What is account takeover?¶
Account takeover is an unauthorised change in effective control of an account or active session.
The attacker may know the password — but they do not have to.
Control can come through stolen sessions, recovery abuse, trusted devices, tokens, consent or already-authenticated access.
Look for the point control changed¶
Useful indicators include:
- new session;
- new device;
- unusual authentication;
- password reset;
- recovery detail change;
- new MFA factor;
- forwarding rule;
- application consent;
- session revocation;
- administrator action.
A timeline is often the clearest way to see it:
That is a much stronger takeover picture than an unusual location alone.
Not every anomaly is takeover¶
Travel, VPN use, shared access, automation and legitimate administration can all produce unfamiliar-looking events.
Use the surrounding account, device and business context.
Containment may not remove every route¶
A password reset may leave:
- sessions;
- refresh tokens;
- trusted devices;
- forwarding rules;
- delegated permissions;
- connected applications.
So record what was actually revoked or changed.
Keep control and person separate¶
The account holder may be:
- the victim;
- an accomplice;
- the offender;
- uninvolved in the disputed session.
How can credentials be stolen? deals with acquisition routes; authentication attacks explains the wider category.
The practical point is: prove when effective control changed, which access route survived and which session performed the disputed activity. Personal attribution comes after that.