How Companies Prevent Account Takeover Fraud


MGM, Caesars, Twilio and Coinbase all run substantial security programs, and all four were compromised through the same moment: somebody called support, said they were locked out, and asked to get back in.
In a recent webinar on closing account recovery gaps, we pointed to a very real pattern: "Over the last twenty-four months, some of the biggest support compromises happened at organizations like MGM, Caesars, Twilio, Coinbase, and they happened through this exact point in time, this exact moment of someone saying, I need to get authenticated back, and I'm locked out."
Javelin's 2026 Identity Fraud Study put account takeover losses above $15 billion in 2025 across 6 million victims, up 18% year over year.
Most organizations have already spent heavily here, and the losses keep climbing anyway, which suggests the money is going out somewhere other than the login screen. Enterprises don't have an account recovery problem. In reality, they have an identity problem, and account recovery just so happens to be where it most often surfaces.
Key takeaways
- Account takeover cost $15 billion in 2025 and reached 6 million people, making it the costliest fraud type tracked.
- Every MFA rollout needs a recovery path, and that path is the weakest control in most stacks.
- Knowledge-based authentication works as a proxy for identity, and the answers sit on the dark web or a public profile.
- Proof and Liminal's research found organizations with mature fraud tooling still losing money at the authorization step.
- Matching a fresh biometric against a sealed credential removes the judgment call attackers exploit.
The recovery path is the weak point
Every MFA deployment needs an answer for someone who lost their factor, and that answer is weak because it exists to work when the primary factors do not.
CISA advisory AA23-320A documents the method: impersonate an employee, call the help desk, request a credential reset or MFA transfer. CISA updated it in July 2025 because it kept working, and in a single sign-on environment one call yields the account.
Proof and Liminal's joint research, the Trust Ledger, found organizations with mature fraud tooling still losing money at the authorization step, because their controls verify accounts rather than the person acting.
What the agent on the call is being asked to decide
Authentication confirms that whoever is asking holds the right factor, whether that is the password, the device or the one-time code. As we’ve argued, holding the factor establishes nothing about who is holding it. Passwords are sold in bulk on the dark web, backup emails are frequently breached, and knowledge-based answers can be assembled from social media at no cost.
KBA questions, security questions, and SMS verification are not identity. They’re proxies for it.
Recovery by judgment, and the alternative
In the current flow for most organizations, the employee fails self-service, escalates to the help desk, answers knowledge-based questions, and the agent makes a trust decision. Every step in that sequence that depends on human judgment is a step where social engineering works.
In the alternative, the employee completes a fresh biometric capture matched against a credential established earlier in the employee lifecycle, combining a live selfie and verified identity evidence into one tamper-evident artifact.
The agent receives a yes or a no, never sees the personal information, and no longer carries a decision they were never equipped to make. Proof's verification is certified at NIST IAL2 by the Kantara Initiative, and behind that yes or no the platform evaluates over 400 fraud risk signals in real time.
Plan the failure path before you need it
Verification fails for ordinary reasons, including bad lighting and a barcode that will not scan, and in most organizations that escalates to a senior technician running knowledge-based questions over video. Proof escalates instead to a trusted referee, which Eric Nelson, a senior solutions consultant at Proof, described while running the live demo as "a trained specialist from our agent network," background checked and trained on identity documents and forensics. The referee can prompt a retry, or accept an alternative document such as a utility bill. "At no point in your flow does IT have to really make a judgment call on a person's identity.”
What gets written down matters as much as the decision itself. Ask what a password reset from eight months ago looks like in your files today, and the answer is usually a ticket note saying the caller was verified. A recorded verification gives an auditor a timestamped account of who was on the call, what they presented, and which steps failed.
Recovery is either the weakest point in your security program or one of the strongest, and your MFA rollout has very little bearing on which.
See how Proof closes the recovery path attackers actually use >

















































.jpg)





























































.jpg)



















