What evidence may show the point at which control changed?¶
In an account takeover investigation, one of the most important questions is when effective control changed from the legitimate user to someone else.
Avoid the dangerous assumption¶
The dangerous assumption is that the first suspicious action must be the moment of takeover.
The account may have been compromised earlier and used quietly before obvious activity appeared.
Possible indicators of a control change include:
- a new device or browser
- a new session
- an unusual authentication event
- password or recovery changes
- new forwarding or inbox rules
- application-consent events
- multi-factor changes
- unexpected account settings
- new API or administrative activity
- a change in normal behaviour.
Compare the suspicious activity with the account’s established pattern.
Ask the legitimate user what they did, which devices they used and when they first noticed a problem.
Do not rely only on location. VPNs, mobile networks, travel and corporate infrastructure can alter apparent geography.
Look for clusters of evidence.
A new session followed by recovery changes, rule creation and data access may be more persuasive than one isolated login.
Also preserve containment events. Password resets, session revocation and account restoration may help define when legitimate control was re-established.
The exact point may remain uncertain. In that case, report a time window rather than inventing precision.
Keep personal attribution separate. Evidence may show that account control changed, but not who gained control.
Shared access, remote control, automation and compromised service accounts may complicate the sequence.
Operational takeaway¶
Use authentication, session, device, account-change and user evidence to define the earliest supported window in which effective control changed.