Account takeover fraud is becoming harder for financial institutions to detect as criminals increasingly operate through legitimate customer credentials. A valid login, established account and routine profile changes can make malicious activity appear genuine, allowing attackers to gain control before an obviously fraudulent transaction takes place.
For financial institutions, this means detection needs to extend beyond authentication and individual transaction checks. ZIGRAM’s analysis highlights the importance of combining signals across the customer journey, including unfamiliar devices, behavioural changes, password and contact-detail updates, new beneficiaries, unusual transactions and connections to potentially risky accounts.
The scale of the threat illustrates why greater visibility is needed. Federal Reserve Financial Services reported more than $15.6bn in US account takeover fraud losses during 2024, up from $12.7bn in 2023. Its 2026 Risk Officer Report also found that 23% of surveyed financial institutions had experienced account takeover activity, an increase of seven percentage points year-on-year.
The FBI has separately reported more than 5,100 complaints linked to account takeover fraud since January 2025, involving losses exceeding $262m. It has warned that criminals are increasingly impersonating financial institution support staff to obtain credentials and authentication codes.
Account takeover generally develops through a series of connected stages. Criminals can first compromise credentials through phishing, social engineering, credential stuffing, malware, password reuse or stolen authentication codes. Once inside an account, they may change passwords, email addresses or telephone numbers, potentially using SIM swapping to intercept authentication messages and make it harder for the legitimate customer to regain control.
The next stage is often a change in account behaviour. An attacker might access the account from an unfamiliar device, modify customer information, add a new beneficiary and then initiate an unusually large transfer. None of these actions independently proves that fraud has occurred, as legitimate customers can also change devices, update their details or make unusual payments. The sequence and combination of events can provide a stronger indication that an account has been compromised.
The final objective is usually to extract or move funds. Criminals may make unauthorised purchases, withdraw money or transfer funds to other accounts under their control. These destinations can include mule accounts and, according to the FBI, accounts connected to digital asset wallets.
This makes account takeover detection a broader exercise than identifying suspicious logins. Device intelligence can highlight unfamiliar or unusual access, while behavioural analytics can identify changes in how a customer normally interacts with an account. Account-change monitoring can flag password resets, contact-detail changes and new beneficiaries, while transaction monitoring can identify unusual values, velocity, destinations and payment patterns.
Network intelligence adds another layer by examining the relationships between accounts, beneficiaries, devices and other entities. A newly added beneficiary that has received funds from several suspicious accounts, for example, may provide additional context that would not be visible from the victim account alone.
The key is to assess these signals together. A new device is not necessarily suspicious, nor is a password reset or new beneficiary. But when several changes occur within a short period, particularly before a high-value transfer, the combined risk can become considerably more significant.
This also highlights a limitation of authentication as a standalone defence. Attackers can obtain genuine passwords, one-time passcodes and authentication credentials through phishing and social engineering. In these cases, an authentication system may correctly validate the credentials while still allowing an unauthorised person to access the account.
Financial institutions therefore need continuous, risk-based monitoring after login. Machine learning can help assess linked indicators and prioritise activity for investigation, while behavioural baselines can provide context around whether a particular transaction or account action is consistent with the customer’s established activity.
Account takeover also increasingly overlaps with wider financial crime risk. Once stolen funds leave a compromised account, they can pass through mule networks or other accounts involved in broader fraudulent activity. Connecting account takeover monitoring with transaction monitoring, entity intelligence and AML controls can therefore help institutions identify whether an apparently isolated incident forms part of a wider network.
This is particularly relevant as fraud and AML teams look towards more integrated FRAML approaches. Rather than investigating the compromised customer account in isolation, institutions can examine where funds travelled, whether the receiving account has links to other suspicious activity and whether common devices, beneficiaries or transaction patterns connect apparently separate incidents.
For financial institutions, the challenge is ultimately moving from detecting individual events to understanding the sequence around them. ZIGRAM’s analysis points towards a model in which behavioural, device, account, transaction and network intelligence work together to identify risk earlier, giving fraud teams greater context before suspicious activity turns into financial loss. As account takeover techniques continue to evolve, that broader view could become increasingly important for detecting compromised accounts while also uncovering the wider financial crime networks behind them.
Read the full ZIGRAM analysis.
Copyright © 2026 FinTech Global









