Bates Research | 09-14-26
When No Money Leaves: Account Takeover as a Manipulation Problem
The familiar account takeover (ATO) incident ends with assets gone. A newer pattern ends with the balance intact and the customer holding something worthless.
Once inside a brokerage account, the attacker sells the customer's existing positions and uses the proceeds to buy thinly traded or lesser-known stocks. No cash is withdrawn, no external account added. The purchases create artificial buying pressure in a security that does not typically experience much trading volume. The attacker then sells previously obtained shares held in separate accounts into the upward pressure created by the takeover purchases and takes the gain somewhere the firm cannot see. The customer is left holding the position when it falls, after its trading market returns to equilibrium in the absence of the artificial pressure.
FINRA has connected account takeovers to pump-and-dump and ramp-and-dump schemes, and the SEC has warned that bad actors controlling an account may liquidate holdings and engage in active trading as needed to support such exploits. In an ATO-driven pump-and-dump or ramp-and-dump, a fraudster breaks into a brokerage account and uses that money to buy up a cheap stock the fraudster already owns, driving the price up just long enough for the fraudster to sell their own shares at a profit, leaving the victim holding the now-deflated stock.
What Exfiltration Controls Miss
Most fraud infrastructure is built to catch money before it leaves the account. Withdrawal limits, outbound identity verification, beneficiary and external-account checks, and a large share of anti-money laundering (AML) alerts are calibrated to trigger the moment funds exit an account. In this typology, they never do.
That has practical consequences for how a firm detects an event and how it explains itself after. The evidence of misconduct is in the order flow, not the cash ledger: liquidation of established holdings, concentration into low-liquidity securities (e.g., penny stocks), timing that lines up with activity in accounts the firm does not control. An account showing no outbound movement is not, on that basis alone, an account in good order.
Congress Calls For Action
On August 20, Senators Ron Wyden and Elizabeth Warren wrote to FINRA CEO Robert W. Cook calling for immediate regulatory action on fraud exploiting the Automated Customer Account Transfer Service (ACATS). Their offices reviewed a dozen major brokerage firms and reported a deeply concerning lack of standardized, consumer-controlled protections across the industry. Copies went to SEC Chairman Paul Atkins and DTCC CEO Frank La Salla. FINRA has been asked to respond by September 17.
The letter seeks to add requirements around customer notification of outgoing transfers, customer-controlled account locks, authenticated confirmation by the sending account holder, and phishing-resistant multi-factor authentication such as passkeys. Versions of each already appear in FINRA guidance as effective practices, but none are strictly required.
ACATS fraud differs from in-account manipulation in what the attacker chooses to do with the account, but both exploit the same entry point. Congressional attention to the first will raise expectations for controls that bear on both. For legal, compliance and investigations teams, reassessing surveillance, authentication, and escalation frameworks now is a proactive step toward internal readiness, whether a rule eventually arrives or not.
How Fraudsters Get Access
Voice phishing (“Vishing”) has become an increasingly pervasive method for collecting credentials and one-time codes. Callers pose as help desk, fraud prevention, or IT support, spoof a legitimate number, manufacture urgency around a security update, and walk the target to a fake login page while capturing the code in real time. Business email compromise (BEC) often supplies the initial lure, sent from a legitimate-looking address so any links survive the usual scrutiny. The follow-up call then supplies the pressure. Neither step requires malware, only social engineering.
Supervision Does Not Have to Wait For a Rule
Treat trading as a compromise signal. Rapid liquidation of established holdings followed by concentrated purchases in low-liquidity securities deserves review or flag-raising, particularly alongside a new device, an unusual login location, or repeated multi-factor authentication (MFA) prompts.
Move authentication off riskier channels. Text-based/SMS codes and simple push approvals can be compromised via phishing exploits including SIM swaps, where a bad actor gains access to SIM card information and can then intercept standard text-based two-factor authentication, or “adversary-in-the-middle” (AiTM) tactics, where the customer is routed to a fraudulent page that sits between them and the real login screen, relaying their username, password, and one-time authentication code to the attacker in real time.
Hardware keys and/or passkeys are more secure forms of MFA that help mitigate these increasingly common attack vectors.
Extend security awareness to the customer directly, not just on the back end. FINRA's own 2021 roundtable with member firms found that the programs identified as more effective also built customer-facing education into several channels at once (client onboarding materials, opt-in account alerts, website resources, and even statement inserts for older investors), rather than relying on a single static disclosure buried in account paperwork.
It's worth noting that FINRA frames these as practices firms reported finding effective, not as requirements. Any website content built along these lines is still a communication with the public, so it would run through the firm's existing FINRA Rule 2210 review and recordkeeping process before publication, the same as any other public-facing disclosure. This topic is no longer hypothetical, as the SEC's May 2024 amendments to Regulation S-P require a written program for detecting, responding to, and notifying customers after unauthorized access to their information.
Require added verification. Certain account activities, such as updated bank information, large liquidations, new devices added to an account, anomalous IP addresses, and contact information updates should be appropriately flagged or escalated with added verification measures, particularly if these types of activities occur within a brief timeframe.
Write the manipulation scenario into the incident response plan. Order and execution records, IP addresses, and device identifiers can only be preserved if the firm is already retaining them. A trading timeline reconstructed six months later from partial data is materially weaker than the one captured on day one.
Pressure-test the plan with tabletop scenarios that begin at a Vishing or AiTM compromise and end in unauthorized trading, rather than at containment.
How Bates Group Helps
When compromised accounts are used to move a price, firms and their counsel face a question that is analytical before it is legal: which trading was manipulative, which was not, and what does the order flow actually show. Bates Group partners with law firms, broker-dealers, exchanges, financial institutions, and regulatory agencies to provide expert support related to:
- Market Manipulation. Analysis of trading activity, market data, communications, and trading strategies to evaluate allegations including wash trading, spoofing, layering, front running, match trading, painting the tape, banging the close, and pump-and-dump schemes. Bates Group has built detailed trading timelines, interactive relationship models, and damages analyses, and has worked from Blue Sheet data and communications to produce demonstrative exhibits used at trial.
- Litigation and Regulatory. Consulting and expert testimony in internal investigations, regulatory inquiries, enforcement actions, and customer arbitrations arising from unauthorized trading and compromised accounts.
- Technology Advisory (digital forensics, eDiscovery, and cybersecurity). Proactive assessments typically include review of internal policies, controls and procedures, standard of care considerations and related information security programs in place, benchmarked against market peers and offering recommendations when applicable. For litigation needs involving ATO or related allegations, additional measures include analysis of log and related session and trade artifacts, strategic partnership with counsel and client, reporting of findings, and expert testimony when necessary.
To discuss surveillance design, a cybersecurity readiness review, or an active litigation need, please contact Bates Group today.
Antonio Rega
Managing Director, Tech Forensics, eDiscovery, Data Privacy/Security