A bank can authenticate the right customer at 9.01am and still lose control of that session by 9.05am, without a single failed login anywhere in between.
Those four minutes, the window right after a customer proves who they are, are where account takeover fraud increasingly plays out now, according to bank and security executives speaking on a recent Fintech News Network webinar.
Banks have spent years tightening the front door with multi-factor authentication, device binding and biometrics. As those defences have improved, fraudsters have started looking for ways around them.
Some account takeover attacks are now targeting customers after they have already passed those checks, according to Goh Ser Yoong, CISO of Ryt Bank.
“The password is now not going to be the top prize,” Ser Yoong explained. “The authenticated session will be.”
Session cookies and other authenticated credentials can let an attacker resume a login without ever entering the customer’s password.
Ser Yoong pointed to infostealer malware and adversary-in-the-middle attacks as the techniques being used to obtain them. A fake login page, for instance, can sit between a customer and the bank during what looks like a normal login.
Once an attacker has what they need to hijack the session, the password has already done its job. Everything about that login can still look legitimate long after control of it has actually changed hands.
Account Takeover Fraud Is Becoming a Trust Problem
Harvinder Singh, RVP APAC for Identity Security at Entrust, connects this shift to a wider change in account takeover fraud.
Stolen passwords and OTPs remain useful, though attackers can now combine compromised identity data with malware, social engineering and deepfakes.
AI now lets fraudsters personalise those attacks using a victim’s own leaked credentials and social media details, writing phishing messages in the customer’s language that are harder to tell apart from a genuine interaction.
“ATO has moved from stealing credentials to stealing trust,” Harvinder observed.
Lucose Eralil, former COO of Security Bank Corporation, put it differently.
“Fraud has moved on from breaking in to exploiting trust gained after entry,” Lucose added.
Once a fraudster controls something the bank already regards as legitimate, an authenticated session, say, getting through the login screen is no longer the main hurdle.
Banks then have to decide whether the trust they have already granted still holds.
One Suspicious Action Rarely Tells the Whole Story
Keeping track of that trust means watching what happens after authentication.
Logging in from a new device is not inherently suspicious. Customers change their contact details, add beneficiaries and transfer money every day.
Harvinder argued that the risk changes when several of those events appear together, such as a customer logging in from a new device, changing contact details and adding a beneficiary.
A fraud system assessing each event in isolation may see several ordinary actions. Connect them and the pattern becomes harder to dismiss.
“This is one entire risk story,” Harvinder noted.
Entrust describes the approach as “continuous trust,” where identity is reassessed as the customer moves through the account rather than settled once onboarding or login is complete.
The principle sounds straightforward. Putting it into practice is harder when those signals are scattered across different parts of a bank.
Banks May Already Have the Signals
Onboarding, authentication, account recovery and transaction monitoring often fall under different teams, each responsible for its own controls.
A fraudster moving through the same account does not encounter those organisational boundaries.
Lucose believes this fragmentation is one reason banks can struggle to recognise account takeover fraud even when warning signs already exist somewhere in their systems.
“It’s not the lack of tools. It’s not the lack of data,” Lucose explained. “It is the absence of what I would call a single decision layer, and a single owner who can convert those signals into actions.”
Each of those signals might sit with a different system entirely, so no single control has the full picture.
Lucose later asked who owns the combined decision when several weak signals fire together.
He argued that better-performing banks are moving towards controls that cover more of the fraud lifecycle, including phishing-resistant authentication, transaction binding and real-time fraud management.
That matters more as the technology banks use to verify customers comes under attack too.
Deepfakes Are Going After What Banks Trust
Biometric verification has made it harder to pass an identity check with a stolen password alone, pushing some attackers toward the biometric process itself.
Earlier deepfake attacks often centred on fake photos or videos meant to convince someone they were looking at a real person. Harvinder pointed to injection attacks that instead feed manipulated content directly into the verification process, bypassing the camera capture the system expects.
Entrust’s Identity Fraud Report, cited during the webinar, found deepfakes involved in one in five biometric fraud attempts, with deepfake selfie attacks up 58% and injection attacks up 40% in a year.
“The face matching is no longer enough,” Harvinder warned.
A successful match says less if the capture process feeding it has already been tampered with.
Session hijacking follows the same logic. Strengthen one control, and attackers look for the point where the system starts trusting the customer, then exploit what happens next.
Continuous monitoring can help, though pushing it too far creates another problem.
Stronger Fraud Controls Can Quickly Become Customer Friction
A bank could respond to every change in behaviour with another authentication request, but customers would probably hate it.
Ser Yoong highlighted the tension between fraud prevention and the experience of legitimate users. Routine activity on a familiar device shouldn’t trigger the same scrutiny as unusual behaviour right after a new login.
Verification should scale with the risk of the activity, not apply evenly to everything.
“The answer is not to make every journey painful,” Harvinder stressed.
Context helps banks tell ordinary behaviour apart from signs that control of the account may have changed, drawing on device information, customer behaviour and recent transaction activity.
Preventing account takeover increasingly means knowing when to challenge trust again, without making every legitimate customer prove themselves twice.
Banks are already trying to solve that problem for human customers. Agentic payments could add software to the equation.
AI Agents Extend the Same Problem
Agentic payments could allow AI agents to make purchases or carry out financial actions on a customer’s behalf.
Delegating authority to software changes who is acting on an account, but banks still need to know whether the action being taken matches the authority originally granted.
Ser Yoong believes attackers could eventually target the agent itself.
“When the agent is holding a delegated authority, compromising the agent will be the next target,” Ser Yoong warned.
Prompt injection is one possible attack route. Instead of stealing a password, an attacker could try to manipulate an authorised agent into acting outside the customer’s intent.
Harvinder said banks would need to know which agent is acting, who authorised it, and under what limits, including when that authority expires or can be revoked.
“In the agentic world, we will need to authenticate intent, authority and accountability,” Harvinder explained.
Lucose would rather keep reusable credentials away from the agent altogether.
“Don’t let the agent possess the credential at all,” Lucose advised.
A scoped, signed and expiring mandate can define what the software is allowed to do, and for how long.
Agentic payment volumes remain small today, so most of this is still being worked out. The security problem, however, is already familiar to banks dealing with account takeover fraud.
Passing authentication establishes trust at one point in time. Keeping that trust valid once someone, or something, begins acting on the account is where the harder work starts.
Lucose captured the issue in the final minute of the webinar.
“The fraudster past onboarding is no longer an intruder in the system,” Lucose remarked. “The system already thinks that they are the customer until it is on the onus on us in banks to prove otherwise.”
Watch the full webinar on YouTube for the complete discussion on how account takeover is evolving beyond onboarding and authentication.
Entrust will also be hosting an Identity Innovation Forum in Kuala Lumpur, Malaysia, with event details as follows:
- Theme: From eKYC to ATO Defense: Building Continuous Trust
- Date: 10th September 2026 (Thursday
- Time: 9.30am to 2.00pm
- Venue: VE Hotel, Kuala Lumpur
Register here to attend the event
Featured image: Edited by Fintech News Singapore based on an image by Magnific.



