logo

Who’s Really Shopping? Retail Fraud in the Age of Agentic AI

ID: e1831137-5403-5b76-b952-bf4f4963ee29

STIX ID: report--e1831137-5403-5b76-b952-bf4f4963ee29

Feed Name: Palo Alto Networks Unit 42

Threat Score
65/100

Date Published: 2026-03-20

Date Updated: 2026-04-28

Author: Matt Brady and Christa McHugh

...
...

**Executive summary:** This Unit 42 analysis examines how agentic commerce and the Universal Commerce Protocol (UCP) could be abused via indirect prompt injection—examples include payload poisoning that silently adds gift cards to a Cart Mandate and logic-hijacking that triggers instant refunds without verification—potentially enabling large-scale retail fraud, chargebacks, and reputational damage; the report recommends protocol guardrails, agent identity/reputation frameworks (Know Your Agent), and AI security assessments to mitigate these risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.