Account Takeover (ATO)
Account takeover is an attack in which a criminal gains control of a legitimate user account and operates it for fraud, theft, or further attacks.
Account takeover (ATO) is the end state most credential attacks are driving toward: a criminal controls a legitimate account — email, banking, SaaS, or social — and can act as its owner. Unlike a breached database, a taken-over account comes with everything that makes fraud easy: history, contacts, stored payment methods, and the implicit trust of everyone who corresponds with it.
How it works
Attackers reach account takeover through several paths, often combined. Stolen or reused passwords are tested at scale via credential stuffing and password spraying. Phishing pages and adversary-in-the-middle proxies capture credentials and session tokens directly — the mechanics behind many QR-code lures, as covered in our quishing guide. SIM swapping hijacks the phone number used for SMS-based recovery, letting the attacker reset passwords they never knew. Infostealer malware harvests saved browser passwords and cookies in bulk.
Once inside, attackers move deliberately: they set up mailbox rules to hide alerts, register their own MFA device for persistence, harvest data, and pivot. A taken-over corporate email account is the launchpad for business email compromise — payment fraud sent from a genuinely internal address, to colleagues who have no reason to doubt it.
How to defend against it
- Eliminate password reuse with a password manager, and enable MFA everywhere — preferring phishing-resistant methods (passkeys, security keys) for email and financial accounts, since those anchor recovery for everything else.
- Harden recovery paths. Remove SMS as a recovery factor where possible; recovery is only as strong as its weakest channel.
- Monitor for takeover signals — new MFA registrations, mailbox forwarding rules, logins from unfamiliar infrastructure — and revoke active sessions, not just passwords, on compromise.
- Reduce the credential-theft rate. Most takeovers start with a human handing over a password. Continuous security awareness training and realistic phishing simulations measurably cut that supply.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo