TL;DR: Account takeover now exploits recovery workflows, help desks, and exception paths rather than login screens, according to Trusona, with 83% of organisations reporting at least one ATO attack last year and criminals stealing more than $262 million in 2025. Verification must replace trust because legacy signals such as email, phone possession, and knowledge-based answers are no longer reliable.
NHIMG editorial — based on content published by Trusona: A CISO's guide to prevent account takeovers
By the numbers:
- In 2025, criminals stole more than $262 million through account takeover schemes.
- 83% of organisations experienced at least one account takeover attack last year.
- 82% of phishing emails are now AI-generated., generated.
Questions worth separating out
Q: How should security teams reduce fraud risk in account recovery workflows?
A: Security teams should require multiple independent proofs for recovery actions, especially when the action can move money, change credentials, or restore access.
Q: Why do email and phone-based identity checks fail in ATO attacks?
A: Email and phone possession are no longer strong proof of identity because attackers can buy breached data, intercept codes through SIM swaps, or impersonate victims with deepfake-assisted pretexts.
Q: What breaks when recovery workflows are treated as convenience features?
A: Support teams end up making identity decisions without the controls normally applied to authentication or authorisation.
Practitioner guidance
- Harden recovery as a high-risk access path Apply stronger verification to password resets, account unlocks, and recovery escalation flows before credentials or factors are reissued.
- Replace weak proofing signals Retire knowledge-based questions and phone-possession checks for sensitive workflows, and use authoritative identity validation where the business impact of impersonation is high.
- Instrument support decisions for auditability Log who approved each recovery or privileged change, what evidence was used, and whether step-up verification was required.
What's in the full article
Trusona's full article covers the operational detail this post intentionally leaves for the source:
- The account recovery and support workflow examples that show where impersonation typically succeeds.
- The practical deployment pattern for adding authoritative identity verification without redesigning the entire identity stack.
- The fraud, customer experience, and incident response angles that matter once recovery abuse has already occurred.
- The product-specific implementation guidance for securing high-risk workflows such as resets, privileged actions, and external portals.
👉 Read Trusona's guide to preventing account takeover through recovery workflows →
Account recovery and ATO risk: are your controls keeping up?
Explore further
Account recovery is now a governed access path, not a support function. Organisations still design recovery as an operational exception, but attackers treat it as the fastest route to trusted access. Once that path is abused, the issue is not authentication failure at the login screen. The issue is that the identity programme allowed a lower-assurance pathway to issue higher-assurance access, which means recovery governance now belongs in IAM and fraud control together.
A few things that frame the scale:
- 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: Who is accountable when a fraudulent recovery or approval occurs?
A: Accountability sits with the organisation that designed the workflow and the controls that govern it. If a recovery or approval path allowed action without adequate verification, that is a governance failure, not just a user mistake. Frameworks such as NIST Cybersecurity Framework 2.0 help teams assign control ownership and review the process.
👉 Read our full editorial: Account recovery has become the new ATO attack surface