IPQSBook your demo
Step 1 · Watch the webinar

How fraudsters take over accounts and how to detect them.

A practical briefing for fraud, risk, and security teams.

WEBINAR · 16 MIN
Alexander HallVP of Fraud Strategy · IPQS

Alexander Hall

VP of Fraud Strategy, IPQS

With 20 years of fraud-related experience, Alexander has worked alongside fraud prevention vendors across North America and Western Europe.

Trusted by thousands of businesses

From startups to Fortune 500 enterprises.

10,000+Honeypots & traps
Since 2011Fighting fraud & abuse
Stack Overflow, IBM, Rakuten, Talkdesk, Fibank and New American Funding

What you’ll learn

The warning signs

Login patterns, device activity, and transaction velocity can reveal an account compromise.

How attackers get in

Credential stuffing, support exploits, social engineering, and stolen sessions.

Team blind spots

Build shared visibility across fraud, security, and customer service before the next attack.

Step 2 · Book your demo

See how IPQS fits your fraud strategy

A focused session with an IPQS Fraud Expert.

  • Explore protection at signup and login

  • See IP, email, phone and device signals

  • Understand first-party fraud intelligence

  • Discuss integration with your existing tools

Before you book

Which industries does the webinar cover?

While IPQS works for every industry, Alexander uses examples from ecommerce, financial services, loyalty programs, and iGaming.

How would this fit into our existing stack?

IPQS is an API based product that easily integrates into your existing workflows. IPQS also provides implementation support, SDKs, and partners with industry leading software providers to ensure a fast, smooth onboarding experience.

See IPQS integrations
What will we cover on the demo?

An IPQS Fraud Expert will walk you through the best solutions for your fraud issues and demonstrate how IPQS fits into your existing technology stack.

Webinar transcript

Transcript from the recording’s captions. Select a timestamp to watch that section.

The account takeover landscape

Hello, everybody. Thank you for taking the time out of your day to check out this video. We are here to discuss what is a very high-level framework that is encountering all the corners of the fraud prevention industry. The framework consists of two dynamics that are taking place. Number one, we have fraudsters who are moving across the entire customer experience at any target platform and creating exploits for every touch point. That's one.

At the exact same time, the second dynamic, the second dimension, is happening, where fraudsters are effectively executing against all of the parameters associated with a target identity, from payment to accounts to identity.

Meet Alexander Hall

My name is Alexander Hall. I am the VP of Fraud Strategy for IPQualityScore, also known as IPQS. And as for my background, I have 20 years of fraud-related experience. I've worked with, alongside up to 100 of the prominent fraud vendors in our space, targeting specifically North America and Western Europe.

Why fraud moves upstream

Let's go ahead and get started. Any platform primarily focuses at the point of transaction. For this example, I'm going to say isolated to e-commerce retail. But this applies to every industry out there, but obviously they have different ways to interact with the platform. So the problem has become our entire arsenal has been aimed at chargeback prevention, and so we aim at the transaction.

That's where all of our defenses are set up. What fraudsters have, for years now, have identified is that if they move upstream, they can improve their hit rate. So they move up to the account level. And there we saw the birth of account takeovers, where born good attacks or born good accounts are then compromised and accessed, and leveraging that historical behavior transact with either stored payment information or by associating new compromised cards or anything like that.

They're learning the value of attacking the account origination point or the account creation point. And of course, this will be different for QSRs, as it is for e-commerce retail, as it is for iGaming, or as it is for banks and all those

Finding the root cause across teams

different things. Well, because of this, what ends up happening at fraud prevention teams is a number of things. Number one, it's hard to measure. It's difficult to measure exactly where the exploit took place. One example that I just recently worked on was a miscategorization of identity theft or a mule account, something at the account origination space at that touch point, being miscategorized as friendly fraud down the stream.

And so what happens is we've trained ourselves to identify when the bad thing happens, go right there and evaluate it. In payments, that's okay. For the most part, we can at least identify that a payment was good or bad or should have been allowed or not allowed. Fine. The problem with fraudsters moving upstream across the platform is if we solve it at the point of checkout following an ATO, we're not solving the ATO.

The problem still exists. So in this particular case, it was proposed to us that we need to solve a friendly fraud problem. And upon evaluation of their entire fraud strategy, what we identified was insufficiencies at the account creation stage. And so when we decided to put our eyes there, because there was always this creeping suspicion that maybe this is an ATO, maybe this is an account origination problem, we kept that in our calculus.

And when we went back and did the evaluation of those two touch points, we realized, oh, no, the people that are gaining access to this platform by creating accounts are accessing it in a way that shouldn't be allowed. We cleaned it up there, and we solved the problem three steps downstream. That is what makes this very difficult for a lot of fraud teams and for numerous reasons. Number one, the subject matter is robust.

Number two, it's very proactive data aggregation. Number three, it's across all of these different channels and all of these different teams that are interacting with this particular platform in all these different ways. Maybe it's IT over here, maybe it's customer service over there, maybe it's the treasury department over there. Getting this continual conversation going between these silos and then building up aggregated data for reporting and monitoring to throw the yellow, orange, and red flags, it's a very difficult and proactive thing. It's a very costly thing.

But unfortunately, it is absolutely necessary in order for us to respond to what fraudsters are doing to us. Fraudsters know that these individual touch points are handled by different teams. Fraudsters will go and investigate the hierarchical organizational makeup, and they will see, does this company have a whole lot of fraud investigators, fraud analysts, head of fraud, fraud managers, or is it dispersed? They can see the company makeup pretty reliably by visiting things like LinkedIn. So when they check that, they have an idea of where they can attack based on the compositional makeup of the organization that they're seeking to attack.

From payments to accounts and identities

And each of those items in that second dynamic going up across the target identities of the victim's identity starts at the payment method, whether it's a check or a credit card, a debit card, one of these different things. They started there, and they went and used it wherever they wanted to use it, wherever they could extract some of that value. So the fraudster will start at the payments instrument and exploit it.

Then they'll move up to the account that manages the payments instrument. Then they think to themselves, "Well, shoot. What if I just create the account that then gets the credit card that I can then go spend? There's a guarantee that it won't be charged back because the actual identity holder can't access the account that the fraudster created on their behalf." But this is the world that we're in, these two dynamics across the platform and across the target identity of the victim identity.

They're both correlating at the same time, and it's causing a lot of headache across all of the orgs. So the question becomes: What do we do about that? How do we solve this? How big of an impact is it to an organization?

Loyalty points and the cost of account takeover

So what I would put forward here, and this is all for in-house processing, it's everything that you can do today. Let's focus on account takeover at e-commerce. One trend that we have identified recently is the targeting of loyalty points. We've seen it at QSRs, we've seen it take off at airlines. We've seen loyalty type programs at iGaming take off. These different programs do have demonstrable value, but on a single account-by-account basis, unless you're a big spender, it's exciting, but it's not that exciting. Well, what fraudsters do is they gain access to the account, and then they'll grab all the loyalty points and either transfer it off or aggregate them in one way or another because they're accessing thousands of accounts, or at least they're attempting to access thousands of accounts.

And so to the fraudster, they're able to extract all of this monumental value across all of these different accounts. And if we look at things in isolation, we're going to realize this one account isn't the whole picture. So what does that do to our team? Now, in the case of just the loyalty point spend on an account-by-account basis, some people might say, "Oh, that's not a big deal." But when you zoom out across your platform and you realize that it's hundreds of thousands of accounts, you do see how big the problem becomes. And across the entire program, what we can expect are impacts beyond, obviously, beyond chargebacks. They're not transacting.

They're not buying. They're just using those loyalty points. And so what does that mean? How do we measure that impact? The impact becomes customer loyalty. I don't know about any of you watching this presentation, but if your account were to be compromised, would you continue to trust that platform, any platform? And there will be varying degrees of answers.

So there's brand reputation, obviously. There's customer trust, which of course impacts brand lifetime value. Then what? Think about your marketing dollars that were spent, your customer acquisition costs. Think about the behaviors of a user whose account has been compromised. Do they stay silent on social media? Are they complaining about it on social media? "Company A let a bad guy into my account and drained all the loyalty points that I was saving up for the past three years.

That was my vacation points." It never stops. And one unfortunate statement that I've heard, and I will repeat, is we don't get to dictate how fraud impacts our programs. The best we can do is understand thoroughly what its impact is. We have brand trust, we have brand reputation, we have lifetime value, we've got acquisition rates. We've got all of these different metrics that go into place, and I'll specify again, for QSRs or e-commerce with a point program dealing with ATOs.

Well, what about manual review rates? What about the cost of data in order to be accurate? Because we don't want everyone to jump through some high friction verification process every time they try to log in when they're 10 miles from their house. So now there's man-hours, and there's manual review hours, and there's trend analysis, and there's manual review for anything that finally made it through.

There's the cost of automation, there's the cost of data, there's all of those different things associated with it. And until we get that full view scope, it's going to be very difficult to get a handle on this, and we're going to continue to bleed financially from these

Protecting the account, not just the balance

impacts. So what do we do? But in plenty of circumstances, I have heard it brought forward to say that because they are after the loyalty points and because they are using the loyalty points once they gain that access, that's where we should focus on. They want the loyalty points, put the loyalty points into a chest, lock it away with a key. I would push back on that. Because the truth of the matter is the only way to gain access to that loyalty box or that loyalty point chest or treasure chest is through accessing an established account, a born-good account. A born-good account that has built up loyalty points, the only way to gain access to those loyalty points is after the login.

Then what happens in conversations, they say, "Oh, but we don't want to do all of these verifications." Well, what I would firmly place on the table, and this is, again, something you guys can do in-house on your own before you ever reach out to any sort of vendor or data aggregator.

Behavioral signals and transaction velocity

One thing that you can do is you can begin to identify when these occurrences take place, how they go about interacting with it. For transaction fraud, there's a lot of card testing, incremental increases of dollar amounts. They associated a new card, they transacted for $5, and they saw how that went. Then they did $10, then they did $20, $50, $100, $500, $1,000. You see this ramp-up of value per transaction.

There are two elements there that are very important. The same thing that goes with loyalty points. Now, loyalty points are less stringent, so if they access something with loyalty points and they transfer it out for 500,000 points, just boop, go out of the platform, that happens plenty. But in the event that they're trying to be careful and go undetected, there are two things that you can look at.

There's the velocity of the way that they're transacted, and there's also the amounts that they're transacting against. Another way would be, of course, being reported up to through customer service, maybe a ticket, maybe a complaint, maybe a phone call. When it goes back to the ATO, that performance becomes equally important because you will see what anomalous behavior is as it is contrasted against what normal, common behavior is. Those behaviors, both velocity and amounts, are going to be very relevant in order to identify what you should or could be decisioning on.

Four ways accounts are taken over

I always speak about the four ways to an account takeover. The first one is the most common, that's credential stuffing. We all understand that username and password combinations are available out there in the world. The bad actors take those combinations, plug it into a form. That's one way, credential stuffing. The second way is customer service exploits. So the bad actor will contact customer service regarding an account, and they'll give a very emotionally driving story in order to assure that they can reset access on this account. So then the password reset goes to the new email, they reset access, and now they just gained access to the account.

Now, in this sense, it's common to see that the actual login request, the login access is handled by the cybersecurity team, IT team over there on that side. But then who's being contacted to trigger the password request? Customer service over there. The third way is going to be social engineering of the end user themselves. They're attacking the person who owns the account. All of these things are happening, and they're going as far as to intercept the OTP that then gets sent out. So even with e-commerce platforms, where they are highly reluctant, and for good reason, but highly reluctant to introduce friction, even in the circumstances where friction is being introduced, the victim of the social engineering is handing over that OTP to the bad actor, and they are then accessing the platform. Now, in that case, what we would be looking for is the velocity of the OTP. There might be a device, a passive device intelligence dynamic that you can employ that will allow you to see that the OTP went to one device, but it was a different device that satisfied the OTP when it attempted to log in.

That would be a very important data point. Normal behavior would be, I triggered my password reset, I got the OTP on my device, and then from my device, I reset. That disconnect of where the OTP was satisfied versus where the OTP was sent, very important. The fourth way is going to be compromised cookies and session data. The idea is that a bad actor will grab all of the cookies and the browser data in order to resume a session that was previously in play, bypassing the login entirely. For that reason, it's going to be very important to have robust device intelligence in play, which can be done without engaging a vendor.

Impossible travel and shared visibility

IP would be very important. Imagine there's a phrase that we use in the industry called impossible travel. The idea there is that one account is logged into in California, and then 10 minutes later, the IP resolves to New York. That doesn't make sense. And by tracking behavioral elements like that, we can start to identify access to an account. Now, in all of these examples, it starts to highlight where the storyline stretches across the entire organization, from customer service to the treasury department, to maybe a dedicated fraud team over to cybersecurity, and all these different elements, and they only get pieces of the puzzle.

Practical takeaways

Fraudsters are exploiting them. So to summarize and end this and give you some quick takeaways. So number one, understand the various ways that ATOs can occur on your platform. Understand what the bad actors would be going for. Understand what anomalous behaviors can be called out. That account-level access thing that I just spoke about, that is pretty common across the entire industry. Those are very good indicators.

Number one, understand the storylines, how it impacts the org, and who it impacts. Number two, break those silos. Figure out how to communicate these robust storylines across the industry or across your platform. Number three, understand your visibility. If you are looking at an event basis, you're missing the big picture about the account basis. There are four layers of visibility.

We have the event level, we have the account level, we have the platform level, where you have visibility across all of the accounts, and then, of course, vendors provide the network level because what's first seen to you is not first seen to us. And number four, build your data proactively because when something anomalous happens that is wholly predictable by the industry, you want to be made aware of it immediately. You do not want it to run for weeks while you try to find an answer and build up new data sets. You want to be able to be notified as quickly as possible so that you can implement the thing that you planned on implementing.

Don't implement it today, but at least have some mechanism in place that allows you to see it when it happens, flip a switch, and turn on the thing that you already built. The opposite side of that is now you do research into the use case, now you try to understand what the impact is, now you try to go find support, maybe it's from a third party or maybe you build in-house, and then it's 18 months later and you finally solve the problem. Be ready today for the problems of tomorrow.

Be proactive, my friends. Have a great one.

Account takeover: inside the threat

Alexander Hall · IPQSTalk to a fraud expert