Account Takeover and Identity Theft

Compromised access, persistence, financial effects and customer recovery

Distinguish the compromised objects

Account takeover occurs when an attacker obtains or abuses access to an existing relationship. Identity theft can also support false applications or impersonation without taking over an existing account. Credential theft, session compromise and unauthorised financial action are related but different facts.

The campaign may involve initial access, persistence, financial activity and discovery in different orders. Detection opportunities can arise in authentication, sensitive changes, payment controls and customer reports. No single device or behaviour signal establishes the whole case.

Takeover response connects suspected access, trust changes, financial effects and controlled recovery.

Initial access and persistence

Phishing, reused passwords, malware, deceptive recovery, insider misuse and stolen sessions can expose access. A SIM swap may intercept SMS or calls used in the process; it does not automatically move app push credentials or every passkey to the attacker.

After access, an attacker may change contact details, register an authenticator, add a payee or alter a mandate. Each change needs appropriate authority, risk controls and evidence. New-device probation or lower limits can be useful policy choices, but a fixed 24–72-hour period is not a universal rule for all banks and actions.

NIST authentication guidance is a reference for authenticator and recovery assurance. The actual service also needs session and action controls. Valid login credentials do not prove the customer intended every subsequent instruction.

Financial effects and classification

Review payments, credit draws, card use and other effects against authoritative records. An instant transfer may have strong settlement finality while still supporting recovery requests, investigation or applicable reimbursement; calling it simply untraceable or always unrecoverable is misleading.

Distinguish an attacker-initiated transfer from a customer-initiated payment under deception. Applicable legal classification and rights depend on the facts and framework. A successful authentication event alone cannot establish either classification.

Receiving accounts may be operated knowingly, under deception, coercion or compromise. Network relationships and rapid onward movement are investigative signals, not proof of guilt. Share information lawfully through appropriate channels without assuming the sending bank has unlimited visibility or authority over recipients.

Containment and evidence

Establish an appropriate independent contact route when current details may be compromised. Restrict relevant activity, revoke affected sessions or authenticators and preserve evidence under the authorised process. The scope depends on the incident; indiscriminately resetting every unrelated credential can cause avoidable harm.

Identify unauthorised trust and entitlement changes and implement approved correction. A payee entry, account mandate and access token require different remediation. Recovery should not erase financial history or silently reverse a legitimate instruction.

Customer restoration and financial remediation

Provide a usable recovery route with appropriate assurance and support. Review actual payment state before recalls, disputes or adjustments. Not every transaction in a broad incident window is fraudulent, and not every payment requires the same recall process.

Communicate confirmed facts, uncertainty and next steps. Preserve applicable claim rights and deadlines. Reimbursement, funds recovery and restoration of login access are separate outcomes; completing one does not necessarily complete the others.

Fictional example: contact change and payout

A customer reports loss of access after an email change and an unfamiliar payout. The bank checks the change authority, session history and original payment status. It contacts the customer through an appropriate independent route and removes confirmed compromised access.

The payout case follows its actual rights and recovery process. Finance distinguishes loss, recovery, reimbursement and outstanding claims rather than treating the requested return as money already received.

Takeaway

Takeover response should contain compromised access, preserve evidence and resolve the affected financial relationship. Restore legitimate customer control without converting every suspicious signal into assumed proof.