Stopping Organized Retail Crime Starts With Connecting What You Know
Organized retail crime has gone digital, transnational, and increasingly violent — here’s how to stay ahead
Retail theft has changed shape over the past several years. A single suspect walking out with a jacket under their arm has increasingly given way to coordinated events: a group hits your store in one city, then shows up at three more locations across two states within the same week, moving stolen merchandise into online resale listings before your team has even finished the incident report. That kind of coordination spans nearly every retail category, from luxury goods to grocery to pharmacy.
If you’re managing retail security investigations today, you’re working against organized networks that operate across your stores, your distribution centers, and the e-commerce marketplaces where stolen goods get resold — often coordinating in ways that are hard to see if you’re only looking at one location or one region at a time.
The state of retail crime in 2026
The numbers tell a clear story of acceleration, not stabilization:
- Shoplifting incidents are still climbing. According to the National Retail Federation’s (NRF) Impact of Retail Theft & Violence 2025 report, retailers reported an 18% increase in average shoplifting incidents in 2024 versus 2023 — on top of a 93% increase between 2019 and 2023. Combined shoplifting and merchandise theft incidents rose 19% year-over-year.
- Organized retail crime (ORC) has gone transnational. Sixty-six to 67% of retailers surveyed reported involvement by transnational ORC groups in thefts against their company in the past year, and these groups are diversifying fast: over the past 12 months, retailers reported increases in phone scams (70%), digital and e-commerce fraud (55%), organized shoplifting (52%), and cargo or supply-chain theft (50%).
- Violence is escalating alongside theft. Threats or acts of violence during shoplifting and theft events rose 17% from 2023 to 2024, and incidents involving the threat, display, or use of a weapon rose 16% in the same period. Roughly three-quarters to over 80% of retailers report that shoplifters are exhibiting heightened aggression compared to a year earlier.
- Repeat offenders are the norm, not the exception. 66% of retailers cite repeat offenders as an increasingly serious problem, and many of the same crews are hitting multiple locations across state lines in a single run.
- The financial toll remains enormous. Estimates of total U.S. retail shrink range from roughly $90 billion to over $112 billion annually, with shrink rates near 1.6–1.7% of sales — among the highest levels in more than a decade.
- Reporting gaps make the problem harder to fight. 64% of retailers say they report less than half of theft incidents to law enforcement, most often citing limited law enforcement response as the reason — which means the true scale of the problem is likely understated even in industry data.
In response, 13 states now have active, dedicated ORC task forces, nearly every state has passed or introduced legislation allowing prosecutors to aggregate the value of stolen goods across multiple incidents, and Congress continues to consider the Combating Organized Retail Crime Act to improve coordination across jurisdictions. Legislation like the INFORM Consumers Act now requires online marketplaces to verify and disclose the identity of high-volume third-party sellers — a direct response to how quickly stolen goods move from a shelf to a resale listing.
Mob violence, swarming attacks, and coordinated theft remain one of the hardest problems in physical security, precisely because they involve overwhelming numbers, distributed operations, and criminal networks that move faster than any single store, region, or company can track alone.
Three ways to stay ahead of organized retail crime
Organized retail crime is hard to fight precisely because it doesn’t show up as one incident — it shows up as five incidents across three states that look unrelated until someone connects them. Each of the three moves below plays a different role in making that connection possible: widening what you can see, shortening the distance between knowing and acting, and turning scattered incidents into one recognizable pattern.
01
Widen what you see
You can’t act on a threat you don’t know about, and today’s threats surface in more places than any one source covers. That means combining your own internal incident history with an external signal: police gang and retail-crime intelligence units, peer security teams (including direct competitors — crews don’t respect brand loyalty, so information shared across companies protects the whole industry), state ORC task forces, and always-on monitoring of social media, encrypted messaging, and the dark web, where crews plan routes and fence stolen goods before a theft even occurs.
None of these sources alone gives you the full picture. A dark web listing might match merchandise stolen from a store two states away; a police bulletin might describe a crew your internal reports already flagged last month. Widening what you see means pulling threat intelligence into one place, to understand your holistic threat landscape instead of sitting in separate inboxes where no one ever compares them.
02
Close the gap between knowing and acting
Knowing about a threat and acting on it in time are two different problems. A license plate recognition (LPR) hit matters far more when it’s automatically checked against vehicles tied to prior incidents. A security officer on the perimeter can respond in real time when your intelligence team has already flagged that a known crew is active nearby. A Be-On-The-Lookout (BOLO) alert protects the next store only if it reaches that store’s team the moment a crew is identified — not after the fact.
This is where physical security and intelligence have to work as one motion instead of two separate steps: intelligence identifies the threat, and your people and processes act on it immediately, at every location that needs to know — not just the one where it was first spotted.
03
Connect incidents into a pattern
A single store report of a shoplifting incident looks like a shoplifting incident. Five reports from five stores across three states, filed by five different store managers, look like five unrelated events — unless something ties them together. That’s usually exactly what organized crews are counting on: that no one on your team, or in law enforcement, will connect the dots across locations and time. And that bet often pays off, since many city police departments are stretched thin by staffing vacancies, leaving property crime low on the priority list.
Case management and link analysis are what make that connection visible: recognizing that the same vehicle, the same face, or the same resale listing shows up across incidents, and building the kind of documented case that internal investigators and law enforcement can actually act on — instead of five open-and-shut reports that never get compared. A well-built, thorough case connecting multiple incidents is also far more likely to get law enforcement’s attention and assistance — in short, it’s handing them the case on a silver platter.
Where Connected Intelligence comes in
Widening what you see, closing the gap between knowing and acting, and connecting isolated incidents into a pattern are three different jobs — but they only work together if the data behind them lives in one place instead of three.
That’s the practical case for a Connected Intelligence platform: one system where your internal incident reports, OSINT and dark web monitoring, LPR and camera data, and case files all reference each other automatically. A vehicle flagged in one city surfaces when it shows up in another. A BOLO reaches every store on alert the instant a crew is identified. Five incidents across three states become one case file instead of five open-and-shut reports that never get compared.
Organized retail crime will keep evolving, and it will keep counting on your data staying scattered. Connecting it is how you stay ahead.