TL;DR: Corporate account takeover succeeds when attackers borrow an employee’s authority through help desk resets, email compromise, or payment workflows, turning routine business actions into fraud, according to Trusona. The control gap is not credential strength alone but whether identity verification happens at the two chokepoints where requests are trusted.
NHIMG editorial — based on content published by Trusona: Corporate account takeover: why business accounts fall differently
By the numbers:
- Account takeover drew about 4,700 complaints and $359.7 million in losses in the FBI’s 2025 reporting.
- 86% of BEC losses moved by wire or ACH, showing how often the fraud is completed through normal finance processes.
Questions worth separating out
Q: What breaks when corporate account takeover is not blocked at the help desk?
A: The reset process becomes a credential issuance channel for attackers.
Q: Why do employee accounts create disproportionate fraud risk in business environments?
A: Employee accounts carry organisational authority, not just personal access.
Q: How can security teams tell whether identity verification is actually reducing takeover risk?
A: Look for fewer successful resets without strong proof, lower override rates, and fewer downstream payment or privilege changes following recovery events.
Practitioner guidance
- Strengthen recovery and reset assurance Require higher-assurance verification before password resets, MFA rebinds, and account recovery completes.
- Add independent checks to payment workflows Reverify the requester before bank detail changes, beneficiary updates, payroll redirects, and wire release above a defined threshold.
- Treat support channels as identity attack surfaces Train service desk teams to recognise that phone-based or chat-based recovery requests can be the attack entry point.
What's in the full article
Trusona's full blog covers the operational detail this post intentionally leaves for the source:
- The full account-takeover workflow examples for help desk resets, payroll diversion, and wire-release fraud
- The control checks used to verify identity against an external authority rather than a voice or a document image
- The practical signals for detecting SIM swap, port-out, and replay attacks during recovery events
- The finance-oriented detail on how to structure verification before money moves
👉 Read Trusona's analysis of corporate account takeover and identity verification →
Corporate account takeover: what identity teams are missing?
Explore further
Corporate account takeover is fundamentally an identity verification failure, not a password failure. The attacker succeeds when a business process accepts a person’s claim as sufficient proof. That shifts the problem from access control alone into assurance, challenge strength, and workflow governance. For IAM and identity verification programmes, the control question is whether the organisation can prove who is requesting the action at the moment authority is being exercised.
A question worth separating out:
Q: Who should own the controls that stop corporate account takeover?
A: Ownership should be shared across IAM, fraud, finance, and help desk operations because the attack crosses all four. IAM defines assurance, fraud teams monitor payment anomalies, finance enforces dual control, and support teams execute recovery. Accountability fails when any one of those groups treats the risk as someone else’s problem.
👉 Read our full editorial: Corporate account takeover exposes the gap in business identity checks