Skip to content
CIM-045 Cyber Incidents & Offender Methods

What is account takeover?

Account takeover occurs when someone gains unauthorised control of an account or its active session.

Avoid the dangerous assumption

The dangerous assumption is that account takeover always begins with the attacker learning the password.

It may instead involve:

  • stolen credentials
  • session hijacking
  • token theft
  • password reset abuse
  • compromised recovery channels
  • malicious application consent
  • SIM-swap-assisted recovery
  • remote control of a trusted device
  • misuse of an already authenticated session.

The key investigative question is when effective control changed.

That may be indicated by:

  • new sign-in locations
  • new devices
  • unfamiliar sessions
  • password or recovery changes
  • new forwarding rules
  • application-consent events
  • unexpected multi-factor approvals
  • new administrative actions
  • changes in user behaviour.

Do not treat every unusual login as takeover. Travel, VPN use, shared access, automation, service accounts and legitimate administration may create similar records.

Equally, do not assume takeover ended when the password was reset. Active sessions, refresh tokens, application permissions, mailbox rules or other persistence may remain.

Preserve the identity-provider records, session information, device details, account changes, user reports and containment actions.

Keep account attribution separate from personal attribution. Evidence may show that an account performed an action. It may not show who controlled the account at that moment.

The account holder may be the victim, an accomplice, a careless user or the offender. That requires corroboration.

Where the account was used for several purposes, identify which functions were actually taken over. An offender may control email while lacking access to another linked service, or may hold one active session without controlling the full account.

Operational takeaway

Treat account takeover as a change in effective control, identify when that change occurred and preserve the evidence of both access and persistence.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.