Part 1: The Gap Nobody Owns
Account takeover is a security failure and a fraud event at the same time. Most companies are organized so that neither team owns it. Attackers exploit exactly that gap.
Security and fraud teams have spent a decade defending the same customers from opposite ends of the same attack and rarely comparing notes. One stops unauthorized access: malicious traffic, credential abuse, account compromise. The other stops the theft that follows: drained balances, fraudulent payouts, refund abuse, and the revenue that leaks afterward. In most companies, these functions report to different leaders, run different tools, and are measured by different metrics. The division made sense when distinguishing between an intrusion and a fraud event was clear-cut, but account takeover ended that.
Attackers don’t care about what constitutes a security incident vs. a fraud event, and account takeover (ATO) is the proof. ATO starts as a textbook security problem: stolen credentials, bot-driven login abuse, session hijacking. The damage appears later, when the logged-in “customer” changes a payout account, drains a loyalty balance, or moves money out. It’s one event with two owners. In most organizations, however, there’s no single owner accountable for the whole chain from compromise to cash-out.
That’s why cybersecurity has a fraud problem.

Security teams aren’t failing. They’re doing exactly what they’re built to do: detect intrusions, triage threats, contain incidents, and shrink attacker dwell time. The gap is that most security teams still treat what happens after a login as someone else’s problem. Security owns the break-in. Fraud owns the loss. The attack runs straight through the seam between them, and that ownership gap is where accountability disappears.
Gartner has a name for closing this gap: “cyber-fraud fusion,” the convergence of fraud prevention, identity, and cybersecurity into a single defense model. Gartner expects the shift to accelerate through 2031 and projects that half of large financial institutions and online retailers will fold fraud responsibilities into cybersecurity teams reporting to the CISO. In short: fraud is turning into a cybersecurity outcome, not a back-office cleanup that happens after the “real” incident is closed.
The threat data points in the same direction. In Sift’s Q2 2026 Digital Trust Index, 22% of consumers reported experiencing an account takeover in the past year, and 26% reported experiencing online payment fraud. Sift’s network data shows ATO attack rates ran highest early in 2025 before easing later in the year, a reminder that this attack is a moving target. The financial stakes keep climbing regardless, as global e-commerce fraud losses are projected to reach $107 billion a year by 2029.
Scale matters, but structure matters more. When an account is compromised, the technical event is brief and hard to distinguish from the real user. The damage shows up after the login succeeds, exactly where neither team is looking.
The security team sees impossible travel, a device anomaly, a spike of credential stuffing. Weeks later, the fraud team sees an altered payment method, an odd refund pattern, a suspicious withdrawal. Support hears about it last, once the money is already gone. Each team holds fragments of the story.
In the same Q2 2026 report, Sift traced a single loyalty fraud ring operating across more than 90 businesses in multiple industries, generating roughly 13,000 attempted transactions and over 100 fraudulent chargebacks at an average transaction value of $223. No merchant saw more than a sliver of that operation. No single company’s team did either. Coordinated attackers exploit fragmentation between companies and teams within a single company.
That fragmentation is also why standard scorecards can mislead. Security metrics measure how fast the Security Operations Center (SOC) reacts to the intrusion. They say nothing, however, about whether the account was later milked for fraud, whether customer trust took a hit, or whether losses kept compounding after the alert was closed. For attacks that keep paying out long after access is achieved, reaction speed is an operational score, not a business score.
None of this requires CISOs to become fraud analysts, or fraud leaders to start running the SOC. But it does require one shared model for attacks that move across identity, access, abuse, and transactions. And it requires an honest look at where the most useful evidence sits, which is usually outside either team’s dashboard.
The next two articles in this series will explore both sides of this issue. Part 2 looks at the same ATO attack from inside each function: what the CISO’s dashboard actually shows, what the fraud leader’s queue actually shows, and why both teams can be right while the business stays wrong about the whole incident. Part 3 lays out a practical operating model for closing the gap: five things security and fraud teams need to share, and four moves any company can start with.
Attackers already treat compromise-to-cash-out as one continuous operation. Defenders should too.
Next in this series: Part 2, One Attack, Two Dashboards: I’ll explore how the CISO and the fraud leader see the same compromise.





