resources / blog /
Account takeover is moving beyond the login and taking your margins with it. How can you protect your store?
September 1, 2026
3 min read

Account takeover is moving beyond the login and taking your margins with it. How can you protect your store?

In January 2026, a Chicago vintage store called Lost Girls Vintage had one hell of a weekend.

Thousands of newsletter subscription emails flooded the inbox, burying a Shopify warning that someone had used a recovery code to access an account. The customer himself had never requested one. Then came a welcome email for Shopify Credit and disclosures for a new line of credit nobody had opened.

The store already had two-factor authentication. And yet, by the time they pieced the scam under the spam together, more than $33,000 was gone.

Now transpose that scene to your own store and you’ve got your own version of what’s popularly called account takeover.  

Here, the recovery code is the innocent way in to your store. The flood of spam is the distraction. And all those reassuring signals around the login, say, a familiar device, a previously seen session, or a known cookie, can make the whole thing look perfectly legitimate. By the time the frantic calls hit your support inbox, your brand’s reputation is already tangled up in the damage.

You see, most fraud is you versus an outsider at your front door. Account takeover is a different animal. It slips a conman inside a relationship you spent years building.  

And that brings us to the million-dollar question in e-commerce - when the password or journey is right, but the person is wrong, how do you tell the difference?

If you’re thinking 2FA is the answer, it’s only part of it. So what else should you look at before you start making every legitimate customer prove they belong? Let’s find out.

Fraud is having a better 2026 than the rest of us

Account takeover started the year on a tear.  

Attempts jumped 78% between January and April 2026, and e-commerce accounts now get hit at roughly 3.4 times the cross-industry average. If that kind of growth showed up on your own dashboard, you would frame it. Sadly, it belongs to the people robbing you. But what makes e-commerce more susceptible to these attacks?

Well, an e-com store sits at an oddly attractive sweet spot for attackers - valuable enough to steal, easy enough to access, and low-risk enough to be worth the gamble.  Take one heartbroken shopper whose account got hijacked:

“my account got hacked the other day and someone was able to use my account (and my credit card 😭) to place a $355 purchase.”

And the damage goes beyond the $355. It’s hard to feel loyal to a store that let someone else spend your money.

On the merchant side, the true invoice towers far above a stolen SKU or a lost shopper. Every $1 directly stolen in an account takeover order costs US merchants 3–4x that amount once chargeback penalty fees, lost inventory, refund processing, and support operations are added.

How do stolen passwords fuel e-commerce account takeover?  

The whole charade becomes much less mysterious once you follow the password backwards.

Somewhere, years ago, your customer used the same password on three different sites. One gets breached. Another leaks through malware. The password joins billions of others floating around underground, waiting for someone to try it somewhere more useful.

And there is an extraordinary amount of inventory to work with. In June 2025, researchers found roughly 16 billion exposed login records across 30 datasets, much of it gathered from infostealer malware and older breaches.  

Your store can easily become the next stop.

The attacker has a list of email addresses and passwords that worked somewhere before. Now imagine trying each combination against your login page one by one. Tedious, right? Unless you get a bot or AI to do it.  

Meet the world’s least creative heist

This is where our story’s true antagonist comes in - credential stuffing.  

The attack is gloriously uncreative - take stolen credentials, automate the guessing, keep the traffic moving, and wait for something to click.  In an average scenario, only 49% of a user’s passwords across different services are unique. The other half are, in effect, keys that could open more than one door. So, attackers don’t crack passwords; they buy them.  

The dark web never forgets

And the bots used to automate the process have learned some innovative tricks of their own.

Instead of sending thousands of requests from one suspicious IP address and practically begging you to block them, attackers can spread attempts across proxy networks and residential IPs. They can target the authentication endpoint directly, change headers, and keep individual attempts low enough to blend into normal traffic.  

Your login page is not the only door that lets the attackers in

Forget dramatic battering rams or server screens flashing red during a cyber siege. Most break-ins arrive disguised as a quiet, polite login request.

Consider outdoor gear giant The North Face back in April 2025. Attackers casually waltzed through nearly twenty-nine hundred customer accounts. Order histories, home addresses, and personal details sat exposed in plain sight.

The key turned effortlessly because, somewhere else on the internet, that password was real.

That distinction is what makes ATO so slippery. And regulators are paying attention to that distinction in a way that can prove costly for merchants who feel like victims themselves.

In January 2025, New York’s Department of Financial Services fined PayPal $2 million after finding that cybercriminals used credential stuffing to access sensitive customer information. The investigation found gaps in PayPal’s cybersecurity controls, including inadequate protection against unauthorized access.

At the end of the day, a stolen password may have started the problem somewhere else, but once it works on your store, the consequences are very much yours.

The password passed. That doesn’t have to mean the customer did

You cannot protect a secret that has already been stolen.

What you can do is make that password less powerful. A username and password can still get a customer through the first checkpoint, but they should have to share the stage with everything else you know about the session.

Stop letting the password do all the work

Passkeys are the cleanest way to take reusable credentials out of the equation. Instead of asking shoppers to remember another password that can be leaked or reused somewhere else, passkeys tie authentication to un-phishable, device-based cryptographic pairs and biometric verification.  

And for customers still using passwords, MFA gives you another checkpoint when a login starts looking "interesting."  

The trick is avoiding the classic security-team solution, which is make everyone suffer equally:

“I will abandon an order if I am prompted to: -Download an app -Enable notifications or other unusual permissions -Make an account and there is no guest checkout option -Enable and verify MFA without being able to complete the order otherwise”

Your regular customer signing in from the same phone she has used for months probably has a very different risk profile from someone arriving on a fresh device and immediately changing the password. One can breeze through. The other can use the extra question.

Then observe the device holding the password

The password tells you what someone knows. The device can tell you whether the person using it makes any sense as a genuine shopper. A genuine shopper tends to leave a fairly boring trail - familiar device, same browser, location, and a reasonable sequence of actions.

An attacker running an automated campaign can leave a rather different one.

Headless browsers can automate login and account creation at a pace no human shopper could sustain. Device fingerprinting, bot detection, IP intelligence, and behavioral signals can help connect those dots before the attacker gets to the useful stuff sitting inside the account.

That matters because ATO rarely ends with the login. The attacker gets in, then starts poking around.

Watch what happens after the login

So far, we know that none of the ATO actions need to scream “fraud” on their own. But start watching what happens after the login and the story gets considerably harder to explain.

One Shopify user discovered that after an attacker got into their Shop account and slipped through a $1,000 gift-card purchase:

“So I woke up this morning to about 600 new emails. Looks like i've had hundreds of new accounts created on various aliases of my email (ie. if my email is abcd@gmail.com, they did abcd+1@gmail.com, abcd+2@gmail.com etc) After some googling, this is apparently called a spam bomb, and is often used to conceal a fraudulent transaction within the 600 new emails.”

That is why your account-creation and customer-update events like emails deserve attention too. Server-side webhooks can flag disposable email domains, suspicious registration bursts, or rapid profile changes and feed those signals into your risk engine before the attacker gets much further.

Make trust part of the customer journey

Think of great security like being a ridiculously good host. You keep an eye on the entrance and fire off a real-time alert the moment something looks suspicious. That way, a shopper knows someone is poking around their account within seconds instead of waking up furious the next morning.

Bring your customers into the defense too. Encourage them to use a unique password for your store and treat unexpected verification emails with a healthy dose of skepticism.

An account takeover can cost you revenue today and customer trust tomorrow. Catch the warning signs early, keep the right checks in place, and you can protect both the money moving through your store and the relationship behind it.

Account Takeover, Credential Stuffing, E-commerce Security, Fraud Prevention, Shopify Store Safety, Bot Detection, Customer Trust

Muskan Banga

About the author

Muskan is a content writer in the warranties and product protection industry, focused on demystifying and simplifying the industry for both her readers and herself. Her process begins with deep research, weaving in real-world examples to make complex ideas feel accessible and relatable. In her spare time, she obsessively devours Substack newsletters and books while losing herself in art films.

🔗 Link copied to clipboard!