Skip to content
Skip to main content
Payments & Banking Technical Explainer

Could a payment account have been compromised?

Yes. An offender can use stolen credentials, an existing session, a compromised recovery channel or remote control even when the provider records successful authentication.

Different access routes leave different evidence

Phishing, credential reuse and malware may produce unfamiliar logins. Compromised email or phone access can enable password resets or interception of one-time codes. Remote-access software can let someone operate the victim's usual device, while session theft may avoid a fresh password altogether.

Relevant signs include new devices or beneficiaries, changed contacts, repeated failures, security alerts, unusual activity and rapid onward transfers. Their absence does not exclude compromise if the normal endpoint or session was used.

Test the claimed route

Preserve logins, device registrations, session and authentication IDs, security changes, risk decisions and support contacts before remediation alters them. Compare these with messages, email, browser history, installed software, notifications and normal account patterns.

Denial alone does not prove takeover, and successful PIN, biometric or code use does not disprove it. Establish whether the alleged route existed and could cause the disputed payment.

The point to remember

Test compromise through the specific access route, joining provider security records to endpoint evidence before attributing an authenticated transaction.

Reference: PAY-012Payments & Banking