POST /account/payout-methodVerifyPayout change from an unknown device
- New device, never seen on account
- Login 1,200 miles from last one
- Password and session valid
Solution
Account takeover (ATO) is when a criminal gains access to a real customer's account, through stolen passwords, phishing, session theft or a hijacked phone number, then uses it to steal money, points, goods or data. Kavra compares each login and sensitive action with the account's own history and flags the ones that do not belong.
POST /account/payout-methodVerifyPayout change from an unknown device
Account takeover is a form of identity fraud where someone other than the owner controls a legitimate account. Unlike a fake account, the victim is real, the account has history, and it often holds something worth stealing: a balance, a saved card, loyalty points, a gift card, a bonus, personal data or access to other people.
That history is what makes ATO so damaging. A long-standing account carries trust that a fresh signup does not. Payment limits are higher, reviews count for more, and support agents are more willing to help. A criminal who gets in inherits all of it, and the first sign is often an angry customer asking where their money went.
Takeovers start in different places. The access method shapes what you will see at login.
| Entry method | How it works | What it looks like to you |
|---|---|---|
| Credential stuffing | Bots replay leaked email and password pairs from other breaches | High volumes of failed logins, a few quiet successes |
| Phishing | A fake login page or message captures the password and often the one-time code | A correct login from a new device, sometimes within minutes of the real user |
| Session theft | Malware or a malicious extension copies session cookies from the victim's browser | An active session appearing on a new device and network with no login at all |
| SIM swap | The criminal convinces a carrier to move the victim's number to a new SIM | Password reset by SMS, then immediate changes to contact details |
| Social engineering of support | An agent is talked into resetting access or changing the email | Account recovery through a channel that bypasses login checks |
| Password guessing | Common or reused passwords tried against known usernames | Slow, low-volume failures spread across many accounts |
Most defenses focus on step two. The loss happens in steps four and five.
Credentials, cookies or phone numbers are bought, phished or tested in bulk. Lists are sorted by which sites they work on and resold.
The attacker signs in, usually through a residential or mobile proxy near the victim's city and a browser profile set to look like an ordinary device.
They look around quietly: balances, saved cards, addresses, order history. Some wait days so the new device looks familiar.
Email, phone, password or two-factor settings are changed, and notification preferences switched off, so the real customer cannot see or stop what comes next.
Money is withdrawn to a new payout method, points are redeemed, goods are shipped to a drop address, or the account is sold on. Some accounts are kept as trusted launch pads for scams against other users.
Any account that can hold or move value is a target. In fintech and banking, attackers change the payout account and transfer balances. In e-commerce they order with stored cards and reroute delivery. In iGaming they withdraw player funds. In travel, loyalty miles and bookings are redeemed. On SaaS products, a taken-over admin account exposes company data.
The strongest signals compare the session with the account's own past, not with an average user.
An account used from the same phone and laptop for years suddenly signs in from a device it has never seen.
A session in one city, then another far away within a time no one could travel.
The login comes through a residential proxy, VPN or datacenter address, instead of the customer's usual carrier or broadband.
Email, phone, password or two-factor settings change right after login, followed by a payout or delivery change.
A valid session cookie appears on hardware and a network that never completed a login. A classic sign of stolen cookies.
The session goes straight to the payout or redemption page with no browsing, at machine speed.
Each control protects one moment. Takeovers route around whichever moment is guarded.
| Defense | What it protects | Where it breaks |
|---|---|---|
| Strong password rules | Guessing | Useless against reused, phished or stolen passwords |
| SMS one-time codes | The login step | SIM swaps and real-time phishing capture or redirect the code |
| CAPTCHA on login | Bulk bot attempts | Human attackers and solving services pass it, and customers pay the friction |
| IP blocklists and geo rules | Known bad networks | Residential proxies place the attacker in the victim's own city |
| Login-only checks | The front door | Stolen sessions skip login, and the damage happens after it |
Treat login as the start of the risk, not the end of it. The strongest programs assess the login, keep watching the session, and apply the most scrutiny to the actions that move value or change who controls the account.
How Kavra helps
Kavra assesses the login and every sensitive action after it, and explains in plain language why a session does or does not look like the owner.
New device, new network, impossible travel and known-bad devices are flagged against what this account normally looks like.
Each account builds its own list of trusted devices. An API lets you mark sessions and devices good or bad and revoke them.
Call Kavra on payout changes, contact changes and withdrawals, with a signed, single-use token bound to that action.
Kavra's own edge network and proxy intelligence reveal residential proxies, VPNs and hosting networks posing as home connections.
Headless browsers, automation frameworks and antidetect profiles are caught by contradictions between layers.
Kavra recommends allow, verify or block. Your backend asks for a second factor only when the evidence calls for it.
FAQ
Something else? Talk to our team.
Reused passwords are a leading cause. When a password leaks from one site, attackers test it on many others through credential stuffing. Phishing is the other big source, because it captures the password and often the one-time code together. Session cookie theft by malware is growing because it skips the login entirely.
It stops many attempts, but not all. Real-time phishing pages relay the code as the victim types it, SIM swaps redirect SMS codes, and stolen session cookies bypass login altogether. Two-factor works best combined with device and network checks on login and on the sensitive actions that follow.
Look for a login from a device the account has never used, a location far from recent sessions, a proxy or hosting network, and quick changes to email, phone, password or payout details. Several of these together in one session is a strong signal that someone other than the owner is in control.
End the active sessions, revoke the unknown device, lock sensitive changes and contact the owner through their original, verified contact details. Reverse recent changes to email, phone and payout methods. Then review linked accounts, because the same attacker device or network often touched other customers too.
In a SIM swap, a criminal persuades or bribes a mobile carrier to move the victim's number to a SIM they control. Every SMS code and password reset link then goes to the attacker. Checking the device and network on the reset and on the changes that follow catches the takeover even when the code is correct.
On every action that moves value or changes control: adding or changing a payout method, withdrawals, changing email, phone, password or two-factor settings, new shipping addresses, gift card and points redemption, and adding API keys or team members. These are the moments a takeover turns into a loss.
Run Kavra on your own traffic in observe-only mode. No risk to your customers, and a clear report of the fraud it finds.