AI Tasks

AI Task Spotlight | Edition No. 08: Account Takeover — Before vs. After Access Change

Published
August 18, 2026
Read Time
7
mins
Gal Perelman
Gal Perelman
Product Marketing Lead, Unit21
Subscribe to stay informed
Table of contents

Every two weeks, we spotlight an AI task from Unit21's task library, something many compliance and fraud teams are configuring and running inside their workflows today.

This edition is a live build, the same way Edition 06 was. Instead of a shipped capability, this is an Alert AI Agent created from nothing, on camera, given a single plain-English instruction, and backtested against two real alerts before either one meant anything for a live queue. The task is a before/after account takeover comparison, and what makes it worth watching isn't the build. It's what the agent finds when the two alerts turn out to be nothing alike.

Why "Before vs. After" Is the Only Question That Matters in ATO

Every account takeover investigation reduces to one question: is the activity after the reported access change still the account holder? Not the transaction that triggered the alert in isolation, the transaction in the context of everything the customer did before.

Answering that by hand means pulling the full transaction history, finding the moment access changed, splitting the data at that point, and comparing both sides across volume, amount, frequency, currency, and flagged activity. That's real work, and it's the kind that gets compressed under caseload pressure into a glance at whatever's most recent, which is exactly the wrong instinct when the whole point is to see the shift.

It's also work that resists a one-size-fits-all answer, because the two alerts in this backtest prove it. One looks like a takeover from a distance. The other looks like nothing until you compare it to itself.

Introducing Unit21's AI Task: Account Takeover Before/After Analysis

Account Takeover Before/After Analysis: What it does

This task was configured in a single instruction, typed directly into the Agentic Task Builder: compare a customer's transaction pattern before and after the reported account access change, using the first flagged transaction as the pivot point, and summarize whether the post-change behavior is consistent with the account holder. No SQL, no schema knowledge, no engineering ticket.

From there, the agent did the mapping itself. It found the linked entities on each alert, explored the transaction schema, identified the first flagged transaction as the pivot for that specific alert, and computed the full set of before/after statistics on both sides of it.

The agent automatically reviews:

  • The full transaction history per flagged entity, split at the first flagged transaction
  • Transaction count, average, minimum, and maximum amount, and total volume on each side of the pivot
  • Monthly transaction frequency before and after, so a change in pace is visible even when amounts aren't
  • Currency footprint on each side, including currencies that quietly stop appearing
  • Flagged transaction count in each period as a proportion of that period's total activity

Account Takeover Before/After Analysis: What the agent outputs

  • A before/after comparison table, every metric side by side, with the date range and period length for each side, so the shift is visible instead of assembled by hand
  • Key observations in plain language, naming the specific dimensions that moved and by how much
  • A consistency assessment that states plainly whether the post-change pattern holds up against the account holder's history, and names its own strongest evidence rather than listing every metric with equal weight
  • A quality check on its own output before the summaries are accepted, confirming the requested metrics were actually returned and the conclusion is grounded in the data behind it

Account Takeover Before/After Analysis: Why this matters

The backtest is where this task earns its keep, because the two alerts don't agree with each other at all.

The first is loud. Monthly transaction frequency rose 68%. Average transaction size climbed 26%. The minimum transaction jumped from $149.02 to $64,323.81, which means the small-value activity that had always been present simply stopped, and a floor appeared where one had never existed. That's the kind of shift an analyst would catch on a first read.

The second is quiet, and this is the one worth paying attention to. Monthly transaction frequency actually declined, from 2.11 transactions a month to 1.55. Average transaction amount rose only modestly and stayed within the account's historical range. The currency profile before and after was identical: the same five currencies, in the same order, with nothing new and nothing missing. Skimmed under caseload pressure, this alert reads as unremarkable, the kind that gets a quick "consistent" and moved along.

The agent didn't skim it. Across more than five years and 140 transactions, zero were flagged. In the period after the access change, all 10 transactions were flagged. It named that discontinuity as the primary indicator of anomalous activity, above the noisier metrics, and concluded the post-change pattern was not consistent with the account holder's history, on that alert, the same way it did on the loud one.

That's the argument for building this check instead of relying on a reviewer's read of the transaction feed. Consistency isn't just faster. It's a task that treats the quiet alert with the same rigor as the obvious one, on alert two just as much as alert one, and on alert two hundred the same as alert two.

Because it's built with Unit21's Agentic Task Builder, this runs inside your existing workflow, in plain English, with no engineering ticket and no waiting on a template that doesn't quite fit your definition of "before" and "after." And because every step of its reasoning stays visible, investigators can act on its findings, challenge them, or escalate them with the backing to defend that decision under examination.

The comparison gets done. Your investigators make the call.

About the AI Task Spotlight Series

The AI Task Spotlight runs every two weeks. Each edition covers one task from Unit21's library, covering what it does, how it works, and who it's for. If a task is solving a real problem for one team, it can probably solve the same problem for yours.

Want to learn more? Sign up for a demo of our AI. Alternatively, stay informed of our AI by signing up for our next AI Task Spotlight.

Gal Perelman
Gal Perelman
Product Marketing Lead, Unit21

Gal Perelman is the Product Marketing Lead at Unit21, where she spearheads go-to-market strategies for AI-driven risk and compliance solutions. With over a decade of experience in the fintech and fraud sectors, she has led high-impact launches for products like Watchlist Screening and AI Rule Recommendations.

Previously, Gal held marketing leadership roles at Design Pickle, Sightfull, and Lusha. She holds a Master’s degree from American University and a Bachelor’s from UCLA, and is dedicated to helping banks and fintechs navigate complex regulatory landscapes through innovative technology.

Learn more about Unit21
Unit21 is the leader in AI Risk Infrastructure, trusted by over 200 customers across 90 countries, including Sallie Mae, Chime, Intuit, and Green Dot. Our platform unifies fraud and AML with agentic AI that executes investigations end-to-end—gathering evidence, drafting narratives, and filing reports—so teams can scale safely without expanding headcount.
Risk and Compliance Operations
|
5
min

Progressive autonomy: the trust ladder for AI in compliance

Gal Perelman
Gal Perelman
Product Marketing Lead, Unit21
This is some text inside of a div block.
Unit21 for Crypto
|
5
min

Gate US leads in one of the fastest-growing corners of crypto, with Unit21’s flexibility and real-time detection by its side

Cassie Pallesen
Cassie Pallesen
VP, Marketing
This is some text inside of a div block.
AI Risk Infrastructure
|
7
min

Building the accountability framework for AI in financial crime: what regulators will ask

Tyler Allen
Tyler Allen
CEO, Unit21
This is some text inside of a div block.
See Us In Action

Boost fraud prevention & AML compliance

Fraud can’t be guesswork. Invest in a platform that puts you back in control.
Get a Demo