← All terms

Account Takeover (ATO)

Account takeover is an attack in which a criminal gains control of a legitimate user account and operates it for fraud, theft, or further attacks.

Account takeover (ATO) is the end state most credential attacks are driving toward: a criminal controls a legitimate account — email, banking, SaaS, or social — and can act as its owner. Unlike a breached database, a taken-over account comes with everything that makes fraud easy: history, contacts, stored payment methods, and the implicit trust of everyone who corresponds with it.

How it works

Attackers reach account takeover through several paths, often combined. Stolen or reused passwords are tested at scale via credential stuffing and password spraying. Phishing pages and adversary-in-the-middle proxies capture credentials and session tokens directly — the mechanics behind many QR-code lures, as covered in our quishing guide. SIM swapping hijacks the phone number used for SMS-based recovery, letting the attacker reset passwords they never knew. Infostealer malware harvests saved browser passwords and cookies in bulk.

Once inside, attackers move deliberately: they set up mailbox rules to hide alerts, register their own MFA device for persistence, harvest data, and pivot. A taken-over corporate email account is the launchpad for business email compromise — payment fraud sent from a genuinely internal address, to colleagues who have no reason to doubt it.

How to defend against it

  • Eliminate password reuse with a password manager, and enable MFA everywhere — preferring phishing-resistant methods (passkeys, security keys) for email and financial accounts, since those anchor recovery for everything else.
  • Harden recovery paths. Remove SMS as a recovery factor where possible; recovery is only as strong as its weakest channel.
  • Monitor for takeover signals — new MFA registrations, mailbox forwarding rules, logins from unfamiliar infrastructure — and revoke active sessions, not just passwords, on compromise.
  • Reduce the credential-theft rate. Most takeovers start with a human handing over a password. Continuous security awareness training and realistic phishing simulations measurably cut that supply.

Related terms

Credential StuffingCredential stuffing is an automated attack that tries username-password pairs stolen from one breach against many other sites, exploiting password reuse.Password SprayingPassword spraying is a brute-force technique that tries a few common passwords against many accounts, staying under lockout thresholds while hunting weak credentials.SIM SwappingSIM swapping is an attack where criminals socially engineer a mobile carrier into transferring a victim's phone number to their SIM, hijacking SMS codes and accounts.Session HijackingSession hijacking is the theft or takeover of an authenticated session — via stolen cookies or tokens — letting an attacker bypass login and MFA entirely.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo