Everybody has cybersecurity tales involving members of the family. Here is a comparatively frequent one. The dialog often goes one thing like this:
“The strangest factor occurred to my streaming account. I bought locked out of my account, so I needed to change my password. Once I logged again in, all my reveals have been gone. All the pieces was in Spanish and there have been all these Spanish reveals I’ve by no means seen earlier than. Is not that bizarre?”
That is an instance of an account takeover assault on a buyer account. Usually what occurs is {that a} streaming account is compromised, in all probability because of a weak and reused password, and entry is resold as a part of a standard digital black market product, typically marketed as one thing like “LIFETIME STREAMING SERVICE ACCOUNT – $4 USD.”
Within the grand scheme of issues, this can be a comparatively delicate inconvenience for many prospects. You’ll be able to reset your credentials with a a lot stronger password, name your financial institution to difficulty a brand new bank card and be again to binge-watching The Crown in brief order.
However what occurs when comparable incidents happen hundreds of occasions every day internationally’s hottest internet purposes?
The Hidden Scale of Account Takeovers (ATO)
Flare’s current report, The Account and Session Takeover Financial system, reveals simply how widespread and dear this difficulty has grow to be. Industries like e-commerce, gaming, productiveness SaaS, and streaming are significantly hard-hit, every seeing over 100,000 newly uncovered accounts monthly.
The report discovered a median account takeover publicity charge of 1.4% amongst platforms starting from 5 million to 300 million customers. Of explicit concern is the rise in session hijacking—a method that permits attackers to bypass multi-factor authentication (MFA) by stealing session cookies, typically by way of infostealer malware.
Returning to the streaming instance, it is doubtless that the attacker did not even have to log in with a password. With an energetic session token in hand, they merely injected it right into a browser utilizing an anti-detect device and gained full entry—with out triggering alerts or MFA challenges.
A serious leisure or e-commerce platform with hundreds of thousands of customers—Netflix, Epic Video games, or Wayfair—can conservatively count on hundreds of buyer accounts to be weak to takeover at any given time.
![]() |
Common New Uncovered Accounts (Month-to-month) – Scaled View from Flare’s The Account and Session Takeover Financial system Report |
What is the Actual Price of an ATO
The financial toll of ATOs is tough to completely quantify, however Flare’s report breaks it down into three main classes: labor, fraud, and buyer churn.
Let’s revisit the streaming instance from earlier. Some customers could chalk the problem as much as dangerous luck and stick round for the subsequent season of Stranger Issues. Others, nevertheless, could cancel out of frustration—particularly once they’ve already needed to reset passwords, take care of bank card points, or just really feel their belief has been violated. A 2023 report from fraud prevention firm Sift discovered that 73% of customers imagine the model—not the consumer—is answerable for stopping ATOs.
We have used streaming for example on this article due to their cultural significance in world leisure, however we do not make any assumptions about their security posture, breach historical past, or enterprise practices.
To know the potential enterprise affect, think about a fictional leisure streaming service. If there are 100 million paying prospects at $120 per 12 months…
- If 0.5% of accounts are taken over—about one-third of the median publicity charge—that is 500,000 affected customers.
- If even 20% of these customers churn, the corporate stands to lose $12 million in annual income.
- In a worst-case situation the place 73% stroll away, the loss grows to $44 million.
That is all very tough “again of serviette” math nevertheless it gives a place to begin for quantifying the monetary dangers related to ATOs.
Keep in mind, that is only a churn danger. Fraud-related losses are a separate dialogue totally! Now extrapolate this problem throughout the a whole bunch of internet purposes that service hundreds of thousands of every day customers.
![]() |
Price of ATOs & Fraud Mechanism Per Business |
Suggestions for ATO Prevention
1. Monitor the Infostealer Ecosystem
Whereas ransomware grabs headlines, infostealer malware is fueling the vast majority of credential-based assaults. Flare’s information reveals a 26% year-over-year improve in exposures involving stolen credentials and session cookies.
In line with Verizon’s 2025 Data Breach Investigations Report (DBIR), 88% of fundamental internet app assaults contain stolen credentials, demonstrating how central infostealers are to fashionable account takeover operations.
2. Detect and Remediate Uncovered Accounts
Organizations can dramatically cut back ATO danger by combining real-time infostealer intelligence with their id and entry administration techniques. This permits the detection and remediation of accounts which were compromised—particularly these with legitimate session cookies, which permit attackers to bypass authentication totally.
Proactive monitoring and auto-remediation can forestall account abuse earlier than it impacts buyer expertise or bottom-line metrics.
3. Talk a Safety-First Strategy
Introducing friction—like pressured password resets—can really feel dangerous for buyer expertise. However most customers count on firms to not solely defend their information but in addition talk any points.
Additionally from Sift’s report- solely 43% of ATO victims have been notified by their firm that their account had been compromised. Prospects who expertise this fraud however aren’t notified could really feel like the corporate just isn’t conscious of account takeovers or have steps to assist them out.
By clearly speaking the aim behind these measures, organizations can reframe proactive security as a value-added characteristic. Transparency round ATO dangers helps prospects really feel safer—and extra loyal—over time.
In regards to the Creator: Nick Ascoli is the Director of Product Technique at Flare and an skilled risk researcher who’s acknowledged for his experience in information leaks, reconnaissance, and detection engineering. Nick is an energetic member of the cybersecurity neighborhood contributing to open-source tasks, usually showing on podcasts (Cyberwire, Merely Cyber, and many others.) and talking at conferences (GrrCON, B-Sides, DEFCON Villages, SANS, and many others.)