TL;DR: Account takeover through impersonation of financial institution support accounted for roughly 4,700 complaints and $359.7 million in losses in 2025, while business email compromise reached $3.05 billion and 86% of those losses moved by wire or ACH, according to Trusona’s analysis of FBI IC3 data. The control gap is no longer login security but verification of the conversation itself, especially in customer support and payment approval flows.
NHIMG editorial — based on content published by Trusona: Account takeover protection for financial services: call centers, wire approvals, and the calls in between
By the numbers:
- Account takeover fraud via impersonation of financial institution support accounted for roughly 4,700 complaints and $359.7 million in losses in 2025.
- Business email compromise reached $3.05 billion across 24,768 complaints, with 86% of those losses moving by wire transfer or ACH.
Questions worth separating out
Q: What breaks when banks rely on phone conversations to approve high-risk account changes?
A: Phone-based approval breaks when the attacker can spoof identity, reuse breached customer data, or clone a familiar voice.
Q: Why do customer recovery flows create more identity risk than normal login?
A: Customer recovery often happens when the account holder is locked out, stressed, or under time pressure, which makes social engineering easier.
Q: What do security teams get wrong about wire fraud controls?
A: Many teams focus on the authenticity of the message instead of the authenticity of the approval.
Practitioner guidance
- Separate request and verification channels for high-risk actions Require out-of-band confirmation for wires, vendor banking changes, customer recovery, and executive approvals so the approval channel cannot be the same channel the attacker controls.
- Replace conversational approval with evidence-based verification Use verification methods that bind the request to a specific identity and transaction, and ensure agents cannot override the result without logged escalation.
- Define a distinct control for customer recovery flows Treat customers, not employees, as the primary population in support verification.
What's in the full article
Trusona's full blog covers the operational detail this post intentionally leaves for the source:
- How the call-verification workflow is structured for customer support and outbound impersonation scenarios.
- The specific approval-threshold design used to pause high-value wire requests before release.
- The operational differences between customer recovery, executive verification, and vendor banking-change checks.
- Example implementation detail for independent verification when the requester has never enrolled a prior factor.
👉 Read Trusona's analysis of account takeover protection for financial services →
Call center impersonation and wire approvals: what controls still fail?
Explore further
Conversation-level identity assurance is now a financial control, not a support convenience. Financial institutions have hardened authentication at login, but the article shows that the highest-risk moments are recovery calls, payment approvals, and banking-detail changes. Those decisions still depend on a human accepting a story as evidence. For IAM and PAM programmes, that means the control boundary must extend into verification of the interaction itself. The practitioner conclusion is clear: approval workflows need independent identity proof, not just policy language.
A question worth separating out:
Q: Who is accountable when impersonation fraud succeeds in a regulated bank?
A: Accountability usually spans fraud operations, IAM or identity verification owners, and the business process owner for the approval flow. The key governance question is whether the institution can show what evidence was collected, who approved the exception, and why the action was permitted under policy and regulatory review.
👉 Read our full editorial: Account takeover fraud in financial services needs stronger call verification