Account Takeover Fraud
A fraudster gains control of a genuine customer's account through credential theft, phishing, or SIM-swap, then changes device, contact, or beneficiary details before rapidly draining funds to mule accounts. Speed and post-compromise profile changes distinguish takeover from normal customer behaviour.
What it is
A fraudster gains control of a genuine customer's account through credential theft, phishing, or SIM-swap, then changes device, contact, or beneficiary details before rapidly draining funds to mule accounts. Speed and post-compromise profile changes distinguish takeover from normal customer behaviour.
Control objective
Detect unauthorised account takeover by identifying anomalous device, credential, and profile changes followed by rapid outflows to mule accounts, and intervene before funds are lost.
Data required
- Device fingerprint and login history
- IP address, geolocation, and session anomalies
- Credential reset and authentication event logs
- SIM-swap and phone-number change signals
- Beneficiary, payee, and contact-detail change events
- Outbound payment amounts, timing, and destinations
- Customer behavioural baseline (typical payees, amounts, hours)
- Beneficiary account risk indicators (mule flags, age, velocity)
Related typologies (Fraud)
Unusual Business Activity vs Declared Profile
Transaction activity that is materially inconsistent with the customer's declared business profile, sector, or expected turnover, potentially indicating front company activity, invoice fraud, or undisclosed business changes.
Authorised Push Payment (APP) Fraud
Social engineering schemes where victims are manipulated into authorising real-time payments to accounts controlled by fraudsters. Includes impersonation of banks, HMRC, solicitors, and romance scams, with losses often irrecoverable once funds are moved through mule networks.
Insurance & Claims Fraud
Fraudulent insurance claims including staged or fabricated losses, inflated or exaggerated claim values, duplicate claims across insurers, and organised claims rings operating across multiple policyholders. Proceeds are extracted as claim settlements and may be laundered through linked bank accounts.
Business Email Compromise & Invoice Redirection
Business email compromise and mandate or invoice redirection fraud. Attackers impersonate suppliers, executives, or counterparties to redirect legitimate payments to fraudster-controlled accounts using altered bank details, often followed by rapid layering through mule accounts to extract funds.
Romance & Investment Scams
Romance and investment scams, including pig-butchering, where victims are manipulated over time into sending payments to scam-controlled bank accounts or crypto wallets. Payments are often escalating, made to fake investment platforms, and rapidly layered or converted to crypto by the receiving network.