Close Menu
    • Fintech Startups Malaysia – List of Fintech Startups and Fintech Companies in Malaysia
    • About Fintech News Network
    • Work With Us
    • Contact Us
    • Media Kit
    • Advertise With Us
    • Fintech Malaysia Newsletter
    • Submit Fintech Startup
    • Submit Press Release
    • Submit Interview Request
    • Submit Fintech Event
    • Webinar Inquiry APAC
    LinkedIn Facebook X (Twitter) YouTube RSS
    • About
      • About Fintech News Network
      • Work With Us
    • Contact Us
    • Media Kit
    • Advertise With Us
    • Fintech Malaysia Newsletter
    • Submit Press Release
    • Submit
      • Submit Press Release
      • Submit Fintech Startup
      • Submit Interview Request
      • Submit Fintech Event
      • Submit Your Vacancy
      • Webinar Inquiry APAC
    • Fintech Events in Malaysia
    • MY Fintech Startup Directory
    Fintech News Malaysia
    part of Fintech News Network

    Fintech News Network

    LinkedIn Facebook X (Twitter) Instagram YouTube TikTok RSS
    Free Newsletter
    • Blockchain
    • Digital Banking
    • Lending
    • Payments
    • Insurtech
    • Wealthtech
    • Regtech
    • Report
    • Startups
    • Events
    Fintech News Malaysia

    Fintech News Network

    Home»Security»How Can Financial Institutions Put a Stop to Account Takeover Attacks
    Security Sponsored

    How Can Financial Institutions Put a Stop to Account Takeover Attacks

    Greg Hancell, Director Product Management - Data Strategy, OneSpanGreg Hancell, Director Product Management - Data Strategy, OneSpanNovember 30, 20216 Mins Read
    LinkedIn Facebook Twitter Copy Link Telegram Email
    How Can Financial Institutions Put a Stop to Account Takeover Attacks
    Share
    LinkedIn Facebook Twitter Telegram Copy Link Email
    Free Newsletter

    Get the hottest Fintech Malaysia News once a month in your Inbox

    Financial Institutions (FI’s) can detect and prevent account takeover attacks using continuous monitoring and adaptive multi-factor authentication.

    Account takeover (ATO) fraud is one of the top causes of fraud losses for banks and financial institutions. An account takeover occurs when a customer’s bank account is digitally ‘broken into’ and acted on by an attacker.

    The methods and techniques attackers use to fraudulently obtain access to a customer’s account credentials are continually evolving.

    These include obtaining data from data breaches, malware, phishing, and other social engineering attacks such as phone scams (read more on common fraud techniques).

    Account takeover is increasing due to lower barriers of entry, high rewards. lower risk of consequence and a fast movement by companies to try and offer digital services in reaction to the pandemic.

    Additionally, attackers have more tools than ever available from the underground market.

    They have more data to utilise, due to a record breaking 37 billion personal data records compromised in 2020 and more potential victims, companies and users that are new to digital services.

    This results in personal data being available to attackers on demand, who can put it to use in an account takeover.

    Source: Pixabay

    Attacks are becoming more advanced and automated, for example an emulation attack with malware which was executed in December 2020 resulting in millions of users accounts being attacked in hours, despite the bank using SMS one time passwords.

    The attackers were able to perfectly emulate devices, breaking security relying on device fingerprinting and intercept the SMS OTP without the victim knowing.

    These attacks can result in identity theft, credentials / OTP’s for attacking a login / recovery process and or personal information to increase the success of social engineering we cannot ignore the threat this poses.

    From a user perspective, these attacks might result in fraudulent payments to new beneficiaries and thus the loss of their savings, losing access to the account, as the attacker changes the authentication method such as registering a new device or changing the password.

    Also the attacker may apply for a new product using the customer’s personal data.

    For financial institutions (FI’s), the impact of account takeover attacks can go well beyond financial losses.

    The FI’s need to move fast to reduce the likelihood of the attack continuing / scaling and recover from the attack itself. The attack can lead users to lose trust in the FI and can impact consumer confidence and growth.

    How Financial Institutions Can Get Better at Detecting and Preventing Account Takeover Attacks

    Source: Shutterstock

    Account takeover attacks cost FI’s billions in payouts and compensation to users. To reduce these losses, FIs must find ways to detect and prevent an attacker from trying to obtain access to an account, and when an attacker is attempting to carry out an action or transactions fraudulently inside a users account.

    Preventing attacks relies on establishing trust with the user and determining their behavior. For example aside from the credentials / OTP being correct, is what they are doing typical for them.

    Trust, is not static. Trust is fluid, everchanging and may increase or decrease based on interactions and outcomes, it is therefore crucial for trust to be determined in real-time.

    In short, FI’s need to address the issue of trust– when can they trust that a genuine user is accessing and using their account, how can they determine if a genuine user is being socially engineered to make a transfer they should not, and how can they determine when an attack is underway?

    To solve this problem, FIs need a profoundly innovative approach – one that enables the collection and analysis of vast cross-channel data to detect and react to attacks in real-time.

    Continuous monitoring is the real time collection and behavioral understanding of users and devices.

    Allowing the understanding of the ‘normal’ behavior of the user – such as the way they interact with the device, how they type, swipe and drag across a page, and how they typically establish and interact with sessions, the types of transfers they make and many more.

    This creates a profile of their normal behavior.

    Machine learning utilises 1000’s of features (intelligence points of a user their device and location) to contrast the normal behavior of the user against suspicious behavior, such as the behavior of a bot or attacker.

    When suspicious behavior is detected, FI’s can react immediately such as request additional authentication from the user, change the authentication approach if a device is compromised and or challenge access or transactions taking place.

    If the users authentication and behavior are deemed low risk then they can proceed. If not, the process is stopped and the attack is prevented.

    The capability to learn from all attacks, indicators of compromise (known malicious data attributes) and fraud enables machine learning models to outperform typical rule sets optimising costs and reducing losses.

    Why Financial Institutions Need to Make ATO Prevention a Priority

    Source: iStock

    Static credentials such as usernames, email addresses and secret answers are vulnerable to attacks due to mass data breaches and users repeat credentials across multiple websites, social media profiles and sign-up accounts.

    Authenticating users at login and using credentials alone is no longer an option.

    Analyst firm KuppingerCole argues that only requiring a username/password for access to online or mobile banking systems is grossly insufficient for account security.

    Financial institutions must continuously monitor the user’s actions and behavior to detect suspicious actors and challenge with setup-up security when risk is detected.

    Additionally, the presence of malware on mobile devices makes users vulnerable to SMSishing attacks and SMS one time password (SMS OTP) interception.

    The increasing sophistication of attacks utilising a blend of technology such as malware, device emulation and session simulation increases the scale of attacks meaning millions of users can be impacted in a day.

    FI’s that use static credentials and SMS OTP are vulnerable to high scale, high impact attacks.

    How Intelligent Adaptive Authentication Technology Can Stop Account Takeovers

    Source: iStock

    Intelligent adaptive authentication (IAA) provides a secure frictionless experience for users to authenticate.

    Continuous monitoring with contextual understanding enables real time decision making and provides the relevant authentication method(s) relevant to the risk and friction.

    The technology uses real-time risk analysis to determine the most suitable authentication method(s) based on the level of risk derived from the context of what a user is doing and the environment they are interacting in i.e. device risk.

    Tailoring the authentication flow to each unique interaction reduces friction and fraud. As the user’s particular contextual patterns and circumstances evolve, the technology is intelligent enough to recognise these changes and adapt.

    OneSpan IAA enables FI’s to deliver digital experiences users love.

    By understanding their behavior and intentions whilst automating authentication decisions resulting in greater UX, reduced operational costs and a reduction in fraud.

    OneSpan

    Featured image credits: Pixabay

    OneSpan
    Share. LinkedIn Facebook Twitter Telegram Copy Link Email

    Author

    Greg Hancell
    Greg Hancell, Director Product Management - Data Strategy, OneSpan

    Greg Hancell has a comprehensive understanding of fraud and risk management to catch known and emergent fraud. Greg is a global fraud consultant that focuses on people, process and tools to enable Financial Institutions to transform from reactive to proactive to identify financial crime and drive down losses. Greg has a keen interest in the utilisation of machine learning, defense in depth and real time monitoring solutions. In the presentation, he will discuss how applying continuous behavioural monitoring with multi-layered online fraud detection solution can increase trust and reduce fraud.

    Related Posts

    Malaysia Weighs Caning, Scam Refunds for Cybercrime Victims

    July 8, 2026

    Scam Victims to Get Repaid Within 7 Days if E-Wallet Providers Fail BNM Safeguards

    July 2, 2026

    Turning Identity Fraud Insights Into Action as AI-Driven Risks Grow

    July 2, 2026

    The Algorithmic Shift: How AI and Big Data are Rewriting the Rules of Lending

    July 1, 2026

    Malaysia Is Accelerating Its Cloud Journey. But Are We Ready for What Comes Next?

    June 29, 2026

    How Alibaba Cloud Is Powering Digital Investing Growth at M+Global

    June 26, 2026

    Meet AI Neko Sensei by AEON Bank, Your New Financial Coach and Ringgit-Savvy Bestie

    June 18, 2026

    Why The Future Of Insurance Is Hiding In Plain Sight

    June 15, 2026
    Insurtech

    PolicyStreet Sees Embedded Insurance Filling the Gaps in Gig Work

    June 15, 2026
    Fintech Malaysia Newsletter
    Subscribe to the most important Fintech Malaysia News
    Follow Us
    • LinkedIn
    • Facebook
    • X / Twitter
    • Instagram
    • YouTube
    • TikTok
    MY Fintech Startup Directory

    Malaysia Fintech Startup Directory

    Security Sponsored

    Turning Identity Fraud Insights Into Action as AI-Driven Risks Grow

    Fintech News MalaysiaJuly 2, 2026
    Featured Fintech Webinars

     Asia's Multi-Billion-Dollar Fraud Crisis

    Featured Fintech eBook

    Own Your Cloud. Control Your Data. Power Your Future.

    Featured Fintech Whitepaper

    How Asia is Redefining the Future of Payments

    Featured Fintech Report

    Featured Fintech Event

    Hong Kong FinTech Week and StartmeupHK

    Featured Fintech Videos

    Tazapay

    Banks Are Not Ready for AI

    Featured Webinar Replay

    iProov webinar

    Featured Fintech Job

    Sales Operations Associate

    Whitepapers & E-Books
    Own Your Cloud. Control Your Data. Power Your Future.
    Own Your Cloud. Control Your Data. Power Your Future.
    time
    APAC Fraud in 2026
    APAC Fraud in 2026
    Sumsub
    Digital-First by Design: How Asia is Redefining the Future of Payments
    Digital-First by Design: How Asia is Redefining the Future of Payments
    HPS
    Upcoming Fintech Events
    Asia's Multi-Billion-Dollar Fraud Crisis: Can Fintechs Still Build Trust
    July 16, 2026
    Featured Online
    Fintech Revolution Summit – Malaysia 2026
    July 23, 2026
    Malaysia
    -
    Kuala Lumpur
    What Will The Bank of 2030 Look Like?
    August 4, 2026
    Featured Online
    BankTech Asia - Kuala Lumpur Series
    August 26, 2026
    Malaysia
    -
    Kuala Lumpur
    BFSI IT Summit 2026
    September 9, 2026
    Malaysia
    -
    Kuala Lumpur
    Promote Event View More
    Fintech Jobs
    Rating
    Director, Credit Risk Business Development
    Kuala Lumpur, Full-Time
    Mastercard
    Senior Manager, Customer Lifecycle Operations (eKYC/eKYB)
    Kuala Lumpur, Full-Time
    TNG Digital
    Vice President, CCPF - Cards Activation, Rewards & Lifecycle Management MY
    Kuala Lumpur, Full-Time
    CIMB
    Head of Technology PMO
    Kuala Lumpur, Full-Time
    AEON Bank
    Trade and Investment Commissioners (Multiple)
    Kuala Lumpur, Full-Time
    Austrade
    Navigation
    • About Fintech News Network
    • Advertise With Us
    • Media Kit
    • Work With Us
    • Contact Us
    • Fintech Malaysia Newsletter
    • Submit Press Release
    • Submit Fintech Startup
    • Submit Fintech Event
    • Submit Your Vacancy
    • Submit Interview Request
    • Fintech Events in Malaysia
    • Malaysia Fintech Startup Directory – List of Fintech Startups and Fintech Companies in Malaysia
    • Privacy Policy / Disclaimer
    Other Fintech News Network Publications
    Fintech News Malaysia
    Fintech News Singapore
    Fintech News Hong Kong
    Fintech News Philippines
    Fintech News Network Indonesia
    Fintech News Network Thailand
    Fintech News Switzerland
    Fintech News Baltic
    Fintech News Nordics
    Fintech News America
    Fintech News Network UAE
    Fintech News Africa
    Get Informed

    Subscribe to Updates

    Subscribe to the most important Fintech Malaysia News

    LinkedIn Facebook X (Twitter) YouTube RSS
    • About Fintech News Network
    • Advertise With Us
    • Media Kit
    • Work With Us
    • Contact Us
    • Fintech Malaysia Newsletter
    • Submit Press Release
    • Submit Fintech Startup
    • Submit Fintech Event
    • Submit Your Vacancy
    • Submit Interview Request
    • Fintech Events in Malaysia
    • Malaysia Fintech Startup Directory – List of Fintech Startups and Fintech Companies in Malaysia
    • Privacy Policy / Disclaimer
    © 2015 - 2026 Copyright CK Finanzpro GmbH. All Rights reserved.

    Type above and press Enter to search. Press Esc to cancel.