Sign in Join
  • HOME
  • Sector Updates
    • Compliance Management
    • Onboarding Verification
    • Financial Crime/Fraud Prevention
    • Identification/Background checks
    • AI & Automation
    • Reporting
    • Transaction Monitoring
    • Communications Compliance
    • Risk Management
    • Cybersecurity/Information Security
  • Legislation Updates
    • KYC
    • AML
    • MiFID II
    • AIFMD
    • Basel III
    • PSD2
    • GDPR
    • Other
  • Features
  • Industry Research
  • Events
    • AML & FinCrime Tech Forum
    • AML & FinCrime Tech Forum USA
    • ESG FinTech Summit
    • Global RegTech Summit – Europe
    • Global RegTech Summit – USA
  • RegTech100
  • Market Maps
    • ESG FinTech
  • Newsletter
  • Courses
    • Professional RegTech Certificate
  • About Us
Sign in
Welcome!Log into your account
Forgot your password?
Sign up
Welcome!Register for an account
A password will be e-mailed to you.
Password recovery
Recover your password
Search
  • Sign in
  • Contact
  • LOG IN
  • REGISTER
Welcome! Log into your account
Forgot your password?
Register for an account
A password will be e-mailed to you.
Recover your password
RegTech RegTech RegTech Analyst
  • HOME
  • Sector Updates
    • Compliance Management
    • Onboarding Verification
    • Financial Crime/Fraud Prevention
    • Identification/Background checks
    • AI & Automation
    • Reporting
    • Transaction Monitoring
    • Communications Compliance
    • Risk Management
    • Cybersecurity/Information Security
  • Legislation Updates
    • KYC
    • AML
    • MiFID II
    • AIFMD
    • Basel III
    • PSD2
    • GDPR
    • Other
  • Features
  • Industry Research
  • Events
    • AML & FinCrime Tech Forum
    • AML & FinCrime Tech Forum USA
    • ESG FinTech Summit
    • Global RegTech Summit – Europe
    • Global RegTech Summit – USA
  • RegTech100
  • Market Maps
    • ESG FinTech
  • Newsletter
  • Courses
    • Professional RegTech Certificate
  • About Us
Home RegTech Cybersecurity/Information Security Account takeover fraud exposes gaps beyond authentication

Account takeover fraud exposes gaps beyond authentication

September 18, 2026
Account takeover fraud exposes gaps beyond authentication

Account takeover fraud is becoming a more difficult threat for financial institutions to identify as criminals find ways to operate using genuine customer credentials. Once an attacker has successfully accessed an established account, their activity can initially resemble that of the legitimate account holder, making the compromise difficult to spot before money is moved.

For financial institutions, detecting this type of fraud requires more than checking whether a login or individual transaction appears legitimate. ZIGRAM’s analysis points to the value of bringing together different indicators across the customer journey, including unfamiliar devices, shifts in behaviour, changes to passwords and contact details, newly added beneficiaries, unusual transactions and links to potentially risky accounts.

The figures show why this wider visibility matters. Federal Reserve Financial Services recorded more than $15.6bn in US account takeover fraud losses in 2024, compared with $12.7bn in 2023. The Federal Reserve’s 2026 Risk Officer Report also found that 23% of surveyed financial institutions had experienced account takeover activity, representing a seven percentage point increase from the previous year.

The FBI has separately recorded more than 5,100 complaints associated with account takeover fraud since January 2025, with reported losses of more than $262m. The agency has also highlighted cases in which criminals impersonate financial institution support staff to persuade customers to hand over credentials and authentication codes.

Account takeover can involve several stages before the financial impact becomes apparent. The initial compromise may involve phishing, social engineering, credential stuffing, malware, reused passwords or stolen authentication codes. Once credentials have been obtained, criminals can attempt to alter passwords, email addresses or telephone numbers, with SIM swapping potentially allowing them to intercept authentication messages and retain control of the account.

Changes to normal account activity can then provide additional warning signs. An attacker may use an unfamiliar device, alter customer information, create a new beneficiary and subsequently attempt to make a large transfer. Looking at any one of these actions in isolation is unlikely to provide enough evidence of fraud, since legitimate customers can also change devices, update personal details or make unusual payments. The wider sequence of activity can provide more meaningful context around a potential compromise.

The attack can ultimately result in funds being taken from the compromised account. This may happen through unauthorised purchases, cash withdrawals or transfers to other accounts controlled by criminals. Money can also be routed through mule accounts and, according to the FBI, accounts linked to digital asset wallets.

As a result, detecting account takeover requires financial institutions to examine more than suspicious access attempts. Device intelligence can identify access from unfamiliar or unusual devices, while behavioural analytics can identify changes in the way an account is normally used. Monitoring account changes can highlight password resets, amended contact details and new beneficiaries, while transaction monitoring can identify unusual payment values, frequency, destinations and patterns.

Network intelligence can provide further context by connecting activity across accounts, beneficiaries, devices and other entities. A beneficiary receiving money from multiple suspicious accounts, for example, could reveal information about the wider risk associated with a transaction that would not be apparent when looking only at the victim’s account.

The effectiveness of these indicators comes from assessing them collectively rather than treating individual events as proof of fraud. A new device does not necessarily indicate an account takeover, just as a password change or newly added beneficiary does not automatically signal criminal activity. However, several changes occurring close together, particularly when followed by a high-value transfer, can create a much stronger risk signal.

This also demonstrates why authentication cannot provide a complete defence against account takeover. Criminals may obtain legitimate passwords, one-time passcodes and other authentication credentials through techniques such as phishing and social engineering. The resulting login can therefore pass authentication checks even though the individual accessing the account is not the genuine customer.

Financial institutions need to maintain visibility beyond the point of login through continuous, risk-based monitoring. Machine learning can be used to evaluate connected indicators and help prioritise activity for investigation, while behavioural baselines can establish whether account activity remains consistent with a customer’s established patterns.

The risk also extends into broader financial crime activity once funds leave a compromised account. Money can move through mule networks and other accounts associated with fraudulent activity, meaning an account takeover may represent one part of a larger financial crime chain. Linking account takeover monitoring with transaction monitoring, entity intelligence and AML controls can provide institutions with a way to investigate these connections.

This is where more integrated FRAML approaches become relevant. Instead of assessing a compromised account as a standalone incident, financial institutions can follow the movement of funds and examine whether receiving accounts have links to other suspicious activity. Common devices, beneficiaries and transaction patterns can also help connect incidents that might otherwise be investigated separately.

For financial institutions, the challenge is therefore not simply identifying an unusual login or individual suspicious transaction, but understanding how multiple events relate to one another. ZIGRAM’s analysis highlights the role of combining behavioural, device, account, transaction and network intelligence to give fraud teams a broader view of potential compromise. This approach can provide greater context around suspicious activity while helping institutions identify connections between account takeover incidents and wider financial crime activity.

Read the full ZIGRAM analysis.

Read the daily RegTech news

Copyright © 2026 RegTech Analyst

Enjoyed the story? 

Subscribe to our weekly RegTech newsletter and get the latest industry news & research

Copyright © 2026 RegTech Analyst

Investors

The following investor(s) were tagged in this article.

  • TAGS
  • Account Takeover Fraud
  • AML
  • Anti-Fraud
  • ATO fraud
  • behavioural analytics
  • credential theft
  • CyberTech
  • financial crime.
  • FRAML
  • Fraud prevention
  • identity and access management
  • mule accounts
  • RegTech
  • transaction monitoring
  • ZIGRAM
Previous articleMIND scores $72m to outrun AI-era data risks
Next articleCan financial services overcome the barriers to AI adoption?
msnaylam

RELATED ARTICLESMORE FROM AUTHOR

casinos
Companies

Why cutting compliance budgets could cost casinos more

Napier AI brings fincrime tools to Microsoft Marketplace
Companies

Napier AI brings fincrime tools to Microsoft Marketplace

AML
AML

AML screening gets an early-warning upgrade

Latest Analysis

Illicit gold puts banks on the AML front line
Advisors

Illicit gold puts banks on the AML front line

September 01, 2026
How CARF is reshaping digital asset reporting
Cryptocurrencies

How CARF is reshaping digital asset reporting

July 30, 2026
Companies

Mastercard launches CBDC partner programme

August 21, 2023
Companies

Spending on RegTech expected to reach $130bn by 2025

March 30, 2021
Advisors

FinTech community welcomes UK FinTech review but fear more must be...

February 26, 2021
  • Term & Conditions
  • Privacy Policy
  • RegTech Analyst’s Editorial mission
  • Contact Us
© Copyright 2026 RegTech Analyst. All Right Reserved

50,000+ RegTech leaders get exclusive industry stories delivered every week

MORE STORIES
SilverSky secures funding to bolster its global Managed xDR strategy
Cybersecurity/Information Security

SilverSky secures funding to bolster its global Managed xDR strategy

April 18, 2024
Cybersecurity/Information Security

Wiz said to raise a further $120m, just months after closing...

May 28, 2021