Skip to content

What is an account takeover?

Account takeover happens when an attacker moves from accessing your account to controlling it. They may change the password, recovery email, and second factor so you cannot get back in. Credential stuffing, phishing, and SIM swapping are common routes to that outcome.

Topic
Attacks
Also called
ATO
Reading time
1 min
Reviewed
On this page

The chain that leads there

Almost every takeover follows the same route: a password is obtained (through a breach, a phishing page, or reuse), it works somewhere, and the attacker then locks down the recovery paths. The critical link is usually your email account, because whoever controls it can reset everything else.

What actually stops it

A unique password per site removes replay. Two-factor authentication means a correct password alone is not enough. An authenticator app or hardware key removes SIM swapping as a route in. Protect the email account first because it can reset almost everything else.

Sources

These primary references support the terminology and current security guidance used in this definition.

Make one account easier today.

Start with the password you keep reusing or the bank card that still shares a PIN. MoolKey is free, and you do not need to move everything at once.

Free forever Works offline Phone or computer