One breach. Two teams. Two completely different stories. Cybersecurity expert Beau R. walks through the same account takeover twice: through the SOC's eyes, then through fraud's. Security catches the front end (credential stuffing, device anomalies) and closes the incident fast. But over 65% of breached accounts had MFA enabled at compromise, per Obsidian Security. Once login succeeds, the SOC's visibility ends, right as the attacker starts probing for value. Fraud picks up the story weeks later: an altered payment method, a payout switched right before a withdrawal. By the time the chargeback confirms it, the trail back to the original compromise has gone cold, so it's written off as an isolated loss. That gap is where the real damage happens. Per Sift's Q2 2026 Index, only 37% of ATO victims found out from the company itself. Read Part 2 in the series: https://lnkd.in/gSN5cwMK #cybersecurity #fraud #accounttakeover #cyberfraudfusion
Last week I walked the expo floor at Black Hat in Las Vegas, and I kept passing booths pitching defenses against account takeover. It took me back to when I started researching and writing about ATO. It was 2014 and I was running marketing for a cyber threat intelligence startup. Twelve years later, the problem isn't solved. In fact, it's much bigger. What was then a somewhat niche security attack is now a global, automated, ~17 billion dollar criminal industry. The harsh reality is that ATO will never be fully stopped. It targets people, not just systems. Attackers evolve past each new defense, and every business must balance security friction and prevention against customer convenience. For most businesses, locking everything down just isn't an option. So, the job can't be total prevention. It's minimizing the impact on customers and the business. And that starts with being able to see the whole attack, which most organizations can't do today. That's what Part 2 of my series with Sift is about. Link below. As always, candid feedback and differing viewpoints welcome and encouraged. #cybersecurity #fraud #accounttakeover #blackhat