alert-neutralalert-urgentalert-warningalert arrow__ctaatm-withdrawalsawardbalance-sheetbellbillbranch-locatorbriefcasebusiness-bankingcalendar cash-managementchart-going-upwardcheck-circlecheck checking-and-savingscheckingcircle_largeclock credit-carddelete documentdollar-arrowsdollar-signe-commercefacebook-sq facebook flickr giftgoogle-plus group-of-peoplePathhamburgerhand-trust handshakehappy_logo_centennialhappy_logo_simplehearthigh-alerthome-loanshome houseinfo-iconinfo instagram keyslinkedin-sq linkedin list loan-servicesPath 4Created with Sketch. Fill 5Created with Sketch. Group 35Created with Sketch. locationlockmail merchant-servicesminus mobile-appmobile-emvmonitormortgage-house nav-downnav-left nav-right-bold nav-rightCreated with Sketch. nav-up online-bankingpay-with-cardpeoplepersonal-bankingpersonal-loansphonepinterest plus pos-terminalsquote__testimonialrepeatresource_articleresource_audioresource_calculatorresource_disclosureresource_downloadresource_external_linkresource_external-linkresource_reciperesource_videoretail-storerows rss safe-depositsavingssearchsend-moneysend-zellesettings stacked-paperworktravel-cardstreetumblr twitter two-arrowsuservimeo vine wealth-managementwordpress youtube Skip navigation

Account Takeover Fraud in the Card Industry

Person holding a credit card and phone

In recent years, account takeover fraud has become a significant threat to the card industry, exploiting vulnerabilities and causing financial losses for both consumers and businesses. Cybercriminals have been conducting socially engineered fraud scams, which allows them to gain unauthorized access to a cardholder’s account. Once the fraudster has control, they can make unauthorized transactions, rack up charges, and potentially damage the cardholder’s financial reputation.

Mechanics of Account Takeover Fraud

Account takeover fraud typically begins with criminals gathering personal information about their targets. Some methods they use to achieve this include phishing emails, fake websites, or malware. Once they acquire sensitive information such as login credentials or personal identification numbers, fraudsters can access the victim’s account.

Hackers are also able to exploit weaknesses in online security measures by their potential victims. For example, if a cardholder uses the same password across multiple sites, a breach at one site could compromise their other accounts. This is also true if a retailer’s website is not adequately protected, a hacker may gain access to large volumes of account information.

Fraudsters also create spoofed numbers showing up as a financial institution. The cardholder believes the person they are talking to is from the Fraud Center or Customer Service Center at their financial institution. The criminal then pretends to help victim out by giving them instructions on what to do with the SMS text they will receive about the transaction they are attempting to make. Through this method, the hacker then begin committing fraudulent transactions. The criminal could also act as if they are going to shut down the card and issue a new card for the cardholder. However, they do not shut down the current card and continue making fraudulent charges.

Strategies to Prevent Account Takeover Fraud

To combat account takeover fraud, it is important to adopt robust security practices. This can include reviewing your account(s) closely, checking your account(s) for any changes to your information (phone number, address, or PIN changes), using strong and unique passwords for each account, enabling two-factor authentication and being vigilant about phishing attempts.

If you feel you have been victimized by a fraud attempt, contact our Customer Care Center immediately at (800) 447-2265 or visit one of our branches.

(function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start': new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0], j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src= 'https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f); })(window,document,'script','dataLayer','GTM-5W5PJ22');