Regulators
PCI Security Standards Council (PCI DSS 4.0) · state AGs · FTC · EU GDPR
$15B+
ATO-driven retail fraud annual loss
Account takeover is now one of the largest fraud categories in retail. Stolen credentials → loyalty-point theft + return-fraud + saved-card abuse. Mid-large retailers absorb 7-figure ATO losses annually.
Source: Javelin Strategy + Sift research · 2025
~55%
Share of e-commerce transactions via guest checkout
A majority of e-commerce transactions still go through guest checkout rather than account creation. This is the conversion-vs-CRM tension at the heart of retail CIAM design.
Source: Baymard Institute conversion research · 2025
Growing
Major retailers with passkey support
Target, Best Buy, eBay, Walmart, Home Depot, and others rolled out passkey support during 2024-2025. Driven by ATO economics + reduced password-reset support costs. Adoption rate among customers is 8-25% depending on prompting strategy.
Source: FIDO Alliance + retailer announcements · 2025
~78%
ObservationRetailers reporting loyalty-program fraud
Practitioner aggregate from retail-CISO discussions. Loyalty-point theft is the fastest-growing form of retail ATO because points are liquid + redeemable + rarely have transaction-level fraud controls.
Source: askmeidentity practice observations · 2026
~24 controls
PCI DSS 4.0 IAM control overlap
PCI DSS 4.0 includes ~24 controls in Requirements 7 + 8 that map directly to IAM (strong authentication, access restriction, MFA on console access). PCI is the dominant compliance driver for retail IAM programs.
Source: PCI Security Standards Council · 2024
Cite this page
Reference our benchmarks in your reporting.
These benchmarks are licensed under CC BY 4.0 — free to cite, quote, and link to with attribution. Pick a format below.
askmeidentity. (2026). The State of Identity, live (v2026.05). Retrieved 2026-05-22 from https://askmeidentity.com/resources/state-of-identity-retail/
"The State of Identity, live." askmeidentity, v2026.05, https://askmeidentity.com/resources/state-of-identity-retail/. Accessed 2026-05-22.
@misc{askmeidentity_state_of_identity_2026_05, title = {The State of Identity, live}, author = {{askmeidentity}}, year = {2026}, note = {Version 2026.05, retrieved 2026-05-22}, url = {https://askmeidentity.com/resources/state-of-identity-retail/} }