Corporate account takeover is the compromise of an employee’s business account (email, identity provider, payroll, banking, or an internal system) used to move money or reach data on behalf of the organization. Consumer account takeover drains one person’s account. Corporate account takeover borrows an employee’s authority and spends the company’s money with it.

The difference is inherited permission rather than size. A consumer ATO victim’s bank sees an unusual transaction. A corporate ATO victim’s finance team sees a routine request from a colleague who is allowed to make it.

The numbers

The FBI’s Internet Crime Complaint Center recorded $20.877 billion in reported losses across 1,008,597 complaints in 2025, up 26% year over year (FBI IC3, 2025 Annual Report, p6).

Two categories inside that total describe corporate account takeover directly.

Category Complaints Losses Average
Business email compromise 24,768 $3,046,598,558 ~$123,000
Account takeover ~4,700 $359.7M ~$76,500

(FBI IC3, 2025 Annual Report, pp7–12)

86% of BEC losses moved by wire or ACH (FBI IC3, 2025). That mechanism is why corporate ATO is a finance problem as much as a security one. The money leaves through a payment process, approved by a person who believed the request was legitimate.

Compare the averages to consumer fraud and the asymmetry is obvious. A single successful business email compromise averages more than $123,000. The attacker needs one.

Consumer and corporate ATO, side by side

Consumer ATO Corporate ATO
Target An individual’s own account and funds An employee’s access and authority
Typical entry Credential stuffing, phishing, reused passwords A phone call to the IT help desk requesting a reset
Who absorbs the loss The individual, often with bank protections The organization, usually with none
What the attacker does next Drains or resells the account Requests a payment, changes bank details, or escalates privilege
Why detection is hard Unusual activity for that user Entirely usual activity for that user
Average reported loss Hundreds to low thousands ~$123,000 per BEC incident (FBI IC3, 2025)

The detection row carries the rest. Consumer fraud controls are built on the premise that the fraudulent action looks different from the legitimate one. In corporate ATO the fraudulent action is the legitimate one, performed by the account that is supposed to perform it.

How the corporate path actually runs

Consumer ATO usually starts with credentials: a reused password, a phishing kit, a stuffing run against a login page. Corporate ATO increasingly starts with a phone call, because the phone call is faster and it defeats the controls the credentials route runs into.

The sequence is consistent enough to describe as a standard play.

Reconnaissance is free. LinkedIn gives an attacker the org chart, reporting lines, job titles, and who joined recently. A new hire is a preferred target because nobody yet knows how they sound or what they normally ask for. Breach corpora supply the personal details that used to serve as verification answers.

The entry point is the help desk, not the login page. The attacker calls IT as an employee who cannot get in. Phone stolen, travelling, locked out, urgent. The ask is a password reset or an MFA rebind. This is the step attackers optimized, and it works because the help desk sits where high privilege meets high pressure. It can reset credentials and rebind MFA, and it is measured on speed and first-call resolution.

CISA documents help desk social engineering as core tradecraft for Scattered Spider (CISA, advisory AA23-320A). Mandiant found voice phishing involved in 23% of cloud intrusions, ranking first in that category, and 11% of intrusions overall (Mandiant, M-Trends 2026). Google Threat Intelligence tracked UNC6671 targeting financial services using spoofed help desk phone numbers, with $10.69 million in ransoms traced (Google Threat Intelligence, August 2026).

Voice is no longer evidence. McAfee researchers produced a clone with an 85% voice match from three seconds of audio in one test (McAfee Labs, 2023). An agent listening for whether someone sounds like the person on the account is evaluating something the attacker now controls. In the 2024 Arup case the deception ran on video: a finance employee joined a call where the CFO and every other participant was synthetic, and approved roughly $25 million across 15 transfers (CNN / FT, May 2024).

Then the account is used as intended. This is what separates corporate ATO from most intrusions. There is no exploit chain and often no malware. The attacker signs in legitimately and makes requests they now have permission to make.

Three destinations account for most of the loss:

Payroll redirect. A request to HR to update direct deposit details, sent from the employee’s real account. Individually small, easy to repeat across many employees, and frequently undetected until payday.

Vendor and wire fraud. A request to finance to update a supplier’s bank details, or to release a payment. It arrives inside a real thread from a real colleague, which is why 86% of BEC losses move by wire or ACH. Trusona’s finance materials describe a $1.2 million wire released in 31 seconds. The window for catching one of these is short.

Privileged access and ransomware staging. Where the compromised account belongs to IT or holds administrative rights, account takeover becomes the beachhead. MGM Resorts reported roughly $100 million in impact for the quarter following its 2023 intrusion (MGM Resorts, Form 8-K, October 2023). Caesars reported a payment of approximately $15 million (Caesars Entertainment, Form 8-K, September 2023). Marks & Spencer put its 2025 incident at around £300 million in operating profit, with roughly £100 million insured (M&S trading statements, 2025). Transport for London’s incident cost about £29 million, and two people were sentenced to five and a half years at Woolwich Crown Court in July 2026 (CPS).

Why the usual controls do not stop it

Each standard control assumes a threat model that corporate ATO steps around.

Multi-factor authentication verifies the factor. The attacker never touches it, and instead asks the help desk to reissue it. MFA that can be reset by a phone call is protected by that phone call.

Anomaly detection looks for behaviour that does not fit. A payroll change submitted by the employee whose payroll it is, from a session established through a legitimate reset, fits.

Email security filters inbound messages from outside. The message came from inside, from a real mailbox, in an existing thread.

Security awareness training tells staff to be suspicious of unusual requests. The request is not unusual. Updating bank details and resetting passwords are ordinary work, and a policy that asks a help desk agent to distrust callers collides with a service level agreement that measures how fast they say yes.

Knowledge-based questions ask for information that sits in a breach corpus or on a public profile. The weakness is in the method rather than in the agent asking: those answers stopped being secret a long time ago.

Each of these controls does its own job well. They are aimed at a different attack, and they share one gap: nobody establishes who is actually making the request.

Where to break the chain

Corporate ATO has two chokepoints, and both are moments when a person is asked to take an identity claim on trust.

The reset. Before a password is changed, MFA is rebound, or account recovery completes.

The money movement. Before bank details change, a payment is released, or a beneficiary is updated.

At both points the useful control is the same: verify the human, not the credential, at the moment of the request.

That means checking against something outside the attacker’s control: a record held by an authority outside your organization, rather than a voice, a document photo, or a fact that has been breached. In the United States, verifying a government-issued ID against the issuing state’s DMV records over the AAMVA network answers whether the record exists and matches. A forged document has no record behind it, so how good the forgery is stops being relevant.

Two signals ride along and both are useful in exactly these conversations. SIM swap and port-out detection flags a phone number that changed hands recently, which is the tell on a takeover in progress. Man-in-the-middle and anti-replay detection confirms the session is live and direct rather than relayed, which is how injection attacks are caught (Trusona’s implementation is patented, US Pat. 10,601,859).

A practical checklist for the two chokepoints:

  • Require identity verification before any MFA rebind or account recovery, with no exception path a caller can talk an agent into.
  • Require it again before bank detail changes, beneficiary updates, and wire release above a threshold your treasury team sets.
  • Make the verification work for people who never enrolled anything, since “I can’t use my MFA” is the pretext.
  • Do not let urgency function as an override, since urgency is how the attack gets through.
  • Measure the override rate. If agents bypass verification 8% of the time, your control covers 92% of requests and attackers will find the 8%.
  • Give agents a result they can act on rather than a judgment call. A red, yellow, or green summary removes the burden of being an expert on deepfakes.

The last point carries the most weight. Most help desk agents are early-career, measured on handle time, and are being asked to detect synthetic media that specialists struggle with. The control has to give them something to read rather than something to judge.

Corporate account takeover ends in a payment or a privilege, and it begins with somebody being believed on a phone call. ATO Protect verifies the person making the request against the authority that issued their ID, in real time, with no pre-registration and no app to install, so a cloned voice and a convincing story stop being enough. See ATO Protect use cases, ATO Protect for Finance, or ATO Protect for HR for the payroll redirect path.

Frequently asked questions

What is corporate account takeover? Corporate account takeover is the compromise of an employee’s business account (email, identity provider, payroll, banking, or an internal system) which the attacker then uses to move money or reach data with that employee’s permissions. Unlike consumer ATO, the attacker inherits organizational authority rather than access to one person’s funds.

How is corporate account takeover different from consumer account takeover? Consumer ATO targets an individual’s own accounts and money. Corporate ATO targets an employee’s access so the attacker can act on behalf of the business, most often through payroll redirects, vendor bank changes, wire release, or privileged system access. Average losses are far higher, and the fraudulent requests look like routine work.

How much does corporate account takeover cost? The FBI’s IC3 recorded $20.877 billion in total reported losses across 1,008,597 complaints in 2025. Business email compromise accounted for 24,768 complaints and $3.05 billion, averaging roughly $123,000 per incident, with 86% of losses moving by wire or ACH. Account takeover specifically drew about 4,700 complaints and $359.7 million.

How do attackers get in? Increasingly by calling the IT help desk and requesting a password reset or MFA rebind as a locked-out employee, rather than by attacking credentials directly. CISA documents this as core Scattered Spider tradecraft, and Mandiant found voice phishing in 23% of cloud intrusions.

Why does MFA not prevent it? MFA verifies a credential. These attacks leave the credential alone and have it reissued to the attacker through the help desk. Any MFA that can be reset by a phone call is only as strong as the verification performed on that call.

How do you prevent corporate account takeover? Verify identity at the two chokepoints: before any credential reset or account recovery, and before any change that moves money. Verification should check the person against an authoritative external source rather than against a voice, a document photo, or knowledge that may already be breached.

Every corporate account takeover passes through a moment where someone decides a person is who they say they are. Verifying at that moment is what closes it.

See how ATO Protect verifies the employee behind the request.