What is account takeover fraud?

Account takeover fraud is unauthorized access to a real customer's account used to buy goods or steal stored payment data, and it files as true fraud (much harder for a merchant to fight) rather than friendly fraud.

‍Account takeover fraud is when someone gets unauthorized access to a real customer's account and uses it to buy things or steal stored payment data. The attacker signs in using credentials the owner never shared.

Takeover needs a third party the owner never let in. A forgotten password is not one.

How account takeover fraud works

The attacker gets a working password, signs in, and switches the account's contact details to his own. Then he orders on the saved card and copies the card details for later. The owner rarely sees a notice in time.

Attackers get that password four common ways:

  • Credential stuffing: testing password pairs leaked from other breaches on your login page.
  • Credential cracking: guessing name and password pairs until one works.
  • Phishing: a fake message that tricks the customer into typing their login details.
  • SIM swapping: posing as the customer to a phone carrier to catch the SMS code.

Stuffing works on most sites because people reuse one password everywhere.

After signing in, the attacker changes the email, phone, and shipping address.

That locks the owner out and sends every notice to the attacker.

Why account takeover fraud matters for merchants

A takeover order that ships comes back to you as a dispute, and the customer has a real claim. Someone else bought it on their card. So it files as true fraud, the opposite of a friendly fraud case.

True fraud disputes are much harder for a merchant to win.

You also pay twice. The goods ship first, then the chargeback and its fee arrive.

Sift's Q3 2025 Digital Trust Index estimates 2025 takeover losses at $17 billion, up from $13 billion a year before.

Some takeovers cost you nothing, though. An attacker who only copies personal data leaves no dispute. An order you stop before it ships costs you the review time alone.

Run your own takeover-related dispute count through our ROI calculator to see what the double-charge risk is actually costing you.

Account takeover fraud vs. true fraud

Account takeover is one route into true fraud, and true fraud covers any unauthorized purchase. It also covers a stolen card number typed into a guest checkout, with no account involved.

The two look different on the order itself:

SignalTakeover orderStolen-card order
Accountestablished, with real order historynone, or brand new
Payment methoda card saved months agoa card number typed in once
Checkoutsigned in as the customerguest checkout
What you can compare it tothe account's own past ordersnothing

Take a repeat customer's account that signs in from a new device. It changes the shipping address, then puts a large order on the saved card. Every card-level check passes it.

Flag the session when the device is new, the address just changed, and the order runs large.

How to detect and stop account takeover fraud

Five controls stop most takeover attempts, and they all sit on the login and account-change screens. Each one blocks a different step the attacker needs:

  • Two-factor authentication on login and account changes: blocks anyone holding only the password.
  • Device fingerprinting and login-location monitoring: flags a session that doesn't match the account.
  • Rate limits on login attempts: slows automated credential-stuffing scripts.
  • Re-authentication before a saved card ships somewhere new: stops the first order after a takeover.
  • Account-change notifications: tell the real owner their email or address moved.

Stripe recommends the first, second, and fifth of these.

3D Secure sits at checkout instead. It checks the cardholder after the attacker is already signed in.

No alert prevents the login itself. But when a hijacked account gets disputed, our Ethoca and Verifi alerts flag it while you can still refund. Refund it and you pay no chargeback fee, and the dispute never counts against your rate.

Good controls make the attacker work harder for less. That is the realistic goal on a busy login system. Attackers then go test those passwords somewhere with weaker checks.

FAQ

Can account takeover happen with a strong password?

Yes, because a strong password still gets stolen through phishing, malware, or a breach at another company. Password strength only protects you against guessing.

Does account takeover fraud show up as a chargeback?

Usually yes, filed by the real account owner as unauthorized true fraud once they see the charge. It reaches you under a fraud reason code, which is the hardest category to win.

Is account takeover the same as identity theft?

No, account takeover hijacks an account that already exists. Identity theft usually means opening new ones in someone else's name.

Уменьшите количество споров уже сегодня

Присоединяйтесь к более чем 800 компаниям, использующим Chargeback, чтобы автоматически предотвращать возвратные платежи — настройка занимает менее 2 минут.