GlossarySecurity awareness

Account takeover

Short answer

Account takeover (ATO) is when an attacker gains control of a legitimate user's account, such as email, a cloud application or a bank account, and uses it as if they were the owner. It is often the first step towards fraud, data theft or a wider intrusion.

How accounts are taken over

Stolen passwords from phishing or malware, reused passwords tested through credential stuffing, passwords guessed through brute force, stolen session cookies that bypass the login entirely, SIM swapping to intercept SMS codes, and repeated push notifications until the user approves one by mistake, known as MFA fatigue.

What attackers do next

With a business email account, attackers read conversations, set up forwarding rules and send fraudulent payment requests to customers or suppliers, the classic BEC scheme. With cloud or SaaS access, they download data or move to other systems. A compromised administrator account can lead to ransomware.

Warning signs

Logins from unusual countries or devices, impossible travel between locations, new inbox rules, MFA methods added or changed, password reset emails the user did not request, and unexpected messages sent from the account.

Prevention

MFA on every account, preferably methods that resist phishing such as passkeys or security keys. A password manager to avoid reuse. SSO with conditional access policies. Alerts on suspicious logins and inbox rules, and a quick process to lock accounts and revoke sessions when something looks wrong.

Related terms

Keep reading on this topic

Turning employees into an active line of defence: awareness training, phishing simulation, device and identity hygiene, and SaaS access control.

Go to the topic hub