The Combating Organized Retail Crime Act: The 2026 Standards-Compliance Briefing on H.R. 2853, the Federal Aggregation Offense, the Coordination Center, and the Detection Record Beneath an ORC Prosecution
Home / Intelligence / The Combating Organized Retail Crime Act:...
Standards & Compliance

The Combating Organized Retail Crime Act: The 2026 Standards-Compliance Briefing on H.R. 2853, the Federal Aggregation Offense, the Coordination Center, and the Detection Record Beneath an ORC Prosecution

How the House-passed Combating Organized Retail Crime Act creates a federal aggregation offense and a coordination center, and why a federal ORC case turns on the time-stamped detection record built at the camera and the dock.

Published June 2026
Read Time 13 min read
Stream Standards & Compliance
348-60
House vote passing H.R. 2853, the Combating Organized Retail Crime Act, May 12, 2026 (U.S. House Clerk)
$5,000
Aggregate value of stolen or counterfeit goods over any 12-month period that triggers the new federal offense (H.R. 2853)
67%
Retailers reporting a transnational ORC group involved in thefts against them in the past year (NRF 2025)

For the first time, Congress is on the verge of treating organized retail crime as a single federal offense. Here is what the Combating Organized Retail Crime Act changes, and the detection record that decides whether a string of thefts becomes a prosecutable case.

348-60House vote passing H.R. 2853, the Combating Organized Retail Crime Act, on May 12, 2026 (U.S. House Clerk, Roll Call 157)
$5,000Aggregate value of stolen or counterfeit goods over any 12-month period that triggers the new federal offense (H.R. 2853, 119th Congress)
67%Retailers reporting a transnational organized-retail-crime group involved in thefts against their company in the past year (NRF, Impact of Retail Theft and Violence 2025)

For more than a decade, organized retail crime existed in a strange federal blind spot. Everyone who worked in loss prevention knew the boosting crews, the fencing operations, and the transnational networks were real and growing, but there was no federal statute that named the conduct, no federal data series that counted it, and no prosecutor who could aggregate a season of coordinated thefts into a single case. A crew could hit a dozen stores across three states, net six figures, and face nothing worse than a string of disconnected misdemeanors. That is the gap the Combating Organized Retail Crime Act was written to close, and on May 12, 2026, the House of Representatives passed it 348-60 under suspension of the rules, sending H.R. 2853 to the Senate.

This briefing is for security directors, loss-prevention leaders, risk officers, and the operations executives at retailers, distribution centers, and logistics operators who will live with the consequences of a federal ORC regime. The short version is that the bill creates a new aggregation offense, stands up a federal coordination center, and adds money-laundering and forfeiture tools to the prosecutor's kit. The longer and more operationally useful version is that a federal ORC case is only as strong as the evidentiary record behind it, and that record is built at the camera, the dock, and the perimeter long before a U.S. Attorney ever sees the file. Where the detection layer sits in that chain is the part most retailers have not yet thought through.

Real IntelliSee perimeter detection overlay identifying an unauthorized person in a dark after-hours exterior scene with a bounding box and confidence score
LIVE CAM-04 · REAR LOT
Actual IntelliSee detection output. An unauthorized person flagged in a live after-hours perimeter feed, bounded and scored at 0.83 confidence. Organized retail and cargo crews stage in exactly this window: dark hours, back-of-store lots, loading docks, and yard perimeters where no employee should be present. The system classifies that a person is in a restricted zone and routes a time-stamped alert to a human in real time. It does not identify who the person is. No facial recognition, no stored video, no individual profiling. What it produces is a contemporaneous, time-stamped detection record, which is precisely the kind of evidence a federal aggregation case is built on.

The federal blind spot CORCA is trying to close

The central problem with organized retail crime is not that the law was silent on theft. It is that the law had no way to see the pattern. Under the FBI's National Incident-Based Reporting System, larceny and theft offenses are broken into categories such as shoplifting, theft from a building, theft from a motor vehicle, and theft of motor-vehicle parts. None of those categories isolates organized retail crime as a distinct phenomenon. As the Congressional Research Service put it in its 2024 report on the subject, NIBRS "does not collect data on theft in a manner that allows for an understanding of ORC separate from other types of theft." A coordinated boosting operation and a single desperate shoplifter are recorded as the same offense type. There is no federal series that counts ORC, because at the federal level there has been no law prohibiting organized retail crime that could generate the count in the first place.

That data gap has real consequences for how the conduct gets charged. A crew that steals $800 of merchandise from one store, drives to the next county, and steals $800 more is not committing one $1,600 crime in the eyes of most state codes. It is committing two separate offenses, each below the felony threshold in many jurisdictions, each handled by a different local prosecutor who may never learn the other case exists. The economic reality, a single enterprise extracting tens of thousands of dollars across a planned route, never assembles into a single charging document. CORCA's core innovation is to let federal prosecutors do what no single local prosecutor can: aggregate the thefts.

The scale of what is going uncounted is visible in the survey data that does exist. The National Retail Federation's 2025 study on the impact of retail theft and violence, drawn from senior loss-prevention executives representing 168 brands and roughly a quarter of total U.S. retail sales, found that 67% of retailers reported a transnational organized-retail-crime group was involved in thefts against their company over the prior year. More than half reported increases over the prior twelve months in phone scams, e-commerce fraud, and physical shoplifting tied to ORC groups, and threats or acts of violence during theft events rose 17% year over year. The FBI's own 2024 Uniform Crime Reporting summary recorded an 8.9% increase in reported shoplifting, even as overall larceny-theft fell, and the bureau took the unusual step of publishing a dedicated special report on reported flash-mob shoplifting incidents from 2020 through 2024. The phenomenon is large enough to warrant its own FBI report but small enough, in the official data architecture, to be invisible as a category.

Why This Matters For Loss Prevention

A federal offense changes what counts as evidence

The moment ORC becomes a federal aggregation offense, the unit of proof changes. A local shoplifting case turns on a single incident: one store, one date, one clip. A federal aggregation case turns on a pattern across stores, states, and months, which means the evidence that matters is the chain of contemporaneous, time-stamped records linking incidents to the same enterprise. Loss-prevention programs built to document individual incidents for civil recovery are not automatically built to feed a multi-incident federal case. The detection record, the alert log, and the event time-stamp become the connective tissue prosecutors need, and most retailers have never been asked to preserve them with that purpose in mind.

The four mechanisms inside H.R. 2853

The Combating Organized Retail Crime Act is not a single rule but a coordinated set of four mechanisms, each addressing a different failure point in the current system. Read together, they move ORC from a fragmented local-enforcement problem toward a federal enterprise-crime model resembling how the government already prosecutes trafficking and racketeering networks. The pipeline below traces the conduct from the theft itself to the courtroom and shows where each statutory mechanism attaches.

H.R. 2853 · Four Statutory Mechanisms

From a string of thefts to a single federal case

How the Combating Organized Retail Crime Act attaches to the conduct at each stage.

MECHANISM 1
Aggregation Offense

New federal crime when stolen or counterfeit goods total $5,000 or more across any 12-month period, letting prosecutors charge a network rather than isolated incidents.

MECHANISM 2
Coordination Center

A center within federal law enforcement to coordinate state, local, and federal investigations of organized theft of cargo, shipments, and goods.

MECHANISM 3
Money-Laundering Reach

New penalties for laundering proceeds from selling or transporting stolen or counterfeit goods, targeting the fencing and resale economy behind the crews.

MECHANISM 4
Criminal Forfeiture

Mandatory criminal forfeiture for transporting or selling stolen goods, stripping the financial incentive that sustains the enterprise.

The aggregation offense is the mechanism with the widest reach. By allowing the government to combine the value of stolen or counterfeit goods that total $5,000 or more across any twelve-month period, the bill converts what is today a scatter of sub-felony incidents into a single prosecutable federal enterprise. The coordination center, established within federal law enforcement, addresses the information-sharing failure that lets crews exploit jurisdictional seams: when a network operates across state lines, no single local agency holds the full picture, and the center is meant to assemble it. The money-laundering and forfeiture provisions go after the economics, targeting the resale and fencing layer that turns stolen merchandise back into cash and stripping the proceeds through mandatory forfeiture. The Congressional Budget Office estimates implementing the act would cost roughly $114 million over the 2026 through 2031 period, a modest federal investment relative to the loss figures retailers report.

Why the federal layer matters on top of the state patchwork

States have not been idle on organized retail crime, and a reasonable question is why a federal statute is needed when most states already have ORC or theft-aggregation laws on the books. The answer is that state laws stop at the state line, and ORC networks are explicitly built to cross it. A crew that structures its route to keep each individual theft below a given state's felony threshold, then moves the merchandise across two or three states to a fencing operation in a fourth, is exploiting precisely the coordination gap that no state statute can reach. The federal aggregation offense and the coordination center are designed for the interstate and transnational dimension that the NRF data shows now dominates the threat.

The Enforcement Gap: State Approach vs. the Federal CORCA Model

DimensionState ORC / theft statutes (today)H.R. 2853 federal model
Jurisdictional reachStops at the state line; no authority over the interstate routeInterstate and transnational; built for cross-border networks
AggregationLimited to thefts within the state, where allowed at allCombines value of goods totaling $5,000+ across any 12-month period
CoordinationLocal prosecutors rarely see other jurisdictions' casesFederal coordination center assembles the cross-jurisdiction picture
Financial disruptionVaries; fencing and laundering often untouchedMoney-laundering penalties plus mandatory criminal forfeiture
Data visibilityNIBRS does not isolate ORC from general theft (CRS R48061)A named federal offense creates a basis for a federal count
Unit of proofSingle incident, single store, single dateA pattern across stores, states, and months tied to one enterprise

The shift in the unit of proof is the line in that table that matters most for anyone running a security or loss-prevention program. Under the state model, the evidentiary burden is satisfied by documenting one incident well. Under the federal model, the burden is satisfied by documenting a pattern, which means linking incidents that may be separated by hundreds of miles and several months and showing they belong to the same enterprise. That is a fundamentally different recordkeeping problem, and it is where the detection layer stops being a deterrent and starts being an evidentiary asset.

The detection record beneath a federal ORC prosecution

A federal aggregation case is assembled from contemporaneous records, and the quality of those records is decided at the moment of the event, not in the months afterward when an investigator tries to reconstruct it. This is the part of CORCA that turns from a legal story into an operational one. The conduct ORC crews engage in, staging in back lots before a smash-and-grab, loitering at a loading dock before a cargo theft, entering a restricted yard after hours, repeating the same approach pattern across multiple sites, is exactly the conduct that a proactive detection layer is built to flag in real time and time-stamp as it happens.

Traditional security camera systems record everything and surface nothing until someone goes looking. The footage exists, but it is undifferentiated and unindexed, and pulling a usable clip months later from a multi-store network is a forensic project in itself. A proactive system inverts that: it generates a discrete, time-stamped detection event at the moment an unauthorized person enters a restricted zone, a person loiters past a threshold, or a vehicle appears in a no-park lane. That event is a structured record with a timestamp, a camera location, a confidence score, and an object classification, the connective tissue a prosecutor needs to tie an incident at one site to an incident at another. The companion analysis of how AI video analytics differ from traditional CCTV walks through that architectural shift from recording to real-time detection in detail.

The distinction that keeps this defensible is the same one that runs through every IntelliSee deployment: the system detects objects and events, not identities. It classifies that a person is present in a restricted zone, not who that person is. It does not perform facial recognition, does not store video, and does not build profiles of individuals. For a loss-prevention program that may one day feed a federal case, that architecture is an advantage rather than a limitation, because it produces clean, narrowly scoped event evidence without the privacy and biometric-compliance exposure that identity-based systems carry. The broader treatment of that privacy posture appears in the biometric privacy compliance briefing.

Privacy By Design

Evidence value without identity surveillance

A time-stamped event record showing an unauthorized person in a restricted zone is strong evidence of the conduct without requiring the system to know the person's identity. That is the privacy-by-design line IntelliSee holds: object and event detection, a human in the loop to verify before any response, no facial recognition, and no stored video. A retailer can build the contemporaneous detection trail a federal aggregation case relies on while staying clear of the biometric-privacy statutes that govern identity systems. The evidentiary value comes from the timestamp, the location, and the classification of the event, not from naming anyone.

Where detection fits across the ORC threat surface

Organized retail crime is not one tactic; it is a portfolio. The NRF data shows crews diversifying across in-store theft, cargo and supply-chain theft, and e-commerce fraud, which means the detection layer has to cover several distinct scenes. The grid below maps the most common physical ORC tactics against the detection capability that addresses each, and against the kind of record each generates for a potential federal case.

After-hours intrusion and staging

Perimeter and unauthorized-access detection flags a person entering a back lot, yard, or dock outside operating hours, the staging behavior that precedes a smash-and-grab or cargo theft. Each detection is a time-stamped event tied to a camera location.

Loitering and pre-incident surveillance

Loitering detection surfaces a person lingering at an entrance, dock, or display beyond a set threshold, a recurring pre-incident indicator that, when repeated across sites, helps establish a pattern of coordinated activity.

Cargo and distribution-yard theft

Yard and dock monitoring detects unauthorized vehicles and personnel in logistics environments, the scene where strategic cargo theft and phantom-carrier fraud play out. The companion cargo theft threat-intelligence briefing covers this surface in depth.

Violence during a theft event

The NRF data shows a 17% rise in threats or violence during theft events. Weapon detection and behavioral flags route a verified alert to staff in real time, addressing the worker-safety dimension that increasingly accompanies ORC.

The record each event produces

Every detection is a structured event: timestamp, camera location, object classification, confidence score. That is the connective tissue a federal aggregation case needs to link incidents across stores and months to a single enterprise, without storing video or identifying anyone.

Architecture that stays defensible

Object-and-event detection, a verified human-in-the-loop response, no facial recognition, no stored video, no individual profiling. This is the configuration that produces usable evidence while avoiding the biometric-privacy exposure of identity-based systems, and it is the IntelliSee baseline.

What a retailer or logistics operator should do now

CORCA has passed the House but not yet the Senate, so the operational window is the time to prepare rather than react. The practical preparation is not legal; it is evidentiary. A security and loss-prevention program that wants its records to be usable in a future federal aggregation case should treat detection events as evidence from the moment they are generated, which means a handful of concrete steps.

First, ensure the detection layer produces time-stamped, location-tagged event records, not just raw footage, so that incidents can be indexed and linked rather than searched for after the fact. Second, establish a retention practice for those event records that matches the federal aggregation window, since a twelve-month aggregation period means evidence older than a single quarter may still matter. Third, document the human-verification step for each alert, because a verified detection carries more evidentiary weight than an unverified one and reinforces the human-in-the-loop posture. Fourth, align loss-prevention intake with the coordination-center model, so that when a federal investigator does come asking, the records are already organized around the pattern rather than the single incident. The economic case for that investment, framed as loss-cost reduction, is laid out in the four-variable ROI framework, and the broader sector context appears in the AI retail security sector playbook.

The durable principle. CORCA does not change what organized retail crime is. It changes what counts as a case. A federal aggregation prosecution is built from contemporaneous, time-stamped records that link a pattern of conduct to a single enterprise, and those records are created at the camera and the dock long before a prosecutor sees them. A detection layer that flags events in real time, time-stamps them, keeps a human in the loop, and identifies no one produces exactly that evidence while staying clear of biometric-privacy exposure. Build the program around the record, not around the headline. The IntelliSee team can walk a loss-prevention or security organization through that posture during a structured risk assessment.

Frequently asked questions about CORCA and AI physical security

What is the Combating Organized Retail Crime Act (H.R. 2853)?

It is a federal bill that expands enforcement against organized retail and supply-chain crime. The House passed it 348-60 on May 12, 2026, and it now goes to the Senate. Its core mechanisms are a new federal offense for stolen or counterfeit goods aggregating to $5,000 or more over any 12-month period, a federal coordination center for organized theft of cargo and goods, new money-laundering penalties for proceeds of stolen-goods trafficking, and mandatory criminal forfeiture. The Congressional Budget Office estimates implementation would cost about $114 million over 2026 through 2031.

Has CORCA become law?

Not yet. As of June 2026, H.R. 2853 has passed the House of Representatives but has not been passed by the Senate or signed into law. The House vote on May 12, 2026 sent the bill to the Senate for consideration. Retailers and logistics operators should treat the current period as preparation time rather than assuming the federal regime is already in force.

Why does organized retail crime need a federal law when states already prohibit theft?

Because state laws stop at the state line and ORC networks are built to cross it. A crew can keep each individual theft below a state's felony threshold, then move the merchandise across several states to a fencing operation, exploiting a coordination gap no single state statute reaches. The federal aggregation offense lets prosecutors combine the value of thefts across jurisdictions, and the coordination center assembles the cross-jurisdiction picture that local prosecutors rarely see. There is also a data dimension: the FBI's NIBRS does not isolate ORC from general theft, so without a named federal offense there is no federal count of the conduct.

How does AI detection support a federal organized-retail-crime case?

A federal aggregation case is built from contemporaneous records that link a pattern of conduct to a single enterprise. A proactive detection system generates a discrete, time-stamped event each time it flags an unauthorized person in a restricted zone, loitering past a threshold, or an unauthorized vehicle in a logistics yard. Each event carries a timestamp, a camera location, an object classification, and a confidence score, which is the connective tissue an investigator needs to tie incidents across stores and months to the same network. Traditional CCTV records everything but surfaces nothing until someone searches it months later; proactive detection produces indexed, usable event evidence as the conduct happens.

Does using AI detection for ORC require facial recognition?

No. IntelliSee performs object, posture, and motion-pattern detection. It classifies that a person is present in a restricted zone or that an event is occurring, not who the person is. It does not perform facial recognition, does not store video, and does not build profiles of individuals. The evidentiary value of a detection record comes from the timestamp, the location, and the classification of the event, not from identifying anyone, which keeps the program clear of the biometric-privacy statutes that govern identity-based systems.

What should a loss-prevention program do to prepare for a federal ORC regime?

Treat detection events as evidence from the moment they are generated. Ensure the detection layer produces time-stamped, location-tagged event records rather than only raw footage, retain those records over a window that matches the 12-month federal aggregation period, document the human-verification step for each alert, and organize loss-prevention intake around the pattern of conduct rather than the single incident so the records are ready if a federal investigator comes asking.

How large is the organized retail crime problem?

The National Retail Federation's 2025 study found 67% of surveyed retailers reported a transnational organized-retail-crime group was involved in thefts against their company over the prior year, with more than half reporting increases in phone scams, e-commerce fraud, and physical shoplifting tied to ORC groups, and a 17% rise in threats or violence during theft events. The FBI's 2024 Uniform Crime Reporting summary recorded an 8.9% increase in reported shoplifting even as overall larceny-theft declined. Precise federal totals are unavailable because, as the Congressional Research Service noted, current crime data does not isolate ORC from other theft.

Continue the research

This briefing covers the federal CORCA legislation and the detection record beneath an organized-retail-crime prosecution. For deeper reading on the surrounding threat surface, the privacy architecture, and the economic case:

Request a Risk Assessment

Talk to an IntelliSee security specialist. No sales pitch — a structured conversation about your environment, your threat profile, and whether computer vision is the right fit.

Request a Risk Assessment