International return fraud: why your EU customers behave differently
Your Shopify store expanded into Europe eighteen months ago. Sales are good. The EU market is mature, the buying power is there, your product resonates. What you've also noticed, and haven't fully explained to yourself, is that the return rate from EU customers runs 20% to 40% higher than your US rate, and the fraud patterns look different enough that your existing fraud model keeps misfiring.
You're not imagining it. EU returns genuinely behave differently from US returns, and the difference isn't cultural. It's structural. The legal framework European customers shop under, specifically the Consumer Rights Directive's 14-day right of withdrawal, produces return patterns that look like fraud to US-tuned scoring models but are often legal consumer behavior. Underneath the legitimate patterns, a distinct set of actual-fraud shapes has evolved that your US fraud model has never seen.
Add the UK, which has its own post-Brexit wrinkles, and international return fraud is a genuinely separate problem from US return fraud. Very little English-language content covers this. Let's walk through it.
The EU 14-day right of withdrawal, and why it changes the fraud shape
The Consumer Rights Directive (2011/83/EU, transposed into national law across all EU member states) guarantees EU consumers the right to return most online purchases within 14 days of delivery, for any reason, for a full refund including standard shipping.
In practice this means:
- The return reason doesn't matter. A customer can return because they changed their mind, the color looked different on their monitor, the size didn't fit, or no stated reason at all. You cannot require a reason. You cannot decline based on reason.
- The original shipping cost is refundable. You must refund the standard outbound shipping (the cheapest option you offered at time of order), even if the customer paid for express. A cost US merchants don't typically bear.
- Return shipping can be charged to the customer, but only if clearly disclosed. If your terms didn't clearly say "customer pays return shipping," the law says you pay.
- You have 14 days to refund after receiving the return. Slow refund processing exposes you to regulatory complaints.
- Certain items are exempt: custom-made goods, perishables, sealed hygienic goods once opened, software/media once opened, and digital content once access began. Most non-custom physical goods are covered.
The result is a return rate floor that sits higher than the US by structural design. EU customers return more because they're entitled to more, and they know it. A 25% to 30% return rate on apparel and consumer goods is normal in the EU. The same SKU might return at 12% to 15% in the US.
This creates two distinct detection problems.
Problem 1: your fraud model's baseline return-rate signals are miscalibrated. A US-tuned signal that says "customer returns more than 30% of orders" is a fraud indicator in a US population where baseline is 12%. In an EU population where baseline is 25%, that same threshold catches a lot of entirely legal behavior. The signal needs market-specific calibration.
Problem 2: the 14-day window creates a specific abuse shape. The "wardrobing in plain sight" pattern (buy, use for two weeks, return) is much easier to execute in the EU because there's no reason requirement. In the US, the customer has to either lie about the reason or hope you don't enforce your return policy. In the EU, they have a legal right to do exactly what they're doing, and the merchant has no way to refuse the refund on reason grounds.
The EU-specific abuse shapes
Wardrobing, normalized
In the US, wardrobing (buy-wear-return) is detectable partly because the customer typically lies about the reason. "The fit wasn't right" or "the color was off" on a product returned with clear signs of use is a trigger for the scoring model.
In the EU, the customer doesn't have to lie. They return within 14 days, cite no reason (or citing withdrawal of consent), and your system has nothing to flag. The product arrives back with clear signs of wear, and you've got to process the refund anyway unless you can prove it's been used beyond what's needed to inspect its characteristics.
That "beyond inspection" standard is the only legal footing you have to push back. Interpreted narrowly by EU consumer-protection bodies. You have to show the item isn't resellable or has materially diminished value from use, and "materially" is a high bar. A dress worn once to an event and returned with perfume on the neckline may not clear it. A laptop that shows 12 hours of use in its system logs might.
Detection focus: since you can't flag on reason, you have to flag on physical condition of the return, velocity pattern, and item category. A customer who returns 8 of 10 apparel orders within 13 to 14 days is executing the wardrobing pattern legally. That's not a customer you want to serve the same way you serve your best customers. Scoring models that carry an EU-specific "return velocity within withdrawal window" signal can identify this cohort and let the merchant respond operationally (slow-ship, require prepayment, eliminate free shipping) without violating the legal refund obligation.
Serial withdrawal across merchants
The 14-day right is merchant-specific in enforcement but cumulative in behavior. A serial returner who runs the pattern across twenty merchants over a year produces a distinct fraud ring signature (same address, same payment method cluster, same shipping/returning cadence) that's detectable if you share signals across the detection ecosystem.
Most Shopify merchants don't, and the serial-withdrawal ring lives in the space between merchants. Fraud-ring detection that triangulates address + payment + device across multiple merchants in the same vertical is one of the few mechanisms that can catch this cohort. RefundSentry's cross-shop identity signals (F1 queries in spec 107) are designed for exactly this pattern.
"Partial return" arbitrage
EU law specifies refund-including-outbound-shipping rules. Some abusers exploit the rules by ordering multi-item orders and returning only the low-value items, keeping the high-value items and often still getting a partial shipping refund via proration. Whether this is legal depends on the wording of your return policy and the specific national implementation, but it's a gray zone that's frequently abused.
The UK post-Brexit wrinkles
The UK left the EU in 2020, and the consumer protection framework for UK consumers is now the Consumer Contracts Regulations 2013, substantively similar to the EU Directive but not identical, and amended over time without EU harmonization.
For Shopify merchants selling into the UK:
- The 14-day cooling-off period still applies, essentially identical to the EU rule.
- Import/VAT complications add new fraud shapes. Orders into the UK under £135 have VAT collected at checkout (post-Brexit rule). Over £135, VAT is collected at import. Abusers exploit the £135 threshold by ordering just under it, receiving goods, and returning with VAT-reclaim complications that your order system may not correctly handle. You can end up refunding VAT you never collected in the first place if your reconciliation isn't precise.
- Return shipping from UK to EU-based fulfillment is slow and expensive. This has created a cohort of UK customers who exploit the "refund without return" loophole. They initiate a return, never ship the goods, and exploit the merchant's unwillingness to chase an international return shipment. Merchants end up eating the loss.
Detection-wise, UK customers with outstanding return-not-received balances should be flagged in your system. A customer with three unreturned-but-refunded orders has a specific profile your scoring engine should weight heavily on subsequent orders.
Language-based fraud-ring signatures
The English-language fraud-detection literature is almost entirely US-centric, and one consequence is that European-specific fraud-ring signatures get missed because the detection models don't look for them.
A few patterns we've seen in our own scoring data.
Name patterns. Fraud rings operating in Germany often register accounts with phonetically-German names that transliterate oddly. Accounts like "Müller" rendered variously as "Mueller," "Muller," "MÜLLER," and "Müeller" across accounts sharing an address. A fraud scoring model that normalizes Unicode for similarity comparison will catch this. One that treats the strings as distinct will not.
Address format. Southern European addresses (Italy, Spain, Portugal) frequently use formats US-built order validation doesn't know how to handle. Apartment-number before street-name, district-code as a separate field, floor-and-interior-number conventions. Fraud rings exploit the validation gaps, entering variations that look like different addresses to a US-tuned system but resolve to the same physical location.
Payment method clustering. Virtual IBAN services popular in Europe (N26, Revolut, Wise) produce payment methods that look fresh to US-built fraud models but are often clustered under a few providers that abusers repeatedly use. Weighting payment-provider reputation, not just payment-method uniqueness, helps.
Cross-border device fingerprinting. A device fingerprint that moves between Ireland, Germany, Netherlands, and Spain over 60 days with orders to each country is a strong fraud signal. Legitimate European customers travel. They don't typically register as the billing customer on four orders to four countries.
What the scoring model needs to do differently for EU/UK
Market-calibrated baseline rates. Return rate signals, account-age signals, order-value-vs-customer-profile signals should all have per-market calibration. A "returns too often" threshold that works for US merchants fails for EU merchants.
Withdrawal-window awareness. A return inside the 14-day window with no reason is not the same signal as a return outside the window with a reason. The scoring engine should know the jurisdictional rule and treat "withdrawal" distinct from "return for cause."
VAT and import handling. For UK and cross-border shipments, the scoring engine needs to understand VAT implications. Orders just under the £135 threshold with return patterns should carry a specific signal.
Unicode-normalized identity matching. Names and addresses with diacritics, transliteration variations, and regional format differences should be normalized before comparison. A fraud-ring detection model that treats "Müller" and "Mueller" as distinct will miss the ring.
Cross-merchant signal sharing. The serial-withdrawal ring spanning twenty merchants is invisible to any single merchant. Detection requires triangulated signals across merchants in the same vertical, which RefundSentry's F1 cross-shop queries enable by design.
Operational responses that stay within EU law
What EU merchants often miss: you can't decline a lawful withdrawal refund, but you can change how you serve a high-risk customer going forward.
Slower shipping for serial returners. If a customer has returned 8 of 10 orders, offer them the slowest eligible shipping tier by default. Many serial returners self-select out when the item wouldn't arrive in time for their intended use.
No free shipping for repeat returners. Your legal obligation is to refund standard outbound shipping on a withdrawal. You can charge for shipping on the next order, and you can decline to offer promotional free shipping to customers with a return-heavy pattern.
Require prepayment / decline BNPL for repeat returners. BNPL is a popular payment rail in Europe, and Klarna-specific return abuse is real in the EU. A customer with a bad return pattern getting their BNPL-eligible option removed is a normal merchant response that EU consumer law doesn't prohibit.
Account-level friction. A customer whose account matches a flagged fraud-ring cluster can be required to verify identity before their next order. Not a refund decline, a pre-order check, and defensible as a fraud-prevention measure.
The point: you can't refuse a withdrawal refund, but you have considerable latitude to decide how you serve a customer going forward. The detection engine's job is to identify the cohort where operational response is appropriate.
The takeaway
International return fraud isn't US return fraud in a different language. It's a structurally different problem shaped by different consumer protection law, different payment infrastructure, different naming/address conventions, and different fraud-ring economics. The US-tuned fraud model imported wholesale into an EU/UK operation will misfire in both directions. Flagging legal withdrawal returns as fraud, missing actual fraud rings that operate on patterns your model wasn't built to see.
If you're selling internationally, the detection stack needs per-market calibration, withdrawal-window awareness, Unicode-normalized identity matching, and cross-merchant signal sharing. The literature is sparse and the tooling is US-centric, which is exactly why the abusers have had a comfortable run. The playbook is catching up. The merchants who run international operations and still use US fraud logic are the ones paying for it.