Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is account takeover?

Account takeover is an unauthorised change in effective control of an account or active session.

The attacker may know the password — but they do not have to.

Control can come through stolen sessions, recovery abuse, trusted devices, tokens, consent or already-authenticated access.

Look for the point control changed

Useful indicators include:

  • new session;
  • new device;
  • unusual authentication;
  • password reset;
  • recovery detail change;
  • new MFA factor;
  • forwarding rule;
  • application consent;
  • session revocation;
  • administrator action.

A timeline is often the clearest way to see it:

09:02Known legitimate session active.
09:14New unfamiliar session created.
09:18Recovery email changed.
09:23Existing sessions revoked.
09:31Disputed activity begins.

That is a much stronger takeover picture than an unusual location alone.

Not every anomaly is takeover

Travel, VPN use, shared access, automation and legitimate administration can all produce unfamiliar-looking events.

Use the surrounding account, device and business context.

Containment may not remove every route

A password reset may leave:

  • sessions;
  • refresh tokens;
  • trusted devices;
  • forwarding rules;
  • delegated permissions;
  • connected applications.

So record what was actually revoked or changed.

Keep control and person separate

The account holder may be:

  • the victim;
  • an accomplice;
  • the offender;
  • uninvolved in the disputed session.

How can credentials be stolen? deals with acquisition routes; authentication attacks explains the wider category.

The practical point is: prove when effective control changed, which access route survived and which session performed the disputed activity. Personal attribution comes after that.

Reference: CIM-045Cyber Incidents & Offender Methods