Friday, June 19, 2026

Security Boulevard Logo

Security Boulevard

The Home of the Security Bloggers Network

Community Chats Webinars Library
  • Home
    • Cybersecurity News
    • Features
    • Industry Spotlight
    • News Releases
  • Security Creators Network
    • Latest Posts
    • Syndicate Your Blog
    • Write for Security Boulevard
  • Webinars
    • Upcoming Webinars
    • Calendar View
    • On-Demand Webinars
  • Events
    • Upcoming Events
    • On-Demand Events
  • Sponsored Content
  • Chat
    • Security Boulevard Chat
    • Marketing InSecurity Podcast
    • Techstrong.tv Podcast
    • TechstrongTV - Twitch
  • Library
  • Related Sites
    • Techstrong Group
    • Cloud Native Now
    • DevOps.com
    • Security Boulevard
    • Techstrong Research
    • Techstrong TV
    • Techstrong.tv Podcast
    • Techstrong.tv - Twitch
    • Devops Chat
    • DevOps Dozen
    • DevOps TV
  • Media Kit
  • About
    • Sponsor

  • Analytics
  • AppSec
  • CISO
  • Cloud
  • DevOps
  • GRC
  • Identity
  • Incident Response
  • IoT / ICS
  • Threats / Breaches
  • More
    • Blockchain / Digital Currencies
    • Careers
    • Cyberlaw
    • Mobile
    • Social Engineering
  • Humor
Security Bloggers Network 

Home » Cybersecurity » Did You Just Try to Login? Why Account Takeover Is Still on the Rise

SBN

Did You Just Try to Login? Why Account Takeover Is Still on the Rise

by Jesse Martin on August 9, 2023

Walking through the exhibit hall this week at Black Hat USA 2023, the number of solutions for “Next Generation Threats” and “AI-Powered Adversaries” might reasonably lead you to believe that this is where a majority of cyber risk lies. Indeed the fixation on well-resourced adversaries capable of doing novel and clever things is so ubiquitous that it might cause you to think that classic problems have been largely “solved.” This begs the question: With so many security vendors out there, why does Account Takeover (ATO) still occur?

Account takeover (ATO) attacks have recently surged, impacting 1 in 4 adults in the US. The primary culprit is credential stuffing, the rapid testing of username and password pairs harvested from previous breaches. What makes this attack vector particularly vexing is its source – not platform vulnerabilities or cryptographic flaws – but the widespread habit of users reusing credentials across sites.

Password reuse remains prevalent, despite the availability of password managers (with estimates ranging from only 22% to 45% of users using them). Compromised credentials on one site embolden malicious actors to attempt entry across multiple platforms using these credentials. Simple and free tools allow bad actors to perform this operation at remarkable speed and scale.

When security teams consider the threat of compromised credentials for internal privileged accounts, their first thoughts may rightly be implementing 2-factor authentication (2FA) as a safeguard against unauthorized logins. After all, this has been a hallmark of identity and access management when it comes to privileged accounts, to say nothing of its inclusion as a requirement in any number of compliance standards. Crucially, however, the best methods for protecting a privileged account aren’t necessarily the best methods for protecting customer accounts.

To be clear, this article doesn’t intend to advocate the abandonment of 2FA. Multi-factor authentication is undeniably an essential tool in the layered protection of privileged accounts. Instead, it critically assesses its applicability and value when countering ATO risks targeting customer accounts. 

MFA: An Increasingly Targeted Vector

As multi-factor authentication (MFA) becomes more widespread, attackers increasingly focus on exploiting these added security layers in account takeover campaigns. 

Despite the popularity of using text messages for delivering one-time passwords (OTPs), this method exposes these crucial passcodes to various vulnerabilities. Attackers can employ manual techniques, like phone porting and sim swapping, to redirect SMS messages to their controlled devices. Additionally, more complex attacks involve SMS interception by exploiting weaknesses in legacy protocols like Signaling System No. 7, man-in-the-middle attacks, and stingray-style cell interceptors.

Although OTPs generated through mobile apps (such as Google Authenticator) or hardware tokens offer improved security, they remain susceptible to exploitation. While these are often compromised through phishing and social engineering, security researchers have also documented a rise in OTP-interception-as-a-service providers. These services automate social engineering by sending their targets messages that suggest suspicious account activity and prompting them to enter their OTP. Users are more likely to comply since these messages don’t request victims’ usernames or passwords (which the attacker may already know from prior credential stuffing attempts).

1.5 Factor Authentication

There is a common thread here that OTPs don’t quite satisfy the classic definition of MFA. MFA is commonly defined as requiring a combination of:

  1. Something a user knows (such as a password)
  2. Something a user has (such as a keycard)
  3. Something a user is (biometrics)

OTPs are commonly considered “something you have” because users typically retrieve them from their device, such as an authenticator app or a password-generating fob. 

On more detailed examination, however, we can see that one-time-passcodes might be better defined as something a user KNOWS because it’s been delivered through something the user HAS in their possession. Although the knowledge is short-lived, as is the passcode’s validity, this still leaves this information more susceptible to theft through user manipulation and social engineering than a physical keycard.

Mobile apps that use push notifications as a second factor align more closely with our definition of “MFA.” However, even these methods aren’t immune to attacks, like MFA fatiguing.  This technique involves repeatedly attempting to log in with compromised credentials, bombarding the legitimate user with push notifications until they finally click, “Yes, it’s me” in their authenticator app, due to confusion, frustration, or by accident. MFA fatiguing has proven so effective that it has been attributed to breaches at major companies such as Microsoft, Cisco, and Uber.

Keep in mind that all of these attacks against multi-factor authentication are built on top of credential stuffing attacks, executed by inexpensive, large-scale botnets.

The Cost of Account Takeover Attacks

The examples in the previous section illustrate that 2FA/MFA is not a perfect solution. Undeniably, it’s of some value, but exactly how much? We know ATO attacks have a variety of associated costs, such as fraud, chargebacks, and customer satisfaction – and it’s essential to consider the value of a dynamic ATO mitigation solution.  

Authentication leader Okta has reported that an estimated 34% of all login attempts are linked to credential stuffing attacks. This statistic should lead us to consider the staggering scale of unmitigated ATO attempts and the immense cost to service these login attempts – even if they completely mitigate an attack. Apart from the infrastructure expenses needed to handle these countless requests, the costs of 2FA challenges, especially those delivered via SMS, can be staggering.

With a truly effective bot mitigation solution, SMS costs can decrease by millions of dollars. One of our customers saved $6 million per month in SMS costs. While 2FA is surely doing its job in hindering the success of these attacks, the resources required to supply these services and infrastructure hardly paint a compelling picture of security ROI.

Although it’s challenging to quantify, we must also consider the cost of a poor user experience. Requiring users to authenticate their identity through multiple factors inherently adds complexity compared to a standard login. In cases of privileged enterprise accounts, this is generally an acceptable requirement. However, customers often have less patience. While users have learned to tolerate MFA challenges in sectors like insurance, banking, and healthcare, users are far less accommodating in highly-targeted sectors like eCommerce, travel, and entertainment. In these industries, the cost of implementing MFA might not be measured in carrier charges for SMS, but in total loss of a customer to competitors who don’t use MFA.

Automation: The Common Thread

While we’ve discussed a number of authentication-related topics in this article, there is a simple commonality: Account Takeover attacks remain remarkably successful, mainly due to their reliance on inexpensive automation and credential stuffing tools. Additional authentication factors offer some mitigation; however, these factors themselves are susceptible to attacks and carry both tangible and intangible costs.  

When considering the best mitigation for ATO attacks, consider the ubiquity of “shift left” initiatives. This idea centers on addressing issues as early as possible to minimize costs. Visualized, the further “left” on the timeline of an issue, the earlier and therefore cheaper it will be to mitigate. 2FA/MFA is about as far “right” as it gets on the timeline of an ATO attack. This analogy is akin to mitigating a rainstorm with an expensive dryer after getting drenched instead of using an inexpensive umbrella to stay dry. 

By reframing ATO attacks as an automation challenge rather than as an authentication problem, we can shift left on the event timeline. In doing so, we can unburden the user experience, reduce costs by addressing the problem earlier in the timeline, and avoid implementing additional measures to compensate for the shortcomings of most 2FA/MFA implementations. While 2FA/MFA undeniably has a place in our layered account protections, it can be relieved of an enormous volume of work by identifying and mitigating these requests as unwanted automation.

Ultimately, ATO attacks are fundamentally bot attacks and must be treated as such.

Effective and Cost-Effective Security

Kasada is on a dedicated mission to combat bots by accurately identifying them as malicious automation that exploits legitimate services meant for genuine users. Rather than doing this through CAPTCHAs that inconvenience users to prove their humanity, Kasada detects the artifacts and indicators of automation invisibly.

Both effective and cost-effective, Kasada defends against Account Takeover attacks and thwarts other bot activity such as fake account creation, retail scalping, promotion abuse, and content scraping. 

Request a demo to learn how Kasada can help protect your customers, align with your risk management “shift everywhere” initiatives, and alleviate the costs of your overworked authentication services and infrastructure.

The post Did You Just Try to Login? Why Account Takeover Is Still on the Rise appeared first on Kasada.

*** This is a Security Bloggers Network syndicated blog from Kasada authored by Jesse Martin. Read the original post at: https://www.kasada.io/account-takeover-still-on-the-rise/

August 9, 2023August 9, 2023 Jesse Martin account takeover, ATO, credential stuffing, Cybersecurity, Uncategorized
  • ← Унифицированный SASE обеспечивает наблюдаемость с точностью
  • Protecting Personal Digital Lives: Why We Started BlackCloak →

Techstrong TV

Click full-screen to enable volume control
Watch latest episodes and shows

Tech Field Day Events

Upcoming Webinars

True Agentic SecOps at Lakehouse Scale
Agentic Software Delivery in 2026: How To Bridge The Gap Between AI Ambition and Delivery Confidence
Untangling the EU Cyber Resilience Act
The Software Supply Chain Just Got Harder to See
Building a Resilient Security Culture in the AI Era with AWS & Datadog

Podcast

Listen to all of our podcasts

Secure by Design

2 weeks ago | Jack Poller

Senator Sanders Wants to Own AI Companies — and Hand America’s Adversaries the Keys

3 weeks ago | Jack Poller

NIST’s Nine: The PQC Signature Race Moves to Round Three

3 weeks ago | Jack Poller

The Quantum Arms Race: Why Washington Just Wrote a $2 Billion Check to Nine Companies

1 month ago | Jack Poller

Beyond Moore’s Law: The Hyper-Acceleration of Autonomous AI Cyber Capabilities

1 month ago | Jack Poller

The Exception Economy: When Security Teams Stop Protecting and Start Negotiating

Press Releases

GoPlus's Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

GoPlus’s Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

Subscribe to our Newsletters

Most Read on the Boulevard

Databricks Acquires Cybersecurity Startup Panther Labs to Fortify AI Defense
SailPoint Acquires Entro to Continuously Detect and Monitor Non-Human Identities
Google Sues Chinese Threat Group Using Gemini AI in Phishing Scams
MSG Breach: Knicks Take the NBA Championship, ShinyHunters Takes the Data 
Malwarebytes Finds Ad Scams Hidden in 40+ World Cup Streaming Sites
CVSS Is Officially Dead: What CISA’s BOD 26-04 Means for Everyone
Claude Fable 5’s pricing makes Sonar Context Augmentation a potent cost lever
Claude Fable 5 and Mythos 5 “abruptly disabled” after US gov. ban
FortiBleed Leak Exposes VPN Credentials for Nearly 74,000 Fortinet Devices
5 Essential Best Practices for AI Data Security in the Post-Quantum Era

Industry Spotlight

NYC Sewers Crawling With Rats and Potential Bad Actors 
Cybersecurity Featured Industry Spotlight Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threats & Breaches 

NYC Sewers Crawling With Rats and Potential Bad Actors 

June 18, 2026 Teri Robinson | Yesterday 0
Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks
Cloud Security Cybersecurity Data Privacy Data Security Featured Incident Response Industry Spotlight Malware Mobile Security Network Security News Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threats & Breaches Vulnerabilities 

Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks

April 12, 2026 Jeffrey Burt | Apr 12 Comments Off on Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks
The Day the Security Music Died
AI and Machine Learning in Security Cybersecurity Featured Industry Spotlight Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

The Day the Security Music Died

April 8, 2026 Alan Shimel | Apr 08 Comments Off on The Day the Security Music Died

Top Stories

Job Seekers Make for Vulnerable Targets
Cybersecurity Data Privacy Data Security Featured News Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

Job Seekers Make for Vulnerable Targets

June 19, 2026 Teri Robinson | 15 hours ago 0
MSG Breach: Knicks Take the NBA Championship, ShinyHunters Takes the Data 
Cybersecurity Data Security Featured News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

MSG Breach: Knicks Take the NBA Championship, ShinyHunters Takes the Data 

June 18, 2026 Teri Robinson | Yesterday 0
Trying to Control AI is Like Holding Sand
AI and Machine Learning in Security Cybersecurity Featured News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

Trying to Control AI is Like Holding Sand

June 17, 2026 Alan Shimel | 2 days ago 0

Security Humor

Randall Munroe’s XKCD 'Horizontal Stabilizers'

Randall Munroe’s XKCD ‘Horizontal Stabilizers’

Download Free eBook

[su_panel border="0px solid #ddd" radius="0" text_align="center" padding-top="0px" padding-bottom="0px"]
The Dangers of Open Source Software and Best Practices for Securing Code
[/su_panel]

Security Boulevard Logo White

DMCA

Join the Community

  • Add your blog to Security Creators Network
  • Write for Security Boulevard
  • Bloggers Meetup and Awards
  • Ask a Question
  • Email: [email protected]

Useful Links

  • About
  • Media Kit
  • Sponsor Info
  • Copyright
  • TOS
  • DMCA Compliance Statement
  • Privacy Policy

Related Sites

  • Techstrong Group
  • Cloud Native Now
  • DevOps.com
  • Digital CxO
  • Techstrong Research
  • Techstrong TV
  • Techstrong.tv Podcast
  • DevOps Chat
  • DevOps Dozen
  • DevOps TV
Powered by Techstrong Group
Copyright © 2026 Techstrong Group Inc. All rights reserved.
×

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.