Account takeover occurs when an unauthorized person gains control of an online account. The intruder may read data, change recovery settings, send scams, make purchases, create ads, or use the account to reach other services.

How accounts are taken over

Common routes include phishing, reused passwords from a data breach, malware, stolen sessions, weak recovery questions, phone-number takeover, and approval of an unexpected authentication prompt.

An attacker may keep access through forwarding rules, connected apps, passkeys, recovery addresses, or sessions even after the password changes.

Warning signs

Look for unfamiliar devices, password or recovery changes, messages you did not send, purchases you did not make, and contacts receiving money requests. A login location is only an estimate, so compare the device, time, and action.

What to do

Use the provider’s official recovery process. Change the password, revoke sessions, remove unknown recovery methods and connected apps, and enable two-factor authentication. Secure the email and mobile-carrier account used for recovery.

Warn contacts about fraudulent messages. Contact financial institutions for unauthorized activity and report work accounts to the organization’s security team.