Account Takeover Attempts: Signs to Watch For

Ruby Watson·
Share

It began, as these things often do, with a notification at an hour when one is meant to be asleep.

A guest of many years, an industrialist from Hamburg whose cheque had cleared at four in the morning more than once, received a polite email in his preferred language informing him that his online play account had been accessed from a device in a city he had never visited. The language was correct. The logo was correct. The link, he later told me, looked as if it belonged precisely where it was supposed to belong. He did what most of us would do. He opened it.

This is the piece about what he saw next, and what the weeks that followed taught a man who had always believed he was careful, and what the rest of us might usefully notice before the same small story finds us at our own small hour.

The Shape Of A Well-Planned Approach

The industrialist's account had been under observation for some time. That was clear in retrospect. The first sign, had he known to look for it, was that the notification arrived on a device he had not used for gambling matters in perhaps six months. The attacker, whoever they were, had identified the email address associated with his account and mapped it against his public professional correspondence. Those two addresses were nominally the same, but one of them had been given out at a trade show in Dusseldorf in 2019 and the other had been used, quite privately, for a handful of high-limit registrations across Europe.

The attacker had worked out that a message styled in the colours of the operator, delivered to the professional address, would be read with less suspicion than a message sent to the private one. Because the professional address saw business correspondence constantly, the email landed in a sea of similar notifications. A certain kind of mind, pressed for time, will click on what it believes it recognizes.

The art of these things is not in the technology at all. It is in the reading of the room. The attacker knew when our guest slept, and when he travelled, and which of his three phones carried his banking app, and they did not press until the conditions were right.

He signed into what he believed was the operator's login page. He entered his credentials. He entered the code that arrived on his mobile. The page loaded a moment later as a perfectly ordinary account summary.

It was not the operator's summary.

The Signs A Careful Player Ought To Notice

I have seen several of these approaches now, across rooms in Monte Carlo and Baden-Baden and at certain quieter establishments along the Riviera, and the tells are remarkably consistent if one knows to look. I list them without drama.

  • An email or message arrives at an hour that is inconvenient to verify. Three in the morning is a favourite. The attacker is counting on the reader's impatience to be greater than their caution.
  • The sender's address, examined closely, is not quite the address of the operator. A letter is substituted, or a domain is slightly reordered, or a subdomain is introduced that the reader's eye reads past at speed.
  • The message asks the reader to confirm something that has just happened, rather than to do something new. Confirmation feels passive. Confirmation feels safer. It is not.
  • A new device has signed into the account, according to the operator's records, in a city the player has never been. The attacker's own session is presented as the thing to confirm.
  • A withdrawal has been requested, or a banking detail has been changed, and the reader is invited to verify or to cancel. Either action authenticates the attacker's foothold.
  • The login page, when reached through the link in the message, is correct in every visible detail but loads from a domain the reader would not recognize if they paused to look at the address bar. Our guests rarely pause.
  • The authentication code, when it arrives on the mobile, arrives exactly when the reader expects it to. This is because the attacker's own login is, at that precise moment, generating the code on the operator's side, and the reader is being asked to relay it.

There is also the quieter approach, which I find rather more troubling. The attacker does not attempt to sign in at all at first. They contact the operator's customer support by chat, posing as the account holder, and attempt to change the recovery address or the verification phone number through a sympathetic representative. The first a careful player knows of this is a small notification from the operator confirming a change they did not request. That notification is, almost always, the last chance to catch the thing before the door is already open.

The Sequence That Followed

The industrialist's funds were not drained at once. That is another pattern I have learned to recognize. A sudden large withdrawal triggers the operator's fraud systems, which is counterproductive for the attacker. Instead, over a period of perhaps three weeks, a succession of modest transfers left the account in directions he had not authorized, each one sized to sit just beneath the review threshold, each one timed to a plausible session of play.

The operator's investigators were cooperative and quietly professional about the matter, as operators of their rank tend to be when a guest of sufficient standing is involved. Most of the funds were recovered, with the usual delays. What was not recovered was our guest's confidence in his own attention, which had been, for many years, a matter of considerable pride.

What It Tells Us, Briefly

The lesson, if a lesson is wanted, is not technical. It is temperamental. The messages that take our accounts are designed to arrive in the moments we are least capable of reading them with care. The domain that does not quite match, the hour that is not quite right, the confirmation that feels passive. They are all small things, individually, and together they are the method.

A careful player, as my old colleague in the cage used to say, is simply someone who pauses for a second longer than the attacker planned for. That is often the whole of the defence.

Related posts