These questions arise from months of discussions with fraud risk managers who often deal with losses originating from breaches in other systems. The pattern is clear: security contains the incident, fraud handles the fallout, and there's a disconnect in visibility between these events.
If you're dealing with fraud cases that seem unrelated to the security incidents your CISO considers "contained," this information is for you.
Do Security Teams Inform Fraud Teams About Compromised Accounts?
Not typically, and it's not due to secrecy. The issue lies in measurement and timing. Security teams focus on containment, tracking metrics like mean time to detect and mean time to contain. Once these metrics are satisfactory, the incident is considered closed. However, containment doesn't mean compromised accounts are secure; it just means the initial threat is halted.
Research by Mastercard shows 60% of fraud and risk executives aren't aware of cyber breaches until after fraud losses occur. This isn't a communication failure; it's a structural gap. By the time fraud patterns emerge, the security incident that could explain them was resolved weeks earlier.
If you're identifying breaches through chargeback patterns instead of incident reports, you're not alone. This is the default scenario.
What Happens Between the Breach and the Fraud Event?
Attackers monetize access in ways that don't resemble traditional attacks. Once logged in as a customer, their actions appear as legitimate account activity: changing recovery details, updating payment methods, testing small transactions, and adding stolen cards to digital wallets. These actions don't trigger intrusion detection because they aren't intrusions. They're post-compromise behaviors, and most organizations lack a team to monitor them.
More than 65% of breached accounts had Multi-Factor Authentication enabled at the time of compromise. While MFA prevents unauthorized logins, it doesn't stop attackers who phish one-time passcodes, hijack live sessions, or gain trusted status through digital wallets. Once logged in, security controls quiet down, and fraud controls haven't yet activated.
You're handling cases in this gap.
Why Don't Customers Report Breaches Faster?
Most customers discover breaches themselves. According to Sift's Q2 2026 consumer survey, only 37% of account takeover victims were informed by the company. The rest noticed suspicious activity, heard from others, or got locked out of their accounts.
This is your early warning system: the customer you're about to challenge with additional security steps. If your fraud prevention model can't differentiate between a compromised account and a legitimate customer with changed behavior, you risk blocking the wrong person. The cost isn't trivial. Across the Sift Global Data Network, a false positive costs $135 on average, and up to $496 in Digital Commerce.
What Signals Should Fraud Teams Receive from Security?
Start with session and device telemetry. When an account logs in from a new device, changes recovery email, and updates payment details in the same session, that sequence is crucial. If the fraud system only sees the payment update and the security system only logs the device anomaly, neither team has the full picture.
You also need access to Indicators of Compromise tied to user accounts, not just infrastructure. If security identifies a credential-stuffing wave against specific accounts, fraud should know which accounts were targeted, even if login attempts failed. Failed attempts often precede successful social engineering.
Breach containment timelines should be mapped to customer IDs. If security resets passwords for 5,000 accounts, your fraud model should treat logins from those accounts differently for the next 30 days. This isn't happening in most organizations because the two teams don't share a customer identifier schema.
How to Build Collaboration Between Security and Fraud Teams
You don't need a shared reporting line. You need a shared event definition and regular meetings. Define account takeover as one event with two phases: compromise (security's issue) and monetization (fraud's issue). Create a weekly case review where both teams discuss active incidents that cross boundaries.
The agenda is straightforward: security provides compromised account lists with session context, fraud provides monetization patterns with user linkage data, and both teams map the timeline. You're looking for the gap between containment and loss, and discussing what each team could have done differently with real-time signals from the other.
This isn't a governance committee. It's an operational group that should produce two outcomes weekly: a list of accounts under active investigation by either team, and a shared set of high-risk indicators for both detection systems.
What Metrics Indicate Success?
Measure the time from compromise to fraud team notification. If it's measured in days or weeks, you're still working in silos. If it's in hours, you've established an effective handoff.
The second metric is Mean Global Linkage for your fraud cases. Sift's network data shows that users associated with fraudulent chargebacks have 15.8x higher linkage to coordinated fraud patterns than those without chargebacks. If your fraud cases appear isolated instead of connected, you're missing the network view that security's threat intelligence could provide.
Track these metrics monthly. They'll show whether collaboration is improving outcomes or just adding meetings.
Next Steps
Start with the next puzzling fraud case. The one with a clean transaction history, an aged account, and an unexpected chargeback. Pull the login and session history for that account, then ask your security team if they noticed anything unusual in the 30 days before the disputed transaction.
If the response is "we'd have to check" or "we don't log that," you've identified your first integration point. Build the query together, document your findings, and repeat with a different case next week. You're not building a platform; you're establishing a practice.
The formal process can come later. Right now, you need to prove the gap is real and that closing it enhances visibility for both teams.



