Account takeovers rise nearly threefold during pandemic
Financial services hit hardest by account hijackers, says Sift report


Account takeover fraud has soared during the pandemic, according to a report released today by anti-fraud company Sift.
Sift’s Q3 2021 Digital Trust & Safety Index claims account takeovers increased threefold between Q2 2019 and Q2 2021. It now represents 39% of all fraud the company blocks.
Most of this increase happened during the pandemic, with attacks rising approximately 2.8 times in the past year alone. The rise is ongoing, the report said, having failed to revert to pre-pandemic levels.
Financial services were the hardest hit, with account takeovers increasing 850% between Q2 2020 and Q2 2021. However, most of these attacks focused on cryptocurrency wallets and accounts, which are a well-known target for scammers.
Criminals don't always do anything immediately obvious to stolen accounts, such as changing passwords. Instead, they test the account credentials on other services — an attack known as credential stuffing — to see if they can access the victim's other accounts too.
Hackers will also mine the accounts for credit card information, personal information, and password hints. This is perhaps why there are so many repeat victims, as half of them have had accounts hijacked multiple times.
RELATED RESOURCE
Sift found that thieves stole money directly from 45% of victims, and 42% of account takeovers resulted in unauthorized purchases with a stored credit card. A quarter of victims lost loyalty and rewards points, and one in five were unsure of the total impact of the account takeover attack.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Automation is becoming a bigger factor in account takeover fraud, Sift warned. Attackers use bots to attempt credential stuffing attacks using large lists of login credentials purchased on the dark web.
They often use lists of servers that attempt to log in from different IP addresses to make their activities less suspicious. Sift correlates the addresses and servers to form clusters of known bad addresses. The number of IP addresses in the largest known IP cluster grew 50-fold between Q1 and Q2 2021, thanks to an automated account takeover fraud group called Proxy Phantom.
Danny Bradbury has been a print journalist specialising in technology since 1989 and a freelance writer since 1994. He has written for national publications on both sides of the Atlantic and has won awards for his investigative cybersecurity journalism work and his arts and culture writing.
Danny writes about many different technology issues for audiences ranging from consumers through to software developers and CIOs. He also ghostwrites articles for many C-suite business executives in the technology sector and has worked as a presenter for multiple webinars and podcasts.
-
Security experts issue warning over the rise of 'gray bot' AI web scrapers
News While not malicious, the bots can overwhelm web applications in a way similar to bad actors
By Jane McCallion Published
-
Does speech recognition have a future in business tech?
Once a simple tool for dictation, speech recognition is being revolutionized by AI to improve customer experiences and drive inclusivity in the workforce
By Jonathan Weinberg Published
-
FBI warns scammers are using cryptocurrency ATMs to siphon cash
News Criminals will stay on phone with victims as they make payments, says advisory
By Danny Bradbury Published
-
Hackers fake DocuSign and offer fraudulent signing methods
News Criminals impersonate the e-signing company to steal credentials
By Rene Millman Published
-
Cyber criminals leak one million credit cards on the dark web
News Among the stolen hoard are customer details from US and Canadian banks
By Rene Millman Published
-
SentiLink raises $70 million for its identity verification platform
News SentiLink’s ID Theft Score helps businesses combat synthetic fraud
By Praharsha Anand Published
-
Content fraud levels continue to rise in 2021
News The pandemic has ushered in a new level of scams and misinformation
By Danny Bradbury Published
-
What is DMARC and how can it improve your email security?
In-depth Protect your customers and brand rep with this email authentication protocol for domain spoofing
By Gabriella Buckner Published
-
FTC warns of rising cryptocurrency fraud
News Marked rise in cryptocurrency losses began just as pandemic took hold
By Danny Bradbury Published
-
E-commerce fraud to surpass $20 billion this year
News Research finds merchants need to do more to implement fraud prevention
By Rene Millman Published