Skip to content
Skip to main content
Accounts & Identity Technical Explainer

What is an account compromise?

An account is compromised when somebody gains unauthorised access to a credential, session, recovery route or other account authority.

That can range from obtaining a password that is never used to actively reading messages, sending content or changing security settings.

So when somebody says “the account was compromised”, the useful question is:

What unauthorised access was actually obtained, and what did it allow?

Compromise can happen at different levels

An intruder might obtain:

  • a password;
  • an active session cookie;
  • a refresh token;
  • access to a trusted device;
  • access to the recovery email or phone;
  • a fraudulent MFA approval; or
  • control of a linked application.

These routes do not all give the same level of control.

Credential exposedPassword or token obtainedPotential authority exists.
Unauthorised accessAccount or session usedProvider records suspicious activity.
Control changesRecovery, MFA or sessions alteredThe intruder may gain persistence or exclude the holder.

The last stage begins to look more like account takeover.

Build the compromise timeline

Useful evidence may include:

  • failed and successful logins;
  • new sessions;
  • security alerts;
  • password changes;
  • recovery changes;
  • MFA changes;
  • trusted devices;
  • new applications;
  • messages or transactions; and
  • session revocation.

Try to identify:

  1. last clearly genuine activity;
  2. first suspicious access;
  3. any security/control changes;
  4. disputed account activity;
  5. the point access ended or was recovered.

The legitimate user may still be active

Compromise does not always mean the genuine user is locked out.

Both may use the account at the same time.

That is why labelling the whole account “compromised” is not enough for event attribution.

A message sent at 10:14 and a payment approved at 11:02 may come from different sessions.

Test the compromise explanation

A genuine account holder may report phishing, unexpected MFA prompts or loss of access.

Compare that account with provider logs, the holder's devices, phishing material, malware evidence and the disputed events.

Do not simply accept or reject the claim.

The practical point is: define the unauthorised authority, when it existed and which account events it can actually explain.

Reference: AI-025Accounts & Identity