Data tokens on this page

Account Takeover Fraud: Take a Proactive Approach to Protect Your Business

Account Takeover Fraud: Take a Proactive Approach to Protect Your Business

The same time-saving capabilities that help businesses work smarter and processes run faster also extend to cybercriminals conducting fraudulent schemes. One of the most financially devastating: account takeover fraud.

Account takeovers occur when cybercriminals gain control of an account and can withdraw and transfer funds, make purchases, change account contact information (locking victims out of their accounts), and eventually sell account details to other criminals.

According to a U.S. Federal Reserve report, account takeover fraud led to over $15.6 billion in reported losses in the U.S. in 2024, up from $12.7 billion in 2023 and $11 billion in 2022. Reported account takeover cases filed with the Financial Enforcement Network (FinCEN) increased by over 36% in 2024.

With sophisticated financial crimes costing businesses and individuals billions of dollars, it’s imperative to know how to detect and prevent fraud, and to ensure your colleagues and employees follow suit. Here’s what to watch out for, and how to protect your organization’s financial security.

How it happens

There are a variety of methods cybercriminals rely on, ranging from impersonation scams where information is willingly handed over to thieves, to hacking into accounts by guessing passwords or through installed malware. Tim Murphy, Director of Fraud Transaction Monitoring at Wintrust Financial Corporation, explains that while artificial intelligence (AI) helps to make thieves’ tactics more powerful, they’re not necessarily new, and most prevention methods hold true in combating these crimes. “Social engineering is not going away, and AI makes it easier—creating better scripts for criminals,” says Murphy. “AI is the cause of some of the fraud, but it’s the same old tactics that come into play.”  

Social engineering

Whether through impersonations, phishing, or texting scams, cybercriminals pretend to be from credible institutions to persuade people into revealing compromising information. Thieves thrive on the ability to rush or scare people into action.

Murphy explains that cybercriminals use a variety of tactics, such as pretending to be your bank, the government, or a company you work with, or asking if you’ve made a specific transaction they’ve created. When you inevitably don’t recognize this transaction, it’s easy to be caught off guard. Often, this is the point where you’ll be asked for your username and password or to share a one-time passcode.

“When you receive an impersonation call, these cybercriminals instill fear and anxiety by making you believe you’re going to lose something,” explains Murphy. “Then they’re right there to ‘help’ fix their manufactured panic.”

Murphy continued, “I try to coach people using a three-step process: pause, think, and verify. Don’t just react. If you didn’t initiate the call, hang up and call your bank directly.”

Social engineering doesn’t always initially involve rushing. Sometimes, even a seemingly harmless question can help unlock key information. Scammers harvest this information and play the long game, continuing to uncover more and more information, building bit by bit. For instance, a scammer may call and pose as a salesperson, asking whom you use as a vendor for a specific service and pretending to have a more competitive offer. What seems like an innocuous answer helps them down the road when they pose as that service provider and send a phony invoice, possibly gaining important account credentials. 

Credential stuffing

This is where strong passwords—and updating passwords—come into play. Thieves systematically test passwords for specific usernames and oftentimes can successfully log in to accounts. Recently, AI has been used to decode credentials based on personally identifiable information.

For instance, with a phone number, email address, and mother’s maiden name, a hacker could generate a username, then spoof the phone number to receive a verification code and use the mother’s maiden name as an answer to a security question. Business bankers working with security advisors offer guidance with multi-layered security defense controls to combat these types of fraudulent attempts.

Data breaches

Data breaches allow thieves access to customer information, which then gives them better luck at credential stuffing or social engineering. Now they don’t even need to pose as a competitor to your current vendor to discover who your vendor is; that information has already been uncovered. Thieves will take this information and build fake websites, pose as tech support, mimic a financial institution—the list goes on. 

Malicious software

Text, emails, and freeware can all be infected with malicious software that captures keystrokes to steal usernames and passwords. Never click on an unexpected link or attachment.

Dumpster diving

In the digital age, this may seem like an outdated form of theft, but thieves still search for sensitive documents that haven’t been shredded. This information can then be used to log into online accounts.  

What can you do?

Take a proactive approach. Provide your staff with training, and not just the staff handling books. Remember, scammers often play the long game through social engineering tactics, and any employee can play a role in accidentally helping them to uncover pertinent information.

“Social engineering training that involves simulated phishing examples can provide excellent coaching for employees,” says Murphy. “People get tired of hearing about social engineering until they get hit.”

Fraud awareness training is linked to faster detection and lower losses. The Association of Certified Fraud Examiners (ACFE) notes that organizations that did not provide training lost nearly twice the amount of money. 

“It’s so important for businesses to educate themselves on regulations—particularly Regulation E and the lack of protection for businesses—and to know the difference between a push and pull payment,” says Brian Mivelli, Vice President, Senior Manager Fraud Investigation at Wintrust Financial Corporation.

Push payments are initiated by the sender, who is essentially “pushing” the payment through, controlling the amount and timing, whereas pull payments occur through automated systems for recurring payments, initiated by the recipient who is “pulling” funds after receiving prior authorization. Think ACH direct debits, recurring subscriptions, monthly memberships, etc.

“You’ll also want to make sure you’re taking advantage of the security resources offered by your bank’s Treasury Management department.” Dual control, ACH origination—these types of tools can help protect your company.

“When you’re making payments, security needs to come before convenience,” says Murphy. “Having dual authentication is key—one person originates the payment, someone else confirms that payment.”

Wintrust offers robust i-BusinessBanking®1 products, with an online treasury management system2 designed for businesses to manage cash flow, payments, and account services. Resources include Positive Pay and Reverse Positive Pay to stay ahead of fraudulent checks, as well as ACH Positive Pay, an automated bank fraud detection service that allows businesses to review and either approve or reject incoming ACH (Automated Clearing House) debits before they clear the account. Companies can proactively block unauthorized ACH transactions by establishing authorized vendor lists and setting filtering criteria (like dollar limits or frequency).

With sophisticated business banking solutions and a dedicated team of experts supporting your account, we can help you keep your business safe. “Wintrust really provides white-glove service, with bankers calling about unusual business payments or a change in historical payment accounts,” says Mivelli. “You’ll know exactly who you’re working with and can call your banker directly if you’re ever concerned about an unexpected transaction.” 

Explore business banking solutions that make a difference.

Find out more about keeping your accounts safe and secure.

Banking products provided by Wintrust Community Banks. Member FDIC. Equal Housing Lender.

1. i-BusinessBanking® Services. Use of online banking required for access to mobile/online banking. Remote deposit requires an established business checking account with the bank. Online banking processing cutoffs remain the same in mobile. Mobile/internet connectivity required. Third-party message, data, &/or internet fees may apply.

2. Treasury Management Services. See your banker or Treasury Management Services Sales Officer. Additional fees may apply.

Share