|
Case Study
ALTO's Impact on Retail Crime Accountability in San Francisco
On July 9, 2024, a department store in San Francisco experienced a theft
carried out by a prolific repeat offender known for targeting local
retailers. Thanks to a prompt incident report, the individual was
apprehended the same day of the incident
This
case underscores the vital role
ALTO plays in the
legal process, ensuring accountability every step of the way. By
leveraging expertise and an extensive network of legal professionals,
ALTO facilitated a seamless progression through multiple court hearings,
ultimately leading to a resolution.
After Apprehension: Case Milestones
Once the offender was taken into custody, ALTO’s legal team submitted
evidence, coordinated with the San Francisco District Attorney’s Office,
and maintained clear communication between store personnel, law
enforcement, and prosecutors. Our local team supported both the DA’s and
the store team throughout the entire process, from the initial hearing
to the sentencing, addressing critical gaps that could have otherwise
led to case dismissal.
Click here to read more
NRF PROTECT
Highlights
Retail security can’t be a siloed effort
Today’s threats potentially impact
every area of business
After a motivational keynote that encouraged attendees of
NRF PROTECT 2025
to become the best version of themselves — and to show up for others —
the slate of sessions during the conference’s first day reinforced the
importance of seeing retail security as a “team sport.” Today’s
threats go far beyond one department to potentially impact every area of
a business.
Whether
educating employees about phishing and smishing dangers; highlighting
the fact that proprietary information shouldn’t be entered into ChatGPT;
training store associates to handle consumers fired up by mis/disinformation;
establishing relationships with law enforcement before an event occurs;
or taking tabletop exercises to the worst-case scenario —
awareness, planning and preparation may be more
important than ever before.
“Mitigating Enterprise Risks: A Comprehensive Approach” saw Matt Gorham,
leader of PwC’s Cyber and Risk Innovation Institute, sit down with Diane
Brown, vice president, IT risk management with ULTA Beauty, and Scott
McBride, chief global asset protection officer and CSO at American Eagle
Outfitters Inc. They dove into, for example, taking a “Goldilocks”
approach to finding the right level of executive protection, referencing
the fatal shooting of UnitedHealthcare CEO Brian Thompson in late 2024:
There’s no one-size-fits-all.
Lisa Kaplan, founder and CEO of Alethea, presented “Navigating an
Evolving Information Ecosystem: Mitigating Threats to Digital and
Physical Assets Posed by Mis/Disinformation.” She spoke about bad
actors’ attempts to influence and change behavior through social media
algorithms, curating content that aligns with previous actions and
preferences. That can generate strong emotions — and inspire real-world
actions.
It’s not illegal; it’s speech, and the narratives being created could
impact business continuity. Kaplan shared a case study of a group of
brands called out for harboring undocumented immigrants. It led to
people showing up, stalking patrons in-store and creating risks of
violence.
Companies must define their own risk, she said, based on the
actors involved (who is spreading the information); their behaviors (how
are they doing it); the content (what are they saying); and who it
targets (whether the brand or an individual).
nrf.com
The U.S. Crime Surge
The Retail Impact
Is Enforcement the Key to Curbing ORC?
How Law Enforcement Task Forces Are
Stepping Up the Fight Against ORC
By
the D&D Daily staff
While new laws targeting organized retail crime (ORC) continue making
headlines, the day-to-day enforcement of those laws often falls to
under-resourced law enforcement teams quietly working behind the scenes.
Across the country, dedicated ORC task forces are stepping up efforts to
track, investigate and dismantle the criminal networks responsible for
billions in annual retail losses.
These specialized units—often comprised of detectives, local police
officers and regional retail loss prevention specialists—play a
critical role in connecting theft incidents across jurisdictions. What
may look like isolated shoplifting cases are frequently part of a
larger, coordinated network involving boosters, fences and even online
marketplaces used to resell stolen goods.
In cities like Los Angeles, Chicago and Miami, law enforcement
agencies have created multi-agency task forces that bring together
local police, Homeland Security Investigations (HSI), district attorneys
and retailers to identify patterns and coordinate responses. These
collaborations are proving essential in a space where ORC groups are
increasingly tech-savvy and mobile—often operating across state lines
and using encrypted communications to evade detection.
Still, challenges remain. Many law enforcement departments face
staffing shortages, limited budgets, and a backlog of cases.
Additionally, traditional criminal databases weren’t designed with
ORC-specific tagging in mind, making it harder to connect repeat
offenders or track regional trends without internal collaboration or
private sector intel.
Some jurisdictions are working to address this by creating
centralized ORC intelligence centers or leveraging real-time
data-sharing tools between retailers and police. Others are investing in
training to help officers better identify ORC-specific red flags during
seemingly routine theft arrests.
Ultimately, while legislation provides the legal framework,
enforcement is what brings results—and task forces are where that
happens. As the retail industry continues pressing for federal
action and stronger penalties, it’s these boots-on-the-ground
collaborations that will determine whether those laws translate into
real disruption of ORC activity.
States Turning Up the Heat on Shopping
Cart Thieves
'It’s a crime that could cost shoppers up to
$2,500 and even land them in jail'
The Surprising Crime Costing Walmart and Target Shoppers Thousands
Rolling a shopping cart off store
property might seem harmless, but in some states, it could cost you
thousands or even jail time.
Walking off with a shopping cart might seem like no big deal, but in
several U.S. states, it’s a crime that could
cost shoppers up to $2,500 and even land them in jail.
Major retailers like Walmart and Target lose an estimated 2 million
carts a year, racking up more than $175 million in replacement
costs. In response, states across the country are cracking down,
introducing stricter laws and steeper penalties to deter what’s now seen
as a serious source of loss.
In Illinois, offenders can be slapped with the highest fine—$2,500—depending
on the cart's value and any prior offenses, according to the Daily Mail.
Jail time is also on the table. And that’s not the only place
getting tough.
In California, cart theft is a misdemeanor that could carry a
$1,000 fine and up to six months behind bars. San Jose now requires
large retailers to install locks or GPS systems to prevent carts from
vanishing.
Florida hits first-time offenders with a $100 civil fine, but
repeat thefts could lead to $1,000 fines and a year in jail. Hawaii,
meanwhile, imposes a $500 fine and 30 days in jail, following
thousands of carts reported missing in Honolulu alone.
Even states with lighter penalties aren’t taking the issue lightly.
Texas cart theft typically carries a $500 fine, but that jumps to $2,000
and jail time if the offender has a record. Washington state hands
out $50 fines and impound fees, but also allows for misdemeanor charges
with up to 90 days in jail.
These laws come as stores battle rising shoplifting and operational
losses. Some are ditching self-checkouts altogether. Dollar Tree
recently removed machines from 12,000 stores and saw an 8 percent sales
jump.
mensjournal.com
Pennsylvania's War on ORC Makes More
Headlines
Organized Retail Crime Unit combating violent thieves
Pennsylvania Attorney General Dave Sunday Attorney General Dave Sunday
joined Philadelphia-area law enforcement and community partners to
discuss Year One achievements of the Office of Attorney General’s
Organized Retail Crime Unit, and how collaboration is resulting in
arrests, prosecutions and recoveries of stolen goods.
The Organized Retail Crime Unit launched July 1, 2024, following Act 42
of 2023 and a new criminal statute that made retail theft of goods
more than $50,000 a first-degree felony. In its first year, the unit
opened more than 65 investigations, charged
more than 40 alleged thieves and recovered nearly $2 million in stolen
goods.
The Organized Retail Crime Unit responds to high-dollar thefts,
typically perpetrated by multiple thieves who manipulate gift cards and
store return/exchange policies — or, in many cases, enter retail stores
in packs and steal as many items as they can as quickly as possible.
“This unit is aggressively pursuing thieves who operate in packs,
oftentimes terrorizing purely innocent store employees and shoppers,”
Sunday said. “The perception that retail theft is a petty crime is
outdated, as these crimes are violent in nature and designed to menace
and frighten bystanders. With the help of our partners, we have made big
strides in stopping these criminal enterprises, and sending a strong
message to anyone thinking of committing these crimes.”
bradfordera.com
NYC Mayoral Front-Runner's
Controversial Views on Public Safety
Zohran Mamdani once supported defunding the
police, before backtracking
A Look at Zohran Mamdani’s Stances on Key Issues
Mr.
Mamdani has proposed creating a Department of Community Safety,
separate from the Police Department, to respond to people having
mental health crises, and to expand violence interrupter programs. In
April, he told The Times that the new department would
free up “police resources to increase clearance
rates for major crimes.”
Mr. Cuomo and other candidates seized on his expressions of support
for major cuts to the department’s budget during his 2020 campaign
for State Assembly. But Mr. Mamdani says he now supports keeping the
police force at its current size. In the final primary debate, he
vowed that he would not “defund the police.”
He said he would, however, curb the department’s massive overtime
budget and that he would consider keeping Jessica Tisch on as police
commissioner. He has praised some of her policies, like cutting the
department’s communications staff and fighting corruption.
nytimes.com
Law enforcement partnership helps lower Montgomery crime rate, state
says
Colorado mandated reporting on police violence, 5 years later, data is
mostly useless
Walmart Seeks to Remake Itself
Can Walmart Shed Its Discount Vibe? Its New Home Office Offers a Clue.
The retailing giant is spending
billions to attract workers to a new headquarters and woo shoppers with
drone delivery and a broader range of items (like Louis Vuitton
handbags).
“There
are no cash registers in the home office.” It’s a mantra at Walmart and
a reminder that every dollar earned comes from its nearly 11,000
stores worldwide. Everything done at its corporate headquarters in
Bentonville, Ark., is an expense.
For decades that expense was minimal — the retailer’s main office was a
spartan distribution center with wood-paneled offices and few windows.
Most of the white-collar employees here were focused on merchandising
and logistics.
But that thinking has changed as the company has had to figure out
how to compete in an increasingly tech-fueled, competitive industry.
A big symbol of that is a multibillion-dollar splurge on a new
headquarters meant to attract and retain top talent and modernize the
ethos of the discount store Sam Walton founded in 1962.
Walmart built its empire by dominating on price. But to maintain that
empire it must now compete on convenience, breadth and speed. During
Associates Week — its annual gathering of thousands of employees from
around the world — the company made a number of tech-focused
announcements, like a new artificial intelligence assistant that it says
will help customers shop online and an expansion of its drone
home-delivery operation to more cities.
nytimes.com
The Down Sides of
Returns Continue to Pile Up
Can In-Store Returns Get Less Clunky?
A new survey finds retailers still struggling with the extra costs
and new workloads created by processing in-store returns while
barely benefiting from returnees making an add-on purchase.
A 2023 study by academic researchers in the UK concluded that returns
from online sales — particularly those made in-store — are eroding
profitability and urged retailers to adopt a strategic approach to
treating returns as a potential profit center. Recommendations included
expanding physical storage space, hiring more staff, and investing in IT
systems to better track and manage returns.
The study stated, “Many businesses have complex procedures for managing
returns. With little senior management oversight of the returns process,
retailers find it difficult to pin down crucial information such as
the rate of return and the costs of handling a returned item.”
A Shopify blog entry noted that BORIS can lead to inaccurate
inventory data, as returned items sit in stockrooms, as well as in-store
congestion and longer lines. Shopify suggested creating designated
areas for handling in-store returns, although the standard checkout
processes returns in many stores.
In March, Kohl’s temporarily stopped accepting Amazon returns at some
stores in a test, following social media complaints from store
associates about the added workload — from lifting heavy boxes and
finding storage space for returned items to managing long customer
lines. Several associates also indicated that customers returning Amazon
packages rarely take advantage of the 25%-off Kohl’s coupon they receive
as an incentive.
retailwire.com
Don't Become Complacent on Workplace
Safety
What OSHA's "Most Cited" Means: Three Lessons for Safer Workplaces
With the same issues appearing
annually on this list, it should be a wake-up call, says Jade Brainard
of KPA.
Each year,
OSHA’s top 10 most frequently cited standards underscore many of
the same issues across industries, from inadequate fall protection
to poor lockout / tagout procedures.
Familiarity can easily breed complacency, especially in a shifting
regulatory environment where rules and enforcement could loosen
under the new presidential administration. But in our line of work,
complacency is quite literally dangerous.
1. Repeat Violations Point To Systemic Issues
That Should Alarm Every Safety Professional
Although the same citations top OSHA’s list year after year, it’s rarely
because employers don’t understand the rules in question. The likelier
root cause: a break-down of protocols under everyday jobsite conditions.
2. View the Top 10 as a List of Blind Spots to
Monitor and Correct
Behind each citation is an opportunity to improve training, strengthen
supervision, or equip workers more effectively. By digging into your
organization’s own inspection and near-miss data, you can identify where
those gaps exist before OSHA does.
3. Safety Still Matters, No Matter How the
Regulatory Winds Blow
The new presidential administration has cast doubt over the future of
OSHA and its regulatory reach. But even amidst uncertainty, it’s
important for safety professionals to maintain a full-court press when
it comes to avoiding the top OSHA violations.
ehstoday.com
Tariffs Taking a Toll
Jewelry retailer shops for buyers amid tariff struggles
Trump's tariff policies cited as
major factor for the once-popular mall staple now facing $500M loan
deadline
Claire's Stores Inc. is weighing a potential sale as the beleaguered
teen jewelry store contends with relentless competition and the
impact of President Donald Trump's tariffs, according to a report.
The company, primarily owned by private equity firms Elliott Management
and Monarch Alternative Capital, tapped Houlihan Lokey Inc to find
potential buyers for some or all of Claire's locations, people familiar
with the matter told Bloomberg.
A recent survey from consulting firm McKinsey revealed that they have
already changed their spending habits or expect to change them soon
in response to tariff announcements. Among them, more than half said
this includes cutting back spending on nonessential items, according to
the May survey.
foxbusiness.com
Walgreens swings to a loss ahead of Sycamore acquisition
Store closures and weak front-of-store comps
led to a retail sales decline in Q3, but U.S. pharmacy and international
sales were strong.
H&M has bad news for its loyal customers
Trump Organization scraps ‘made in the USA’ tag for its gold T1
smartphone

|
|
Retail Crime Has Moved to the Cyber
Space
Recent cyberattacks show just how much crime
against retailers has evolved
Not Your Father's Retail Crime Landscape
For decades, retail crime was a brick-and-mortar challenge—shoplifting,
internal theft, smash-and-grabs—tackled with cameras, EAS tags, guards,
and locked cases. Shrink—inventory loss—was measured by what could be
seen or carried out the door, with success defined by catching
thieves or lowering annual shrinkage.
Today, as e-commerce integration expands attack surfaces, the
battlefield has moved online. Cybercriminals target loyalty
programs, payment systems, backend databases, and vendor portals. Loss
prevention directors now sit in boardrooms and SOCs, working with
cybersecurity teams on fraud detection, identity and access management,
and third-party risk. This shift demands new skills, technology
investment, and a move from reactive tactics to proactive, digital-first
risk management.
The retail sector is once again under siege as cybercriminals
escalate their efforts to exploit vulnerabilities in some of the world’s
most prominent brands. In recent weeks, major retailers such as
Victoria’s Secret and Adidas have joined the growing list of victims
affected by sophisticated cyberattacks. These breaches, linked to
compromised third-party vendors, underscore a sobering reality: the
global retail industry is facing an intensifying cybersecurity crisis,
fueled by increasingly complex digital ecosystems and persistent human
error.
Google’s Threat Analysis Group recently issued a stark warning that
the same threat actors behind a series of cyberattacks on major UK
retailers, including Marks & Spencer and Co-op, are now targeting
U.S.-based retailers. These attacks, which compromised customer
data, disrupted supply chains, and damaged consumer trust, have become
part of a broader trend of targeted retail cybercrime. What’s
particularly alarming is the root cause: mismanaged third-party access
and identity security lapses.
While physical threats continue to define what retail theft and crime
mean to most of the general public, recent breaches have made clear that
cybersecurity in retail is no longer just a technical issue; it’s a
business continuity imperative. With threat actors evolving faster
than many defenses, the sector must respond with equal urgency, focusing
on proactive identity protection, continuous monitoring, and zero-trust
architectures.
securityinfowatch.com
Security - Privacy - Trust
AI security issues dominate corporate worries, spending
Two reports illustrate how business
leaders are thinking about and budgeting for generative AI.
Security, privacy and related trust issues remain some of businesses’
biggest concerns about generative artificial intelligence, according
to a pair of reports. As businesses face more pressure to integrate AI
into their workflows, they are confronting difficult questions about the
technology’s reliability and auditability.
Many companies are allocating new slices of their budgets to AI
investments, including in agentic AI, which uses autonomous systems to
perform complex tasks.
Two reports — one that KPMG released on Thursday and one that Thales
released last month — illustrate how generative AI is raising security
concerns for business leaders.
Business leaders surveyed by KPMG reported prioritizing security
oversight in their generative AI budgeting decisions, with 67% saying
they plan to spend money on cyber and data security protections for
their AI models. Fifty-two percent cited risk and compliance as a
budgetary priority.
Those spending decisions reflect corporate executives’ growing worries
about AI security. In KPMG’s new Q2 2025 report, 69% of leaders cited
concerns about AI data privacy, a significant increase from the 43%
who cited it in Q4 2024. Regulatory concerns around AI also grew, from
42% to 55%.
cybersecuritydive.com
Preventing the Next Global Outage
Microsoft to make Windows more resilient following 2024 IT outage
The company has been working with
security partners to make sure future software updates don’t lead to
operational disruptions for customers.
Microsoft plans to roll out key platform upgrades in July in an effort
to build greater operational resilience into the Windows platform,
following the 2024 global IT outage linked to a faulty software
update from CrowdStrike.
The changes — including quick machine recovery and other features
letting Microsoft 365 users continue accessing the cloud in a protected
environment — are part of a Windows overhaul that Microsoft announced
in November to build a more secure environment that would prevent
software updates from causing widespread operational disruptions for
enterprise customers. In September, the company met with major security
firms to discuss how such an overhaul would work.
“We recognize our shared responsibility to enhance resiliency by
openly sharing information about how our products function, handle
updates and manage disruptions,” David Weston, corporate vice president
of enterprise and OS security at Microsoft, said in a blog post released
Thursday.
Microsoft’s partners welcomed the changes and said they would create
a more secure environment for customers.
cybersecuritydive.com
ClickFix attacks skyrocketing more than 500%
Building cyber resilience in always-on industrial environments |
|
Amazon's War on Counterfeits
Amazon's anti-counterfeit team helped company secure over $180M in penalties
Amazon's Counterfeit Crimes Unit (CCU) has helped the company secure over $180
million in court-ordered penalties and 65 criminal convictions worldwide.
The CCU, established five years ago, comprises former prosecutors,
investigators, and intelligence experts.
It has worked with law enforcement agencies and brands across 12 countries,
including India, China, the US, and the UK, to combat counterfeit goods.
CCU's proactive approach blocks 99% of suspected
counterfeit listings
Since its inception, the CCU has filed over 200 civil lawsuits. Amazon claims
that its proactive approach, driven by artificial intelligence (AI) and human
expertise, blocks over 99% of suspected counterfeit listings before brands even
need to act. In one case, the CCU traced fake goods from a US-based seller to
manufacturers in China, resulting in coordinated raids and the seizure of more
than 2,100 counterfeit products and a $1.1 million judgment against the
ringleader.
The unit has partnered with over 50 government agencies
Amazon has partnered with over 50 government agencies, including EUROPOL, US
Homeland Security Investigations, and the City of London Police. These
collaborations have been instrumental in cracking down on counterfeiting
networks that often cross international borders. The company also provides tools
like Brand Registry and Transparency to help businesses protect their
intellectual property on its platform.
Amazon aims to drive counterfeits to zero
Despite the progress made, Amazon acknowledges that the threat of counterfeits
is an evolving challenge. The company plans to continue investing in advanced
detection technologies and enforcement strategies, with the goal of driving
counterfeits to zero. "We're constantly enhancing our tools and technology to
stay ahead," it said in its 2024 Brand Protection Report.
newsbytesapp.com
Stores - But No Shoppers
The locations will fulfill online orders only
Walmart tests dark stores
As the retailer accelerates its delivery
efforts, the brick-and-mortar locations will fulfill online orders — but are not
open to the public.
Walmart is testing dark stores, or brick-and-mortar locations that fulfill
online orders but are not open to the public, the company confirmed
Wednesday. The retailer is currently piloting the concept in Dallas.
The dark stores will carry some of the retailer’s most popular products,
as was first reported by Bloomberg. Another location is planned for Bentonville,
Arkansas, the retailer’s hometown, per the publication.
A dark store may look like a regular shopping location,
but there’s a catch: the public isn’t allowed inside.
“We regularly test new tools, features, and capabilities to better connect
with and serve our customers — wherever and however they choose to shop,” a
Walmart spokesperson said in an email to Retail Dive. “Regardless of the
channel, our goal remains the same: to deliver a fast, seamless, and engaging
customer experience.”
Dark stores are used to speed up and streamline online fulfillment, which
is important for a retailer that is accelerating its operations. The company has
been using its store footprint and technology, including drones, to advance
delivery in recent years.
Walmart U.S. achieved e-commerce profitability in Q1 for the first time, with
sales up 21%, a metric CFO John David Rainey said is “an important milestone for
our company.”
retaildive.com
Amazon again worst performer in UK grocery suppliers' survey, regulator says |