How do investigators recognise account takeover?¶
Look for a timed change in account control, not just an unusual login or a denial from the account holder.
A convincing takeover picture usually combines security changes, new access routes and activity that fits the new controller.
Start with the security events¶
Useful signs include:
- password reset;
- recovery email or phone change;
- new MFA factor;
- unknown trusted device;
- session revocation;
- security alerts;
- new application access; and
- sudden loss of access by the genuine user.
One event can have an innocent explanation. Several connected changes in a short period are much more useful.
Then look at what the account did¶
After the suspected control change, ask whether the account:
- sent unusual messages;
- changed payment details;
- contacted unfamiliar people;
- downloaded or accessed new material;
- altered account settings;
- or behaved outside the holder's normal role.
A takeover timeline might look like:
That gives you a sequence to test.
Test the holder's explanation¶
Ask when they noticed the problem, what alerts they saw, what devices they were using and what they did next.
Then compare that account with:
- provider security logs;
- holder devices;
- phishing messages;
- malware evidence;
- network records; and
- recovery history.
A genuine takeover claim should fit the technical timeline.
A false claim should be tested against exactly the same evidence.
Allow for concurrent access¶
The account holder and intruder may both be active.
That means some events may be clear while others remain uncertain.
Do not force every event into one user's column simply because takeover has been established.
The practical point is: recognise takeover through the sequence from genuine control to new access and security change, then attribute each disputed event using the session and device evidence around it.