Insight
|
Share
How Banks Can Reduce Account Takeover Risk After Login

HOW BANKS CAN REDUCE ACCOUNT TAKEOVER RISK AFTER LOGIN
Account takeover is usually framed as a login problem.
A criminal obtains a password, intercepts a one-time code or persuades a customer to approve an authentication request. The immediate security objective is therefore to stop the unauthorised person from entering the account.
Strong authentication remains essential. But account takeover does not necessarily end when a login succeeds.
Once access has been granted, the session may provide everything an attacker needs to change customer details, add a beneficiary, reset credentials, access sensitive information or initiate a payment.
The login may be valid. The session may remain active. But the bank may no longer know who is in control.
THE IDENTITY GAP AFTER LOGIN
Digital banking systems are very good at assessing the point of entry.
KYC establishes the customer’s identity during onboarding. Passwords, possession factors, one-time codes and device biometrics help determine whether access should be granted. Device intelligence, behavioural analysis and transaction monitoring contribute additional risk signals.
These controls answer important questions:
Are the credentials correct?
Is the device recognised?
Does the connection appear suspicious?
Does the customer’s behaviour differ from an established pattern?
Is the transaction unusual?
But another question remains:
Is the enrolled customer still present and in control when a sensitive action takes place?
An authenticated session can continue even after the person using it changes. The customer may step away from an unlocked device. Another person may be handed the device. A session may be hijacked or controlled remotely. Valid access can also be converted into persistent control by changing contact details, credentials, or trusted devices.
The point of compromise and the point of financial loss may therefore occur at different moments.
HOW AN ACCOUNT TAKEOVER DEVELOPS INSIDE THE SESSION
A fraudster does not always attempt a high-value payment immediately after gaining access.
They may first take a series of lower-profile actions:
Change the registered email address or telephone number
This may allow alerts, recovery messages or security codes to be intercepted and can delay the genuine customer becoming aware of the intrusion.
Add a new beneficiary
Creating a payee can prepare the account for a later transfer. By the time the payment is initiated, an important part of the takeover has already occurred.
Reset credentials
Changing a password or PIN can turn temporary access into persistent account control.
Enrol another device
Registering an additional trusted device can give the attacker a separate route into the account.
Access sensitive information
Statements, personal details and transaction histories can support further fraud, impersonation or social engineering.
Initiate or approve a payment
This is often the final monetisation step, but it may be the last event in a sequence of changes rather than the first sign of compromise.
If stronger identity assurance is applied only when the payment is released, the bank may miss earlier opportunities to interrupt the takeover.
WHY EXISTING CONTROLS STILL MATTER
Continuous identity assurance should not be positioned as a replacement for the existing banking security stack.
Each control contributes something different.
Device and network intelligence can identify suspicious infrastructure, device reputation and known patterns of misuse.
Behavioural biometrics can detect unusual navigation, typing, touch or cursor behaviour and may identify indicators of automation or manipulation.
Transaction monitoring can identify payments and account activity that fall outside expected patterns.
These systems are essential. However, they do not necessarily establish the physical identity of the person present throughout the session.
This is where continuous identity assurance can add another layer.
The FFIEC’s guidance for financial institutions supports a risk-based, layered approach to authentication and access. It highlights enhanced controls for higher-risk activities, alongside monitoring, logging and periodic assessment of control effectiveness.
The principle is important: security should respond to the level and context of risk rather than rely on one authentication event or one control.
WHAT CONTINUOUS IDENTITY ASSURANCE ADDS
YEO’s Continuous Facial Recognition SDK enables an organisation to check whether the person present continues to match the enrolled customer during selected parts of a digital session.
Facial matching, liveness detection and supported depth signals are processed on the user’s device. The bank can configure when the identity signal is required and how its systems respond to the result, without creating a central YEO biometric database.
Depending on the bank’s policy, a mismatch, absence or failed-liveness event could result in:
an additional authentication request;
a temporary hold on the action;
a change in the session’s risk score;
referral to fraud operations; or
termination of the session.
The objective is not to challenge every customer continuously. It is to give the bank additional confidence at the points where identity matters most.
APPLYING ASSURANCE TO HIGH-RISK ACTIONS
A risk-based implementation could introduce continuous identity assurance around actions such as:
adding or changing a beneficiary;
updating contact or security details;
resetting a password or PIN;
enrolling a new device;
beginning an account-recovery process;
accessing particularly sensitive information; or
authorising a high-value or unusual payment.
The appropriate trigger will differ between institutions, customer groups and journeys.
A bank may decide to use CFR continuously within one sensitive journey, at defined checkpoints, or as a step-up response when device, behavioural or transaction controls identify elevated risk.
In this model, CFR consumes the risk signals the bank already generates rather than competing with the systems that produce them.
CREATING BETTER EVIDENCE
Reducing account takeover risk is not only about preventing an action. Banks also need sufficient evidence to investigate what happened.
A login record can show that the correct credentials or authentication factors were accepted. It may not establish who was present several minutes later when an account change or transaction occurred.
A session-level identity event can add context to the bank’s existing device, behavioural, transaction and audit records. This may support:
fraud investigation;
customer-dispute review;
security governance;
control-effectiveness assessment; and
the reconstruction of events following suspicious activity.
Continuous identity assurance should not be treated as absolute proof or used in isolation. It provides an additional signal that can strengthen the wider evidential picture.
WHAT CONTINUOUS IDENTITY ASSURANCE CANNOT DO
CFR addresses identity and presence. It is not a complete fraud-prevention system.
It does not replace controls designed to detect:
money-mule networks;
automated bot activity;
compromised-device infrastructure;
unusual transaction patterns across accounts; or
social engineering where the genuine customer remains present and voluntarily performs the action.
For example, confirming that the enrolled customer is present does not establish whether that customer is being coached or deceived.
Behavioural analysis, transaction monitoring, device intelligence, customer education and fraud operations remain essential. The value of CFR is that it adds identity evidence those controls may not directly provide.
START WITH ONE JOURNEY
Banks do not need to begin with a full-scale deployment.
A focused pilot can select one high-risk, high-volume journey and establish a measurable baseline for:
post-login fraud events;
authentication challenges;
false positives;
customer abandonment;
challenge-related support demand; and
fraud-investigation outcomes.
The CFR-enabled journey can then be compared with the current process to determine whether the additional identity signal reduces residual risk without introducing unacceptable friction.
The relevant commercial question is not whether CFR can take credit for the bank’s entire fraud exposure.
It is whether continuous identity assurance can address a defined identity gap after the existing fraud stack has done its job.
BEYOND THE FRONT DOOR
Login authentication answers an essential question: should this person be granted access?
It does not always answer what happens next.
As digital banking journeys become faster and more interconnected, banks need to consider how confidence in identity is maintained between entry and the sensitive actions that follow.
Account takeover does not end at login.
Neither should identity assurance.
To explore how YEO’s CFR SDK could support a defined digital-banking journey, visit https://www.yeomessaging.com/sdk or speak to the YEO team about a session-assurance review.
REFERENCES
Federal Financial Institutions Examination Council, Authentication and Access to Financial Institution Services and Systems:
https://www.ffiec.gov/sites/default/files/media/press-releases/2021/authentication-and-access-to-financial-institution-services-and-systems.pdf
National Institute of Standards and Technology, Digital Identity Guidelines: Authentication and Authenticator Management:
https://pages.nist.gov/800-63-4/sp800-63b.html
HOW BANKS CAN REDUCE ACCOUNT TAKEOVER RISK AFTER LOGIN
Account takeover is usually framed as a login problem.
A criminal obtains a password, intercepts a one-time code or persuades a customer to approve an authentication request. The immediate security objective is therefore to stop the unauthorised person from entering the account.
Strong authentication remains essential. But account takeover does not necessarily end when a login succeeds.
Once access has been granted, the session may provide everything an attacker needs to change customer details, add a beneficiary, reset credentials, access sensitive information or initiate a payment.
The login may be valid. The session may remain active. But the bank may no longer know who is in control.
THE IDENTITY GAP AFTER LOGIN
Digital banking systems are very good at assessing the point of entry.
KYC establishes the customer’s identity during onboarding. Passwords, possession factors, one-time codes and device biometrics help determine whether access should be granted. Device intelligence, behavioural analysis and transaction monitoring contribute additional risk signals.
These controls answer important questions:
Are the credentials correct?
Is the device recognised?
Does the connection appear suspicious?
Does the customer’s behaviour differ from an established pattern?
Is the transaction unusual?
But another question remains:
Is the enrolled customer still present and in control when a sensitive action takes place?
An authenticated session can continue even after the person using it changes. The customer may step away from an unlocked device. Another person may be handed the device. A session may be hijacked or controlled remotely. Valid access can also be converted into persistent control by changing contact details, credentials, or trusted devices.
The point of compromise and the point of financial loss may therefore occur at different moments.
HOW AN ACCOUNT TAKEOVER DEVELOPS INSIDE THE SESSION
A fraudster does not always attempt a high-value payment immediately after gaining access.
They may first take a series of lower-profile actions:
Change the registered email address or telephone number
This may allow alerts, recovery messages or security codes to be intercepted and can delay the genuine customer becoming aware of the intrusion.
Add a new beneficiary
Creating a payee can prepare the account for a later transfer. By the time the payment is initiated, an important part of the takeover has already occurred.
Reset credentials
Changing a password or PIN can turn temporary access into persistent account control.
Enrol another device
Registering an additional trusted device can give the attacker a separate route into the account.
Access sensitive information
Statements, personal details and transaction histories can support further fraud, impersonation or social engineering.
Initiate or approve a payment
This is often the final monetisation step, but it may be the last event in a sequence of changes rather than the first sign of compromise.
If stronger identity assurance is applied only when the payment is released, the bank may miss earlier opportunities to interrupt the takeover.
WHY EXISTING CONTROLS STILL MATTER
Continuous identity assurance should not be positioned as a replacement for the existing banking security stack.
Each control contributes something different.
Device and network intelligence can identify suspicious infrastructure, device reputation and known patterns of misuse.
Behavioural biometrics can detect unusual navigation, typing, touch or cursor behaviour and may identify indicators of automation or manipulation.
Transaction monitoring can identify payments and account activity that fall outside expected patterns.
These systems are essential. However, they do not necessarily establish the physical identity of the person present throughout the session.
This is where continuous identity assurance can add another layer.
The FFIEC’s guidance for financial institutions supports a risk-based, layered approach to authentication and access. It highlights enhanced controls for higher-risk activities, alongside monitoring, logging and periodic assessment of control effectiveness.
The principle is important: security should respond to the level and context of risk rather than rely on one authentication event or one control.
WHAT CONTINUOUS IDENTITY ASSURANCE ADDS
YEO’s Continuous Facial Recognition SDK enables an organisation to check whether the person present continues to match the enrolled customer during selected parts of a digital session.
Facial matching, liveness detection and supported depth signals are processed on the user’s device. The bank can configure when the identity signal is required and how its systems respond to the result, without creating a central YEO biometric database.
Depending on the bank’s policy, a mismatch, absence or failed-liveness event could result in:
an additional authentication request;
a temporary hold on the action;
a change in the session’s risk score;
referral to fraud operations; or
termination of the session.
The objective is not to challenge every customer continuously. It is to give the bank additional confidence at the points where identity matters most.
APPLYING ASSURANCE TO HIGH-RISK ACTIONS
A risk-based implementation could introduce continuous identity assurance around actions such as:
adding or changing a beneficiary;
updating contact or security details;
resetting a password or PIN;
enrolling a new device;
beginning an account-recovery process;
accessing particularly sensitive information; or
authorising a high-value or unusual payment.
The appropriate trigger will differ between institutions, customer groups and journeys.
A bank may decide to use CFR continuously within one sensitive journey, at defined checkpoints, or as a step-up response when device, behavioural or transaction controls identify elevated risk.
In this model, CFR consumes the risk signals the bank already generates rather than competing with the systems that produce them.
CREATING BETTER EVIDENCE
Reducing account takeover risk is not only about preventing an action. Banks also need sufficient evidence to investigate what happened.
A login record can show that the correct credentials or authentication factors were accepted. It may not establish who was present several minutes later when an account change or transaction occurred.
A session-level identity event can add context to the bank’s existing device, behavioural, transaction and audit records. This may support:
fraud investigation;
customer-dispute review;
security governance;
control-effectiveness assessment; and
the reconstruction of events following suspicious activity.
Continuous identity assurance should not be treated as absolute proof or used in isolation. It provides an additional signal that can strengthen the wider evidential picture.
WHAT CONTINUOUS IDENTITY ASSURANCE CANNOT DO
CFR addresses identity and presence. It is not a complete fraud-prevention system.
It does not replace controls designed to detect:
money-mule networks;
automated bot activity;
compromised-device infrastructure;
unusual transaction patterns across accounts; or
social engineering where the genuine customer remains present and voluntarily performs the action.
For example, confirming that the enrolled customer is present does not establish whether that customer is being coached or deceived.
Behavioural analysis, transaction monitoring, device intelligence, customer education and fraud operations remain essential. The value of CFR is that it adds identity evidence those controls may not directly provide.
START WITH ONE JOURNEY
Banks do not need to begin with a full-scale deployment.
A focused pilot can select one high-risk, high-volume journey and establish a measurable baseline for:
post-login fraud events;
authentication challenges;
false positives;
customer abandonment;
challenge-related support demand; and
fraud-investigation outcomes.
The CFR-enabled journey can then be compared with the current process to determine whether the additional identity signal reduces residual risk without introducing unacceptable friction.
The relevant commercial question is not whether CFR can take credit for the bank’s entire fraud exposure.
It is whether continuous identity assurance can address a defined identity gap after the existing fraud stack has done its job.
BEYOND THE FRONT DOOR
Login authentication answers an essential question: should this person be granted access?
It does not always answer what happens next.
As digital banking journeys become faster and more interconnected, banks need to consider how confidence in identity is maintained between entry and the sensitive actions that follow.
Account takeover does not end at login.
Neither should identity assurance.
To explore how YEO’s CFR SDK could support a defined digital-banking journey, visit https://www.yeomessaging.com/sdk or speak to the YEO team about a session-assurance review.
REFERENCES
Federal Financial Institutions Examination Council, Authentication and Access to Financial Institution Services and Systems:
https://www.ffiec.gov/sites/default/files/media/press-releases/2021/authentication-and-access-to-financial-institution-services-and-systems.pdf
National Institute of Standards and Technology, Digital Identity Guidelines: Authentication and Authenticator Management:
https://pages.nist.gov/800-63-4/sp800-63b.html
Get the
Document

Share

About us
We stopped asking "who logged in." We started asking "who's still there." YEO began as a secure messaging app. Today we build the patented continuous identity verification infrastructure that regulated industries trust to prove who's really there.
© 2026 YEO messaging Ltd is registered in England and Wales 10785061.
🇺🇸 US Patent No: 10,607,035 (Granted March 31, 2020)
🇬🇧 GB patent No: 1713943.7 (Granted February 2022)
🇨🇳 Chinese patent 201880071020.4 (Granted April 2nd 2024)
🇪🇺 EU patent No: PCT/EP2018/073464 (Granted July 2026)
© 2026 YEO messaging Ltd is registered in England and Wales 10785061.
🇺🇸 US Patent No: 10,607,035 (Granted March 31, 2020)
🇬🇧 GB patent No: 1713943.7 (Granted February 2022)
🇨🇳 Chinese patent 201880071020.4 (Granted April 2nd 2024)
🇪🇺 EU patent No: PCT/EP2018/073464 (Granted July 2026)
© 2026 YEO messaging Ltd is registered in England and Wales 10785061.
🇺🇸 US Patent No: 10,607,035 (Granted March 31, 2020)
🇬🇧 GB patent No: 1713943.7 (Granted February 2022)
🇨🇳 Chinese patent 201880071020.4 (Granted April 2nd 2024)
🇪🇺 EU patent No: PCT/EP2018/073464 (Granted July 2026)

