Skip to content
Skip to main content
Accounts & Identity Operational Explainer

How do investigators recognise account takeover?

Look for a timed change in account control, not just an unusual login or a denial from the account holder.

A convincing takeover picture usually combines security changes, new access routes and activity that fits the new controller.

Start with the security events

Useful signs include:

  • password reset;
  • recovery email or phone change;
  • new MFA factor;
  • unknown trusted device;
  • session revocation;
  • security alerts;
  • new application access; and
  • sudden loss of access by the genuine user.

One event can have an innocent explanation. Several connected changes in a short period are much more useful.

Then look at what the account did

After the suspected control change, ask whether the account:

  • sent unusual messages;
  • changed payment details;
  • contacted unfamiliar people;
  • downloaded or accessed new material;
  • altered account settings;
  • or behaved outside the holder's normal role.

A takeover timeline might look like:

08:55Normal holder session active.
09:11New unfamiliar session appears.
09:14Recovery email changed.
09:22Disputed messages begin.
09:40Holder reports loss of access.

That gives you a sequence to test.

Test the holder's explanation

Ask when they noticed the problem, what alerts they saw, what devices they were using and what they did next.

Then compare that account with:

  • provider security logs;
  • holder devices;
  • phishing messages;
  • malware evidence;
  • network records; and
  • recovery history.

A genuine takeover claim should fit the technical timeline.

A false claim should be tested against exactly the same evidence.

Allow for concurrent access

The account holder and intruder may both be active.

That means some events may be clear while others remain uncertain.

Do not force every event into one user's column simply because takeover has been established.

The practical point is: recognise takeover through the sequence from genuine control to new access and security change, then attribute each disputed event using the session and device evidence around it.

Reference: AI-027Accounts & Identity