Account takeover fraud is becoming a more difficult threat for financial institutions to identify as criminals find ways to operate using genuine customer credentials. Once an attacker has successfully accessed an established account, their activity can initially resemble that of the legitimate account holder, making the compromise difficult to spot before money is moved.
For financial institutions, detecting this type of fraud requires more than checking whether a login or individual transaction appears legitimate. ZIGRAM’s analysis points to the value of bringing together different indicators across the customer journey, including unfamiliar devices, shifts in behaviour, changes to passwords and contact details, newly added beneficiaries, unusual transactions and links to potentially risky accounts.
The figures show why this wider visibility matters. Federal Reserve Financial Services recorded more than $15.6bn in US account takeover fraud losses in 2024, compared with $12.7bn in 2023. The Federal Reserve’s 2026 Risk Officer Report also found that 23% of surveyed financial institutions had experienced account takeover activity, representing a seven percentage point increase from the previous year.
The FBI has separately recorded more than 5,100 complaints associated with account takeover fraud since January 2025, with reported losses of more than $262m. The agency has also highlighted cases in which criminals impersonate financial institution support staff to persuade customers to hand over credentials and authentication codes.
Account takeover can involve several stages before the financial impact becomes apparent. The initial compromise may involve phishing, social engineering, credential stuffing, malware, reused passwords or stolen authentication codes. Once credentials have been obtained, criminals can attempt to alter passwords, email addresses or telephone numbers, with SIM swapping potentially allowing them to intercept authentication messages and retain control of the account.
Changes to normal account activity can then provide additional warning signs. An attacker may use an unfamiliar device, alter customer information, create a new beneficiary and subsequently attempt to make a large transfer. Looking at any one of these actions in isolation is unlikely to provide enough evidence of fraud, since legitimate customers can also change devices, update personal details or make unusual payments. The wider sequence of activity can provide more meaningful context around a potential compromise.
The attack can ultimately result in funds being taken from the compromised account. This may happen through unauthorised purchases, cash withdrawals or transfers to other accounts controlled by criminals. Money can also be routed through mule accounts and, according to the FBI, accounts linked to digital asset wallets.
As a result, detecting account takeover requires financial institutions to examine more than suspicious access attempts. Device intelligence can identify access from unfamiliar or unusual devices, while behavioural analytics can identify changes in the way an account is normally used. Monitoring account changes can highlight password resets, amended contact details and new beneficiaries, while transaction monitoring can identify unusual payment values, frequency, destinations and patterns.
Network intelligence can provide further context by connecting activity across accounts, beneficiaries, devices and other entities. A beneficiary receiving money from multiple suspicious accounts, for example, could reveal information about the wider risk associated with a transaction that would not be apparent when looking only at the victim’s account.
The effectiveness of these indicators comes from assessing them collectively rather than treating individual events as proof of fraud. A new device does not necessarily indicate an account takeover, just as a password change or newly added beneficiary does not automatically signal criminal activity. However, several changes occurring close together, particularly when followed by a high-value transfer, can create a much stronger risk signal.
This also demonstrates why authentication cannot provide a complete defence against account takeover. Criminals may obtain legitimate passwords, one-time passcodes and other authentication credentials through techniques such as phishing and social engineering. The resulting login can therefore pass authentication checks even though the individual accessing the account is not the genuine customer.
Financial institutions need to maintain visibility beyond the point of login through continuous, risk-based monitoring. Machine learning can be used to evaluate connected indicators and help prioritise activity for investigation, while behavioural baselines can establish whether account activity remains consistent with a customer’s established patterns.
The risk also extends into broader financial crime activity once funds leave a compromised account. Money can move through mule networks and other accounts associated with fraudulent activity, meaning an account takeover may represent one part of a larger financial crime chain. Linking account takeover monitoring with transaction monitoring, entity intelligence and AML controls can provide institutions with a way to investigate these connections.
This is where more integrated FRAML approaches become relevant. Instead of assessing a compromised account as a standalone incident, financial institutions can follow the movement of funds and examine whether receiving accounts have links to other suspicious activity. Common devices, beneficiaries and transaction patterns can also help connect incidents that might otherwise be investigated separately.
For financial institutions, the challenge is therefore not simply identifying an unusual login or individual suspicious transaction, but understanding how multiple events relate to one another. ZIGRAM’s analysis highlights the role of combining behavioural, device, account, transaction and network intelligence to give fraud teams a broader view of potential compromise. This approach can provide greater context around suspicious activity while helping institutions identify connections between account takeover incidents and wider financial crime activity.
Read the full ZIGRAM analysis.
Copyright © 2026 RegTech Analyst
Copyright © 2026 RegTech Analyst





