Skip to content
AI-025 Accounts & Identity

What is an account compromise?


id: "AI-025" title: "What is an account compromise?" series: "Accounts and Identity" content_type: "video-script" status: "draft" owner: "IF Digital"


What is an account compromise?

Script

An account compromise means somebody has gained access to an account, or to information that could allow access, without the legitimate user's permission.

That may involve a stolen password.

It may involve a session cookie, recovery email account, authentication token, trusted device or multi-factor approval.

Sometimes the offender has full control.

Sometimes they have only limited access.

They may be able to read messages but not change the password. They may be able to send content through an existing session but not recover the account. They may have obtained credentials that have not yet been used.

That distinction matters.

Do not treat every compromise as a complete takeover.

Start by identifying what access was actually achieved.

Was there a successful login?

Was an existing session used?

Were recovery details changed?

Was multi-factor authentication disabled?

Were new devices added?

Were messages read, sent or deleted?

Was money moved or account information altered?

Then establish when the compromise began and when it ended.

The legitimate user may have continued using the account while the offender also had access.

Activity from both users may therefore appear in the same period.

Look for security alerts, unfamiliar devices, new sessions, password resets, changed recovery details and unexpected account activity.

The account holder's report is important, but it is not conclusive on its own.

Compare what they say with provider records, device evidence and the timing of the disputed activity.

Also consider whether the claimed compromise is realistic.

Was the password reused elsewhere?

Was there a phishing message?

Was the device infected?

Did someone else have physical access?

A compromise is an alternative explanation for account activity.

It should be tested, not automatically accepted or dismissed.

The key question is not simply whether the account was compromised.

It is what access the intruder obtained, when they obtained it, and which activity can reasonably be attributed to them.


Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.