BlogIdentity Fraud

How Account Takeover Develops Inside a Trusted Customer Account

An established customer, valid credentials and a clean history. Over ten days, a series of routine-looking changes reshaped the identity behind the account.

Illustrative portrait for the Daniel Harper scenarioIllustrative scenario
Daniel HarperActive customer
Age
34
Location
New York, NY
Customer since
6 months ago
Payment history
Six months on time
Prior fraud indicators
None
Risk level · system viewLow riskPassed onboarding without issue and built a clean history over time.

Account takeover (ATO) rarely announces itself. Take Daniel Harper, an illustrative example: an established customer with six months of on-time payments, valid credentials and no prior indicators of fraud.

To traditional fraud systems, Daniel appears low risk. Over the next ten days, a series of seemingly routine actions gradually reshapes the identity behind his account. No single event looks fraudulent enough to trigger intervention. Together, they describe identity drift – and a possible account takeover in progress.

What traditional controls see

  • Valid credentials
  • An established history
  • No obvious high-risk activity

A 10-day account takeover timeline

Each step on its own has an ordinary explanation. The system view at each point shows why none of them raised an alert.

  1. Day 0Normal activity
    • Routine logins
    • No anomalies
    • Consistent behavior
    System viewAcceptable variance
  2. Day 2New login
    • New device (Windows, Chrome)
    • Slight location drift, not flagged
    System viewAcceptable variance
  3. Day 3Profile changes
    • Email changed
    • Phone number updated
    • Device updated
    System viewUser-initiated update
  4. Day 5Security reset
    • Password reset
    • MFA settings changed
    System viewRoutine account maintenance
  5. Day 10High-risk action
    • New credit request submitted
    • Funds scheduled for disbursement
    System viewTrusted returning customer
No single event appeared fraudulent enough to trigger intervention.

Four signals of identity drift

Traditional systems confirm the account. Heka assesses whether the identity behind it remains consistent – by cross-validating breach, contact and behavioral evidence from independent sources rather than checking each change in isolation.

Breach exposure
The original email appeared in recent breach data and dark web sources, indicating potential credential compromise.
Compromised credentials are frequently used in account takeover attacks.
Email analysis
The new email address shows little to no real-world footprint and no historical association with Daniel.
New, unestablished emails are commonly used by fraudsters to take control of accounts.
Phone analysis
The new phone number has no historical linkage to Daniel and is not associated with his known devices.
A phone number change with no history behind it can indicate identity manipulation.
Behavioral analysis
Account activity deviates from the established profile and patterns, and ATO and manipulation indicators accumulate over time.
Behavioral deviations can expose risk that credential checks alone miss.

One account, two views

The same ten days look very different depending on whether you check the account or the identity behind it.

What conventional controls saw

  • Valid credentials and an established history
  • Each change treated as a routine, user-initiated update
  • A trusted returning customer requesting credit

Credit request proceeds and funds are scheduled for disbursement.

What the combined identity evidence revealed

  • The original email exposed in breach data
  • A new email and phone with no history linked to Daniel
  • Behavior drifting away from the established profile

Identity drift is flagged for the fraud team’s review before funds move.

Account takeover develops inside trusted accounts

The account still looked safe. The person behind it may no longer have been Daniel. Account takeover often develops this way: gradually, inside a trusted account, through changes that each pass on their own.

Checking whether the identity behind an account stays consistent across breach exposure, contact data and behavior gives fraud teams a way to see that drift while there is still time to act. The decision stays with the institution’s own controls and reviewers.

Explore: Identity Fraud Detection · How a global payments platform reduced account-takeover reviews by 90%

Book a Demo