ATO (Account Takeover)
Account takeover, or ATO, is a form of fraud in which a criminal gains unauthorised access to a customer's existing account in order to make payments, steal stored value or extract personal data.

Account takeover, or ATO, is a form of fraud in which a criminal gains unauthorised access to a customer's existing account in order to make payments, steal stored value or extract personal data.
What Is Account Takeover?
Unlike identity fraud, where a criminal creates a new account using stolen details, account takeover targets a genuine, already-established account. Attackers typically gain access through stolen or leaked credentials, phishing, or credential-stuffing attacks that test large batches of usernames and passwords against a login page until one succeeds.
How Account Takeover Happens
Once inside an account, a criminal can add or use stored payment methods, change shipping details, redeem loyalty rewards or move funds, often before the genuine account holder notices anything is wrong. Because the account itself is legitimate, ATO transactions can look identical to genuine customer behaviour, making them harder to catch with rules based purely on transaction value or location.
Why ATO Matters for Merchants
Beyond the direct financial loss, ATO damages customer trust and can result in chargebacks once the genuine account holder disputes the fraudulent activity. Detecting it typically relies on behavioural signals, such as unusual login patterns or device fingerprinting, layered into a broader fraud detection strategy rather than transaction rules alone.
Preventing Account Takeover
Strong authentication, such as two-factor authentication and step-up checks for unusual activity, meaningfully reduces ATO risk. Merchants can also draw on platform-level intelligent fraud management that flags suspicious account activity across the payment stack, alongside consumer education, covered in payment fraud: consumer awareness and defence.
ATO vs Card Fraud
Account takeover is often confused with straightforward card fraud, but the two require different defences. Card fraud typically involves stolen card details being used on an unrelated, often newly created, account, whereas ATO compromises a genuine, existing account and can expose far more than just payment data, including saved addresses, order history and loyalty balances. Because ATO transactions come from a real account with a real transaction history, standard fraud rules based on spending patterns are less effective, and detection instead depends more on identifying anomalies in login behaviour, device fingerprints and session activity that don't match how the genuine account holder typically behaves.
Frequently Asked Questions
Identity theft typically involves creating a new account or credit line using stolen personal details, while account takeover involves gaining unauthorised access to an existing, genuine account.
Common methods include credential stuffing using previously leaked passwords, phishing attacks that trick users into revealing login details, and malware that captures credentials directly from a device.
It significantly reduces the risk, since a stolen password alone is no longer enough to access the account, though it isn't a complete guarantee against more sophisticated attacks.
Costs are typically split between the merchant, who may face chargebacks and lost goods, and the payment provider or issuer, depending on where the liability sits contractually.
Unusual login locations or devices, rapid changes to account details, and behaviour that deviates from the account holder's usual pattern are common signals used in detection.

Still Have Questions?
Let’s Find the Right Solution for You
Stay Connected with Us!
Follow us on social media to stay up to date with the latest news, updates, and exclusive insights!


