By MFJ Staff | Sources: ZIGRAM, Internet Crime Complaint Center, and FinTech Global
Key takeaway: Merchants, issuers, and fraud teams should expect account-security investment to keep moving beyond the login screen. Post-authentication monitoring can catch the sequence of small, individually plausible changes. These include a new device, a contact-detail update, or an unfamiliar beneficiary, that together signal a takeover in progress before funds actually move.
Account takeover (ATO) fraud is increasingly slipping past login-only defenses. Attackers use genuine stolen credentials and mimic legitimate account activity, according to a new analysis from fraud and financial-crime intelligence firm ZIGRAM, summarized by FinTech Global.
The scale of the problem is significant and growing. In a November 2025 public service announcement, the FBI’s Internet Crime Complaint Center reported more than 5,100 complaints tied to account takeover fraud since January 2025, with losses exceeding $262 million; losses have likely grown since. Much of that activity involves criminals impersonating financial institution support staff to obtain credentials and authentication codes.
Separately, Federal Reserve Financial Services cites industry research showing ATO losses in the U.S. reached $15.6 billion in 2024, up from $12.7 billion in 2023. The Fed’s own 2026 Risk Officer Report found 23% of surveyed financial institutions had experienced account takeover activity, up seven percentage points year-over-year.
The analysis argues that authentication alone cannot catch this kind of fraud. Attackers are often validating with real, correctly entered credentials obtained through phishing scams or social engineering, so a login system working exactly as designed can still hand an account to the wrong person.
Instead, ZIGRAM’s analysis calls for combining signals across the customer journey: unfamiliar devices, behavioral changes, password and contact-detail updates, new beneficiaries, unusual transaction patterns, and connections to other flagged accounts. No single signal is conclusive on its own. A new device or a password reset can be entirely legitimate. But several such changes clustering in a short window, particularly ahead of a high-value transfer, meaningfully raise risk.
Why it matters: Fraudsters increasingly rely on real credentials rather than obviously fake ones. As a result, the industry’s historical emphasis on login-time authentication is becoming less sufficient on its own. Detection is shifting toward continuous, risk-based monitoring. Device intelligence, behavioral analytics, account-change monitoring, transaction monitoring, and network intelligence are increasingly treated as one connected system rather than separate checks.
Source: ZIGRAM; FinTech Global; FBI/IC3 Public Service Announcement I-112525-PSA (Nov. 25, 2025)












