TL;DR: Account takeover is both a security intrusion and a fraud event, but most organisations split ownership between teams that measure different outcomes, according to Sift’s Q2 2026 Digital Trust Index and related analysis. That seam lets attackers move from credential abuse to cash-out while accountability disappears, making cyber-fraud fusion a governance issue, not just an operations issue.
NHIMG editorial — based on content published by Sift: Account Takeover Cybersecurity Has a Fraud Problem Part 1: The Gap Nobody Owns
By the numbers:
- In Sift’s Q2 2026 Digital Trust Index, 22% of consumers reported experiencing an account takeover in the past year.
- Global e-commerce fraud losses are projected to reach $107 billion a year by 2029, according to Sift.
- One loyalty fraud ring in Sift’s Q2 2026 report spanned more than 90 businesses, generated roughly 13,000 attempted transactions, and produced over 100 fraudulent chargebacks.
Questions worth separating out
Q: What breaks when account takeover is split between security and fraud teams?
A: The attack runs through the gap between intrusion response and loss prevention.
Q: Why do account takeovers create a data-governance problem as well as an identity problem?
A: Because the attacker inherits the user’s existing permissions, so the true risk is not only who signed in, but what that identity can reach.
Q: How do security teams know whether ATO controls are actually working?
A: Effective ATO controls reduce successful abuse across recovery, step-up, and session channels, not only failed logins.
Practitioner guidance
- Map the compromise-to-cash-out flow Document the exact sequence from credential abuse or session hijack through payout changes, withdrawals, refunds, and chargebacks so one owner can see where loss begins.
- Unify login and transaction telemetry Correlate authentication events, device signals, and post-login monetary actions in one workflow so security and fraud teams investigate the same case record.
- Assign shared ownership for ATO cases Create a named incident owner who is accountable from initial compromise through financial resolution, instead of handing the case off once the login alert is closed.
What's in the full article
Sift's full article covers the operational detail this post intentionally leaves for the source:
- How Sift breaks down the CISO view versus the fraud leader view of the same account takeover chain
- The specific metrics behind Sift's Q2 2026 Digital Trust Index and what changed across the year
- Practical examples of how compromise turns into chargebacks, withdrawals, and payout abuse
- The follow-on articles in the series that outline a shared operating model for security and fraud teams
👉 Read Sift's analysis of why account takeover exposes the security and fraud ownership gap →
Account takeover: what happens when no team owns the full chain?
Explore further
Account takeover is a governance failure as much as a security incident. The article is right to frame ATO as a single chain that crosses teams, because the business impact appears after authentication, not at the login screen. Security programmes that stop at intrusion response leave the loss-making phase unowned. For identity governance, the key point is that assurance must extend into post-authentication actions, not just access grant decisions.
A question worth separating out:
Q: Who should be accountable when an account takeover affects customer or brand accounts?
A: Accountability should sit with the identity, security, and business owners together, because the impact crosses authentication, fraud, and reputation. Frameworks such as the NIST Cybersecurity Framework 2.0 help organisations assign ownership across identify, protect, detect, respond, and recover functions.
👉 Read our full editorial: Account takeover exposes the security and fraud ownership gap