Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Account takeover fraud: are your identity controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15754
Topic starter  

TL;DR: Account takeover fraud is rising fast, with 62% of businesses saying they are losing more money to ATO than before and projected losses reaching $91 billion by 2028, according to Fingerprint. The problem is not just stolen credentials but the control gap between authentication, device trust, and high-risk action approval.

NHIMG editorial — based on content published by Fingerprint: Account takeover fraud prevention and detection guidance

By the numbers:

Questions worth separating out

Q: How should banks reduce account takeover risk without making login unusable?

A: Use risk-based authentication so low-risk sessions stay friction-light while suspicious logins trigger stronger checks.

Q: Why do stolen credentials still matter in environments with MFA?

A: Stolen credentials matter because they are often the first step in a chain that ends with social engineering or MFA fatigue.

Q: What breaks when organisations rely only on password policies to stop ATO?

A: Password policy alone does not stop credential stuffing, phishing reuse, malware theft, or already-compromised accounts.

Practitioner guidance

  • Block known-compromised credentials Use password breach checks and deny authentication when a password appears in known breach corpora or credential dumps.
  • Add risk-based step-up for sensitive actions Require additional verification for password changes, payout events, new-device logins, and other high-risk account actions.
  • Tune login rate limits and lockout logic Apply progressive delays and rate limits that slow brute force and stuffing without creating unnecessary lockout pressure on normal users.

What's in the full article

Fingerprint's full article covers the operational detail this post intentionally leaves for the source:

  • Step-by-step prevention guidance for password policy, MFA, rate limiting, and step-up authentication.
  • Examples of device intelligence and browser-level signals used to spot suspicious account activity.
  • Operational guidance on sandboxing and user-facing account transparency features that reduce fraud impact.
  • Source-side discussion of how Fingerprint's visitor identification approach fits into an ATO defence stack.

👉 Read Fingerprint's full guide to account takeover fraud prevention →

Account takeover fraud: are your identity controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 15339
 

Password-only authentication is now a broken assumption for account security. ATO succeeds because a valid credential is treated as proof of legitimate intent, even though the credential may be stolen, reused, or bought. That assumption was designed for a world where the password was the primary trust signal. The implication is that IAM programmes must stop treating authentication success as the end of the decision path.

A question worth separating out:

Q: Who is accountable when account takeover succeeds despite verification controls?

A: Accountability sits across identity, fraud, and operations, because takeover usually exploits a gap between onboarding, monitoring, and transaction decisioning. If a business relies on one team to verify the customer and another to catch abuse later, the attacker can move through the handoff. Governance should assign ownership across the full account lifecycle.

👉 Read our full editorial: Account takeover fraud exposes the limits of password-only IAM



   
ReplyQuote
Share: