Account takeover occurs when an unauthorized person gains control of an online account. The intruder may read data, change recovery settings, send scams, make purchases, create ads, or use the account to reach other services.
How accounts are taken over
Common routes include phishing, reused passwords from a data breach, malware, stolen sessions, weak recovery questions, phone-number takeover, and approval of an unexpected authentication prompt.
An attacker may keep access through forwarding rules, connected apps, passkeys, recovery addresses, or sessions even after the password changes.
Warning signs
Look for unfamiliar devices, password or recovery changes, messages you did not send, purchases you did not make, and contacts receiving money requests. A login location is only an estimate, so compare the device, time, and action.
What to do
Use the providerâs official recovery process. Change the password, revoke sessions, remove unknown recovery methods and connected apps, and enable two-factor authentication. Secure the email and mobile-carrier account used for recovery.
Warn contacts about fraudulent messages. Contact financial institutions for unauthorized activity and report work accounts to the organizationâs security team.