Account Takeover Fraud Continues to Rise as Cybercriminals Refine Their Tactics
From the desk of Jim Eccleston at Eccleston Law
Cybercriminals continue to refine account takeover schemes, driving billions of dollars in losses for businesses and consumers each year. According to Crain's Chicago Business, account takeover fraud allows criminals to gain control of financial accounts, transfer or withdraw funds, make unauthorized purchases, change account information, and even sell compromised account credentials to other bad actors.
A report from the U.S. Federal Reserve found that reported account takeover fraud losses reached more than $15.6 billion in 2024, an increase from $12.7 billion in 2023 and $11 billion in 2022. The report also noted that reported account takeover incidents filed with the Financial Crimes Enforcement Network (FinCEN) increased by more than 36 percent during 2024.
According to Crain's Chicago Business, advances in artificial intelligence have made many fraud schemes more convincing, but the underlying tactics remain largely unchanged. Criminals continue to rely heavily on social engineering by impersonating trusted organizations, including banks, government agencies, or familiar businesses, to pressure victims into revealing usernames, passwords, or one-time authentication codes.
Fraud specialists emphasize that urgency remains one of the most effective tools for scammers. Criminals frequently create a false sense of panic by claiming that an unauthorized transaction has occurred or that an account faces immediate risk. Once victims react emotionally, scammers attempt to obtain sensitive account credentials.
Crain's Chicago Business reports that cybersecurity professionals encourage individuals to follow a simple approach when confronted with unexpected requests for account information: pause, evaluate the situation, and independently verify the request by contacting the financial institution through an official phone number rather than responding directly to the caller or message.
Social engineering campaigns also may unfold over extended periods. Rather than immediately seeking account credentials, fraudsters sometimes gather seemingly harmless pieces of information through casual conversations. They later use those details to impersonate trusted vendors or service providers and increase the credibility of future fraudulent requests.
Strong password management remains an important defense against account takeover fraud. Notably, criminals continue to exploit reused passwords, stolen credentials obtained through data breaches, and personal identifying information to gain unauthorized access to financial accounts. Artificial intelligence has further enhanced criminals' ability to generate likely usernames and security question responses using publicly available or previously compromised information.
Malware, phishing emails, fraudulent text messages, and malicious attachments also continue to serve as common entry points for account compromise. Security experts recommend avoiding unexpected links or attachments and exercising caution before providing any sensitive information online.
Eccleston Law LLC represents investors and financial advisors nationwide in securities, employment, transition, regulatory, and disciplinary matters.
Tags: eccleston, eccleston law, account takeover fraud, cybersecurity, financial fraud, cybercrime, securities law





