Account Takeover Fraud Statistics: The Latest ATO Data for 2026

Account takeovers (ATO) remain one of the most significant forms of identity fraud in 2026.. In 2025, more than 6 million U.S. consumers experienced an ATO attack, which is an 18% increase from the previous year. Losses associated with account takeover exceeded $15 billion, making it the costliest individual fraud category tracked by Javelin Strategy & Research.

At the same time, the data reveals an important shift in the fraud landscape. Account takeover losses actually declined 4% year over year despite the increase in victims. Fraudsters are targeting more accounts, using increasingly automated attacks and finding value in accounts that extend well beyond traditional banking.

From credential attacks and bots to deepfakes and AI-assisted social engineering, the methods used to compromise digital identities continue to evolve. The following account takeover fraud statistics provide a snapshot of the scale of the problem in 2026, where attacks are occurring, and how businesses and consumers are being affected.

Key Account Takeover Fraud Statistics for 2026

The latest statistics show that ATO attacks are affecting millions of consumers while becoming part of a broader identity fraud ecosystem that spans account creation, authentication, transactions, and account recovery.

Among the most important statistics include:

  • More than $15 billion was lost to account takeover attacks in the U.S. in 2025.
  • 6 million U.S. consumers experienced account takeover in 2025, an 18% increase year over year.
  • 22% of U.S. consumers reported experiencing account takeover during the past year.
  • Account takeover volume increased 141% between H1 2021 and H1 2025.
  • 8.3% of global digital account creation attempts were suspected of fraud in 2025.
  • 46% of consumers experiencing ATO said they either lost trust in the affected company or stopped using it permanently.
  • More than 97% of identity attacks observed by Microsoft were password attacks.
  • One in five biometric fraud attempts involved a deepfake
  • 39% of contact center fraud calls were associated with account takeover attempts, according to Pindrop.
  • Banking and financial accounts accounted for 46% of consumer-reported ATO incidents 

Taken together, these numbers illustrate why account takeover should no longer be viewed simply as a login security problem. An attack may begin with stolen credentials, but the consequences can extend through password recovery, payment changes, loyalty redemptions, high-value transfers, and other activity throughout the customer lifecycle.

Account Takeover Losses Remain Above $15 Billion

U.S. account takeover losses exceeded $15 billion in 2025, even as total ATO losses declined 4% from the previous year.

According to Javelin Strategy & Research’s 2026 Identity Fraud Study, account takeover remained the single costliest fraud category it tracked. Approximately 6 million U.S. consumers experienced ATO during 2025, an 18% increase from 2024.

That creates an interesting divergence in the data: more people are experiencing account takeovers, even though the aggregate financial losses associated with those attacks have declined slightly.

The trend becomes even clearer when viewed against the broader identity fraud landscape. Javelin estimated total U.S. identity fraud losses, excluding scams, at $27.3 billion in 2025, essentially unchanged from $27.2 billion the previous year. Approximately 18 million people were affected.

New-account fraud moved in the opposite direction. Losses increased to approximately $7 billion, while the number of victims rose 31% to 5.4 million.

That matters because new-account fraud and account takeover are different manifestations of the same underlying identity problem. In one scenario, a fraudster uses stolen or synthetic identity information to establish a new account. In the other, an attacker compromises an identity that a business has already learned to trust.

The FBI’s broader cybercrime data provides additional context. The FBI Internet Crime Complaint Center recorded $20.877 billion in reported cybercrime losses during 2025, up 26% year over year, across more than 1 million complaints. Identity theft complaints increased 48%, from 21,403 in 2024 to 31,675 in 2025.

The FBI does not maintain a dedicated account takeover category, so its identity theft and personal data breach figures should not be treated as direct measures of ATO. They nevertheless illustrate the scale of the identity and credential ecosystem that helps enable account compromise.

Account Takeover Has Increased Dramatically Over the Past Five Years

While loss estimates provide one way to understand ATO, fraud network telemetry provides another. TransUnion reported a 21% increase in global digital account takeover volume between H1 2024 and H1 2025, extending a much longer pattern of growth.

Attackers are also targeting different stages of the customer journey. TransUnion found that 8.3% of global digital account creation attempts were suspected of fraud in 2025, making account creation the riskiest stage of the consumer lifecycle. That represented an 18% year-over-year increase.

The significance of these numbers extends beyond account opening. Fraudsters who successfully create accounts using stolen or manipulated identities can establish accounts that appear legitimate before using them for later fraudulent activity. Conversely, legitimate accounts that have already passed identity checks can become targets for takeover months or years later.

This creates a challenge for fraud prevention systems built around a single point in time. An identity that was legitimate when an account was created does not guarantee that the person controlling that account today is the same person.

Bots and Automated Attacks Are Increasing the Scale of Identity Fraud

More than half of all web traffic was automated in 2025, while attacks against APIs continued to rise.

Automation has fundamentally changed the economics of account takeover. Instead of manually testing individual usernames and passwords, attackers can use automated tools to test enormous numbers of credentials, identify active accounts and concentrate their efforts on successful combinations.

One report found that more than 53% of web traffic was automated in 2025, leaving humans responsible for approximately 47%. Twenty-seven percent of bot attacks targeted APIs rather than traditional user interfaces.

Other research illustrates the pressure being placed on those APIs. One study found a 113% year-over-year increase in average daily API attacks per enterprise, rising from 121 to 258. It also found that 61.2% of API attacks involved unauthorized workflows or abnormal activity, up from 30% in 2024.

Login traffic provides another window into the problem. F5 Labs found that 10.6% of web authentication traffic and 5.2% of mobile API authentication traffic was malicious, even in environments where bot mitigation was already deployed.

These attacks are particularly important for account takeover because automation allows criminals to operate at a scale that would be impossible manually. A single leaked credential database can be tested against numerous services, exploiting the tendency of consumers to reuse usernames and passwords across different accounts.

More Than 97% of Identity Attacks Are Password Attacks

Password spray and other large-scale password attacks accounted for more than 97% of identity attacks observed by Microsoft.

Microsoft reported that identity-based attacks increased 32% during the first half of 2025, with password attacks representing more than 97% of the total. Microsoft also found that 85% of usernames targeted by password-spray attacks had already appeared in known credential leaks.

The concentration of attack infrastructure is striking as well. Just 20 autonomous system numbers, representing approximately 0.04% of networks, were responsible for more than 80% of malicious password-spray traffic measured by Microsoft.

Multifactor authentication remains one of the strongest defenses against credential attacks. Microsoft has reported that MFA can block more than 99% of identity attacks. But MFA should not be viewed as the end of the identity security process.

Attackers increasingly target pathways that exist around authentication, including account recovery, session theft, social engineering and changes to trusted account information. A criminal who gains control of an authenticated session does not necessarily need to defeat the original login process again.

This is why account takeover prevention increasingly requires organizations to evaluate identity throughout the account lifecycle rather than treating successful authentication as permanent evidence of trust.

Banking Is the Most Common Account Takeover Target, but ATO Extends Far Beyond Finance

Banking and financial accounts were the most commonly compromised account type in 2026, but social media, gaming, delivery, subscription and other everyday accounts are also significant targets.

One study found the following breakdown among consumers reporting account takeover:

Account typePercentage of ATO attacks
Banking and financial accounts46%
Social media38%
Food and grocery delivery23%
Gaming and gambling23%
Subscriptions22%
Utilities20%
Ticketing15%
Cryptocurrency12%

These figures demonstrate that attackers follow stored value, not simply stored money.

A compromised food delivery account may contain payment credentials. A gaming account can contain valuable digital goods. A loyalty account can hold points that can be transferred or redeemed. Ticketing and subscription accounts can have resale value, while social media accounts can provide an established identity that can be exploited for scams or further social engineering.

This broadening attack surface also means organizations outside financial services increasingly need to think about account takeover as an identity problem.

Financial Services Remain a Major Target for ATO

Financial services accounted for 46% of account takeover incidents in 2026.

The attraction is straightforward: financial accounts provide attackers with a direct path to monetary value.

However, different datasets show that ATO risk is not concentrated exclusively in banking. One study found the highest average ATO rate in 2025 within Internet & Software at 0.99%, followed by digital commerce and travel at 0.82%. Finance and fintech registered an average rate of 0.39%.

TransUnion’s broader fraud data similarly found significant risk outside financial services. Among U.S. transactions in 2025, suspected digital fraud rates reached 11.7% in online communities such as dating sites and forums and 9.8% in gaming.

The takeaway is that any account containing money, payment credentials, personal information, reputation, digital assets, access privileges or accumulated value can become attractive to an attacker.

AI and Deepfakes Are Changing Account Takeover Attacks

One in five biometric fraud attempts involved a deepfake, while deepfaked selfies increased 58% year over year.

Account takeover has traditionally been associated with stolen passwords and credential stuffing, but generative AI is expanding the tools available to attackers.

Deepfakes can be used in attempts to impersonate legitimate customers during identity checks. Generative AI can improve phishing and social engineering content. Automated systems can help criminals execute attacks at greater scale, while injection techniques can introduce manipulated media directly into verification workflows.

Deepfakes represented one in five biometric fraud attempts, with deepfaked selfies increasing 58% and injection attacks increasing 40% year over year.

Pindrop’s research into contact center fraud provides another example. Account takeover accounted for 39% of fraud calls, including attempts involving credential resets, changes to personally identifiable information and reinstatement of restricted accounts. Pindrop also reported a 1,300% increase in the rate of deepfake attacks over one year, from approximately one every two days to seven per day.

Meanwhile, the FBI recorded 22,364 complaints containing its new AI descriptor in 2025, representing approximately $893 million in reported losses.

AI does not replace traditional account takeover techniques. Instead, it can make different stages of an attack more scalable and convincing, combining credential theft, impersonation, social engineering and automated activity into increasingly complex attack chains.

Account Takeover Is Increasingly a Multi-Step Attack

Multi-step identity fraud schemes increased 180%, from 10% to 28% of identity fraud.

This is one of the most important changes in how organizations should think about account takeover.

Fraud does not necessarily begin and end with a malicious login. An attacker may obtain credentials through phishing or an infostealer, access an existing account, change information associated with that account, establish new payment details and then wait before attempting to extract value.

The individual actions may appear legitimate when viewed independently.

That makes context increasingly important. A successful password followed by a device change may not necessarily indicate fraud. Neither may an address change or a high-value transaction. But several unusual signals appearing together can tell a very different story.

Account takeover detection therefore increasingly depends on connecting signals across an entire interaction rather than asking whether any individual event looks fraudulent in isolation.

MFA Is Essential, but Identity Verification Cannot End at Login

MFA can stop more than 99% of identity attacks, but attackers can still target recovery processes, authenticated sessions and activity occurring after login.

The continued effectiveness of MFA should not be understated. For credential-based attacks, it remains one of the most valuable security controls available. The challenge is that account takeover is broader than credential theft.

Once a user has successfully authenticated, businesses continue making implicit trust decisions throughout the relationship. Those moments can require different levels of assurance.

Rather than subjecting every customer to maximum friction during every interaction, organizations can introduce step-up verification when risk changes. Identity document verification, biometrics, device intelligence, behavioral signals and transaction context can provide additional evidence when an interaction warrants greater scrutiny.

The objective is not to verify customers repeatedly for the sake of verification. It is to establish the appropriate level of trust for the action being performed.

Consumers Are Willing to Accept More Verification When the Risk Justifies It

Ninety-three percent of consumers said they would accept additional verification at login or checkout if it reduced their risk of fraud.

Fraud teams have traditionally faced a difficult tradeoff. Stronger controls can reduce fraud, but excessive friction can frustrate legitimate customers and lower conversion.

The latest data suggests consumers are more receptive to additional security when they understand why it is being used.

A study found that 93% of consumers were willing to accept additional verification during login or checkout if doing so reduced fraud risk. At the same time, unnecessary intervention has a measurable cost. One estimate put the the average cost of a false positive at $135 across its network, rising to $496 in digital commerce.

The challenge is therefore not choosing between security and customer experience. It is determining when additional friction is justified.

Risk-based identity verification can allow low-risk users to continue with minimal interruption while triggering stronger verification when account behavior, transaction characteristics, device signals or other evidence indicates elevated risk.

Account Takeover Can Permanently Damage Customer Trust

Nearly half of account takeover victims either lost trust in the affected company or stopped using it altogether.

The financial impact of account takeover does not end when fraudulent transactions are reimbursed.

One report found that 22% of U.S. consumers experienced account takeover during the previous year. Among victims, 35% said they lost trust in the company involved and another 11% stopped using it permanently.

How organizations respond also matters. Thirty-seven percent of victims said the company notified them about the takeover, while 13% discovered the problem only after being locked out of their own account. One in five said resolving the incident took more than a week, including 4% whose cases remained unresolved when surveyed.

By contrast, 82% of consumers said their perception of a company would improve if it resolved a fraud incident quickly.

Those statistics turn account takeover from a fraud-loss calculation into a customer-retention issue.

Consumers entrust organizations with their identity information, payment credentials and account data. When that trust is compromised, the quality and speed of the response can determine whether the relationship survives.

Why Account Takeover Requires Continuous Identity Intelligence

Account takeover exposes a fundamental weakness in traditional approaches to digital identity: trust changes over time.

A legitimate person may create an account and successfully pass identity verification. The same person may later enable MFA and use that account safely for years. None of those events guarantees that every future interaction with the account is legitimate.

Modern fraud attacks move across the customer journey. They adapt and target the moments where trust is assumed rather than verified.

That is why identity decisions increasingly need to incorporate multiple layers of evidence. Documents and biometrics can establish identity, while device, behavioral and transactional signals can provide context around how that identity is being used. Higher-risk moments can then trigger additional verification rather than forcing every customer through the same process.

At Microblink, we describe this broader approach as Know Your Actor: understanding who or what is behind an interaction and continually evaluating whether the available evidence supports the action being attempted.

This is particularly important as AI agents become more common. Digital interactions will increasingly involve not only humans, but software acting on their behalf. Establishing identity at account creation will remain important, but organizations will also need to understand who is acting, under whose authority, and whether the behavior makes sense within the context of the relationship.

The Account Takeover Statistics to Watch in 2026 and Beyond

The latest data does not point to the disappearance of account takeover. It points to its evolution.

Losses can decline while victim counts rise. Authentication defenses can improve while attackers shift toward account recovery or authenticated sessions. Fraud rates can decline in aggregate while specific industries, account types or stages of the customer journey become more heavily targeted.

That is why no single statistic provides a complete picture of ATO.

The clearest trend across the 2025 and 2026 data is that identity fraud is becoming more interconnected. Credential attacks, automated bots, synthetic identities, deepfakes, social engineering and account takeover increasingly overlap rather than functioning as separate categories.

For organizations, the implication is equally clear. Identity cannot be treated as something established once at onboarding and then trusted indefinitely. As attackers become more adaptive, organizations need the ability to establish and re-establish trust throughout the customer lifecycle.

27 أغسطس، 2026

اكتشف حلولنا

استكشاف حلولنا على بُعد نقرة واحدة فقط. جرّب منتجاتنا أو تحدث معنا مع أحد خبرائنا للتعمق أكثر في ما نقدمه.