Join our Newsletter — 33% off our NHI Course
Home› FAQ› Authentication, Authorisation & Trust› Why do account takeover risks rise when more…
Authentication, Authorisation & Trust

Why do account takeover risks rise when more customers return to online shopping and loyalty programmes?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 26, 2026 Domain: Authentication, Authorisation & Trust

Account takeover risk rises because returning users often log in after long gaps, while attackers can exploit reused passwords, breached credentials, and stale account hygiene. Loyalty balances and stored customer data create immediate value for fraudsters. When digital traffic climbs quickly, merchants also face more noise, making suspicious activity harder to separate from normal reactivation behaviour.

Why customer return waves change the account takeover equation

When shoppers come back after a long gap, security teams lose the benefit of recent behavioural familiarity. Old passwords, old devices, and old recovery settings reappear at the same time that attackers are already testing breached credential sets and credential stuffing against dormant accounts. That combination turns “welcome back” traffic into a larger attack surface, especially when fraudsters are targeting accounts with stored value or saved payment data.

Reactivation also creates a timing problem. A customer who has not logged in for months may trigger password resets, MFA re-enrolment, email change flows, or address updates, and those journeys are exactly where takeover attempts often concentrate. For customer identity programmes, the practical issue is not just authentication strength, but how safely the account is restored to active use after inactivity.

Merchant teams should treat reactivation as a distinct security moment, not just a normal login event, because the account may be more exposed than the user expects and the attacker may only need one weak recovery path.

Why loyalty programmes amplify the fraud incentive

Loyalty accounts are attractive because they are monetisable even when the customer is not directly spending money. Points, miles, vouchers, stored card tokens, profile data, and purchase history can all be converted into immediate value through redemptions, resale, or downstream fraud. If an attacker gets into one account, the objective is often to drain value quickly before the account owner notices.

This is why loyalty security is not just about preventing login compromise. It is also about protecting redemption flows, account recovery, profile edits, and contact details that control where benefits are delivered. A takeover that cannot be easily cash-outed is less attractive to criminals; a takeover that can be redeemed instantly becomes a fast path to loss.

Good customer identity design, including stronger recovery controls and step-up checks on high-value actions, helps reduce the incentive and the blast radius. NHIMG’s Customer IAM (CIAM) Guide covers the controls that matter most here, including account takeover resistance, secure recovery, and step-up authentication.

Why spikes in normal traffic make attacker behaviour harder to spot

When online shopping volumes rise, the signal-to-noise ratio gets worse. More login attempts, more password resets, more legitimate reactivations, and more loyalty redemptions make fraud operations blend into ordinary customer behaviour. Attackers exploit that crowded environment by pacing attempts, spreading them across many accounts, and using familiar-looking patterns that resemble returning-user activity.

This makes detection less about one suspicious event and more about correlation: repeated use of breached credentials, unusual device or geography changes, sudden recovery requests, and abnormal redemption behaviour after a long dormancy period. If monitoring only looks for isolated anomalies, it will miss the combined pattern that reveals takeover in progress.

Teams should also remember that account takeover is often a precursor, not the end state. Once the account is controlled, the attacker may change the email address, add a new device, pivot into stored payment methods, or exploit loyalty value before the customer can intervene.

Risk and Threat Considerations

Return-to-shopping periods create a concentrated fraud window because dormant-account reactivation, breached credential reuse, and loyalty redemption pressure often happen together. The risk is not just more login abuse, but faster monetisation once access is achieved.

Failure mechanism: Attackers test reused or stolen credentials against returning customers, then exploit weak recovery paths, profile-change flows, or redemption journeys to lock in control and extract value before the legitimate user notices.

Impact: Merchants can see direct financial loss, customer support load, false positives that obscure real attacks, and longer-term trust damage if customers believe loyalty balances and stored data are easy to steal.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP ASVS, NIST SP 800-63, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP ASVSV6 — AuthenticationReturning-customer takeovers depend on weak login assurance and reused credentials.
V8 — AuthorizationAttackers abuse post-login actions like profile change and redemption.
Recommendation — Strengthen authentication for high-risk return logins and step up assurance on suspicious access. Restrict sensitive post-login actions behind stronger authorization checks.
NIST SP 800-63Digital Identity GuidelinesThe question centers on authentication and account recovery assurance for consumer logins.
Recommendation — Use phishing-resistant and risk-based identity guidance for reactivation and recovery flows.
CIS Controls v8CIS-5 — Account ManagementDormant customer accounts, recovery paths, and reactivation hygiene are central to takeover risk.
Recommendation — Review dormant accounts, recovery controls, and access paths before peak shopping periods.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementCredential reuse and stale authenticators are a core takeover driver in returning users.
Recommendation — Rotate, expire, and monitor authenticators so stale credentials cannot be reused.

Practitioner Guidance

What to prioritise: Treat dormant-account return, password reset, and first redemption after inactivity as higher-risk moments than routine sign-in. Put step-up checks and anomaly review around those paths first, because that is where takeover usually converts into loss.

What to verify: Confirm that recovery flows cannot be used to silently replace the customer’s email, phone, or device without additional assurance, and make sure high-value loyalty redemption is not possible immediately after a weak reauthentication event.

What good looks like: Legitimate returning customers can regain access without friction that drives abandonment, but attackers cannot move from login to redemption in one low-assurance step.

Practitioner takeaway: The real control problem is not just stopping bad logins, it is preventing a compromised return session from turning quickly into fraud, value extraction, or durable account control.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 26, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org