External · ATO
Account takeover via stolen credentials
Fraudsters phish or buy credentials to access a customer's banking or wallet app.

Attack scenario
Attacker logs in from a new device in a different region using breached username and password.
How SEC@R prevents it
Sensitive data remains dormant by default Activated only with trusted device presence and real-time user consent Data utility is limited to the authorized session Automatic deactivation when the session ends or the trusted device moves away Prevents phishing, bots, credential theft, and unauthorized transactions before they occur.
- Dormant-by-default data activation
- Fraud Indicator Check before release
- FIDO2 + multi-device verification
- Quarantine Mode on trust break
Outcome: Citizens are not victimized; the bank never receives a valid activation request from a fraudster.






