Monday, June 15, 2026

Security Boulevard Logo

Security Boulevard

The Home of the Security Bloggers Network

Community Chats Webinars Library
  • Home
    • Cybersecurity News
    • Features
    • Industry Spotlight
    • News Releases
  • Security Creators Network
    • Latest Posts
    • Syndicate Your Blog
    • Write for Security Boulevard
  • Webinars
    • Upcoming Webinars
    • Calendar View
    • On-Demand Webinars
  • Events
    • Upcoming Events
    • On-Demand Events
  • Sponsored Content
  • Chat
    • Security Boulevard Chat
    • Marketing InSecurity Podcast
    • Techstrong.tv Podcast
    • TechstrongTV - Twitch
  • Library
  • Related Sites
    • Techstrong Group
    • Cloud Native Now
    • DevOps.com
    • Security Boulevard
    • Techstrong Research
    • Techstrong TV
    • Techstrong.tv Podcast
    • Techstrong.tv - Twitch
    • Devops Chat
    • DevOps Dozen
    • DevOps TV
  • Media Kit
  • About
    • Sponsor

  • Analytics
  • AppSec
  • CISO
  • Cloud
  • DevOps
  • GRC
  • Identity
  • Incident Response
  • IoT / ICS
  • Threats / Breaches
  • More
    • Blockchain / Digital Currencies
    • Careers
    • Cyberlaw
    • Mobile
    • Social Engineering
  • Humor
Security Bloggers Network 

Home » Security Bloggers Network » ATO Attacks Severely Harm User Experience and Brand Reputation

SBN

ATO Attacks Severely Harm User Experience and Brand Reputation

by Arkose Labs on March 2, 2023

Account takeover (ATO) attacks, where bad actors  gain unauthorized access to genuine user accounts and abuse them for criminal activities, have evolved into a thriving ‘business’ for attackers and a nuisance for companies, as they often lack full visibility into the volumes of ATOs they face.

Account takeover (ATO) attacks are among the biggest issues in cybercrime today, and they’re only becoming  more frequent. Fraudsters commit these attacks to drain funds directly from accounts and/or use compromised accounts as launchpads for various other crimes—such as money laundering, phishing scams, and sending out spam. On the other hand, businesses spend time, effort, money, and reputation, trying to clean up the mess.

However, by implementing a robust authentication solution, like that of Arkose Labs, businesses can not only reduce the risk of account takeover, but also save precious resources and time. This also leads to better ROI and cost savings, as businesses don’t need to rely on manual processes to handle fraud cases. Furthermore, an authentication solution can also be used to reduce false positives and increase the efficiency of fraud prevention operations.

What is the true cost of ATOs in your business?

The True Cost of ATOs – Are your customer accounts safe?
RECOMMENDED RESOURCE
The True Cost of ATOs – Are your customer accounts safe?
ACCESS Infographic

Lack of visibility

The  lack of visibility into the extent of damage caused by ATOs  makes them challenging to detect. This lack of visibility is clearly highlighted in the results of a recent Arkose Labs’ survey of 100 IT professionals across industries. Nearly 30% of the companies polled reported no increase in ATO attacks in 2020 while half of the companies reported only a slight increase.

This statistic is in stark contrast with the volume of ATO attacks recorded on the Arkose Labs network—a 50% spike over the second half of 2020, and a 90% increase in Q4. This shines the spotlight on the lack of visibility into the volumes of ATO attacks that businesses face.

Businesses face financial and reputational losses

Often, the effects of account takeover attacks are discovered once downstream abuse has been committed and financial losses incurred. In addition to losing millions of dollars every year, ATOs adversely impact the good user experience (with 90% of the companies agreeing) to cause brand erosion and customer churn. These are rather long-term damages as it takes years of effort to build a brand and acquire customers.

The Arkose Labs’ survey reveals that 5% of the large companies (with over 10,000 employees) reported annual costs exceeding $1 million, while 10% of the companies reported losses of between $500,000 and $1 million. However, it is important to note that these losses do not include cleanup costs, application downtime, operational costs, and reimbursements to customers for loss of funds. This means the actual losses are much higher.

Another big concern pertains to regulatory compliance. When bad actors are able to successfully scale up ATO attacks, affected businesses attract regulatory attention, hefty penalties, and uncomfortable questions regarding the lack of adequate security on their platforms. 

Luckily, with the right security measures in place, businesses can protect themselves from automated attacks and remain compliant with the latest regulations. This can not only help them save costs, but also improve their ROI by ensuring their data and customers are kept safe from malicious threats. Additionally, businesses can use this opportunity to gain an edge over the competition by demonstrating their commitment to security and compliance, which can help them build trust in the market.

Account takeover attacks are pervasive across industries

Although every industry is facing the brunt of ATOs,  some of the worst affected include professional services, healthcare, financial institutions, and e-commerce platforms.E-commerce firms are obliged to keep user accounts safe as it can harm them through fraudulent transactions, payments fraud, and negative brand reputation, which can, in turn, impact their revenues.

With the most valuable customer data in their possession, financial institutions are a prime target for attackers. They are also the most regulated industry, which means a successful ATOs  can result in massive fines and greater regulatory measures imposed on them, with the legal and compliance costs adding up to the financial losses. A whopping 94% of financial institutions polled in the Arkose Labs’ survey agreed to ATO attacks degrading user experience for their customers.

Who keeps an eye on ATOs?

There is no clear-cut consensus on who, in an organization, is responsible when it comes to fighting fraud—each department believes it is the role of the other. For instance, while a majority of the respondents in our survey would hold the information security department responsible, others say preventing ATO is the responsibility of the fraud, engineering, or product teams. The verdict is also divided according to the size of the company, with 55% of the larger companies saying information security should handle ATOs, followed by fraud 29%, and engineering at 14%.

Fighting ATO attempts, however, must be the prerogative of all organizations, regardless of their size, with a dedicated team to handle them centrally. That said, investments in fraud prevention are abysmally low with a majority of companies reported spending 1-5% of their tech budget on fraud and 3% having no dedicated budget at all! This is at a time when the volumes of account takeover attacks are increasing and estimated costs of handling them can add up to 8% of the annual revenue for digital businesses.

By investing in fraud prevention, businesses can not only reduce the cost of ATO attempts, but also save on costs in other areas such as customer service and chargebacks. With better security, businesses will also see a better ROI in the long run, with the potential for increased customer retention and better customer experience.

Adopt a proactive, zero tolerance to fraud approach

Businesses often take reactive steps to stop ATOs , which include implementing more stringent controls, banning accounts, and classifying higher percentages of traffic as suspicious. These measures, however, disrupt the digital experience for authentic users and often lead to false positives. Therefore, the most viable approach to fighting ATO attacks is to stop the attackers right at the entry gates.

Arkose Labs adopts a zero tolerance to fraud approach which uses friction smartly to ensure authentic users can continue to enjoy seamless user experience, while bad actors are accurately identified and challenged. Based on each user’s risk assessment, enforcement challenges are presented. These challenges continually step up in complexity to wear out malicious users and undermine cyberattacks. 

To gain further insights into the state of account takeover attacks in your industry, please download a copy of the survey report now.

 

*** This is a Security Bloggers Network syndicated blog from Arkose Labs authored by Arkose Labs. Read the original post at: https://www.arkoselabs.com/blog/ato-attacks-severely-harm-user-experience-and-brand-reputation/

March 2, 2023March 2, 2023 Arkose Labs account takeover
  • ← Acunetix releases a security check for Fortinet RCE flaw
  • USENIX Security ’22 – Umar Iqbal, Charlie Wolfe, Charles Nguyen, Steven Englehardt, Zubair Shafiq – ‘Khaleesi: Breaker Of Advertising And Tracking Request Chains’ →

Techstrong TV

Click full-screen to enable volume control
Watch latest episodes and shows

Tech Field Day Events

Upcoming Webinars

Agentic Software Delivery in 2026: How To Bridge The Gap Between AI Ambition and Delivery Confidence
The Cost of Exposure: Managing the Operational Risks of Executive Security Incidents
Untangling the EU Cyber Resilience Act
The Software Supply Chain Just Got Harder to See
Building a Resilient Security Culture in the AI Era with AWS & Datadog

Podcast

Listen to all of our podcasts

Secure by Design

2 weeks ago | Jack Poller

Senator Sanders Wants to Own AI Companies — and Hand America’s Adversaries the Keys

3 weeks ago | Jack Poller

NIST’s Nine: The PQC Signature Race Moves to Round Three

3 weeks ago | Jack Poller

The Quantum Arms Race: Why Washington Just Wrote a $2 Billion Check to Nine Companies

4 weeks ago | Jack Poller

Beyond Moore’s Law: The Hyper-Acceleration of Autonomous AI Cyber Capabilities

1 month ago | Jack Poller

The Exception Economy: When Security Teams Stop Protecting and Start Negotiating

Press Releases

GoPlus's Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

GoPlus’s Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

Subscribe to our Newsletters

Most Read on the Boulevard

Zscaler Launches Industry-First Zero Trust Security for Agentic AI
ServiceNow Fixes Flaw That Could Lead to Unauthorized Access to Instances
Linux Kernel Bug Caused by Single Character Opens Path to Root Access
HackerOne Unveils Agentic AI Platform to Discover and Validate Vulnerabilities Faster
Survey: Organizations Take Too Long to Fix Application Vulnerabilities
Atomic Arch npm Campaign Adds Malicious Dependency
ServiceNow Breach Explained: API Exposure, Risks & Security
Top 8 AI App Dev Platforms in 2026
South Korea Fines Coupang $400M Over Data Breach Affecting Millions
CISA BOD 26-04: Frequently asked questions about the new risk-based patching directive

Industry Spotlight

Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks
Cloud Security Cybersecurity Data Privacy Data Security Featured Incident Response Industry Spotlight Malware Mobile Security Network Security News Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threats & Breaches Vulnerabilities 

Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks

April 12, 2026 Jeffrey Burt | Apr 12 Comments Off on Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks
The Day the Security Music Died
AI and Machine Learning in Security Cybersecurity Featured Industry Spotlight Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

The Day the Security Music Died

April 8, 2026 Alan Shimel | Apr 08 Comments Off on The Day the Security Music Died
The Lock, Not the Alarm: How Palo Alto’s Koi Acquisition Rewrites Endpoint Security
Featured Industry Spotlight Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Uncategorized 

The Lock, Not the Alarm: How Palo Alto’s Koi Acquisition Rewrites Endpoint Security

February 18, 2026 Jack Poller | Feb 18 Comments Off on The Lock, Not the Alarm: How Palo Alto’s Koi Acquisition Rewrites Endpoint Security

Top Stories

Google Sues Chinese Threat Group Using Gemini AI in Phishing Scams
Cloud Security Cybersecurity Data Privacy Data Security Endpoint Featured Identity & Access Mobile Security Network Security News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threat Intelligence Threats & Breaches 

Google Sues Chinese Threat Group Using Gemini AI in Phishing Scams

June 14, 2026 Jeffrey Burt | 10 hours ago 0
ServiceNow Fixes Flaw That Could Lead to Unauthorized Access to Instances
Cloud Security Cybersecurity Data Privacy Data Security Featured Identity & Access Incident Response Mobile Security Network Security News Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Vulnerabilities 

ServiceNow Fixes Flaw That Could Lead to Unauthorized Access to Instances

June 11, 2026 Jeffrey Burt | 4 days ago 0
Zscaler Launches Industry-First Zero Trust Security for Agentic AI
AI and ML in Security Cybersecurity Featured News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Zero-Trust 

Zscaler Launches Industry-First Zero Trust Security for Agentic AI

June 10, 2026 Jon Swartz | 4 days ago 0

Security Humor

Randall Munroe’s XKCD 'Soniferous Aether'

Randall Munroe’s XKCD ‘Soniferous Aether’

Download Free eBook

[su_panel border="0px solid #ddd" radius="0" text_align="center" padding-top="0px" padding-bottom="0px"]
7 Must-Read eBooks for Security Professionals
[/su_panel]

Security Boulevard Logo White

DMCA

Join the Community

  • Add your blog to Security Creators Network
  • Write for Security Boulevard
  • Bloggers Meetup and Awards
  • Ask a Question
  • Email: [email protected]

Useful Links

  • About
  • Media Kit
  • Sponsor Info
  • Copyright
  • TOS
  • DMCA Compliance Statement
  • Privacy Policy

Related Sites

  • Techstrong Group
  • Cloud Native Now
  • DevOps.com
  • Digital CxO
  • Techstrong Research
  • Techstrong TV
  • Techstrong.tv Podcast
  • DevOps Chat
  • DevOps Dozen
  • DevOps TV
Powered by Techstrong Group
Copyright © 2026 Techstrong Group Inc. All rights reserved.
×

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.