Skip to content
Skip to main content
Accounts & Identity Technical Explainer

What is account takeover?

Account takeover is a compromise where somebody else gains practical control of the account.

That may mean changing the password or recovery details, adding a new authentication factor, removing trusted sessions or locking the genuine user out.

The key idea is the shift in control.

Look for the control change

Useful provider events include:

  • password reset;
  • recovery email or phone change;
  • new MFA enrolment;
  • trusted-device enrolment;
  • session revocation;
  • application consent;
  • security-setting changes; and
  • account-recovery activity.

A simple sequence might be:

Example takeover sequence
09:11 · unfamiliar session created09:14 · recovery email changed09:16 · new authenticator added09:18 · existing sessions revoked09:22 · disputed messages begin

That is much more persuasive than a single unusual login.

Takeover does not always mean lockout

Some intruders deliberately avoid changing settings.

They may continue using the account quietly while the genuine holder remains active.

So loss of access is strong evidence when present, but it is not essential.

Attribute events by time and session

Once control has shifted, do not automatically assign every later event to the intruder.

An older legitimate session may survive.

The genuine holder may regain access.

Two people may use the account during the same period.

BeforeKnown genuine controlNormal devices, factors and sessions.
TransitionSecurity/control changesRecovery, factors or sessions altered.
AfterDisputed activityAttribute each event to its session and device.

How do investigators recognise account takeover? develops the practical indicators.

The practical point is: account takeover is a demonstrable change in practical control. Reconstruct that transition, then attribute later activity event by event.

Reference: AI-026Accounts & Identity