Microleap
Microleap
Microleap
Close Menu
    • About Fintech News Network
    • Work With Us
    • Contact Us
    • Media Kit
    • Advertise With Us
    • Fintech Malaysia Newsletter
    • Submit Fintech Startup
    • Submit Press Release
    • Submit Interview Request
    • Submit Fintech Event
    • Submit Vacancy
    • Webinar Inquiry APAC
    • Fintech Startups in Malaysia
    LinkedIn Facebook X (Twitter) YouTube RSS
    • About
      • About Fintech News Network
      • Work With Us
    • Contact Us
    • Media Kit
    • Advertise With Us
    • Fintech Malaysia Newsletter
    • Submit Press Release
    • Submit
      • Submit Press Release
      • Submit Fintech Startup
      • Submit Interview Request
      • Submit Fintech Event
      • Submit Vacancy
      • Webinar Inquiry APAC
    • Fintech Events in Malaysia
    • MY Fintech Startup Directory
    Fintech News Malaysia

    Fintech News Network

    LinkedIn Facebook X (Twitter) Instagram YouTube TikTok RSS
    Free Newsletter
    • Blockchain
    • Lending
    • Payments
    • Insurtech
    • Wealthtech
    • Regtech
    • Report
    • Startups
    • Events
    • Jobs
    Fintech News Malaysia

    Fintech News Network

    Home»Security»How Can Financial Institutions Put a Stop to Account Takeover Attacks
    Security Sponsored

    How Can Financial Institutions Put a Stop to Account Takeover Attacks

    Greg Hancell, Director Product Management - Data Strategy, OneSpanGreg Hancell, Director Product Management - Data Strategy, OneSpanNovember 30, 20216 Mins Read
    LinkedIn Facebook Twitter Copy Link Telegram Email
    How Can Financial Institutions Put a Stop to Account Takeover Attacks
    Share
    LinkedIn Facebook Twitter Telegram Copy Link Email
    Free Newsletter

    Get the hottest Fintech Malaysia News once a month in your Inbox

    Financial Institutions (FI’s) can detect and prevent account takeover attacks using continuous monitoring and adaptive multi-factor authentication.

    Account takeover (ATO) fraud is one of the top causes of fraud losses for banks and financial institutions. An account takeover occurs when a customer’s bank account is digitally ‘broken into’ and acted on by an attacker.

    The methods and techniques attackers use to fraudulently obtain access to a customer’s account credentials are continually evolving.

    These include obtaining data from data breaches, malware, phishing, and other social engineering attacks such as phone scams (read more on common fraud techniques).

    Account takeover is increasing due to lower barriers of entry, high rewards. lower risk of consequence and a fast movement by companies to try and offer digital services in reaction to the pandemic.

    Additionally, attackers have more tools than ever available from the underground market.

    They have more data to utilise, due to a record breaking 37 billion personal data records compromised in 2020 and more potential victims, companies and users that are new to digital services.

    This results in personal data being available to attackers on demand, who can put it to use in an account takeover.

    Source: Pixabay

    Attacks are becoming more advanced and automated, for example an emulation attack with malware which was executed in December 2020 resulting in millions of users accounts being attacked in hours, despite the bank using SMS one time passwords.

    The attackers were able to perfectly emulate devices, breaking security relying on device fingerprinting and intercept the SMS OTP without the victim knowing.

    These attacks can result in identity theft, credentials / OTP’s for attacking a login / recovery process and or personal information to increase the success of social engineering we cannot ignore the threat this poses.

    From a user perspective, these attacks might result in fraudulent payments to new beneficiaries and thus the loss of their savings, losing access to the account, as the attacker changes the authentication method such as registering a new device or changing the password.

    Also the attacker may apply for a new product using the customer’s personal data.

    For financial institutions (FI’s), the impact of account takeover attacks can go well beyond financial losses.

    The FI’s need to move fast to reduce the likelihood of the attack continuing / scaling and recover from the attack itself. The attack can lead users to lose trust in the FI and can impact consumer confidence and growth.

    How Financial Institutions Can Get Better at Detecting and Preventing Account Takeover Attacks

    Source: Shutterstock

    Account takeover attacks cost FI’s billions in payouts and compensation to users. To reduce these losses, FIs must find ways to detect and prevent an attacker from trying to obtain access to an account, and when an attacker is attempting to carry out an action or transactions fraudulently inside a users account.

    Preventing attacks relies on establishing trust with the user and determining their behavior. For example aside from the credentials / OTP being correct, is what they are doing typical for them.

    Trust, is not static. Trust is fluid, everchanging and may increase or decrease based on interactions and outcomes, it is therefore crucial for trust to be determined in real-time.

    In short, FI’s need to address the issue of trust– when can they trust that a genuine user is accessing and using their account, how can they determine if a genuine user is being socially engineered to make a transfer they should not, and how can they determine when an attack is underway?

    To solve this problem, FIs need a profoundly innovative approach – one that enables the collection and analysis of vast cross-channel data to detect and react to attacks in real-time.

    Continuous monitoring is the real time collection and behavioral understanding of users and devices.

    Allowing the understanding of the ‘normal’ behavior of the user – such as the way they interact with the device, how they type, swipe and drag across a page, and how they typically establish and interact with sessions, the types of transfers they make and many more.

    This creates a profile of their normal behavior.

    Machine learning utilises 1000’s of features (intelligence points of a user their device and location) to contrast the normal behavior of the user against suspicious behavior, such as the behavior of a bot or attacker.

    When suspicious behavior is detected, FI’s can react immediately such as request additional authentication from the user, change the authentication approach if a device is compromised and or challenge access or transactions taking place.

    If the users authentication and behavior are deemed low risk then they can proceed. If not, the process is stopped and the attack is prevented.

    The capability to learn from all attacks, indicators of compromise (known malicious data attributes) and fraud enables machine learning models to outperform typical rule sets optimising costs and reducing losses.

    Why Financial Institutions Need to Make ATO Prevention a Priority

    Source: iStock

    Static credentials such as usernames, email addresses and secret answers are vulnerable to attacks due to mass data breaches and users repeat credentials across multiple websites, social media profiles and sign-up accounts.

    Authenticating users at login and using credentials alone is no longer an option.

    Analyst firm KuppingerCole argues that only requiring a username/password for access to online or mobile banking systems is grossly insufficient for account security.

    Financial institutions must continuously monitor the user’s actions and behavior to detect suspicious actors and challenge with setup-up security when risk is detected.

    Additionally, the presence of malware on mobile devices makes users vulnerable to SMSishing attacks and SMS one time password (SMS OTP) interception.

    The increasing sophistication of attacks utilising a blend of technology such as malware, device emulation and session simulation increases the scale of attacks meaning millions of users can be impacted in a day.

    FI’s that use static credentials and SMS OTP are vulnerable to high scale, high impact attacks.

    How Intelligent Adaptive Authentication Technology Can Stop Account Takeovers

    Source: iStock

    Intelligent adaptive authentication (IAA) provides a secure frictionless experience for users to authenticate.

    Continuous monitoring with contextual understanding enables real time decision making and provides the relevant authentication method(s) relevant to the risk and friction.

    The technology uses real-time risk analysis to determine the most suitable authentication method(s) based on the level of risk derived from the context of what a user is doing and the environment they are interacting in i.e. device risk.

    Tailoring the authentication flow to each unique interaction reduces friction and fraud. As the user’s particular contextual patterns and circumstances evolve, the technology is intelligent enough to recognise these changes and adapt.

    OneSpan IAA enables FI’s to deliver digital experiences users love.

    By understanding their behavior and intentions whilst automating authentication decisions resulting in greater UX, reduced operational costs and a reduction in fraud.

    OneSpan

    Featured image credits: Pixabay

    OneSpan
    Share. LinkedIn Facebook Twitter Telegram Copy Link Email

    Author

    Greg Hancell
    Greg Hancell, Director Product Management - Data Strategy, OneSpan

    Greg Hancell has a comprehensive understanding of fraud and risk management to catch known and emergent fraud. Greg is a global fraud consultant that focuses on people, process and tools to enable Financial Institutions to transform from reactive to proactive to identify financial crime and drive down losses. Greg has a keen interest in the utilisation of machine learning, defense in depth and real time monitoring solutions. In the presentation, he will discuss how applying continuous behavioural monitoring with multi-layered online fraud detection solution can increase trust and reduce fraud.

    Related Posts

    Agrobank Fraud Case Results in 47 Arrests After RM203.8 Million Loss, Says Minister

    February 5, 2026

    AI in Finance Works Best As An Ecosystem, Says Huawei’s Roger Wang

    January 30, 2026

    Malaysia Loses RM542 Million to Scams in 2025, Only RM34 Million Recovered

    January 27, 2026

    Malaysian Banks Urge Customers to Update Browsers and Mobile Systems

    December 22, 2025

    PayNet Fintech Hub Is Sparking a New Kind of Collaboration in Malaysia

    December 19, 2025

    Modernising Bank Payments: How Banks Can Win in Merchant Acquiring

    December 10, 2025

    The Silent Disruptor: Unmasking Digital Fraud in APAC’s Financial Networks

    December 10, 2025

    ESG in Action: Setlary’s RM100 Million Boost to Champion Employee Financial Wellness

    December 5, 2025
    Digital Banking

    Five Years On, And Asia’s Digital Banking Experiment Is Finally Growing Up

    Sponsor: MambuJanuary 13, 2026
    Fintech Malaysia Newsletter
    Subscribe to the most important Fintech Malaysia News
    Follow Us
    • LinkedIn
    • Facebook
    • X / Twitter
    • Instagram
    • YouTube
    • TikTok
    MY Fintech Startup Directory

    Malaysia Fintech Startup Directory

    Featured Fintech Event

    Money2020 Asia

    Featured Fintech Video

    How to Build an AI First Bank

    Featured Webinar Replay

    Webinar - Inside Asia Pacific’s Fraud Crisis and the Battle to Stop It

    Upcoming Fintech Events
    UK - Southeast Asia Tech Week 2026
    February 9, 2026
    -
    February 13, 2026
    Malaysia, Philippines, Singapore
    -
    Kuala Lumpur, Manila
    Money20/20 Asia 2026
    April 21, 2026
    -
    April 23, 2026
    Thailand
    Digital Transformation Summit - Malaysia 2026
    April 23, 2026
    Malaysia
    -
    Kuala Lumpur
    Fintech Revolution Summit – Malaysia 2026
    July 23, 2026
    Malaysia
    -
    Kuala Lumpur
    Promote Event View More
    Fintech Jobs
    Group Product Manager – Payments and FX Lead
    Full-time, On-site
    DK Bank
    View
    Analyst, Transaction Monitoring
    Kuala Lumpur, Full-time, On-site
    Airwallex
    View
    Project Management Officer
    Kuala Lumpur, Full-time, On-site
    Hytech
    View
    Chief Operating Officer (COO)
    Federal Territory of Kuala Lumpur, Full-time, Hybrid
    Direct Lending
    View
    Product Owner (Cards, Deposits and Campaigns)
    Federal Territory of Kuala Lumpur, Full-time, On-site
    Boost Bank
    View
    Add Vacancy View More
    Whitepapers & E-Books
     The Tipping Point for Innovation in B2B Payments
    The Tipping Point for Innovation in B2B Payments
    Visa Direct
    Navigation
    • About Fintech News Network
    • Advertise With Us
    • Media Kit
    • Work With Us
    • Contact Us
    • Fintech Malaysia Newsletter
    • Submit Press Release
    • Submit Fintech Startup
    • Submit Fintech Event
    • Submit Interview Request
    • Submit Vacancy
    • Fintech Events in Malaysia
    • Directory
    • Privacy Policy / Disclaimer
    Other Fintech News Network Publications
    Fintech News Malaysia
    Fintech News Singapore
    Fintech News Hong Kong
    Fintech News Philippines
    Fintech News Network Indonesia
    Fintech News Network Thailand
    Fintech News Switzerland
    Fintech News Baltic
    Fintech News Nordics
    Fintech News America
    Fintech News Middle East
    Fintech News Africa
    Get Informed

    Subscribe to Updates

    Subscribe to the most important Fintech Malaysia News

    LinkedIn Facebook X (Twitter) YouTube RSS
    • About Fintech News Network
    • Advertise With Us
    • Media Kit
    • Work With Us
    • Contact Us
    • Fintech Malaysia Newsletter
    • Submit Press Release
    • Submit Fintech Startup
    • Submit Fintech Event
    • Submit Interview Request
    • Submit Vacancy
    • Fintech Events in Malaysia
    • Directory
    • Privacy Policy / Disclaimer
    © 2015 - 2026 Copyright CK Finanzpro GmbH. All Rights reserved.

    Type above and press Enter to search. Press Esc to cancel.