What Is Account Takeover Fraud?

Financial services organizations need and want to protect their customers’ accounts from unauthorized use, including account takeover fraud

Account takeover fraud (ATO) occurs when an unauthorized person takes control of an account. The fraudster takes steps to actively control the account, for example by applying for a new card or changing the account contact information or password. In this post I’ll talk specifically about account takeover in financial services and the steps that can be taken to detect, prevent and mitigate against it.   


Key Takeaways

  • Account Takeover Is Now a Leading Fraud Category. It represents nearly one in five (18%) of all UK National Fraud Database cases, with 78,000+ reported in 2025. Criminals concentrate on the weakest points, with mobile, online retail, and credit cards making up 90% of filings.
  • The Attack Has Become an Industrialized Supply Chain. Data is harvested in breaches, sold on the dark web, and tested at scale through credential stuffing. AI-powered impersonation, synthetic media, and SIM hijacking now amplify these tactics.
  • Detection Is Hard Once an Account Is Compromised. Because a fraudster presents valid credentials, and first-party fraud also exists, institutions struggle to separate the real account holder from the impostor. This is why credential checks alone are insufficient.
  • Effective Defense Must Be Layered and Adaptive. There is no single fix: adaptive authentication, real-time two-way confirmation, and network analytics each address a different stage. Flexibility lets institutions evolve as fast as the fraudsters.
  • FICO Delivers Layered Protection with Proven Results. FICO® Falcon® Fraud Manager, a Chartis category leader trusted by 10,000+ institutions, uses self-learning analytics to detect fraud in real time. For example, PULSE, a Discover company, achieved a 50% higher detection rate, 40% more fraud dollars blocked, and 25% fewer false positives

According to the CIFAS Fraudscape 2026 report, account takeover now accounts for nearly one in five (18%) of all fraud-risk cases filed to the UK's National Fraud Database, with more than 78,000 cases reported in 2025. Mobile phone accounts, online retail, and personal credit cards together make up 90% of these cases: a clear sign that criminals are concentrating their efforts where authentication can most easily be bypassed.

CIFAS account takeover fraud

Source: Fraudscape 2025 - Cifas

How Account Takeover Fraud Has Evolved: From Manual Methods to High-Tech Attacks

Account takeover fraud is nothing new, but in the past criminals were reliant on more manual ways to collect enough knowledge about a victim in order to access and then take control of their accounts. Traditional ATO methods included: 

  • Trawling through personal trash for financial documents
  • Stealing mail containing account statements or card details
  • Bribing or pressuring financial institution employees to disclose customer data

While these methods are still used now, developments in recent years have made things much easier for the criminals. Today’s world of cybercrime means that fraudsters can buy enough information about people and their finances from the dark web to enable them to take over financial accounts.

The Dark Web as a Marketplace 

The dark web offers a marketplace for data stolen in large-scale breaches, with the volume and richness of available records continuing to grow year on year as criminal networks expand their data harvesting operations. The data available for purchase on the dark web can be very rich including; 

  • Personal information such as date of birth, email address, Social Security number / national ID and phone number
  • Account specific information such as usernames and passwords.

As people frequently use the same passwords across multiple accounts, the theft of one account’s information can make all their accounts vulnerable. 

Testing Stolen Data 

With large volumes of data at their disposal, the fraudsters then need to test it, to find out if they can actually access accounts. Once more, there are old-school and high-tech routes to do this.

  • Credential stuffing:  They can use automated tools to mount mass attempts to access accounts with credential stuffing.
  • Social engineering and telephony channels: The CIFAS Fraudscape 2026 report identifies AI-powered impersonation and synthetic media as escalating threats, alongside the continued targeting of mobile accounts through tactics such as SIM hijacking — enabling criminals to bypass authentication and impersonate legitimate account holders.

What Do Fraudsters Do with Accounts They Have Taken Over?

Fraud exists within a supply chain. The criminals that committed a data breach to access records are not the same criminals that use the data to determine if an account is accessible. Similarly, having tested the data and found the vulnerable accounts, those criminals frequently sell the account records to other fraudsters that then take over the account.

The Quick Cash-Out

What happens next varies. Some fraudsters are looking for a quick return on their investment and simply transfer available funds to accounts in their control – often through the use of networks of money mules.

Systematic Account Compromise

Other fraudsters are playing a longer game, looking to leverage the account they have taken over to maximize gains. This is a process that can include several steps:

  • They establish longer-term control of the account, for example by changing account details such as address, mobile phone number and date of birth.
  • They have a card for the account re-issued with their details and sent to an address (such as a mailbox) they control.
  • They use the account they have taken over to maximize the funds available to them, for example by increasing credit limits or by using the account as a gateway to open more lucrative accounts such as a loan.  Once they judge they have maximized the amount they can obtain before the risk to them becomes too high, they cash out by transferring all the funds to accounts under their control.

When this happens it is extremely difficult for the financial institution to separate the legitimate account holder from the fraudster and determine what account activity was carried out by whom. Financial institutions also have to deal with significant issues of first-party fraud, so can’t make too many assumptions about apparent cases of account takeover.  It can be a long and distressing process for a legitimate accountholder who can’t prove their account ownership.

How Can Financial Institutions Tackle Account Takeover Fraud?

Stopping account takeover fraud means both preventing it from happening and detecting suspicious activity so that intervention can happen.

Strong customer authentication

Identity authentication is a big part of account protection and banks, and other financial institutions place a great deal of emphasis on protecting the log-in process. In the European Union, PSD2 regulation for strong customer authentication is perhaps more frequently associated with checking a customer’s identity when they make a remote payment. However, PSD2 also covers the authentication of account holders when they access or use a payment account — for example, when they login to their bank account, change or add contact information or perhaps add an additional account holder. Any activity on a payment account that increases fraud risk requires strong customer authentication. Financial institutions have many different ways to check that someone using an account is the legitimate accountholder, but to meet the requirements of PSD2 their checks must cover two of three categories:

Strong customer authentication

While account security is of paramount importance, the vast majority of people using accounts are the legitimate account holders. Increasing security to a level that they find using their accounts too difficult provides poor customer experience and can lead to customers changing their account providers. This means that financial institutions must balance the need for security with the need to provide legitimate customers with a good experience and they can do this through a process of adaptive authentication, which allows them to apply the right level of security to every interaction.

Customer communications for confirmation

Once a fraudster has accessed an account the game has not been lost. The more details they change on an account the more control they have, but before they make changes the bank has the contact information for the real accountholder.  As well as authenticating customers wanting to make changes, banks can use real-time, automated, and two-way communications with their customers to confirm such actions are desired.

For example, if a change of address is requested then a text message can be sent to the mobile phone number on record asking the legitimate customer to confirm they want to make the change. If an attempt is made to change a mobile phone number a message through a banking app, email or even by letter, the institution can confirm that such changes are required by the legitimate accountholder.

Understanding criminal networks

Organized crime usually operates on a large scale; fraudsters are looking to take over as many accounts as they can. While this is a threat to a financial institution deemed to have poor defenses, it can also be an opportunity to identify accounts that have been taken over.

As with application fraud, criminals have limited contact information they can use to manage the accounts they are controlling. They recycle mobile numbers, emails, and addresses using the same contact information for multiple accounts under their control. By deploying link analysis across an account portfolio, banks can see where those connections are and use this as evidence to uncover criminal activity. Leveraging network analytics will even uncover connections that are several degrees removed.

Account Takeover Fraud – No Single Fix

The complexity of account takeover fraud means that financial institutions have to take a layered approach to prevention and detection. When and how fraud prevention solutions are deployed must be balanced with other factors such as customer experience and operational costs. Flexibility is key to both creating the necessary balance and evolving at least as fast as the fraudsters can. 

FICO's Solutions for Detecting and Preventing Account Takeover Fraud

Account takeover protection is a core area of emphasis for FICO, which has been recognized by Chartis as a category leader in enterprise fraud management, trusted by more than 10,000 global institutions, underpinned by 30+ years of fraud-fighting experience and 100+ fraud AI and machine-learning patents. FICO enables clients to profile the behavior of individuals, accounts, cards and more in real time across every channel. FICO also enables automated, two-way customer confirmation to validate suspicious activity before a fraudster can establish control. Financial institutions ready to evaluate FICO's account takeover detection capabilities can explore all our enterprise fraud innovations.

How FICO Can Help You Fight Account Takeover Fraud

  • Financial institutions seeking a proven, AI-native approach to account takeover detection can explore FICO® Enterprise Fraud Solution. FICO is a Chartis category leader trusted by more than 10,000 institutions. 
  • Account takeover is now being scaled by AI, from deepfake-enabled attacks to industrial-scale social engineering, yet only 28% of financial institutions have fully deployed AI/ML fraud detection at scale. Research from Finextra, in association with FICO, surveying 202 global fraud, risk, and technology leaders, examines how institutions are responding to AI-driven threats and where critical gaps remain. Read the report: Fraud in the Age of AI.
  • Financial institutions evaluating their account takeover defenses can look to demonstrable results. To discuss how FICO® Enterprise Fraud Solution can strengthen your institution's protection against account takeover, request a consultation with a FICO fraud specialist. 
  • Behind many account takeovers lies the next stage of the crime: moving stolen funds through mule accounts before detection is possible. FICO's white paper, Closing the Back Door: Real-Time Detection Strategies for Fraud Money Mules, examines how these networks operate and how financial institutions can detect and disrupt them. 

This is an update of a post from 2022.


Frequently Asked Questions

Beyond the tactics covered above, risk leaders are watching the rapid scaling of AI-powered impersonation, deepfake-enabled social engineering, and synthetic media, alongside the continued targeting of mobile accounts through SIM hijacking. Because fraudsters increasingly automate and industrialize these attacks, institutions should prioritize real-time, self-learning detection that adapts to new patterns rather than static rules that quickly fall behind.

Effective prevention depends on monitoring behavior continuously across every channel rather than at a single checkpoint. Self-learning analytics that profile the normal behavior of individuals, accounts and cards can flag the subtle deviations that signal a takeover even when valid credentials are presented, enabling intervention before a fraudster establishes control. This is where solutions such as FICO® Enterprise Fraud Solution apply adaptive behavioral analytics to detect anomalies in real time.

When an account is taken over, fraudulent balances and transfers can surface later as apparent delinquencies, inflating charge-offs and complicating recovery because the legitimate account holder disputes activity they did not authorize. Early, upstream detection of compromised cards and merchants, together with clear separation of genuine hardship from fraud, helps institutions reduce non-recoverable losses and avoid pursuing collections on fraud-driven debt.

Data privacy regulations shape how customer and behavioral data can be collected, stored, and analyzed for fraud detection, which directly affects the design of monitoring and authentication systems. Institutions generally need to balance strong customer authentication and real-time behavioral analytics against data-minimization and consent obligations, making explainable, well-governed analytics important for both effectiveness and compliance.

Useful measures include the account detection rate, the share of fraud dollars blocked, false-positive rates, and the time to detect and intervene on a compromised account, all balanced against customer-experience impact.

chevron_left Blog home
RELATED POSTS

Take the next step

Connect with FICO for answers to all your product and solution questions. Interested in becoming a business partner? Contact us to learn more. We look forward to hearing from you.