Account takeover happens when a criminal logs into an account that is not theirs, using credentials that were bought, guessed or phished. This post covers what drives ATO fraud, why passwords and SMS codes no longer hold on their own, and which controls actually stop an attacker at the login screen.
The FBI’s Internet Crime Complaint Center logged 1,008,597 complaints in 2025, up from 859,532 the year before, and phishing and spoofing were the most frequently reported category of all. Those campaigns exist to harvest one thing, a working username and password. Once a criminal has that pair, nothing needs to be broken into. They simply log in as you. That is account takeover fraud, and it is what this post is about.
What is Account Takeover Fraud?
Account takeover (ATO) fraud is the type of identity fraud that involves unauthorized criminal access to a user’s account to use it for some type of personal and financial gain. The increased presence of people on the internet and involvement in activities like online shopping and banking and convenient funds transfer has opened new opportunities for criminals looking to make extra cash.
Account takeover fraud can involve the exploitation of multiple types of online accounts. The accounts criminals go after tend to fall into four groups.
- Online banking accounts, where the goal is a transfer out to an account the criminal controls.
- E-commerce accounts, where stored card details and saved addresses turn into free goods.
- Mobile and wallet accounts, where a provisioned card can be spent in a shop the same day.
- Social media accounts, which get used to ask the victim’s family and friends for money.
Ecommerce platforms are the most profitable for criminals due to frictionless payment systems. In e-commerce sites, due to instant purchase functionality, all the billing information is stored in the user account, which makes it convenient for customers to make purchases. But it also makes it easy for criminals to simply change the shipping address and start making a purchase once they discover the login credentials.
Impact of ATO frauds
Account takeover fraud rates have been on the rise for the last few years. Every year the individuals and businesses incur huge losses due to ATO frauds. Mostly customers are the ones who endure monetary losses. In addition, in most cases, they not only lose time in resolving fraud but also suffer a damaged reputation and relationships, for example, in the case of social media account takeover. Businesses, however, suffer losses in the form of chargebacks and bruised reputation.
The shape of the problem is easier to see in aggregate. UK Finance recorded 3.81 million unauthorised fraud cases in 2025, up 11 per cent on the year, while the value of those losses fell 5 per cent to £703.4 million. More people are being hit, for less each time. That is a volume business, and volume businesses run on automation.
KREM2 reported a case of ATO fraud in which the victim, “Allie Raye”, was not aware of the fraud until she started receiving shipping notices and orders from Amazon. Even after discovering it, it was very difficult for her to stop the fraudulent orders, which included several gift cards. It took her around three weeks to regain control of her account. Amazon absorbed the loss and refunded her in full.
Factors Fueling ATO Frauds
Account takeover fraud is a serious concern not only for the individuals but businesses as well. The technological innovations have made the fraudsters more sophisticated in accessing users’ information. There are multiple factors that are fueling ATO frauds, some of them are:
Data breaches
One of the main driving factors behind account takeover frauds is the increasing trend of data breaches. The purpose of a data breach is to access the records of the customers containing their information, for example, usernames, passwords, account numbers, and card numbers. The list obtained from the breach is sold on the black market, where cybercriminals are readily looking for users’ data.
When the username and password of an account are known, hackers try the same combination on multiple online platforms through various automated tools, known as credential stuffing. The attack works on reuse. One breach at a retailer becomes a working key at a bank, a marketplace, and an email provider, because the same pair was used at all four. An attacker does not need a high hit rate when the list runs to millions of rows, and the attempts cost almost nothing.
Weak Password Practices and Inefficient Authentication
More online presence of individuals means more accounts. It means users have to remember all the usernames and passwords for different accounts. The difficulty of memorizing them encourages users to set the same passwords for multiple accounts. This is a very common yet highly risky practice.
Most of the organizations still rely on the binary authentication method, using a username and a password. Anyone having access to those credentials can easily log in to the account and do whatever they want. This is one of the main reasons for account takeover.
Social Engineering Tactics
The advent of technology has significantly provided fraudsters and imposters with advanced social engineering tactics, and phishing is one of them. Through phishing attacks, cybercriminals are accessing user credentials by tricking the users. There are multiple ways through which these attacks can occur, including through email, text message, or even over the phone. However, the purpose is the same, trying to get the users to hand over their information.
An example of such an attack is receiving an email that persuades you to click the link and prompt the login page to enter your credentials on a login page, which are stolen by criminals.
What has changed is the production cost. For the first time in its history, the IC3 report carries a section on artificial intelligence, covering 22,364 complaints and close to $893 million in losses in 2025. The tactics it lists are fake social profiles, cloned voices, forged identity documents and convincing video of people the victim knows. A phishing call that used to fail on a wrong accent now arrives in the voice of the victim’s bank manager.
Threat by Device
Another factor that is driving the ATO fraud threat is through smart devices. Mobiles and mobile applications are prime targets of cybercriminals for ATO fraud. One of the major reasons for this is the technology lag. Regardless of advanced tools designed to protect users on web browsers, those tools do not work for mobile apps at the same time.
The wallet is now the prize. UK Finance reported that in 2025 criminals were compromising one-time passcodes in order to register cards to digital wallets they controlled, or to push transactions straight through. A stolen card number used to need a checkout page. Provisioned into a wallet, it works in a shop.
How to Prevent ATO Frauds?
Most prevention advice treats these controls as a stack where more is better. They are not interchangeable. Each one closes a specific door and leaves the others open, so it is worth being precise about which attack each control actually stops.
| Control | Stops credential stuffing | Stops real-time phishing | Stops SIM swap and OTP theft | Stops deepfake or injected video | Friction for the user |
| Username and password only | No | No | No | Not applicable | Low |
| SMS one-time passcode | Yes | No, the code is relayed live | No | Not applicable | Low |
| Authenticator app code | Yes | No, the code is relayed live | Yes | Not applicable | Low |
| Passkey or FIDO2 security key | Yes | Yes, the credential is bound to the domain | Yes | Not applicable | Low once enrolled |
| Device and behavioural signals | Partly, flags anomalies | Partly | Partly | No | None, runs passively |
| Face verification with liveness | Yes | Yes | Yes | Only with certified presentation and injection attack detection | Medium, used at high-risk events |
Identity Verification at the Time of Onboarding
No doubt ATO fraud is a major concern for businesses, especially for ecommerce, however, it can be prevented using proper user verification at the time of onboarding. Sometimes after committing the ATO fraud, the fraudsters use that information of the user to create another account. Through digital identity verification services, businesses can confirm the identity of real users and hinder the fraudster from creating fake accounts, which is identity theft.
Identity Authentication
The main factor that fuels ATO fraud is the lack of proper authentication checks. In this world of no trust, stealing someone’s credentials is no longer a difficult task. By applying social engineering, fraudsters can trick users into providing their information. If online businesses adopt stronger authentication such as two-factor authentication and biometric verification through face verification, account takeover fraud can be prevented.
Users who fail to verify and authenticate their identity can be hindered from accessing the account in real time.
Phishing-Resistant Authentication and Passkeys
Two-factor authentication is a floor, not a ceiling. A one-time passcode still has to be typed in, which means it can be asked for. Attackers run a proxy that sits between the victim and the real login page, collects the code the moment it is entered, and uses it within its validity window. The victim sees a normal login. The criminal sees a live session.
A passkey removes the thing that can be handed over. The credential is bound to the domain it was created for and never leaves the device, so a lookalike domain gets nothing to relay. Where passkeys are not yet available to your users, an authenticator app is a meaningful step up from SMS, because it at least survives a SIM swap.
Monitoring Payments
ATO frauds are mostly committed to gain monetary benefit. Frictionless mobile and online payments are no doubt improving the user experience, but at the same time they are grabbing the attention of cybercriminals. Whenever imposters take over an account, a bank account for instance, the first thing they do is transfer money to their own account.
Due to a lack of payment monitoring or authentication before processing transactions, cybercriminals are successful in making fraudulent payments. Monitoring the payment every time a user requests a transaction can combat fraudsters in real time. The signals worth watching are the ones a legitimate customer rarely produces at once: a new device, a changed delivery address, and a high-value order in the same session.
Face Verification, A Strong Control Against ATO Frauds
Face verification is a form of biometric verification powered by artificial intelligence and machine learning. Traditional verification and authentication checks have failed to prevent fraudsters from accessing users’ data and personally identifiable information (PII). Integrating a face verification API with existing platforms can identify fraudsters who try to enter the system through spoofing.
The part that decides whether this works is liveness. Face matching on its own compares two images, and an attacker with a photograph, a replayed video, or a generated face can satisfy that comparison. Presentation attack detection checks that a real person is in front of the camera. Injection attack detection checks that the frames reaching your server came from that camera rather than from a virtual one. Ask any vendor which of the two they do, and which independent testing they have been through.
How Shufti Helps Stop Account Takeover at Login
Account takeover is a re-verification problem more than an onboarding problem. The person who passed your checks at sign-up is not necessarily the person logging in eight months later, and a password proves nothing about which of the two it is. Shufti runs biometric face authentication against the identity captured at onboarding, with liveness and presentation attack detection in the same call, so a high-risk event such as a password reset, a new device or a payout request can be gated on the actual person rather than on something they know. Verification returns in under three seconds, at 99.8 per cent accuracy, across 240+ countries and territories and more than 10,000 document types.
Frequently Asked Questions
What is account takeover fraud?
Account takeover fraud is unauthorised access to an account that already belongs to someone else, used for financial or personal gain. The criminal does not create a new identity. They use credentials obtained through a breach, a phishing message or a guessed password to log in as the real account holder.
How do fraudsters get the credentials in the first place?
Three routes dominate. Data breaches put username and password pairs into circulation. Credential stuffing then replays those pairs across other sites, which works because people reuse them. Social engineering covers the rest, where the victim is persuaded to hand the details over directly through a phishing email, a text or a phone call.
Is two-factor authentication enough to stop account takeover?
Not on its own. Two-factor authentication stops credential stuffing, because a stolen password alone no longer gets an attacker in. It does not stop real-time phishing, where a proxy collects the one-time passcode as the victim types it and uses it immediately. Passkeys close that gap because the credential is tied to the legitimate domain and cannot be relayed.
How is account takeover different from identity theft?
Identity theft is the broader category, covering any misuse of someone's personal data. Account takeover is one form of it, where the target is an account that already exists. The related pattern is application fraud, where stolen data is used to open a new account rather than to enter an existing one.
Can deepfakes be used to take over an account?
Yes, and the pressure point is account recovery rather than login. Cloned voices are used against call centre agents and against voice authentication, and generated video is used against face checks that match images without testing for liveness. The FBI recorded 22,364 artificial intelligence-related complaints in 2025, with losses of nearly $893 million. Presentation and injection attack detection are what separate a face check that resists this from one that does not.















