Key Takeaways
- In 2023, account takeover (ATO) incidents represented 24% of all data breaches reported.
- ATO attacks surged by 35% from 2022 to 2023 globally.
- 83% of organizations experienced at least one ATO attempt in 2023.
- Global ATO fraud losses exceeded $10 billion in 2023.
- Average cost per ATO breach reached $4.5 million in 2023.
- Banks lost $2.8 billion to ATO fraud in 2023.
- Credential stuffing, primary ATO method, comprised 65% of attacks.
- Phishing emails led to 32% of successful ATOs.
- Stolen credentials from data breaches used in 81% ATO.
- Financial services saw 40% of all ATO incidents.
- Retail/e-commerce victims in 28% ATO cases.
- Millennials aged 25-34 hit hardest by ATO, 35% cases.
- MFA blocked 99% of ATO attempts in adopters.
- Behavioral biometrics detected 92% ATO in real-time.
- Device fingerprinting stopped 85% automated attacks.
Account takeover fraud surged globally last year, becoming a major threat across industries.
Attack Vectors
Attack Vectors Interpretation
Detection and Prevention
Detection and Prevention Interpretation
Financial Losses
Financial Losses Interpretation
Prevalence and Trends
Prevalence and Trends Interpretation
Victim Profiles
Victim Profiles Interpretation
Sources & References
- Reference 1VERIZONverizon.comVisit source
- Reference 2AKAMAIakamai.comVisit source
- Reference 3PROOFPOINTproofpoint.comVisit source
- Reference 4IC3ic3.govVisit source
- Reference 5EXPERIANexperian.comVisit source
- Reference 6RSASECURITYrsasecurity.comVisit source
- Reference 7IMPERVAimperva.comVisit source
- Reference 8BLOGblog.cloudflare.comVisit source
- Reference 9APWGapwg.orgVisit source
- Reference 10OKTAokta.comVisit source
- Reference 11BIGCOMMERCEbigcommerce.comVisit source
- Reference 12FASTLYfastly.comVisit source
- Reference 13FICOfico.comVisit source
- Reference 14KASPERSKYkaspersky.comVisit source
- Reference 15FEEDZAIfeedzai.comVisit source
- Reference 16MCAFEEmcafee.comVisit source
- Reference 17HAVEIBEENPWNEDhaveibeenpwned.comVisit source
- Reference 18MANDIANTmandiant.comVisit source
- Reference 19ESECURITYPLANETesecurityplanet.comVisit source
- Reference 20SOPHOSsophos.comVisit source
- Reference 21MARKETSANDMARKETSmarketsandmarkets.comVisit source
- Reference 22LOOKOUTlookout.comVisit source
- Reference 23FTCftc.govVisit source
- Reference 24LASTPASSlastpass.comVisit source
- Reference 25RECORDEDFUTURErecordedfuture.comVisit source
- Reference 26NETSKOPEnetskope.comVisit source
- Reference 27PONEMONponemon.orgVisit source
- Reference 28SALTsalt.securityVisit source
- Reference 29ACFEacfe.comVisit source
- Reference 30IBMibm.comVisit source
- Reference 31ABAaba.comVisit source
- Reference 32LEXISNEXISlexisnexis.comVisit source
- Reference 33NRFCnrfc.usVisit source
- Reference 34ALLIANZ-COMMERCIALallianz-commercial.comVisit source
- Reference 35PYMNTSpymnts.comVisit source
- Reference 36HISCOXhiscox.comVisit source
- Reference 37CHAINALYSISchainalysis.comVisit source
- Reference 38HHShhs.govVisit source
- Reference 39IATAiata.orgVisit source
- Reference 40NEWZOOnewzoo.comVisit source
- Reference 41VISAvisa.comVisit source
- Reference 42IABiab.comVisit source
- Reference 43MARSHmarsh.comVisit source
- Reference 44FINTECHFUTURESfintechfutures.comVisit source
- Reference 45CHARGEBACKS911chargebacks911.comVisit source
- Reference 46FBIfbi.govVisit source
- Reference 47HOSPITALITYNEThospitalitynet.orgVisit source
- Reference 48CROWDSTRIKEcrowdstrike.comVisit source
- Reference 49BLACKHAWKNETWORKblackhawknetwork.comVisit source
- Reference 50GSMAgsma.comVisit source
- Reference 51ACIWORLDWIDEaciworldwide.comVisit source
- Reference 52GDPRgdpr.euVisit source
- Reference 53MALWAREBYTESmalwarebytes.comVisit source
- Reference 54MICROSOFTmicrosoft.comVisit source
- Reference 55CYBEREASONcybereason.comVisit source
- Reference 56PORTSWIGGERportswigger.netVisit source
- Reference 57OWASPowasp.orgVisit source
- Reference 58ZDNETzdnet.comVisit source
- Reference 59BREAKDEVbreakdev.orgVisit source
- Reference 60ARMISarmis.comVisit source
- Reference 61AARPaarp.orgVisit source
- Reference 62PEWRESEARCHpewresearch.orgVisit source
- Reference 63NIELSENnielsen.comVisit source
- Reference 64CONSUMERFINANCEconsumerfinance.govVisit source
- Reference 65HOOTSUITEhootsuite.comVisit source
- Reference 66UPWORKupwork.comVisit source
- Reference 67BIO-KEYbio-key.comVisit source
- Reference 68NISTnist.govVisit source
- Reference 69GARTNERgartner.comVisit source
- Reference 70DATATRACKERdatatracker.ietf.orgVisit source
- Reference 71CLOUDFLAREcloudflare.comVisit source
- Reference 72SPLUNKsplunk.comVisit source
- Reference 73PINGIDENTITYpingidentity.comVisit source
- Reference 74FIDOALLIANCEfidoalliance.orgVisit source
- Reference 75MAXMINDmaxmind.comVisit source
- Reference 76EXABEAMexabeam.comVisit source
- Reference 77KNOWBE4knowbe4.comVisit source
- Reference 78CYBERARKcyberark.comVisit source
- Reference 79ISACAisaca.orgVisit source






