5 Account Takeover Signals Fraud Teams Can’t Afford to Ignore
Account takeover has a reputation problem, and not the one you'd expect. Block rates for account takeover (ATO) have been improving industry-wide, a genuine sign of progress. But averages can hide as much as they reveal.
When my Trust and Safety team at Sift looked closely at the pattern behind that improvement, alongside recent fraud ring investigations and a survey of consumers who had actually lived through an account takeover, a more complicated picture emerged. ATO isn't going away. It's concentrating, changing shape, and testing whether fraud teams can see past the accounts they already trust.
Here are five signals I keep coming back to when I speak with fraud teams about where to focus next.
1. Improving averages can mask concentrated risk
A block rate moving in the right direction is usually the number leadership wants to see. Our global ATO rate fell 28% year over year, from 1.33% to 0.95%, and most industries improved along with it. Internet and software was a notable exception, with its ATO rate rising 6% over the same period. That contrast shows why a strong global average can obscure increasing risk in a specific vertical, where account value, user behavior, and attacker tactics may look very different.
Fraud teams need to benchmark performance against the patterns shaping their own industry, not just the network average. Compare ATO rates across verticals, then break your own data down by product, customer segment, channel, and account type. That’s how you see where risk is concentrating before it becomes visible in the topline number.
2. Everyday accounts, not just bank logins, are the target
Banking and financial accounts are still the most commonly reported ATO target, but social media isn't far behind, and food delivery, gaming, gambling, and subscription accounts all draw real attention from attackers too. Account value no longer depends only on direct access to funds. Fraudsters go wherever there are stored credentials, stored payment methods, loyalty points, or resale potential. That same account data also feeds a bigger problem: it becomes raw material for building synthetic identities, which attackers can use to pass verification checks that would otherwise catch a fabricated profile.
This shift shows up clearly in a loyalty program fraud ring our team traced across the Sift network. Bad actors combined compromised accounts with newly created ones to commit first-party fraud and mileage plan abuse, spanning dozens of businesses. None of it required touching a bank account directly.
3. Authentication is a baseline, not a solution
Two-factor authentication has become table stakes across the industry, but adoption alone hasn't moved the needle much lately, holding at roughly 8.2% across the Sift Global Data Network. 2FA is a baseline control, not a competitive edge, and it isn't sufficient on its own. More than 65% of breached accounts are estimated to have had MFA enabled at the time of compromise.
That gap changes what fraud teams should actually be measuring. A login control confirms someone entered the right credentials. It says nothing about whether the session, the device, or the behavior afterward still matches the account's history. Effective ATO defense pairs authentication with account-change monitoring and downstream behavior analysis, because attackers who clear the login step still leave a trail in what they do next.
4. ATO rings hide inside mixed signals
Across the Sift network, accounts tied to fraudulent chargebacks show up far more connected to other flagged activity than accounts without them, a pattern you'd expect from a coordinated ring rather than isolated bad luck. That distinction matters because ATO rings rarely present a clean signal. In the loyalty ring mentioned above, the same cluster contained victimized customers, compromised accounts, and manual accepts sitting right alongside manual blocks.
Attackers often spend months mirroring a legitimate account owner's behavior before acting, so a single transaction can look completely normal. What gave this fraud ring away wasn't any one purchase. It was the pattern across sessions and devices, and, in particular, a change to the account's email address, which our data flags as one of the leading indicators of takeover.
That mixed signal profile is also why a blanket response doesn't work. Blocking every account in a suspicious cluster risks locking out legitimate customers who are caught in the same network by coincidence. This is why ATO is so tricky to respond to: you can't just wipe out the account. It's closer to removing a tumor than pulling a plug, the goal is to cut out the threat without harming the patient. Targeted friction, such as step-up authentication or a re-verification prompt, does exactly that. It interrupts the attacker without punishing the customer whose account was compromised.
5. Response quality decides whether you keep the customer
Detection is only half the job. How a customer first learns about an ATO incident often reveals how quickly the business caught it. In our survey, only 37% of victims heard about the compromise from the company first. The best outcome is the company catching suspicious activity and prompting the legitimate user to reauthenticate before any value is extracted, not simply notifying the customer after the fact. The worst is a customer discovering the problem only after they’ve already lost access.
What happens next matters just as much. Most victims resolved the issue within a few days, but 20% didn't. Even among those who stayed, trust often took a hit: 35% kept using the platform with less trust, while 11% left for good. I saw that hit to trust firsthand in my previous role at Meta: people who'd been through an account takeover kept logging in, but posted or shared noticeably less for weeks afterward, quietly rebuilding confidence before they fully re-engaged. Nearly half either questioned the relationship or ended it outright. Speed and transparency can change that outcome. Eighty-two percent said a fast resolution would improve their view of a company, and proactive, clear communication had a similar effect, while slow or opaque handling pushed sentiment in the opposite direction.
Fraud teams may not own the customer conversation, but they shape the information, timing, and decisions behind it. Build strong working relationships with customer experience and communications teams before an incident happens, not in the middle of the response.
Bringing it together
None of these five patterns are new problems on their own. Compromised accounts, limited authentication context, connected fraud rings, and slow incident response have all been discussed in this industry for years. What the latest data shows is how much they now depend on each other. A fraud ring that looks isolated in one merchant's data can be part of a pattern spanning dozens of businesses. In my experience, that's a bit like spotting one cockroach: if you can see it, there are almost certainly more you haven't found yet. An account that passed multi-factor authentication can still be compromised. And a fraud team that stops an attack but fumbles the customer conversation can still lose that customer.
Fraud teams that treat detection, network context, and incident communication as one connected discipline are better positioned to protect revenue and customer trust as account takeover evolves. Shared fraud intelligence is more powerful than any single business’s data alone, helping teams learn from attack patterns forming elsewhere before they are hit directly.

About Sift
Sift is the leading fraud prevention platform delivering digital trust to 700+ global brands, allowing them to grow confidently by stopping fraud while enabling excellence in customer experience. Backed by a global data network of over one trillion annual events, Sift helps companies convert risk into revenue and scale without compromise. Brands including Hertz, Yelp, and Poshmark rely on Sift to unlock growth and deliver seamless consumer experiences.
Contact us
To learn more, visit sift.com.

About the author
Kevin Lee is Field Chief Technology Officer at Sift. He helps customers implement strategies that cross-functionally align risk and revenue programs. Prior to Sift, he spent over 14 years leading various risk, chargeback, spam/scams, and trust and safety organizations at Meta, Square, and Google. Connect with Kevin on LinkedIn