How do investigators recognise account takeover?¶
id: "AI-027" title: "How do investigators recognise account takeover?" series: "Accounts and Identity" content_type: "video-script" status: "draft" owner: "IF Digital"
How do investigators recognise account takeover?¶
Script¶
An account holder says their account was taken over.
What should you look for?
Start with changes in control.
A new password.
A different recovery email address.
A changed telephone number.
A new multi-factor authentication method.
Unknown trusted devices.
Existing sessions suddenly revoked.
Those events can show that somebody was trying to secure the account for themselves and exclude the legitimate user.
Then look at changes in behaviour.
Messages may be sent to unusual contacts.
The language may change.
Payment details may be replaced.
The account may start advertising scams, requesting money or accessing information the genuine user would not normally use.
Login records may also show a change.
A new device.
A new application.
An unfamiliar location.
A different IP history.
But none of those features proves takeover by itself.
People travel, replace devices, use VPNs and change their own settings.
The evidence becomes stronger when several changes happen together and match the time the user reports losing control.
Security notifications can be particularly useful.
Providers may send emails or messages when passwords, recovery details or authentication settings change.
The genuine user's device may retain those alerts even after the account becomes inaccessible.
Also examine the recovery process.
When did the holder first report the problem?
What steps did they take?
Did they regain access?
What did the provider confirm?
Be alert to incomplete or misleading accounts.
A person may claim takeover to distance themselves from activity they carried out.
That does not mean the claim should be dismissed.
It means the claim must be tested against the technical and surrounding evidence.
A convincing takeover timeline usually shows three things.
The account was under the genuine user's control.
A series of security or access changes occurred.
Activity then took place that is consistent with another person controlling the account.
Recognise takeover through evidence of changing control, not merely because the account holder denies the activity.