October 8, 2026 · 6min read
7 ATO Attacks Stopped in Under 30 Minutes: Re-imagining the Digital Banking Journey
Account takeover (ATO) fraud is not a single, isolated incident. It’s a progression. Yet many digital fraud prevention strategies only evaluate risk at the point of transfer or payment. This limited view misses the subtle signals that arise before money leaves an account. Compromised identities, new devices, and unusual behavioral patterns often surface long before the transaction itself.
To stop ATO, financial institutions must shift from isolated events to consider the entire digital banking journey. In this article, we’ll explore a recent real-world case where a European bank blocked seven account takeover attempts in less than 30 minutes.
Key Takeaways
- Account takeover attack fraud begins long before money moves, as identity, device, behavioral, and account signals evolve during the session.
- ATO represents a major portion of digital fraud. Feedzai mapped 142,841 fraud events to account takeover across six months of labeled customer data, representing nearly one in four mapped fraud events.
- In the US, the FBI recorded approximately 4,700 account takeover complaints resulting in over $359.7 million in reported losses in 2025.1
- Individual events such as an unknown IP address or a new beneficiary may appear legitimate on their own, but their sequence reveals the true risk of account takeover fraud.
- To stop modern ATO, financial institutions must look beyond individual transactions and continuously verify whether the user is truly the legitimate customer.
- Feedzai’s Digital Trust solution connects device, network, and behavioral intelligence to assess risk across the entire session, blocking fraudulent transfers before losses occur.
1 Account. 7 Account Takeover Attempts. 27 Minutes. Zero Losses.
To understand how ATO develops in real time and how connecting identity intelligence with transaction risk stops attacks before losses occur, consider a real-world example observed at a European retail bank. We’ve anonymized the organization.
The account had been behaving normally. Then, at 12:22, the risk picture changed.
12:22 | A new device appears
Fraudster activity: A previously unseen IP address and new device appeared, followed immediately by a €5,900 transfer attempt, more than six times the largest legitimate transaction in the preceding case history. The beneficiary had not previously appeared as a payee for this customer.
- What Feedzai saw: Feedzai’s Digital Trust solution, which uses device, network, and behavioral intelligence to assess risk across the digital journey, immediately identified an Unknown Device and Device Anomalies and issued a challenge. Those Digital Trust signals fed directly into Transaction Fraud for Banking, or TFB, enriching the transaction risk context as the payment activity unfolded.
Grow Digital Banking. Reduce Fraud.
"A bank that remembers its customers can say yes to more of them, and keep saying yes as they prove themselves, instead of treating a known customer like a stranger every time they log in." — Ali Adib, Principal Product Marketing Manager, Feedzai
12:29 to 12:36 | The fraudster persists
Fraudster activity: Seven minutes later, the fraudster attempted a second €5,890 transfer to the same beneficiary. At 12:33, the fraudster switched to a second new beneficiary and continued trying to move €5,890. Another attempt followed at 12:36.
- What Feedzai saw: Digital Trust continued to surface the device risk, while the transactional picture was changing too. The beneficiary was new to the customer and had never appeared in their payee history, adding another risk signal alongside the identity and device context. When the fraudster switched to a second new beneficiary, that context strengthened further. An additional Potential Fraud Risk signal also appeared.
Identity risk and transaction risk were now building the same picture.
12:47 | The fraudster changes tactics
Fraudster activity: After repeated attempts at close to €5,900, the fraudster abruptly reduced the transfer amount to €1,400.
The payment amount changed. So did the behavior around it.
- What Feedzai saw: Digital Trust surfaced further indicators, including Paste Detected, Suspicious Behavior, and Device Switch. Because Digital Trust and TFB are connected, those signals are fed into the TFB decision alongside the transaction context. TFB raised an alert and declined the transaction.
12:48 to 12:49 | The attack continues
Fraudster activity: Two further attempts followed within two minutes, first for €1,400, then €1,390.
- What Feedzai saw: Digital Trust continued to surface suspicious session behavior, while TFB alerted on both transactions, and both were declined.
Then the pattern stops.
No further fraud-labeled attempts appear in the case. The following day, legitimate account activity resumes from an IP address previously seen in the customer’s history.
In the end, here are the key numbers that summarize the attack.
- Seven fraud-labeled transfer attempts.
- 27 minutes.
- Two new beneficiaries.
- One new device.
- One previously unseen IP.
- A deliberate drop from almost €5,900 to €1,400.
- Zero losses.
Digital Trust surfaced the risk at the point of access and fed that intelligence into TFB as the attack unfolded. TFB combined that context with the transactional risk and declined the later attempts.
This is where identity signals and transaction risk converge. No single moment tells the whole story. The power lies in connecting identity, device, behavioral, and transaction signals before the payment becomes the only decision point.
ATO Exposes the Gap Between Fraud and Identity
The bank’s story highlights how the sequence of events enables ATO attempts. Before the payment attempts, credentials may already have been compromised. Before the transaction, a new device may have appeared. Before money moves, behavior may already have changed.
This reveals an important lesson: fraud begins long before a payment is initiated. The transaction is where bad actors attempt to cash out.
Feedzai has mapped 142,841 fraud events to account takeover during six months of customer fraud labels. That’s nearly one in four mapped fraud events.
Feedzai’s finding sits inside a much wider shift in digital fraud. Account takeover is already measurable at scale. In the US, the FBI recorded approximately 4,700 account takeover complaints and $359.7 million in reported losses in 2025.1
Related digital banking fraud data shows the same pressure on digital channels. UK Finance recorded 37,646 remote banking fraud cases in 2025, up 11%, driven by a 21% increase in mobile banking cases.2 Losses fell 27% to £104.4 million.
ATO exposes the weakness of treating identity as one decision and fraud as another. Successful authentication shows that the required credentials were presented. It does not prove who is using them.
The question is no longer only “Did this user authenticate?” It’s “Is this still the customer we know?”
The Transaction Is the Outcome. The Journey Is the Evidence.
Banks already authenticate customers, assess devices, monitor behavior, and score transactions. The problem is that ATO can develop across those controls. At the same time, each event (e.g., a new device, a different IP address, a new beneficiary, or an unusual payment) might be legitimate.
But put them together in the same journey with clearer context, and the risk picture changes.
When you treat those signals as separate moments, the story fragments. Follow one account takeover from the first change in behavior to the moment money moves, and the pattern becomes much clearer.
From ‘Is This Transaction Fraudulent?’ to ‘Is This Still Our Customer?’
Feedzai connects identity, device, behavioral, and transaction intelligence across the digital journey, allowing risk context to build as interactions unfold. By the time a payment is attempted, the decision does not have to start with the transaction. It can inherit the context of what happened before it.
That does not mean treating every unusual interaction as fraud. Customers change phones, travel, and make new payments every day. Continuous context should not mean continuous friction. Instead, the goal is to recognize when individually plausible events begin to form an implausible journey.
Authentication Alone is Not a Complete Fraud Strategy
Regulation already points in the same direction. In the UK, Strong Customer Authentication (SCA) applies when customers access payment accounts online, initiate electronic payments, or perform certain remote actions that may create fraud risk.3
For transaction risk analysis, FCA technical standards require real-time risk analysis to consider factors including abnormal spending or behavioral patterns and unusual information about device or software access and location.4
A new device, changed behavior, an account change, or a new receiving account can all alter the context of what happens next. The challenge is not simply to authenticate the customer. It is to recognize when the customer’s risk profile changes.
Trust Is Not a Single Decision
Fraud doesn’t start at the transaction. Stopping account takeover shouldn’t either.
The payment is the final step in an account takeover attempt. Several other critical steps occurred beforehand.
- Before the payment, there was an identity.
- Before the transaction, there was a session.
- Before the decline, there were signals.
Trust cannot be established once and continuously assumed thereafter. As the journey changes, so does the customer’s risk. By connecting the dots across the entire customer journey, stopping account takeover stops being a guessing game, allowing banks to stay one step ahead of fraudsters by continuously building trust into every transaction.
Additional Resources
- Blog: A Guide to Account Takeover (ATO) Fraud Prevention & Detection
- Report: Feedzai Fraud Readiness Index 2026
- eBook: Grow Digital Banking. Reduce Fraud.
- Solution: Identity. One continuous risk profile.
Frequently Asked Questions about Account Takeover in Digital Banking
What is Account Takeover (ATO) fraud in digital banking?
Account takeover (ATO) fraud occurs when a cybercriminal gains unauthorized access to a customer’s bank account to steal funds or personal data. While traditional detection focuses on the final transaction, modern ATO develops gradually across the digital banking journey through compromised credentials, unseen devices, and subtle changes in user session behavior.
Why is transaction-only monitoring ineffective against ATO?
Transaction-only monitoring evaluates payments in isolation, often after the account compromise has already occurred. Fraudsters frequently use legitimate credentials and stay within normal payment thresholds, making transactions appear valid. Effective defense requires analyzing pre-transaction signals, such as device anomalies and behavioral changes, to detect risk before money attempts to move.
How do identity and behavioral signals help stop account takeover?
Identity and behavioral signals provide essential context by evaluating how a user interacts with their account during a session. By monitoring network data, device switches, and typing patterns alongside transactional history, financial institutions can spot non-customer behavior early and block fraudulent transfer attempts without adding unnecessary friction for legitimate users.
What is the role of Feedzai’s Digital Trust in ATO prevention?
Feedzai’s Digital Trust assesses risk continuously across the digital banking session using device, network, and behavioral intelligence. By feeding real-time identity signals directly into Transaction Fraud for Banking (TFB), it creates a comprehensive risk picture that allows financial institutions to identify compromised accounts and decline fraudulent payments in real time.
How does Strong Customer Authentication (SCA) relate to ATO detection?
Strong Customer Authentication (SCA) provides a critical control point by verifying credentials during login or high-risk actions. However, authentication only captures a single moment, whereas risk continuously evolves. Regulatory standards increasingly require real-time transaction risk analysis that considers session behavior, device access, and spending patterns alongside basic authentication.
Footnotes
1 https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
2 https://www.ukfinance.org.uk/news-and-insight/press-release/fraud-report-2026-press-release
3 https://www.fca.org.uk/firms/strong-customer-authentication
4 https://www.handbook.fca.org.uk/techstandards/PS/2021/2021_01/chapter-iii/022.pdf
All expertise and insights are from human Feedzaians, but we may leverage AI to enhance phrasing or efficiency. Welcome to the future.