Account Takeover and Social Engineering Fraud Explained
Not all payment fraud starts with stolen card numbers. In account takeover and social engineering attacks, the fraudster targets people — customers, staff or account holders — and tricks or hacks their way into legitimate accounts, then uses those accounts to move money or make payments that look entirely genuine to the payment system.
These attacks are dangerous precisely because they pass technical checks: the payment comes from the real account, on the real device profile, sometimes even authenticated by the real (deceived) account holder. Preventing them requires securing accounts and educating people, not just screening transactions.
What is account takeover?
Account takeover (ATO) is when a fraudster gains control of someone else's account — internet banking, an e-commerce profile with saved cards, a merchant dashboard or an email account — and uses it for fraud. Common entry routes include:
- Credential stuffing — trying username and password combinations leaked from other breaches, which works whenever people reuse passwords.
- Phishing — fake login pages that harvest credentials.
- SIM swap fraud — the attacker fraudulently ports the victim's mobile number so that one-time PINs sent by SMS arrive on the attacker's device.
- Malware — keyloggers or remote access tools on the victim's device.
Once inside, the attacker can pay with saved cards, change payout banking details, redirect settlements, or approve transactions the victim never intended.
What is social engineering?
Social engineering manipulates people into doing the fraudster's work for them. Typical patterns in South Africa include:
- Phishing emails and smishing (SMS phishing) impersonating banks, SARS, courier companies or payment providers, with links to fake login or "verify your card" pages.
- Vishing — phone calls from someone claiming to be the bank's fraud department, creating urgency ("your account is being drained right now") to extract an OTP or PIN, or to get the victim to approve a transaction in their banking app.
- Refund and support scams — the "agent" needs your card details to process a refund.
- Business email compromise — impersonating a supplier or executive to redirect legitimate payments to a fraudster's account.
The single most important fact to remember: banks and legitimate payment providers never ask for your PIN, password, OTP or full card details by phone, SMS or email. Any such request — no matter how convincing the caller or how official the message looks — is fraud.
How do you protect customer and business accounts?
- Enforce multi-factor authentication (MFA), preferring app-based authentication over SMS, which is vulnerable to SIM swaps.
- Never reuse passwords; use a password manager and unique passwords per system.
- Monitor for anomalies — logins from new devices or locations, changes to banking or contact details, and unusual payout instructions should trigger verification.
- Add friction to sensitive changes. Changing settlement banking details or adding a new payout beneficiary should require re-authentication and, ideally, a delay or second approver.
- Verify changes out-of-band. If a "supplier" emails new banking details, confirm on a phone number you already have on file — never the number in the email.
- Train staff to recognise urgency, secrecy and authority pressure as red flags, and to feel safe pausing a payment to verify.
What should you do if an account is compromised?
- Lock the account and revoke active sessions and API keys immediately.
- Contact your bank or payment provider to freeze pending payouts or reverse in-flight payments where possible — speed matters enormously.
- Reset credentials and re-verify contact and banking details on the account.
- Review the audit trail to establish what the attacker accessed and changed. See logging, masking and audit trails.
- Report the incident to your bank's fraud line and, where applicable, the South African Police Service. Treat it as a payment incident with a structured response — see payment incident response.
Related topics
Card Testing and Velocity
How fraudsters use card testing attacks to validate stolen card numbers, and how velocity checks, CAPTCHAs and risk rules protect your checkout.
3DS and Fraud Prevention
How 3D Secure authentication reduces card-not-present fraud, when it shifts chargeback liability to the issuer, and its limits as a fraud control.