Skip to content
AI-026 Accounts & Identity

What is account takeover?


id: "AI-026" title: "What is account takeover?" series: "Accounts and Identity" content_type: "video-script" status: "draft" owner: "IF Digital"


What is account takeover?

Script

Account takeover is a form of compromise in which another person gains enough control to operate the account as if they were the legitimate user.

They may change the password.

Replace the recovery email address.

Take control of the telephone number.

Add their own authentication device.

Remove existing sessions.

Lock the genuine user out.

At that point, the offender is not merely accessing the account.

They are controlling it.

Account takeover may be used to contact victims, steal money, access private information, impersonate the holder or exploit trust already attached to the account.

The takeover may be obvious.

The legitimate user may suddenly lose access.

But some offenders avoid changing anything because they want to remain hidden.

They may continue using the account alongside the genuine holder.

For investigators, the first task is to identify the control changes.

When was the password reset?

When were recovery details altered?

Were new devices or authentication methods added?

Were previous sessions revoked?

Did the provider record unusual login locations or security alerts?

Then compare those events with the disputed activity.

A message sent after the offender changed the recovery details may be more likely linked to the takeover than a message sent months earlier.

Do not assume that every action after a takeover was performed by the offender.

The legitimate user may still have had an active session or later regained access.

Build a timeline.

Include the last clearly genuine activity, the first suspicious event, the account-control changes, the disputed activity and the recovery of the account.

Account takeover is not just a login.

It is a change in practical control.

The strongest evidence usually comes from showing how control moved from the legitimate user to the intruder and what the intruder did once that control was obtained.


Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.