Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking & Finance Review®

Global Banking & Finance Review® - Subscribe to our newsletter

Company

    GBAF Logo
    • About Us
    • Profile
    • Privacy & Cookie Policy
    • Terms of Use
    • Contact Us
    • Advertising
    • Submit Post
    • Latest News
    • Research Reports
    • Press Release
    • Awards▾
      • About the Awards
      • Awards TimeTable
      • Submit Nominations
      • Testimonials
      • Media Room
      • Award Winners
      • FAQ
    • Magazines▾
      • Global Banking & Finance Review Magazine Issue 79
      • Global Banking & Finance Review Magazine Issue 78
      • Global Banking & Finance Review Magazine Issue 77
      • Global Banking & Finance Review Magazine Issue 76
      • Global Banking & Finance Review Magazine Issue 75
      • Global Banking & Finance Review Magazine Issue 73
      • Global Banking & Finance Review Magazine Issue 71
      • Global Banking & Finance Review Magazine Issue 70
      • Global Banking & Finance Review Magazine Issue 69
      • Global Banking & Finance Review Magazine Issue 66
    Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends
    Original content: Global Banking and Finance Review - https://www.globalbankingandfinance.com

    Global Banking & Finance Review® is a global financial intelligence and recognition platform delivering authoritative insights, data-driven analysis, and institutional benchmarking across Banking, Capital Markets, Investment, Technology, and Financial Infrastructure. Global Banking & Finance Review® operates a Digital-First Banking Awards Program and framework — an industry-first digital only recognition model built for the modern financial era, delivering continuous, transparent, and data-driven evaluation of institutional performance.
    Copyright © 2010-2026 GBAF Publications Ltd - All Rights Reserved. | Sitemap | Tags

    Editorial & Advertiser disclosure

    Global Banking & Finance Review® is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    1. Home
    2. >Business
    3. >5 Ways to Help Your Customers Avoid Account Takeover Hacks in 2021
    Business

    5 Ways to Help Your Customers Avoid Account Takeover Hacks in 2021

    Published by maria gbaf

    Posted on August 24, 2021

    7 min read

    Last updated: February 15, 2026

    Image of business professionals reviewing graphs and charts, emphasizing the importance of cybersecurity strategies to prevent account takeover hacks in the financial sector.
    Business professionals analyzing graphs and charts for cybersecurity strategies - Global Banking & Finance Review
    Why waste money on news and opinion when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    Tags:cybersecurityfraud preventionfinancial services

    Five Strategies to Safeguard Customers Against Account Takeover Hacks

    By Steven Freidkin, CEO of Ntiva, an MSP providing IT and cybersecurity services, and IT consulting for financial institutions and other organizations.

    The financial sector has seen cybersecurity threats grow rapidly in volume and strength since the beginning of pandemic lockdowns.

    One of the most worrying of these new threats are what’s called account takeover fraud, commonly known by the acronym ATO. This is where hackers gain access to a customer’s account by obtaining their login credentials, usually through phishing emails or stolen database information. Financial ATO, which now accounts for a third of all financial account attacks, targets bank and credit card accounts to ultimately access bank clienteles’ funds.

    To protect account holders, the Financial Industry Regulatory Authority (FINRA) recently published a regulatory notice to help firms better protect their customers’ data and identity. While it’s not mandatory for financial firms to implement this new FINRA advice, they should still take the time to assess their current cybersecurity practices to ensure their clients are adequately protected.

    Unfortunately, cybersecurity is always a hot topic in the banking sector as financial firms spend an estimated $18.5 million each year on defending themselves and their clients from hacks, which is the most of any industry.

    Whether it be updating password policies or improving ID verification methods, there are a few tips that the finance sector can immediately implement to make sure their customers are better protected from ATOs.

    Rethinking Password Policies

    One of the major vulnerabilities that ATOs take advantage of is reused passwords. And there are lots of holes to exploit as more than 50 percent of people use the same password for multiple accounts, and 13 percent use the same for every account they have, per a recent Google study.

    The National Institute of Standards and Technology (NIST) recommends that organizations have automated password checkers in place that screen passwords against a blacklist of commonly used codes or ones that have been exposed. Then, customers are immediately told to come up with a new combination that will better protect them. This is one of the most effective ways to prevent takeover hacks and modern software services allow organizations to screen passwords in real time, without causing delays for customers.

    Alternatively, organizations should also rethink making customers change their password every year. On top of the process being tedious for the customer and leading to lots of lost passwords, it also becomes more likely that clients will continue to choose weaker and weaker passwords.

    Case in point, researchers at the University of North Carolina discovered that if a hacker has access to a previous password, they can successfully predict up to 41 percent of the time what a user’s new password will be in less than three seconds.

    Verifying ID During Account Creation

    Being able to successfully monitor incoming customers as they open accounts can stop an ATO attempt at its source. Considering that ATOs aren’t easily identified once they’ve begun, financial institutions can protect themselves and their clients by closely surveilling applications that are deemed high risk.

    It’s important for organizations to make sure they get as much upfront info from the client during the onboarding process as possible, while making sure it doesn’t negatively impact customer experience or turn clients away.

    Companies can then use this biographical information – like a social security number or home address – to verify a customer’s ID and make sure everything checks out. FINRA also recommends for organizations to ask customers for any additional documents that can then be cross-checked with credit bureaus, like home purchases.

    Organizations that may not have the bandwidth to take this on within their own teams can always hire vendors that are able to discover red flags in the application or account creation process.

    Authenticating ID During Login

    Requiring added protection through ID and login authentication can go a long way to making sure customers are safe from takeover hacks. Many banks and financial institutions are now directly encouraging their users to take up multi-factor authentication, which uses a second factor on top of a common password, usually a code sent via text or email.

    There’s a reason that the multi-factor authentication method has become so widely adopted. According to Microsoft, it prevents 99.9 percent of hacking attempts.

    Organizations should also consider adaptive authentication, which personalizes the best types of multi-factor authentication based on a specific users’ risk profiles. For example, if a customer wants to complete a more serious transaction – like transferring money to a foreign country or logging in from an unknown device – the authentication system can be triggered to require additional information beyond just the account password.

    Monitoring the Back End

    Organizations should also be prepared to surveil client accounts on the back end to make sure there is nothing out of the ordinary. If there is a dramatic spike in failed login attempts by certain accounts in a span of minutes or hours, that’s a clear warning sign. That can often signal that an ATO hacker is trying to get control of a user’s information through credential stuffing. This is where bots rapidly try out different combinations of stolen passwords or usernames.

    Other red flags in this area include an abnormal number of transfers or big purchases made at suspicious times, like immediately after an account is created. IT teams can also monitor for phishing emails coming from customers’ accounts or emails, as compromised accounts could be easy to detect by telltale communications that are misspelled or include suspicious attachments.

    Controls on the back end that further require ID verification for suspect behavior are a great way for organizations to identify and weed out an ATO. Organizations can install a list of security questions for transaction attempts that trigger the authentication system or require a phone call confirmation if a purchase or wire transfer would be abnormal.

    Those in the finance sector may look beyond their own platform and hire trusted third party monitors to track down passwords and account information that is available on the dark web. This way, an organization can screen for bad passwords that should automatically be blocked during account creation or password resets.

    Using AI to Detect Threats

    The more automated processes a financial institution has in place, the more likely they are to prevent and respond to threats.

    A web application firewall (WAF) can be set up to automatically stop ATO attacks by working in tune with an organization’s existing software infrastructure. WAFs are particularly adept at preventing credential stuffing, which account for nearly half of the attacks aimed at the financial industry.

    And because ATO bots use VPNs and proxies to mask their locations, firms can install automated triggers that block any activity coming from a country where the organization does not have any customers. Suspect IPs can then be separated into a distinct category, often called a sandbox, that freezes their account activity until the matter is resolved.

    Unfortunately, takeover hacks will only continue to grow in popularity as we move further towards a cashless world. It will be up to financial institutions to have the proper safeguards in place to ensure their clients are appropriately protected.

    By setting up these automated solutions that can monitor ATO attempts or stronger password and authentication policies, banks can successfully stave off these increasingly common attacks.

    Frequently Asked Questions about 5 Ways to Help Your Customers Avoid Account Takeover Hacks in 2021

    1What is account takeover fraud?

    Account takeover fraud, commonly known as ATO, occurs when hackers gain access to a customer's account by obtaining their login credentials.

    2How can financial institutions protect against ATO?

    Financial institutions can implement strategies such as rethinking password policies, verifying customer IDs during account creation, and using multi-factor authentication to enhance security.

    3What role does multi-factor authentication play in preventing ATO?

    Multi-factor authentication is widely adopted because it can prevent 99.9 percent of hacking attempts, adding an essential layer of security for customer accounts.

    4Why is monitoring back-end activities important?

    Monitoring back-end activities helps organizations identify unusual behavior, such as spikes in failed login attempts or suspicious transactions, which may indicate an ATO attempt.

    5How can AI be utilized in combating ATO?

    AI can enhance threat detection through automated processes, such as web application firewalls that prevent ATO attacks and monitoring for suspicious activities based on user risk profiles.

    More from Business

    Explore more articles in the Business category

    Image for Apricorn Becomes First and Only Hardware-Encrypted USB Storage Device Manufacturer to Achieve AS9100 Certification
    Apricorn Becomes First and Only Hardware-Encrypted USB Storage Device Manufacturer to Achieve AS9100 Certification
    Image for SME Payment Disputes: The Real Cost Isn’t Legal Fees
    SME Payment Disputes: The Real Cost Isn’t Legal Fees
    Image for Mirabaud Group Secures Top-10 Position in SPBIx Assessment
    Mirabaud Group Secures Top-10 Position in SPBIx Assessment
    Image for Previous UK Property Market Conditions include Lower Interest Rates and Flexible Lending
    Previous UK Property Market Conditions include Lower Interest Rates and Flexible Lending
    Image for Estate Planning Strategies for Blended Families
    Estate Planning Strategies for Blended Families
    Image for The Role of Workforce Management in Cutting Costs and Driving Growth
    The Role of Workforce Management in Cutting Costs and Driving Growth
    Image for Beyond the Glass Ceiling: Women, Wealth, and the New Era of Ownership
    Beyond the Glass Ceiling: Women, Wealth, and the New Era of Ownership
    Image for California Invests in Seismic-Resilient Utilities as W.A. Rasic Construction Advances Key Projects
    California Invests in Seismic-Resilient Utilities as W.A. Rasic Construction Advances Key Projects
    Image for Michael Shanly and the Growth of Shanly Homes & Sorbon Estates
    Michael Shanly and the Growth of Shanly Homes & Sorbon Estates
    Image for Small Claims Court Without a Lawyer: What Individuals and Businesses Can Realistically Do Themselves
    Small Claims Court Without a Lawyer: What Individuals and Businesses Can Realistically Do Themselves
    Image for Beyond the Auction Block: How the Art Market Values What It Cannot See
    Beyond the Auction Block: How the Art Market Values What It Cannot See
    Image for Inside MAB Group’s Growth: What Is Actually Being Measured
    Inside MAB Group’s Growth: What Is Actually Being Measured
    View All Business Posts
    Previous Business PostMcDonald’s milkshakes off the British menu after supply chain issues
    Next Business PostD&I experts disclose best ways to create a work culture is where it safe to speak out