How accounts are taken over
Stolen passwords from phishing or malware, reused passwords tested through credential stuffing, passwords guessed through brute force, stolen session cookies that bypass the login entirely, SIM swapping to intercept SMS codes, and repeated push notifications until the user approves one by mistake, known as MFA fatigue.
What attackers do next
With a business email account, attackers read conversations, set up forwarding rules and send fraudulent payment requests to customers or suppliers, the classic BEC scheme. With cloud or SaaS access, they download data or move to other systems. A compromised administrator account can lead to ransomware.
Warning signs
Logins from unusual countries or devices, impossible travel between locations, new inbox rules, MFA methods added or changed, password reset emails the user did not request, and unexpected messages sent from the account.
Prevention
MFA on every account, preferably methods that resist phishing such as passkeys or security keys. A password manager to avoid reuse. SSO with conditional access policies. Alerts on suspicious logins and inbox rules, and a quick process to lock accounts and revoke sessions when something looks wrong.




