Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Account recovery and ATO risk: are your controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19563
Topic starter  

TL;DR: Account takeover now exploits recovery workflows, help desks, and exception paths rather than login screens, according to Trusona, with 83% of organisations reporting at least one ATO attack last year and criminals stealing more than $262 million in 2025. Verification must replace trust because legacy signals such as email, phone possession, and knowledge-based answers are no longer reliable.

NHIMG editorial — based on content published by Trusona: A CISO's guide to prevent account takeovers

By the numbers:

Questions worth separating out

Q: How should security teams reduce fraud risk in account recovery workflows?

A: Security teams should require multiple independent proofs for recovery actions, especially when the action can move money, change credentials, or restore access.

Q: Why do email and phone-based identity checks fail in ATO attacks?

A: Email and phone possession are no longer strong proof of identity because attackers can buy breached data, intercept codes through SIM swaps, or impersonate victims with deepfake-assisted pretexts.

Q: What breaks when recovery workflows are treated as convenience features?

A: Support teams end up making identity decisions without the controls normally applied to authentication or authorisation.

Practitioner guidance

What's in the full article

Trusona's full article covers the operational detail this post intentionally leaves for the source:

  • The account recovery and support workflow examples that show where impersonation typically succeeds.
  • The practical deployment pattern for adding authoritative identity verification without redesigning the entire identity stack.
  • The fraud, customer experience, and incident response angles that matter once recovery abuse has already occurred.
  • The product-specific implementation guidance for securing high-risk workflows such as resets, privileged actions, and external portals.

👉 Read Trusona's guide to preventing account takeover through recovery workflows →

Account recovery and ATO risk: are your controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19154
 

Account recovery is now a governed access path, not a support function. Organisations still design recovery as an operational exception, but attackers treat it as the fastest route to trusted access. Once that path is abused, the issue is not authentication failure at the login screen. The issue is that the identity programme allowed a lower-assurance pathway to issue higher-assurance access, which means recovery governance now belongs in IAM and fraud control together.

A few things that frame the scale:

A question worth separating out:

Q: Who is accountable when a fraudulent recovery or approval occurs?

A: Accountability sits with the organisation that designed the workflow and the controls that govern it. If a recovery or approval path allowed action without adequate verification, that is a governance failure, not just a user mistake. Frameworks such as NIST Cybersecurity Framework 2.0 help teams assign control ownership and review the process.

👉 Read our full editorial: Account recovery has become the new ATO attack surface



   
ReplyQuote
Share: