Skip to content
Skip to main content
Payments & Banking Operational Explainer

Could an exchange account be controlled by another person?

Yes. Credentials, sessions or personal actions can be shared, stolen, remotely controlled or directed by someone other than the registered customer.

Control can be technical or instructional

Phishing, credential sale, existing sessions and remote access can enable direct use. A customer may instead complete actions after deception or instruction. New endpoints may be legitimate, while familiar endpoints can still be compromised.

Reconstruct access and benefit

Compare logins, sessions, authentication, recovery, contact and withdrawal-address changes with normal endpoints, trading and communications. Preserve provider and device evidence before security changes where possible.

Separate holder, technical operator, person directing activity, knowledge and beneficiary. Another operator does not automatically exclude the customer's involvement.

The point to remember

Test third-party control through converging access, endpoint, communication and benefit evidence rather than registration alone.

Reference: PAY-177Payments & Banking