Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is account sharing?

Account sharing is use of one identity by several people, whether approved, tolerated or prohibited. It weakens personal attribution but does not make the recorded activity unusable.

Define the sharing practice

Identify who knew credentials, who was permitted to use them, authentication, devices, locations and whether sessions carry personal sub-identifiers or approval codes. A claim of sharing should identify possible users and explain the real practice.

Shift records, terminal IDs, commands, physical access, communications and application sub-accounts may distinguish operators even when the principal username cannot.

Report accountability and attribution separately

Do not assign activity automatically to the formal owner. Equally, shared use does not end the investigation where contextual evidence identifies a controller.

Sharing may breach policy and represent a control weakness regardless of who performed the disputed act. Record that failure separately so it neither accuses the owner nor becomes a reason to abandon attribution.

Key takeaway

Treat shared-account events as activity by a common identity and build personal attribution from secondary device, session, timing and contextual evidence.

Reference: CIM-240Cyber Incidents & Offender Methods