All articles Fraud & ATO

Account Recovery Fraud: Stopping the 'I Lost Access' Takeover

Account recovery is the flow you build for the customer who lost their phone, forgot their password, and no longer has their authenticator. It is also the flow attackers love most, because it is designed to grant access to exactly that situation.

Recovery fraud is social engineering against your weakest, most permissive path. Whether the decision is made by a support agent or a self-service form, the defense is the same: use everything you know about the account’s device history to weigh whether this recovery is plausible.

Recovery relaxes controls by design

Normal login assumes the user has their credentials and their second factor. Recovery assumes they have lost one or both — so it substitutes softer proofs: a recovery email, a knowledge question, an ID upload, a support conversation. Each of those is easier for a prepared attacker to satisfy than a passkey.

You cannot remove that flexibility without stranding real customers. What you can do is add a signal the attacker cannot fake: the history of devices that used the account before it was ever locked out.

Turning device history into recovery evidence

Every account accumulates a device footprint over its lifetime. Prynt records a stable visitorId for each device, so at recovery time you have a roster to compare against:

  • Is the recovery request coming from a device the account has used before? That strongly favors a genuine user.
  • Is it a completely new device on a proxy or datacenter network? That favors fraud.
  • Does the requesting device appear in your reputation network tied to prior abuse elsewhere?
  • Is there velocity — one device attempting recovery across many accounts?

None of these is a yes/no verdict on their own, but together they give a support agent or an automated flow a defensible basis to grant, challenge, or decline.

Designing the recovery decision

Bake the signal into the flow rather than treating it as an afterthought:

  1. On a recovery request, resolve the device and pull the account’s prior device history.
  2. If the device is recognized, allow a lighter recovery path.
  3. If the device is new and low-risk (residential network, no reputation hits), require standard identity proofs.
  4. If the device is new and high-risk (proxy, datacenter, reputation flags), escalate to the strongest verification and add a cool-down.
  5. Notify the account’s known devices whenever recovery is attempted, giving the real owner a window to intervene.

For agent-assisted recovery, surface the device verdict directly in the support console so the human is not deciding blind.

The chain does not end at recovery

A successful takeover recovery is usually the first step, not the last. The attacker then changes the recovery email, swaps the phone number, and disables the original factors to lock the real owner out permanently. Score those follow-on changes with the same new-device lens, and impose delays so a wrongly granted recovery can still be reversed.

Explainability protects everyone

Recovery decisions get challenged — by customers who were declined and by teams reviewing a takeover after the fact. Reason codes that name the signals (“recovery from a never-seen device on a datacenter IP, no prior history”) make the call defensible and let you tune the balance between security and stranded users.

Weigh the history you already have

Recovery will always be your most permissive flow, but it does not have to be blind. The device history an account built up before it was locked out is evidence the attacker cannot manufacture, and folding it into the recovery decision is what separates a real lockout from a takeover.

Prynt is free to start. See how known versus new devices score in the playground, then bring that verdict into your recovery flow and support tooling.

Try it free

Prynt is device intelligence with a free tier — visitor IDs, bot & fraud Smart Signals, and behavioral biometrics, powered by a cross-site network. Start free.

Keep reading