Account takeover fraud is climbing at US banks, and the Federal Reserve’s own data confirms it. Federal Reserve Financial Services (FRFS), the Fed’s operational arm for payment services, surveyed more than 400 financial institutions in the fourth quarter of 2025. It found a broad-based rise in fraud losses. Criminals are leaning harder on stolen or compromised credentials to get inside legitimate accounts.

The FRFS 2026 Risk Officer Survey found a 7% increase in the number of institutions reporting that an unauthorized party had taken over an account, measured against the Fed’s own FraudClassifier model. The increase was sharpest in two channels. Twelve percent of institutions said account takeover fraud was rising through ACH transfers, and 14% said the same for wire transfers. Both figures describe a criminal gaining access to a customer’s online banking login and originating payments directly. Neither is a scam where the account holder is tricked into sending money themselves.

Why real-time rails raise the stakes

The detail that matters for US banks building out instant payments is settlement finality. A FedNow or RTP transfer is a credit push that clears in seconds and cannot be recalled once sent. Both networks advertise that as their core advantage over ACH, where a bank can still claw back a misdirected or fraudulent debit for days. When a criminal who has taken over an account originates a payment on an instant rail, the receiving bank has no obligation to return the stolen funds. The sending institution has no mechanism to force it. That asymmetry is why the Fed treats account takeover as a distinct risk category for its real-time services, rather than folding it into general card or cheque fraud.

The Fed has been expanding what these rails can move. Federal Reserve Financial Services raised the FedNow Service’s network transaction limit from $1 million to $10 million, effective November 2025, citing growing commercial demand for higher-value transfers. A bigger ceiling widens what a successful account takeover can move in a single payment. That is part of why the Fed paired the expansion with fraud-specific guidance, rather than treating it as a purely commercial decision.

The newest rails are not where the losses are concentrating

The FRFS survey itself complicates any simple story about real-time payments driving the account takeover rise. Instant and real-time payments were, in the survey’s own words, “a relative bright spot,” with comparatively few institutions reporting fraud attempts or losses on those rails specifically. The sharper increase sat with what the Fed classifies separately as faster payments, covering bank mobile apps and person-to-person transfers. Both fraud attempts and reported losses in that category grew more than in any other payment type the survey tracked.

Read together, the two findings describe a risk that has not yet arrived in force on FedNow and RTP themselves. Its underlying driver, credential compromise, is already spreading across every channel a bank operates. A criminal does not need a flaw in FedNow or RTP to use them. Stolen login credentials, usually harvested through phishing or a prior data breach, work on whichever payment rail the account holder has enabled. Instant rails simply remove the days a bank previously had to catch the transfer before it settled.

Credential theft is the common thread

The Fed’s Account Takeover Fraud Mitigation Toolkit, built by Federal Reserve Financial Services for the industry, describes the mechanism plainly. A criminal gains unauthorized access to a legitimate user’s account, then exploits that access to withdraw funds, make purchases or sell the account details to other criminals. Many change the registered email address or phone number first, locking the real customer out before they can raise the alarm. The toolkit attributes the recent rise to consumers’ larger digital footprints, wider criminal access to breached personal data, and newer automation tools that make large-scale credential testing cheaper to run.

That overlaps with a separate and growing threat Fintechly has covered directly: synthetic identity fraud, where a criminal builds a new identity from a mix of real and fabricated personal data rather than hijacking an existing one. The two are different crimes with the same root cause. US consumer data has been breached often enough that criminals can now assemble convincing profiles of real or invented people with relatively little effort.

What banks are doing about it

The FRFS survey asked institutions what was helping. The answers cluster around moving fraud detection closer to the moment a payment is sent, rather than after it clears. Respondents pointed to real-time behavioural monitoring alerts, biometric identity verification layered onto existing login checks, and mandatory callbacks or PIN authorisation for high-value wire transfers. None of these fully substitutes for stopping the credential theft itself. That is why identity verification at login, not just at payment, has become the more urgent fix for several of the banks surveyed.

US banks are not alone in reaching for that fix. In the UK, several banks are preparing a live pilot for identity checks built directly into their banking apps, extending authentication beyond a password to the transaction itself. It is a model US institutions building out instant-payment fraud controls are watching closely.

Banks weighing how exposed their own FedNow or RTP deployment is can find the mechanics of irrevocable settlement set out in Fintechly’s explainer on what the FedNow Service does and does not enable. The companion piece on how the RTP network settles payments covers the equivalent mechanics on the bank-owned rail. Fintechly’s separate reporting on synthetic identity fraud’s growth as America’s fastest-rising bank crime covers the related identity-fabrication threat in full.

The common lesson from the Fed’s own data is plain. Account takeover fraud is a credential problem before it is a payments problem. Faster settlement has not caused the rise so far, but it removes the safety margin banks relied on once the fraud gets through. That is exactly why the Fed built a dedicated toolkit for it, rather than treating it as a footnote to older forms of payments fraud. A fuller view of the companies building fraud and identity infrastructure for US banks is on Fintechly’s regtech sector directory.