Account Security

Account Takeover in Ecommerce: How to Recognize a Hijacked Account

Account takeover losses hit $17B and 61% of attacks target ecommerce. Here's how ATO works, why it's growing, and the signals that reveal a hijacked account.

Cover image for Account Takeover in Ecommerce: How to Recognize a Hijacked Account

An account takeover is one of the hardest kinds of fraud to catch, because nothing about the account is fake. The email is real, the payment method is real, the order history is real. Someone else is just driving.

It’s also one of the fastest-growing. Account takeover losses are estimated to have risen from $13 billion in 2024 to $17 billion in 2025, and around 61% of ATO attacks target ecommerce. Credential-stuffing traffic against login pages grew 148% year over year through late 2025, and TransUnion measured a 37% year-over-year rise in suspected account takeover in early 2026.

How accounts get taken over

Most takeovers don’t start with your platform at all. Attackers buy lists of email-and-password pairs leaked from other breaches and replay them against your login page, betting that people reuse passwords. That’s credential stuffing, and it’s mostly automated. The rest come from phishing (tricking the user into handing over a password or one-time code) and from SIM swaps that intercept those codes.

Once they’re in, the playbook is fast: change the contact details so the real owner stops getting alerts, drain stored value or loyalty points, place orders to a new address, or use the trusted account to run scams on other users.

The signals that reveal a hijacked account

Because the credentials are valid, you catch ATO by watching for behavior that doesn’t fit the person.

  • Login from a new device, location, or country, especially right before a sensitive change.
  • A contact-detail change followed quickly by a purchase or payout. Email, phone, or shipping address updated, then money moves.
  • A sudden shift in behavior. A quiet account that logs in at an odd hour and immediately checks out, or starts messaging other users.
  • Velocity that no human matches. Many login attempts in seconds is credential stuffing, not a forgetful customer.
  • New shipping address that doesn’t match years of history.
  • Loyalty or stored balance cashed out soon after a login from somewhere new.

The pattern to internalize: a takeover almost always shows a break between the account’s past and its present. The identity is consistent; the behavior is not.

Why a password reset isn’t enough

By the time you force a reset, the damage may be done and the attacker may already control the recovery channel. Catching ATO early means watching the login and the first few actions after it, not waiting for a customer to report that their points are gone. The accounts worth protecting hardest are the ones with stored value, saved payment methods, or trust that can be turned against other users.

Takeovers often pair with two other patterns: the phishing that steals the credentials, and the impersonation the hijacked account then runs against other people.

Sources

← Back to all posts