The surge in digital and mobile banking adoption has led to an increase in fraudsters deploying more account takeover (ATO) attacks.

Digital is a low-risk, high-reward environment for cyberattacks, Andy Renshaw, senior vice president at fraud and risk management company Feedzai, told Bank Automation News. Account takeovers increased threefold between 2019 and 2021, according to a report from fraud detection company Sift.
“We’ve seen digital viewers become digital users, and people who were passive become active users,” Renshaw said. “That creates accessibility for fraudsters, giving them the ability to execute and scale. If they attempt account takeover with 100 people, but only three or four of them are successful, that’s good business.”
Digital has given ATO a “target-rich,” low consequence ecosystem where the weakness of passcodes provides ample ammunition, he said.
“Stolen credentials are widely available, but many digital processes can be reverse engineered,” Renshaw said. “If you think about your own personal services, like password resets, those processes don’t tend to be onerous. Fraudsters typically know the processes for large organizations or banks, especially within their region, so they can pick out the precise data they need at speed and scale.”
Methods of attack
ATO attempts channel through two major vectors: phishing, which is performed through fraudulent phone calls, e-mail or direct messages, and malware, which collects sensitive information as the victim operates a compromised device.
“I could deploy Trojan or malware in what you might call a ‘man in the middle’ attack,” Renshaw said. “Every time you log on, I’m collecting information and replaying it in the background.”
The end game of an ATO is not just a quick swipe of funds. Fraudsters can alter banking details, change personal information and cut off the victim’s contact with the bank. Repeat attacks are not uncommon, and a successful ATO can create cyclical disaster for the victim.
“Being a victim of fraud once is horrible,” Renshaw said. “But imagine it happening to you the day that you felt your bank had sorted it all out and you were reassured. You get going again, and you get attacked again.
“That’s where it can get really nasty,” he added.
Management and mitigation
Banks play an indispensable role in the prevention of attacks on their customers. Device fingerprinting and biometric behavioral analysis are strategies that prove essential in stopping ATO fraud, David Mattei, strategic advisor at Aite-Novarica Group, told BAN.
“What we’re seeing in the leading solutions is that they need to take a multipronged approach: Device fingerprinting, to get a sense of ‘who is this person’ or looking at location and behavioral biometric patterns to see if a transaction’s IP address correlates to consistent user locations,” Mattei said.
User education embedded within the banking experience is another preventive strategy, with warning screens and multifactor authentication playing a role in staying active and engaged with customers, Renshaw said.
For banks whose customers could see accounts wiped clean and financial information compromised within minutes, the issue is one of trust.
“If you get an experience right with a customer, even if they’ve suffered a loss, they know you have their back,” Renshaw said. “If you get it wrong, it becomes more damaging the other way, and that can damage your long-term business.”
Bank Automation Summit, taking place March 1-2 in Charlotte, is the first and only event to focus solely on automation in banking. The event will feature the brightest minds from across financial services on intelligent automation strategies and deployment. Learn more and register here for Bank Automation Summit 2022.





