# Covid-19 has made your customer accounts more valuable
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2021-09-15
Category: BUSINESS
Category URL: https://financedigest.com/category/business
Meta Title: Why Account Takeover Attacks are Thriving Amidst Rapid
Meta Description: Discover why account takeover attacks are on the rise, how fraudsters are infiltrating accounts, and what industries are most vulnerable. Stay informed and
URL: https://financedigest.com/covid-19-has-made-your-customer-accounts-more-valuablehtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/young-surprised-model-looking-at-tablet-in-studio-isolated-orange-background-sbi-302849723-1736837875342-compressed.jpg)

_By_ **_Mairtin O’Riada,_** _CIO and co-founder,_ [_Ravelin_](http://www.ravelin.com/)

Account takeover (ATO) attacks have long been a threat to merchants, but the rapid digital acceleration we’ve seen because of the pandemic has created perfect conditions for ATO to thrive.

Now, [36%](https://pages.ravelin.com/account-takeover-report) of merchants rank account takeover as the number-one threat they are facing.

Why? Existing fraudsters were given more time to focus on attacks, financial hardship drove new people to turn to fraud, and the number of potential victims boomed — with people across the globe being forced online to work, shop and be entertained.

**What is “account takeover”?**

ATO occurs when a fraudster infiltrates a genuine customer’s account. Fraudsters like this tactic as it can be harder to [detect than traditional online payment fraud](https://www.financedigest.com/the-clues-to-detecting-fraud-are-hidden-in-relationships.html "THE CLUES TO DETECTING FRAUD ARE HIDDEN IN RELATIONSHIPS"). By accessing an account through existing credentials, rather than creating a fresh account and using stolen card details, [businesses are duped into thinking any activity](https://www.financedigest.com/euro-zone-business-activity-contracted-again-in-aug-outlook-bleak-2.html "Euro zone business activity contracted again in Aug, outlook bleak") is that of a legitimate customer.

It’s not only ecommerce [businesses that face](https://www.financedigest.com/overcoming-challenges-faced-by-women-in-business.html "Overcoming challenges faced by women in business") this threat. Any online account can fall into the hands of fraudsters, including subscription services, banks and emails. And once access is gained, there are several routes a fraudster can take to monetise the account. For example, using saved card details to make orders, redeeming loyalty points, or extracting [customer data](https://www.financedigest.com/manchester-arts-centre-the-lowry-selects-logpoints-siem-technology-to-safeguard-customer-data.html "Manchester arts centre The Lowry selects LogPoint’s SIEM technology to safeguard customer data") to sell online.

Fraudsters are having a lot of [success in obtaining accounts](https://www.financedigest.com/what-successful-accounting-looks-like-in-the-age-of-the-consumer.html "What successful accounting looks like in the age of the consumer") through phishing. Over the past 12 months, there’s been a spike in sophisticated phishing attacks, with [research](https://www.cpomagazine.com/cyber-security/phishing-attacks-actively-using-alternative-exfiltration-methods-including-google-forms-and-telegram-bots/) finding that email is the most popular method of tricking customers into giving away their login credentials.

Another method commonly used to infiltrate customer accounts is credential stuffing. Here, fraudsters use software to try leaked credentials that they’ve bought or obtained through [data dumps on several popular websites — all in the hope](https://www.financedigest.com/oil-eases-as-weak-asian-data-more-lockdowns-dampen-demand-hopes.html "Oil eases as weak Asian data, more lockdowns dampen demand hopes") that a victim has used the same username and password across different sites. And all too often, this is the case.

**Which accounts have been impacted most?**

Account takeovers are on the rise [across all industries](https://www.financedigest.com/digital-transformation-across-the-banking-industry.html "Digital transformation across the banking industry"). Our [research](https://pages.ravelin.com/account-takeover-report) shows that over the past year half of merchants experienced a rise in account takeovers — suffering on average one high-impact attack per week.

Of course, in the hands of a professional fraudster any customer account can be valuable, but some [businesses have found themselves targeted](https://www.financedigest.com/julius-baer-2022-profits-fall-as-it-hits-business-cycle-targets.html "Julius Baer 2022 profits fall as it hits business cycle targets") more than others during the pandemic.

So, what makes an account a hot target?

Naturally, goods in high demand are easier for attackers to sell, so this is a huge consideration for fraudsters. They’re looking to make money fast, so the ability to make instant purchases on an [account is a big win](https://www.financedigest.com/b2b-specialist-pr-agency-the-digital-voice-announces-three-key-account-wins.html "B2B Specialist PR Agency The Digital Voice Announces Three Key Account Wins"). Also, digital goods appeal to attackers, because of the extra effort involved in selling physical goods.

With this in mind, [it’s no wonder the gaming industry in particular has fallen victim to an increasing number of account](https://www.financedigest.com/midlands-accountants-say-its-never-too-early-to-get-financial-protection.html "MIDLANDS ACCOUNTANTS SAY IT’S NEVER TOO EARLY TO GET FINANCIAL PROTECTION") takeovers. The online gaming industry skyrocketed during various lockdowns, as people resorted to indoor entertainment. Not only did popularity spike, but the existence of in-game currency made them even more lucrative targets — with people spending [way more money](https://www.forbes.com/sites/mattgardner1/2020/05/08/people-are-spending-ridiculous-time-and-money-on-gaming-during-coronavirus/?sh=38675d6a32fe) in game than before.

Ravelin also found that online grocery accounts became very desirable to fraudsters throughout the pandemic. These [retailers saw more attacks than any other — experiencing over five per month](https://www.financedigest.com/advice-for-retailers-as-covid-restrictions-ease-this-independent-retailer-month.html "Advice for retailers as COVID restrictions ease this Independent Retailer Month"). The massive [increase in online traffic](https://www.financedigest.com/benefits-of-increasing-blog-traffic-with-guest-blogging-and-posting-service.html "Benefits of Increasing Blog Traffic With Guest Blogging and Posting Service"), combined with depleting staff due to compulsory isolation, meant fraud teams quickly became overstretched. This increased the likelihood of fraudulent activity flying under the radar.

What’s more, loyalty points that are stored on many grocery accounts are an enticing bonus for attackers. Tesco found itself combatting mass ATO attempts in May last year against Clubcard holders, affecting 600,000 customers.

And it’s not only booming industries being targeted. Accounts in the travel industry became prime targets for fraudsters, [despite the industry feeling some of the worst effects from Covid](https://www.financedigest.com/asias-factory-activity-contracts-despite-chinas-covid-reopening.html "Asia’s factory activity contracts despite China’s COVID reopening"). Air miles and loyalty [points are a jackpot for ATO attackers](https://www.financedigest.com/new-intelligence-points-to-pro-ukraine-group-in-nord-stream-attack-nyt.html "New intelligence points to pro-Ukraine group in Nord Stream attack -NYT") as they’re easily accessible and extremely rewarding. And because people couldn’t travel, victims weren’t checking their accounts. And if the victim doesn’t notice, it makes it far more difficult for fraud teams to mitigate the issue.

**How businesses can combat ATO**

To successfully combat ATO, my advice is to rely on a combination of human input and automation. As a starting point, organisations should be adding an extra layer of security to [customer accounts by way](https://www.financedigest.com/customer-engagement-whos-leading-the-way.html "Customer engagement – who’s leading the way?") of two-factor authentication.

Businesses also [need to monitor customer](https://www.financedigest.com/stay-ahead-of-the-curve-and-meet-your-customers-payments-needs.html "STAY AHEAD OF THE CURVE AND MEET YOUR CUSTOMERS PAYMENTS NEEDS") logins and new devices, which sounds obvious, but we’ve seen many companies simply fail to do this. Attackers often use basic scripting tools that spam a login with credentials, hoping for a combination that works. But if you’re monitoring logins, and you’ve set specific rate limits for logins based on the device, username and IP address, taking into [account your business-specific operational requirements](https://www.financedigest.com/whats-required-of-accounting-to-build-a-better-tomorrow.html "What’s required of Accounting to build a better tomorrow") and customer behaviour, you can prevent the most obvious attacks. You can also autonomously check if a particular customer has updated their password with compromised credentials by using an [API](https://developer.ravelin.com/apis/ato/#credentials-check), which can help you avoid the most egregious of user errors.

But if a fraudster _has_ successfully cracked a password and gained entry, look out for the signs of suspicious subsequent activity. You may see a sudden upsurge in logins compared to normal, which is a red flag that an attack is taking place, and you may also see odd changes to account details, for example a change of phone number. If your logins require a one-time text message code, a sudden change of phone number is a red flag as it could be a sign that the fraudster is looking to direct those text messages to their own mobile devices.

Machine learning can really help be your eyes and ears across all your accounts here. But also bear in mind that fraudsters may display behaviour that are definitely fraudulent to you, but perhaps not for other businesses. For example, an unusually large order may be a strong indicator of [fraud for your business if most of your customers](https://www.financedigest.com/id-fraud-is-on-the-rise-can-financial-services-do-more-to-protect-their-customers.html "ID fraud is on the rise: can financial services do more to protect their customers?") tend to spend roughly the same with each order. That means, if you do use machine learning, you must tailor it to make sure it picks up the right indicators of [fraud for your business](https://www.financedigest.com/why-your-business-is-vulnerable-to-supplier-fraud.html "Why Your Business is Vulnerable to Supplier Fraud"). Otherwise, you’ll either miss fraud cases (because the machine learning isn’t looking for the right signals), or you’ll [end up with high false positive rates](https://www.financedigest.com/ecb-goes-big-with-50-basis-point-hike-ending-negative-rates-era.html "ECB goes big with 50 basis-point hike, ending negative rates era"). Both scenarios cost you money because either you’re missing fraud cases or you’re making the payment [experience difficult for genuine customers](https://www.financedigest.com/is-your-customer-experience-exceptional.html "IS YOUR CUSTOMER EXPERIENCE EXCEPTIONAL?"), who may go elsewhere to make their purchase.

**ATO isn’t going anywhere**

Given the pandemic has given ATO the chance to thrive, there’s never been a more [important time to deal](https://www.financedigest.com/eu-seeks-deal-on-law-preventing-import-of-deforestation-linked-goods.html "EU seeks deal on law preventing import of deforestation-linked goods") with the issue. The sooner you begin to [fight back](https://www.financedigest.com/2016-the-fight-back-of-the-established-brand.html "2016 – THE FIGHT BACK OF THE ESTABLISHED BRAND") with technology, the sooner your machine learning can improve, and the stronger you’ll be at keeping the bad guys out and keeping your customers safe.

That can sound like a daunting task. And while you can’t outsource your fraud responsibility, you can work with a technology partner to reduce both the losses to ATO itself and the [cost of defending](https://www.financedigest.com/uks-sunak-under-fire-over-cost-of-living-defends-his-tax-cut-plans.html "UK’s Sunak, under fire over cost of living, defends his tax cut plans") against it.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

