What is account takeover?¶
Account takeover is a compromise where somebody else gains practical control of the account.
That may mean changing the password or recovery details, adding a new authentication factor, removing trusted sessions or locking the genuine user out.
The key idea is the shift in control.
Look for the control change¶
Useful provider events include:
- password reset;
- recovery email or phone change;
- new MFA enrolment;
- trusted-device enrolment;
- session revocation;
- application consent;
- security-setting changes; and
- account-recovery activity.
A simple sequence might be:
That is much more persuasive than a single unusual login.
Takeover does not always mean lockout¶
Some intruders deliberately avoid changing settings.
They may continue using the account quietly while the genuine holder remains active.
So loss of access is strong evidence when present, but it is not essential.
Attribute events by time and session¶
Once control has shifted, do not automatically assign every later event to the intruder.
An older legitimate session may survive.
The genuine holder may regain access.
Two people may use the account during the same period.
How do investigators recognise account takeover? develops the practical indicators.
The practical point is: account takeover is a demonstrable change in practical control. Reconstruct that transition, then attribute later activity event by event.