What is an account takeover?
Account takeover happens when an attacker moves from accessing your account to controlling it. They may change the password, recovery email, and second factor so you cannot get back in. Credential stuffing, phishing, and SIM swapping are common routes to that outcome.
- Topic
- Attacks
- Also called
- ATO
- Reading time
- 1 min
- Reviewed
On this page
The chain that leads there
Almost every takeover follows the same route: a password is obtained (through a breach, a phishing page, or reuse), it works somewhere, and the attacker then locks down the recovery paths. The critical link is usually your email account, because whoever controls it can reset everything else.
What actually stops it
A unique password per site removes replay. Two-factor authentication means a correct password alone is not enough. An authenticator app or hardware key removes SIM swapping as a route in. Protect the email account first because it can reset almost everything else.
Sources
These primary references support the terminology and current security guidance used in this definition.
