Account Takeover Prevention: Methods That Work

Account takeover prevention works best when merchants protect login, account changes, and checkout together, then refund likely takeover orders before fulfillment.

Account takeover prevention stops an attacker from ordering on a hijacked account before the real owner disputes the charge. Pair login controls, like multi-factor authentication and device checks, with a pre-dispute alert that catches the order after those controls miss.

I ran alerts on my own stores for years before I advised anyone else on them. Takeover orders taught me where that tooling fits. It tells you about the order in time to refund it, long after the login is gone.

Work through the five controls below and you'll know which one to add first.

Key takeaways

  1. 01Guard the login, the account-change screen, and the order itself.
  2. 02Turn on multi-factor authentication first, since Google measured 96% of bulk phishing blocked.
  3. 03Require a fresh login before a saved card ships to a new address.
  4. 04Watch for a new device, a detail change, and a size jump together.
  5. 05Refund a flagged takeover order early, because true fraud rarely wins on appeal.
  6. 06Daily phishing volume topped 134,600 in April 2026 and keeps climbing.

Not sure what your dispute volume is costing you? Run the numbers in about a minute.

How do you prevent account takeover fraud?

Prevent account takeover by checking the login, the account-change screen, and the order itself. Each point closes a gap the one before it leaves open. A control at one point does nothing for an attacker who defeats it and moves on to the next.

Multi-factor authentication stops most credential-stuffing logins on its own. A device-change notification catches the one that gets through, and re-authentication at order time catches the one that gets past both:

  1. The login stops an attacker who has only the password.
  2. The account-change screen catches an attacker who gets past the login.
  3. The order stops an attacker who gets past both.

You layer them because an attacker who defeats one control walks straight into the next.

The password itself usually comes from a breach on some other site.

That's why this looks like an account takeover fraud problem long before it looks like a payments one.

Why account takeover is a chargeback problem

A takeover that produces an order produces a dispute, and that dispute lands on you. The part that costs merchants money starts after the login, which is where most prevention advice stops.

The real account owner sees a charge they don't recognize and files it as fraud. That puts the order in the true fraud category, the hardest kind to win. The issuer files it under a chargeback reason code built for that exact claim, the cardholder saying someone else made the purchase.

Your evidence shows the account existed and the order shipped, while the cardholder's claim is that someone else was in the account. The issuer sides with the cardholder.

Stolen credentials feed a takeover attempt, and the phishing that harvests them is climbing sharply. Average daily phishing volume across Akamai's commerce customers climbed from 56,600 in February 2026 to 134,600 in April 2026.

 
Average daily phishing volume, Akamai commerce customers
 
Feb 2026
56,600
 
Apr 2026
134,600
 
Up 138% in two months across Akamai commerce customers. Source: Akamai State of the Internet research, 2026.

Your chargeback risk starts at the completed purchase. An attacker who only takes saved card details or personal data leaves no dispute behind.

Summary: A takeover order becomes a true-fraud dispute, and true fraud is the category merchants win least often.

Prevention methods that stop takeover fraud

Multi-factor authentication, device fingerprinting, rate limits, re-authentication at checkout, and account-change alerts are the five controls that stop a takeover.

They run at the three points above:

  1. Multi-factor authentication blocks a login when the attacker has only the password.
  2. Device fingerprinting flags a session that doesn't match the account's history.
  3. Rate limits slow the automated scripts that test stolen credential lists.
  4. Re-authentication at order stops a saved card shipping to a fresh address.
  5. Account-change notifications tell the real owner while they can still act.

Checkout-level tools like 3D Secure check the card, so they sit outside these five account-level controls.

Take them in order.

1. Multi-factor authentication

Turn on multi-factor authentication at login and at every account-change screen, because it's the only one of the five with a published block rate.

Google's research with NYU and UC San Diego tested an SMS code sent to a recovery phone number. That code blocked 100% of automated bots, 96% of bulk phishing attacks, and 76% of targeted attacks, and on-device prompts did better again, at 100%, 99%, and 90%.

   
Attacks blocked by second factor, by attack type
 
Automated bots
100%
 
Bulk phishing
96%
 
Targeted attacks
76%
 
SMS code to a recovery phone number. On-device prompts blocked 100%, 99%, and 90%. Source: Google Security Blog, 2019.

Plan around the gap between those two block rates.

Bulk phishing casts a wide net, and a second factor breaks it. A targeted attacker who already knows your customer can work around that factor, which is why the account-change controls below still matter.

2. Device fingerprinting

Record the device and rough location behind every login, so you can flag a session that doesn't match the account's history. On Shopify, WooCommerce, and most major platforms you add this with a fraud-prevention app from the app store.

The signal works because attackers rarely get the victim's hardware along with the password. They show up on a different browser and usually a different country.

Say an account has signed in from one phone in Ohio for two years, then appears on a desktop in another region.

Customers travel and buy new phones, so a mismatch on its own isn't proof. Hold the order when the device mismatch arrives with an account-detail change, or with an order well outside the account's history.

3. Rate limits on login attempts

Cap failed login attempts per account and per IP address, because credential stuffing depends on volume. An attacker testing a leaked list needs thousands of tries to find the few reused passwords.

Five to ten failed attempts per account in an hour stops the script and leaves real customers alone. Prefer a CAPTCHA over a hard lock. A lock lets an attacker shut out your real customers on purpose.

Add a separate cap per IP address to catch one source spraying many accounts.

An attacker running a slow attack from thousands of addresses stays under any per-IP limit you set. You catch that one with the device and location signals above.

4. Re-authentication before a saved card ships

Ask for a fresh password or second factor whenever someone pays with a saved card and adds a shipping address in the same session. Of the five, this one fires at the exact moment the attacker tries to get goods out the door.

An attacker inside an account wants the saved card and a delivery address they control. Make them re-authenticate between those two actions and they need the second factor to ship anything.

Digital goods break the pattern. A downloadable product has no shipping address to change, so the login-level signals do the detecting instead.

5. Account-change notifications

Email the account's original address whenever the password, email, phone number, or shipping address changes. Send it to the address on file before the change, because attackers change contact details first so the real owner never sees the confirmation.

Name what changed and when, and give a one-click way to reject it. A customer who catches it in the first hour saves you the order and the dispute both.

Plenty of customers leave email unread for days, and those are the ones this misses. Never hold an order on the notification alone. A customer who hasn't opened their email hasn't cleared anything.

How takeover connects to true-fraud chargebacks

A hijacked account placing one large order on a saved card is the hardest pattern to catch, because every card-level check on that order passes. The card is real and the customer is signed in.

Fraud scoring is mostly built around new accounts and new cards, and a takeover order has neither. The account holds years of order history, and the card was saved long before the attacker showed up. Only account-behavior checks catch anything.

Picture a returning customer's account on your store.

It signs in from a device it has never used, then changes the shipping address. The order that follows is four times the size of anything in the account's history, on the card saved last spring:

Checkout checkResult on a takeover orderWhy
Card validityPassesThe card is real and active
Address verification (AVS)PassesCompares to the card's billing record, which the attacker matched
Card security code (CVV)PassesStored with the saved card

Score device and login-location mismatch before checkout runs, and let it hold an order on its own. Fold it into the checkout score instead and a clean card outweighs it every time.

How to spot account takeover before shipping

A new device, an account-detail change, and an unusually large order in one session flag a takeover before it ships. Here's what each one looks like:

  1. A login device or location with no history on the account.
  2. An account-detail change in that same session.
  3. An order size that breaks the account's own pattern.

Read all three together, because each one alone throws false positives all day. People move house and take trips, so blocking on a single signal costs you real sales.

The combination is what narrows it to takeover, since a real account holder rarely does all three in one session.

An attacker who knows this places a small order to the address already on file and defeats all three. That order ships, and the dispute arrives weeks later.

Summary: One signal is noise, and three together inside one session is a takeover worth holding.

When prevention fails: what a pre-dispute alert catches

A pre-dispute alert catches the cardholder's dispute as a notice, before it becomes a chargeback, giving you a window to refund the takeover order. Once the order has shipped, that window is the only thing left, because no login control reaches a dispute that's already filed.

Ethoca (Mastercard) and Verifi (Visa) run those notices. In that window you refund the order and stop the chargeback, its fee, and its effect on your chargeback rate.

We connect to Ethoca alerts, so a takeover order gets flagged whichever of its member banks the cardholder's bank routes through.

We connect to Verifi too, so the same alert reaches you on the Visa side of a takeover order.

A chargeback alert pays off when the order is still refundable. A downloaded file or a spent service credit is gone. For physical goods already in transit you stop the chargeback and its fee, though you usually don't get the merchandise back. Refunding still beats losing the same money to the dispute.

Want a chargeback alert running behind your own login controls?

Talk to us about alerts and see which networks cover your traffic.

Not sure what that risk adds up to first?

Run the numbers.

How we sourced our data

The two figures in this article come from named third-party research, not our own platform data. The phishing-volume numbers trace to Akamai's own commerce-customer research. The multi-factor block rates trace to Google's published study with NYU and UC San Diego.

Both citations link to the original publisher above, at the point where each figure appears.

FAQ

Can prevention stop an attack from someone else's breach?

Yes, because these controls act on the login attempt itself. A leaked password still has to get past your second factor, your rate limits, and your device checks.

Does two-factor stop takeover if the attacker has the phone?

No, and that's the SIM-swap case, where an attacker talks a carrier into moving the victim's number to their own device. App-based or hardware-key factors close that gap because they never travel with the phone number.

Is a chargeback from account takeover the merchant's fault?

Card networks treat it as your liability in almost every card-not-present case, whatever the cause. You can be blameless and still pay, which is why the controls above matter more than whose fault it was.

Should you refund a suspected takeover order or wait?

Refund it once the signals line up and the goods haven't shipped, since a chargeback costs you the order, a fee, and a mark on your ratio. Wait only if you're genuinely unsure the order is fraudulent.

Réduisez votre taux de litiges dès aujourd'hui

Rejoignez plus de 800 entreprises qui utilisent Chargeback pour éviter les rétrofacturations automatiquement. La configuration prend moins de 2 minutes.