Evaluating the Effectiveness of Two-Factor Authentication (2FA) in Mitigating Account Takeover Fraud
A Natural Experimental Study on Canadian Banks
Bibliographic Data
| ID | 21309274 |
|---|---|
| Authors | Eden Kamar (0009-0001-1135-5697, Georgia State University, Atlanta, GA, USA, corresponding author), C Jordan Howell (0000-0003-4443-5068, University of South Florida, Tampa, FL, USA), David Maimon (0000-0003-1492-2762, Georgia State University, Atlanta, GA, USA), Isabelle Fraser (Private Researcher, Toronto, Canada) |
| Year | 2026 |
| Publication date | 2026-05-05 |
| Peer Reviewed | Yes |
| Open Access | Yes |
| Type | ARTICLE |
| Venue | Crime & Delinquency (JOURNAL) |
| Journal identifiers | ISSN: 0011-1287 • E-ISSN: 1552-387X |
| Publisher | SAGE Publications (PUBLISHER • US) |
| DOI | 10.1177/00111287261441235 |
| OpenAlex | W7160350828 |
| Language | EN |
| References cited | 34 |
Account takeover fraud involves cybercriminals using stolen credentials to access online accounts, with financial institutions often targeted due to their monetary value. Despite growing adoption, the effectiveness of cybersecurity measures like two-factor authentication (2FA) remains underexplored. This study evaluates 2FA as a target hardening strategy within the situational crime prevention (SCP) framework. Using a natural experimental design, we analyzed cyber threat intelligence from illicit markets between March 2021 and February 2022, during which three major Canadian banks implemented 2FA, two optionally and one mandatorily. Bayesian time series analysis revealed that mandatory 2FA significantly reduced the number of compromised bank accounts, whereas optional 2FA did not. These findings inform crime prevention policy and contribute to theoretical developments in cybercrime research
Authentication (law) · Confidentiality · Cybercrime · Natural experiment · Situation awareness · Situational ethics · Benford’s Law and Fraud Detection · Cybercrime and Law Enforcement Studies · Imbalanced Data Classification Techniques
Motivating Is Security Compliance
Information Security Policy Compliance
What Do Systems Users Have to Fear? Using Fear Appeals to Engender Threats and Fear that Motivate Protective Security Behaviors1
A Theoretical Extension of the Technology Acceptance Model
A Depiction and Classification of the Stolen Data Market Ecosystem and Comprising Darknet Markets
Information system security policy noncompliance
Vendor communication themes in darknet Ransomware-as-a-Service (RaaS) advertisements
Risk Avoidance Behavior on Darknet Marketplaces
An Examination of Email Fraudsters’ Modus Operandi
Natural experiment methodology for research
Assessing the Extent of Crime Displacement and Diffusion of Benefits
Situational Crime Prevention
Situational Crime Prevention
Malicious Spam Distribution
| Citation velocity | historical |
|---|---|
| Highly cited | No |