a suspect repeatedly buying $95 gift cards via tap-to-pay while receiving instructions remotely. The man purchased more gift cards at other stores the same day and returned to repeat the transactions; he remains a suspect, HSI said.
- Miami case: Authorities allege Dancliff Labady used TJX store-branded credit cards added to his digital wallet to make nearly $95,000 in purchases across stores by adding his phone number to customer accounts at Synchrony Bank. Labady has pleaded not guilty; Synchrony said it is cooperating with law enforcement.
Methods to hide illicit apps and data
In multiple seizures, investigators found apps that stored stolen card data disguised as harmless games — often anime-themed — designed to evade casual detection on phones seized during arrests. Telegram channels were observed selling login credentials for retail accounts for minimal amounts, and investigators say older email accounts often bypass rudimentary fraud checks.
Industry response and law enforcement challenges
Retail security teams and law enforcement say these cases are complex and resource-intensive. Local prosecutors may not pursue cases unless losses meet thresholds or qualify as federal crimes, allowing some activity to persist. Investigators and asset-protection leaders urge better information sharing between retailers and law enforcement to identify patterns and disrupt networks more effectively.
Legislative and enforcement efforts
Retailers and federal investigators have supported broader information-sharing legislation. The Combating Organized Retail Crime Act — previously advanced in the House and under consideration in related federal measures — aims to improve coordination for tackling complex cross‑jurisdictional schemes. HSI’s Project Red Hook continues to target gift‑card laundering networks tied to Chinese organized crime.
Key quotes
- Adam Parks, assistant special agent in charge, U.S. Homeland Security Investigations: “We know that there are hundreds of individuals at any one time doing this across the country.”
- Scott Glenn, VP of asset protection, The Home Depot: “It’s very low risk for the bad actors… it’s become a more preferred method over the last several years.”
- Jeff Otto, chief marketing officer, Riskified: “When the bank reaches out to say, ‘Hey, is that you loading the card?’ They’ve already got access to the victim’s email.”
Why it matters
These digital fraud schemes shift retail loss from overt physical theft to covert financial crime, complicating detection and recovery. The tactics exploit gaps between convenience-focused retail platforms and the higher security standards used by banks, creating persistent vulnerabilities for consumers and merchants.
What’s next
Law enforcement says continued federal investigations, Project Red Hook arrests and improved retailer-law enforcement data sharing are central to disrupting these networks. Industry players emphasize stronger account security, multi-factor authentication, and fraud-detection improvements — but officials note these are incremental against highly organized, scalable operations that leverage both technology and human networks.
Bottom Line for Traders
Source-supported facts indicate retailers with large e-commerce platforms and stored payment credentials remain attractive targets for tap-to-pay and account-takeover fraud. The rising incidence of these schemes could sustain pressure on retailers’ loss-prevention costs, compliance programs, and potentially on reputational risk — factors investors and risk teams may monitor alongside broader retail fundamentals.
— Additional reporting by Paige Tortorelli
$HD Live Price, Interactive Charts and Performance Graphs
Market data may be delayed. See StockMarketLoop’s financial disclaimer.

