ATO is a real threat.
This is based on a true incident: a student in Pune downloaded what looked like a study planner app.
It had good reviews. It did what it said. He used it for two weeks without any problem.
What he did not know was that the app was also running silently in the background, reading cached browser logins, forwarding incoming SMS messages, and waiting for the right moment. That moment came when the attacker had collected enough: his bank login credentials, his registered mobile number, and now, through the SMS forwarding, his incoming OTPs.
The SIM swap happened first. His phone lost signal. The attacker’s device began receiving every message sent to his number.
Then they logged into his banking app. The credentials were correct. The OTP was sent. The attacker entered it. Authentication succeeded.
In 45 minutes, the attacker moved through his payment application, crypto wallet, and insurance programme, stealing ₹3.6 lakh.
Every security check passed. Every authentication step was completed correctly. The bank’s systems recorded a successful, verified login.
The student found out when he got his signal back and checked his balance.
What Account Takeover Actually Is and Why It Is Different From Every Other Fraud
Account takeover, or ATO, is one of the most misunderstood fraud categories in financial services because it looks nothing like traditional fraud from the inside.
Traditional fraud creates something false: a fake identity, a forged document, a synthetic account. Security systems are trained to look for things that should not exist.
Account takeover uses something real: a legitimate customer account, valid credentials, and a verified identity. The account exists. The credentials are correct. The authentication succeeds. The person logged in passes every check the bank has.
The only false thing is that the person logged in is not the account holder.
Account takeover attacks rarely start with obvious fraud signals anymore. The credentials are often correct, MFA gets completed successfully, and the login looks legitimate. But somewhere between authentication and transaction activity, fraudsters quietly take control.
This is the fundamental architecture problem. Banks have built their security at the door. Verify the person entering. If the verification passes, trust everything that follows. Account takeover exploits the gap between the door and everything that happens inside.
The Scale in India That Every NBFC and Bank Must Understand
India has created one of the world’s most ambitious digital payment ecosystems. The UPI ecosystem processed 18.4 billion monthly transactions worth ₹300 trillion in 2025, creating a massive attack surface for real-time digital fraud.
The fraud numbers that have emerged from this scale are significant and accelerating.
The RBI’s June 2025 bulletin pointed out an increase of ATO frauds by 310% year on year, with neobanks and digital wallets as the most preferred targets.
UPI fraud losses hit ₹805 crore across 10.64 lakh complaints in the first eight months of FY26 alone.
UPI fraud cases in FY24 reached 13.42 lakh incidents worth ₹1,087 crore, nearly doubling from FY23’s losses of ₹573 crore.
The RBI’s Annual Report for FY 2024-25 recorded 13,516 digital payment fraud cases accounting for 56.5 percent of all reported banking frauds.
The pattern across all of these numbers is consistent. The attacker is not breaking into the bank’s systems. They are using the customer’s own credentials to walk through the front door. And the front door, built on OTP-based two-factor authentication, is proving insufficient for the sophistication of attacks being deployed at scale.
UPI frauds jumped 85% in FY24 and maintained that trend through 2025, with SIM swap operations, OTP-redirecting malware, and social engineering as the primary attack vectors.
One survey finding captures the scale in human terms: one in five UPI users in India has been hit by fraud, a proportion that represents not an edge case but a systemic risk built into the way authentication currently works across India’s banking landscape.
The Scale in the United States That Financial Institutions Cannot Ignore
The United States faces a parallel crisis with the same structural cause and different surface characteristics.
The FTC reported $12.5 billion in fraud losses in 2024, with account takeover representing a significant and growing portion of that figure.
Since January 2025, the FBI’s Internet Crime Complaint Center logged more than 5,100 account takeover fraud complaints with losses exceeding $262 million. That figure covers only reported incidents.
In 2025, over 4% of all verification attempts were fraudulent, and more than 85% of those involved impersonation, underscoring how determined attackers are at commandeering digital identities.
The credential supply chain enabling these attacks is staggering in scale. 1.7 billion stolen credential records were shared in underground forums in the past year. With that volume of username and password combinations available for purchase at minimal cost, credential stuffing, trying known credentials against banking platforms at machine speed, has become the cheapest and most scalable entry method in the attacker’s toolkit.
PayPal experienced a credential-stuffing attack in which cybercriminals accessed around 35,000 accounts using previously leaked credentials. In 2025, PayPal was fined $2 million for the breach.
Verizon’s 2025 Data Breach Investigations Report found that credential abuse was the most common initial access vector in breaches at 22%, followed by vulnerability exploitation at 20% and phishing at 16%.
The US regulatory response has also been moving. The CFPB clarified that many ATO-related losses may qualify as unauthorised electronic fund transfers under Regulation E, meaning banks could be held liable for reimbursement, even if the customer was tricked into providing credentials. That liability shift is significant. Banks that assumed customer negligence would shield them from ATO losses are now facing a regulatory environment where the institution’s security architecture, not the customer’s behaviour, is the standard being evaluated.
The Five Attack Methods Every Bank Must Have a Countermeasure For
Understanding how account takeover is carried out is the foundation for defending against it. The methods are consistent across India and the US, with minor variations in prevalence.
- Method 1: Credential Stuffing
Attackers purchase username and password combinations from underground markets where they have been collected from previous data breaches across any number of platforms. Automated bots test these credentials against banking login portals at high speed. Where a customer has reused the same password across a banking platform and any other breached platform, the bot finds a valid combination and flags it for human exploitation.
This attack requires no interaction with the customer. It is entirely automated. A bank that processes 100,000 login attempts per day and has no velocity detection or anomaly analysis on login patterns is providing a free testing service to credential stuffing operations.
- Method 2: SIM Swap
Criminals convince mobile operators to transfer a victim’s phone number to a new SIM card. Once they control the number, they can intercept all OTPs sent to it and take over accounts. Average losses from SIM swap fraud range from ₹2 lakh to ₹25 lakh because it specifically targets high-balance accounts.
The SIM swap exploits the human element in telecom verification. A fraudster with enough personal information about the target, which they obtain through data breaches, social media, and social engineering, can impersonate the customer convincingly enough to pass a telecom operator’s identity check.
In India, the Department of Telecommunications implemented a 5-day SIM swap cooling period in 2025, meaning a newly issued SIM cannot be used for mobile banking for five days. In the US, the FCC enacted new rules requiring mobile carriers to verify identity and notify customers before porting a number. Both regulatory responses acknowledge the structural vulnerability without eliminating it.
- Method 3: OTP Malware and Redirection
As the Pune student’s case demonstrates, malware specifically designed to intercept OTPs has become a primary attack vector. The malware does not need to be sophisticated to be effective. It simply reads incoming SMS messages and forwards them to the attacker, in real time, while the legitimate user’s phone also receives the message.
Malicious software installed on a user’s device can read incoming SMS messages, including OTPs, and forward them to attackers without the user’s knowledge.
The attack succeeds because OTP-based authentication assumes that possession of a phone number equates to identity. OTP malware breaks that assumption entirely. The attacker and the customer both have the OTP simultaneously. The attacker simply uses it first.
- Method 4: Social Engineering and Vishing
Scammers impersonate bank officials or customer service agents and manipulate users into sharing their OTPs over the phone. In India, this has evolved into elaborate multi-step operations where callers have detailed knowledge of the customer’s account, recent transactions, and personal details, information harvested from data breaches that make the impersonation highly convincing.
The psychological mechanism is authority and urgency. The caller claims to be from the bank’s fraud prevention team, warns the customer that their account is under attack, and asks them to provide an OTP to verify their identity and prevent unauthorised access. The OTP they provide is the OTP the attacker uses to complete the takeover.
- Method 5: Session Hijacking After Legitimate Authentication
This is the method that breaks the assumption underlying most banking security architectures. The attacker allows the customer to authenticate legitimately and then takes over the session. This can happen through browser session token theft, man-in-the-browser malware that intercepts authenticated sessions, or through account recovery flows that are less protected than the primary login.
Modern ATO attacks increasingly blend in with legitimate customer behavior, making standalone MFA and static fraud rules insufficient for detecting sophisticated login fraud or unauthorised account access in real time.
Why OTP Is the Problem, Not the Solution
This requires a direct statement because it runs against ten years of banking security messaging in India and the US.
OTP is better than a single password. That comparison is not in dispute. The question is whether OTP is sufficient against the attack methods documented above. The evidence is clear that it is not.
India’s UPI ecosystem has made passwords and OTPs insufficient on their own, especially when attackers already control valid credentials.
OTP verifies two things. First, that the person logging in knows the account credentials. Second, that they have access to the registered mobile number at the moment of login.
OTP does not verify that the person logging in is the account holder. SIM swap transfers access to the mobile number. OTP malware shares access to every OTP simultaneously. Social engineering exploits the human tendency to comply with authority. Session hijacking bypasses the login entirely.
In each of these attack scenarios, OTP verification is either bypassed or irrelevant. The attacker passes the OTP check. Authentication succeeds. The bank’s systems record a verified login.
The authentication model was designed to stop someone who does not know the password and does not have the phone. It was not designed to stop someone who has obtained both. And the industrial scale at which stolen credentials and phone access are now available means that designing only for the first scenario is structurally insufficient.
The Shift From Identity to Behavior – What Banks Must Understand
The evolution in ATO prevention that financial institutions in both markets are being pushed toward is captured in a specific conceptual shift: from verifying identity at login to verifying behavior throughout the session.
Identity verification answers the question: is this person who they say they are at the moment of authentication?
Behavioral verification answers a different question: does this session look like it belongs to the real account holder throughout the duration?
These are not the same question, and they catch different attacks.
An attacker who has stolen credentials and OTP access passes identity verification. They look exactly like the account holder at the moment of login. They fail behavioral verification because they do not type the way the account holder types, they do not navigate the application the way the account holder navigates it, they initiate transactions the account holder has never initiated before, and they are accessing the account from a device and IP address that do not match the account holder’s established pattern.
Behavioral authentication uses several signal categories simultaneously.
- Device fingerprinting establishes a profile of the devices the account holder has historically used to access their account. Browser type, screen resolution, installed fonts, network characteristics. An account accessed for the first time from an entirely clean browser profile on an unrecognised device is a signal, even when credentials and OTP have passed verification.
- Typing dynamics and navigation patterns establish how the account holder actually interacts with the application. Speed of keystrokes, pause patterns between fields, navigation sequence through menus. These are difficult to replicate because they are subconscious. An attacker who has credentials and OTP still does not know that the account holder always navigates to recent transactions before initiating a transfer.
- Transaction pattern analysis compares each transaction against the account holder’s historical behaviour. Transaction amount, recipient type, time of day, frequency of activity in a session. A first-time transfer to a new recipient account for an amount that falls outside the account holder’s normal range, initiated within minutes of login, is a pattern that behavioral models flag regardless of whether authentication was successful.
- Session anomaly detection watches for changes in session behaviour that indicate a handoff. A session that begins on one IP address and transitions to another mid-session. A session where activity stops for an unusual period and then resumes with a different behavioural signature. These are indicators of session hijacking that are invisible to authentication-based controls.
Institutions that have measurably reduced ATO losses have combined identity verification at account opening with real-time session monitoring and a defined recovery workflow, applying controls at three distinct stages: before login, at login, and throughout the session.
The Regulatory Landscape – What India and the US Now Require
Both regulatory environments are moving in the same direction, driven by the same evidence.
- India: RBI’s Evolving Requirements
The RBI’s 2026 mandate for stronger 2FA reflects the vulnerability of OTP-only systems when SIM control is lost or credentials are compromised.
RBI’s Master Direction on Fraud Risk Management from January 2024, and the subsequent circular on Digital Payment Fraud from March 2025, together create a clear mandate for all scheduled commercial banks and NBFCs with digital payment channels. All regulated entities must implement real-time fraud monitoring and scoring for digital payment transactions above ₹10,000, with automated alerts and escalation workflows for transactions flagged as high risk.
The RBI’s new Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, effective July 31, 2026, which we covered in detail on this blog, goes further in requiring continuous monitoring capabilities, 24×7 CSOC operations, and device-level controls that together create the infrastructure for behavioral session monitoring even if they do not prescribe the specific methodology.
- United States: FFIEC Guidance and CFPB Liability Shift
The FFIEC’s guidance on digital banking security encourages multi-factor authentication, out-of-band verification, and layered controls for high-risk activities.
The layered controls language is specifically relevant to the behavioral authentication discussion. The FFIEC has consistently maintained that no single authentication method is sufficient for high-risk transactions and that financial institutions must layer controls at multiple points in the transaction lifecycle, not only at login.
The CFPB clarified that many ATO-related losses may qualify as unauthorised electronic fund transfers under Regulation E, meaning banks could be held liable for reimbursement, even if the customer was tricked into providing credentials.
This liability clarification has changed the calculus for US financial institutions. If a customer was successfully social-engineered into sharing their OTP and the institution’s only defence was OTP verification, the institution may bear liability for the loss. That regulatory pressure, combined with the reputational cost of ATO incidents, is accelerating investment in behavioral authentication architectures across US banking.
What Banks and NBFCs Must Implement
These are the operational priorities that emerge from the combined evidence of the Indian and US ATO landscape.
- Deploy velocity and anomaly detection on login events, not just authentication success.
A login that successfully passes authentication after 200 failed attempts in the previous hour is not a safe login. Authentication success is not the only signal that matters at the login stage. Login velocity, geographic anomalies, device consistency, and time-of-day patterns must all be evaluated alongside authentication outcome.
- Implement real-time session behavioural monitoring.
The authentication event is the beginning of the security evaluation, not the end of it. A session monitoring system that scores behavioral consistency throughout the customer’s session, against their established individual profile, is the control that catches ATO after the attacker has successfully authenticated.
- Classify high-risk transactions and apply stepped-up authentication specifically for them.
Not every transaction carries the same risk. A balance inquiry on a known device from a regular location is different from a first-time transfer to a new recipient account for an amount outside the account holder’s normal range. Risk-based transaction classification allows high-friction authentication to be applied precisely where the risk warrants it, without degrading the experience for routine low-risk activity.
- Replace SMS OTP with phishing-resistant authentication methods for high-value transactions.
SMS OTP should not be the authentication method for transactions above a material threshold. Authenticator app-based TOTP, push notifications with transaction detail display, hardware tokens, and biometric authentication are all more resistant to the SIM swap and OTP redirection attacks that SMS OTP is vulnerable to. At least one of the two authentication factors must be dynamic, meaning uniquely generated for each transaction, per RBI’s 2026 mandate. Dynamic authentication that does not depend on SMS interception meets this requirement more robustly.
- Build a customer notification architecture that is faster than the attacker.
A customer who receives an immediate notification when their account is accessed from an unrecognised device, when a new payee is added, or when a high-value transaction is initiated, has the opportunity to interrupt the attack before it completes. Notification latency is directly related to fraud loss. Banks and NBFCs that notify customers in real time rather than in batched end-of-day alerts give customers the window to call the fraud line before funds clear.
- Train customer service teams on ATO recovery workflows.
When a customer calls to report ATO, the recovery workflow determines how much additional damage occurs. A customer service team that knows immediately how to freeze the account, revoke all active sessions, initiate a SIM swap check with the telecom operator, and escalate to the fraud investigation team reduces the loss. A team that reads from a general account complaint script while the attacker continues operating extends it.
- Audit your account recovery flows with the same rigor as your login authentication.
ATO attackers frequently exploit account recovery as the path of least resistance once primary authentication has been strengthened. Password reset flows that rely on SMS OTP are as vulnerable to SIM swap as the primary login. Security question-based recovery is exploitable through social media and data breach information. Account recovery flows must be evaluated against the same threat model as the primary authentication path.
The Connection to Data Breaches You Have Already Read About
Account takeover does not exist in isolation from the broader breach landscape that this blog has been documenting throughout 2026.
The Pune student’s case began with a study planner app that harvested cached browser credentials. Where do cached credentials come from? Previous data breaches that left email addresses and password combinations in underground markets. 1.7 billion stolen credential records were shared in underground forums last year. The Bank of Baroda breach we covered earlier this month, where one compromised employee email account led to over a terabyte of customer data being posted on the dark web, is itself a credential harvest event. That data feeds the next wave of ATO attacks. The CDSL breach in 2022 exposed customer data that took four years for SEBI to formally penalise. That data has been available to ATO operators since the moment it was posted.
Breaches and account takeover are not separate problem categories. Breaches generate the data that enables ATO. ATO generates the losses and reputational damage that drive customers away from digital channels. The organisations that treat them as separate workstreams are managing one cycle of a problem while feeding the next.
Final Thought
The Pune student’s study planner app passed every app store review. The attacker’s SIM swap request passed the telecom operator’s verification. The OTP entry passed the bank’s authentication check.
Every gatekeeper said yes. The attacker walked through every door.
The student found out forty-five minutes later when the balance showed zero.
This is the account takeover problem in its most concrete form. The systems designed to keep attackers out are being used to let them in. The verification methods that were adequate for the threat environment of ten years ago are being systematically defeated by attackers who have spent the intervening decade figuring out exactly how to defeat them.
The institutions that will win the ATO problem are not the ones that add another OTP step to their authentication flow. They are the ones that recognise that the login is the beginning of the security evaluation, not the conclusion of it. That behavioral consistency throughout a session is a more reliable signal of genuine identity than possession of a phone number at the moment of login. That the ₹805 crore in Indian fraud losses and the $12.5 billion in US fraud losses are not the cost of a problem that cannot be solved. They are the cost of institutions that are still solving the problem of yesterday.
At Skeletos IT Services, we help Indian banks, NBFCs, and financial institutions design and implement the layered security architecture that addresses account takeover at every stage of the transaction lifecycle, from pre-authentication device intelligence to in-session behavioral monitoring to post-transaction anomaly detection. If you want to understand where your current authentication architecture has gaps that ATO attacks are designed to exploit, we can help you assess it.
Note: This blog references data from the RBI June 2025 ATO Fraud Bulletin, RBI Annual Report FY 2024-25, Veriff Fraud Report 2026, Verizon 2025 DBIR, FBI IC3 2025 Advisory, FTC 2024 Consumer Sentinel Report, and Bureau ID 2026 India Fraud Report. All figures are from verified public sources. This blog is for awareness and educational purposes. Consult your compliance and technology teams for institution-specific guidance.

