Skip to main content

ETHNOS_APP

Home • Search • Journals • List 0

Evaluating the Effectiveness of Two-Factor Authentication (2FA) in Mitigating Account Takeover Fraud

A Natural Experimental Study on Canadian Banks

Bibliographic Data

ID21309274
AuthorsEden Kamar (0009-0001-1135-5697, Georgia State University, Atlanta, GA, USA, corresponding author), C Jordan Howell (0000-0003-4443-5068, University of South Florida, Tampa, FL, USA), David Maimon (0000-0003-1492-2762, Georgia State University, Atlanta, GA, USA), Isabelle Fraser (Private Researcher, Toronto, Canada)
Year2026
Publication date2026-05-05
Peer ReviewedYes
Open AccessYes
TypeARTICLE
VenueCrime & Delinquency (JOURNAL)
Journal identifiersISSN: 0011-1287 • E-ISSN: 1552-387X
PublisherSAGE Publications (PUBLISHER • US)
DOI10.1177/00111287261441235
OpenAlexW7160350828
LanguageEN
References cited34

Account takeover fraud involves cybercriminals using stolen credentials to access online accounts, with financial institutions often targeted due to their monetary value. Despite growing adoption, the effectiveness of cybersecurity measures like two-factor authentication (2FA) remains underexplored. This study evaluates 2FA as a target hardening strategy within the situational crime prevention (SCP) framework. Using a natural experimental design, we analyzed cyber threat intelligence from illicit markets between March 2021 and February 2022, during which three major Canadian banks implemented 2FA, two optionally and one mandatorily. Bayesian time series analysis revealed that mandatory 2FA significantly reduced the number of compromised bank accounts, whereas optional 2FA did not. These findings inform crime prevention policy and contribute to theoretical developments in cybercrime research

Authentication (law) · Confidentiality · Cybercrime · Natural experiment · Situation awareness · Situational ethics · Benford’s Law and Fraud Detection · Cybercrime and Law Enforcement Studies · Imbalanced Data Classification Techniques

  • Motivating Is Security Compliance

    Open Access•Anthony Vance, Mikko Siponen et al.•Information & Management•2012

  • Information Security Policy Compliance

    Burcu Bulgurcu, Hasan Cavusoglu et al.•MIS Quarterly•2010

  • What Do Systems Users Have to Fear? Using Fear Appeals to Engender Threats and Fear that Motivate Protective Security Behaviors1

    Scott R Boss, Dennis F Galletta et al.•MIS Quarterly•2015

  • A Theoretical Extension of the Technology Acceptance Model

    Open Access•Vivek Venkatesh, Viswanath Venkatesh et al.•Management Science•2000

  • A Depiction and Classification of the Stolen Data Market Ecosystem and Comprising Darknet Markets

    Open Access•C Jordan Howell, Taylor Fisher et al.•Journal of Contemporary Criminal…•2023

  • Information system security policy noncompliance

    Open Access•Gaurav Bansal, Steven Muzatko et al.•Information Technology and People•2021

  • Vendor communication themes in darknet Ransomware-as-a-Service (RaaS) advertisements

    Open Access•Taylor Fisher, Zacharias P Pieri et al.•Computers in Human Behavior•2025

  • Risk Avoidance Behavior on Darknet Marketplaces

    Open Access•C Jordan Howell, David Maimon et al.•Crime & Delinquency•2024

  • An Examination of Email Fraudsters’ Modus Operandi

    Open Access•David Maimon, C Jordan Howell et al.•Crime & Delinquency•2023

  • Natural experiment methodology for research

    Open Access•Scott T Leatherdale•International Journal of Social…•2019

  • Assessing the Extent of Crime Displacement and Diffusion of Benefits

    Open Access•Rob T Guerette, Kate J Bowers et al.•Criminology•2009

  • Situational Crime Prevention

    Ronald V Clarke•Crime and Justice•1995

  • Situational Crime Prevention

    Ronald V Clarke•Crime and Justice•1983

  • Malicious Spam Distribution

    Robert C Perkins, C Jordan Howell et al.•Deviant Behavior•2022

Citation velocityhistorical
Highly citedNo

Tools

Open DOI
Ethnos_APP • Open Source Project • MIT License • Frontend v2.0.0 • Privacy and Cookies • API Documentation: api.ethnos.app/docs • API Source Code: GitHub • DOI: 10.5281/zenodo.17049435 • Frontend Source Code: GitHub • DOI: 10.5281/zenodo.17050053 • cruz.rio.br • Expectantes Misericordiae