What Is Account Takeover Fraud? Attacks, Signs, & Prevention
When a customer loses access to their account, they usually don’t know right away.
A purchase shows up that they didn’t make, loyalty points disappear, or maybe a saved payment method gets swapped out. By the time they contact support, the fraud has already happened.
Account takeover fraud works because it’s quiet. Attackers use stolen credentials leaked in breaches or bought in bulk and test them at scale using bots.
This guide covers how account takeover fraud works, what signals to watch for, and what it takes to stop it.
What is account takeover fraud?
Account takeover (ATO) fraud happens when an attacker gains unauthorized access to a legitimate user account and exploits it, typically for financial gain, data theft, or both.
Unlike identity theft, which involves creating or assuming a false identity, account takeover targets accounts that already exist. Real accounts, with real stored value: saved payment methods, loyalty points, order history, personal data. That’s what makes them worth targeting.
Once inside, attackers move fast. They might make unauthorized purchases, drain loyalty points, change account credentials to lock the real user out, or sell verified account access to other fraudsters. In some cases, the account itself isn’t the end goal. Instead, it’s the entry point for broader fraud activity across linked accounts or payment methods.
Any business with user accounts is a potential target. But the risk is highest wherever accounts hold stored value or payment details: e-commerce, travel, financial services, gaming, and subscription platforms.
How do account takeover attacks happen?
Most account takeover fraud follows the same basic chain: attackers acquire stolen credentials from dark web markets, deploy bots to test them against login pages at scale, then monetize the accounts they get into—stealing personal data, draining loyalty points, exploiting saved payment methods, or selling verified access to other fraudsters.
The two most common methods are credential stuffing, where bots test username and password combinations stolen from other breaches, and credential cracking, which uses brute-force techniques to guess passwords directly. Both rely on automation to be profitable since neither is feasible at scale without bots.
What makes modern ATO attacks hard to catch is how sophisticated that automation has become. In one credential stuffing attack blocked by DataDome, hackers sent 5.7 million requests over two days, spread across 250,000 different IP addresses, 8,000 autonomous systems, and 215 countries. Each IP averaged just 10 to 20 requests to avoid triggering user-level or session-level alerts, making the attack impossible for a WAF to detect.

Website requests blocked by DataDome during the credential stuffing attack
Beyond credential attacks, account takeover attacks can also result from phishing, malware that captures login sessions, or session hijacking—where an attacker takes over an authenticated session without needing a password at all.
The method varies, but the outcome is the same: access to an account the attacker has no right to be in.
What is the impact of account takeover fraud?
The direct losses are the most visible part of ATO fraud. Account takeover fraud losses in the U.S. exceeded $15.6 billion in 2024, up from $12.7 billion the year before—and that figure only captures reported losses. The true cost is higher.
According to LexisNexis Risk Solutions, every $1 lost to fraud costs North American financial institutions more than $5 when investigation, compliance, remediation, and reputational damage are factored in.
For businesses, the financial hit comes from multiple directions at once: unauthorized transactions, chargebacks, account recovery costs, and the operational burden on support teams managing the fallout. Fraud teams spend time on disputes that could have been prevented. Engineering resources get pulled into incident response. And throughout all of it, customers are waiting.
The customer impact is where the longer-term damage sets in. 75% of consumers say they would not continue shopping on a site where they had experienced an account takeover, according to Sift. That doesn’t necessarily mean they’ll file a complaint or leave a review—they just don’t come back. That churn is real and is rarely captured in fraud loss figures.
It’s also worth noting that account takeover isn’t the endpoint. Once inside an account, attackers can access linked payment methods, exploit loyalty balances, or use a verified account as a launchpad for broader fraud. The initial compromise is often just the start.
How can businesses prevent account takeover fraud?
Preventing account takeover fraud requires controls at multiple layers: authentication, account monitoring, and the traffic reaching your login endpoints. Here are three things you’ll want to have in place to prevent account takeover fraud.
1. Enforce strong authentication
Multi-factor authentication is the most effective single control for stopping credential-based attacks. Even if an attacker has a valid username and password, a second factor blocks them from getting in.
Additionally, step-up authentication—where additional verification is required for high-risk actions like changing a payment method or updating a recovery email—adds another layer.
Encouraging strong, unique passwords still matters too. 62% of Americans say they “often” or “always” reuse a password, which means one leaked credential can cascade into multiple compromised accounts. Making breach-monitoring tools available to users so they’re notified when their credentials appear in a known breach can also help close that gap.
2. Monitor account activity, not just logins
What a user does after logging in is as telling as how they got in. Unusual post-login behavior like a shipping address change, a new payment method, or a large redemption of loyalty points can indicate that an attacker is already inside. Set up alerts for any account changes and notify users immediately, giving them the chance to flag activity they didn’t initiate.
On the business side, watch for patterns across sessions: impossible travel, logins from unfamiliar devices or geographies, high failure rates before a successful authentication, and spikes in account lockouts or password reset requests. These signals rarely trigger in isolation during a real attack, but the value is in combining them.
3. Control the traffic reaching your login endpoints
Authentication controls protect against attackers who already have valid credentials. They don’t stop the automated traffic being used to test millions of credential combinations in the first place.
That requires analyzing the intent behind login requests: whether traffic is automated, what behavioral pattern it fits, and whether it looks like a real user or a bot cycling through a list.
Rate limits and IP blocking help at the margins, but distributed attacks are designed to stay under those thresholds. DataDome’s approach looks at the full picture: device fingerprints, session behavior, request distribution, and infrastructure signals—analyzed across the entire login journey in under 2 milliseconds, not just at the moment of authentication. Because the attacks that cause the most damage don’t look alarming request by request. They only reveal themselves when you’re watching the pattern.
Why are CAPTCHAs and WAFs alone not enough to prevent ATO fraud?
CAPTCHAs and WAFs both have a place in a security stack, but neither was built to catch account takeover fraud specifically.
WAFs filter traffic based on known vulnerabilities: SQL injection, cross-site scripting, malformed requests. They’re looking for exploits in your code. A bot running credential stuffing and a real user logging in send identical requests to your login page—there’s no signature to match, so the WAF waves it through.
CAPTCHAs are a similar story. They used to work. Now, CAPTCHA farms employ human solvers for pennies per challenge, and AI-based solvers can clear most visual puzzles automatically. Presenting a CAPTCHA to every login adds friction for real users without reliably stopping the bots you’re actually worried about.
What both tools miss is intent. They can’t tell you whether a login attempt is part of an automated campaign, or whether a pattern of requests spread across thousands of IPs adds up to something coordinated. Catching that requires behavioral detection built specifically for account abuse—analyzing sessions, device signals, and traffic patterns in real time, not matching requests against a static rulebook.
How does DataDome help prevent account takeover?
Account takeover fraud doesn’t announce itself. Instead, it typically looks like a login, a profile update, or even a legitimate user completing a transaction. Catching it requires understanding what’s behind the request, not just what the request looks like.
DataDome’s Account Protect analyzes intent and behavioral signals continuously across the full account journey—from login through to post-authentication activity. It builds a picture of what normal looks like for each user, then flags when something doesn’t fit: a login from an unfamiliar device, rapid profile changes after authentication, transaction patterns that don’t match prior behavior. That coverage beyond the login page is what makes the difference.

Account Protect works alongside Bot Protect, not as a replacement for identity controls like MFA, but as an additional layer that understands automated intent at scale. It detects credential stuffing campaigns, fake signups, and AI-operated account abuse—stopping threats before they reach your users and before they create downstream costs.
With DataDome, the results are measurable: 99% reduction in account takeovers, 95% time saved on fraud disputes, and detection in under 2 milliseconds with a false positive rate below 0.01%. Legitimate users get through without friction. Attackers don’t.
Test your site’s vulnerabilities today, or book a demo to learn more about DataDome.
Account takeover fraud FAQs
Account takeover (ATO) fraud happens when an attacker gains unauthorized access to a legitimate user account and exploits it, typically to steal personal data, make unauthorized purchases, drain loyalty points, or sell verified account access to other fraudsters. It differs from identity theft in that it targets existing accounts rather than creating false identities. Any business with user accounts that store payment details or personal information is a potential target.
Bots make account takeover attacks fast, scalable, and cheap. Where a human attacker might manually test a handful of stolen credentials, a bot can test millions in hours—distributed across hundreds of thousands of IP addresses to avoid triggering rate limits or IP blocks. Modern bots also mimic human behavior: they rotate IPs, use realistic browser fingerprints, and keep individual request volumes low enough to blend in with legitimate traffic. This is why ATO is fundamentally an automation problem as much as a credential problem.
MFA significantly reduces the risk of credential-based attacks, but it isn’t sufficient on its own. It doesn’t stop phishing attacks that capture both credentials and MFA codes in real time, session hijacking that bypasses authentication entirely, or post-login fraud where an attacker has already gotten through. MFA also relies on users actually enabling it, which many don’t.
Account takeover fraud is most prevalent wherever user accounts hold stored value or payment details. E-commerce, financial services, travel, gaming, and subscription platforms are consistently the highest-risk sectors. That said, any business with user accounts is a potential target—attackers will go where the value is, and where defenses are weakest.