General Archives – Page 55 of 266 – Forter

In recent years, the number of account takeover (ATO) attacks has skyrocketed , increasing 307% between April 2019 and June 2021. And in 2019, eCommerce businesses and consumers lost an estimated $16.9 billion to ATO attacks. ATO fraud is a rapidly growing and costly problem that online businesses must address. So, this post delves into this problem, explaining:

What is Account Takeover Fraud?

Account takeover fraud is where a bad actor gains access and takes over an account using stolen or hacked credentials. Once a fraudster gains access to an account, they engage in fraudulent activities. While all online accounts are vulnerable to ATO fraud, fraudsters tend to target accounts they consider highly valuable, like bank accounts and retail accounts with stored payment information.

How Do Fraudsters Commit ATO Fraud?

Bad actors will typically use automated tools like botnets and machine learning (ML) to engage in massive and ongoing attacks against consumer-facing websites. With automated tools, they commit ATO fraud using techniques like:

Fraudsters don’t always use automated tools for ATO fraud. They can gain access and take over accounts through:

Fraudsters typically target accounts that will bring the most value, doing many fraudulent activities with the accounts they take over.

What Do Fraudsters Do with the Accounts They Take Over?

Fraudsters can do a lot of damage once they gain access to an account. Let’s look at ATO fraud for a few industries:

We’ve highlighted only a few industries that fraudsters target for ATO fraud. However, every online business in every industry faces some risk of ATO fraud attacks.

How Big Is the Risk of ATO Fraud for Online Businesses?

ATO fraud is a huge risk for online businesses because it involves online accounts created by legitimate users. Many fraudsters try to emulate legitimate user behavior once they take over a legitimate account, making ATO fraud difficult to detect. Also, 40% of the fraudulent activity related to an account takeover occurs within 24 hours.

Fraudsters often work together in crime rings and use advanced tools like botnets and peer-to-peer virtual private network (P2P VPN) services. With these advanced tools, fraudsters can distribute login attempts across thousands to millions of IP addresses and attempt hundreds of thousands of logins in just one day.

Sometimes fraudsters will wait months before doing anything with the accounts they’ve taken over. They wait a while and then suddenly use multiple accounts all at once or in a short time frame, quickly getting as much value from the accounts as possible. This technique is known as “bust-out fraud,” and it makes detecting ATO fraud more difficult.

Some fraudsters don’t use automated tools for ATO attacks. They have human labor (click farms) manually enter login credentials so that the attacks go undetected by tools that look for automated login attempts.

Fraudsters use sophisticated tools and techniques to commit ATO fraud. However, businesses can take steps to help prevent ATO fraud and detect when fraudsters have taken over accounts.

How Can Businesses Reduce the Risk of ATO Fraud?

You can significantly reduce the risk of ATO fraud by implementing the following:

1) Two-Factor Authentication

Requiring that users enable two-factor authentication (2FA) for account logins can help prevent fraudsters from taking over accounts. Many businesses use 3D Secure (3DS) to implement 2FA on their websites. 3DS is a technology created by Visa and Mastercard to securely authenticate users. Users validate their identity using two of the following:

2FA is a good first defense against account takeover. However, fraudsters have found ways to bypass it — via SIM swap fraud, for example. So, you need to add a second line of defense in the form of a real-time fraud prevention solution.

2) A Real-Time Fraud Prevention Solution

It is impossible to prevent ATO fraud completely, as some fraudsters will find their way onto your platform. But with real-time Account Protection that leverages an identity graph of more than one billion identities — which includes personas and behavior patterns — you can identify unusual behavior from user accounts quickly. You can identify behavior and activities generated from automated tools like bots and ML algorithms. You can also detect unusual behavior before checkout, automatically presenting suspicious users with 2FA at the payment stage when needed.