Atlas record

Account Takeover

Account takeover is when an attacker signs in to your email, social media or banking account in your place and takes control of it. A single captured account, an email account above all, can become the key to every other account.

In briefAccount takeover is when an attacker signs in to your online account with details they have stolen or guessed and takes control of it.
How it works
  • The attacker obtains a password through phishing, data leaks or malicious software.
  • They also try the password they have obtained on other accounts opened with the same email address.
  • Once in, they try to shut you out by changing the recovery email, the telephone number and the password.
  • They use the account to transfer money, to send fraudulent messages or to gather personal data.
  • Through the captured account they set new traps for the people close to you in the contact list.
Warning signs
  • Password reset or verification code messages arriving without your asking
  • Sign-in notices from devices and locations you do not recognise
  • Changes in the account settings (recovery address, telephone, forwarding rules) that you did not make
  • Messages you did not send appearing as sent
  • Your password suddenly no longer working
  • People close to you warning you that 'a strange message came from you'
How to protect yourself
  • Turn on two-step verification for all your important accounts, starting with email.
  • Use a different password for each account; a password manager makes that order sustainable.
  • Do not share verification codes with anyone, on any grounds.
  • Look over the sign-in history and the list of connected devices on your accounts from time to time.
  • Use leak notification services to check whether your email address has appeared in past leaks.
  • Close old accounts you no longer use.
If it happens to you
  • If you can still reach the account, change the password immediately and sign out of every device.
  • If you cannot reach it, start the platform's official account recovery process without losing time.
  • Check and put right the recovery details (email, telephone) and any forwarding rules.
  • Change the passwords of all the accounts where the same password was used.
  • Warn the people in your contact list against fake messages that may come from your account.

The most valuable target: email

An email account is the central lock of digital life: the 'forgotten my password' links of all the other accounts go there. That is why the most valuable target for attackers is often not a banking application but email. Once your email is taken, an attacker can reset the passwords of the accounts attached to it one by one; for that reason the strongest protections should be applied to email first.

How do passwords get captured?

Three routes stand out: the password being typed onto a phishing page by the user; a password revealed in another site's data leak being tried on every account where it is the same; and malicious software on the device stealing keystroke records. The first two do not even call for technical knowledge; leak lists and automatic trial tools are readily available. Using the same password in two places is what turns a single leak into the loss of many accounts.

The strength of two-step verification

Two-step verification means a second proof (a code, an application approval or a physical key) is asked for even if the password is captured, and on its own it prevents the great majority of account takeovers. Here is the critical detail: your approval code is a password too, and it is shared with nobody, whoever asks and on whatever grounds. A 'bank official' who asks for your code is, by definition, not an official.

Related terms: Phishing, Fake Text Messages, Malware, Remote Access Scams

From the same atlas

First published: 2026-08-12Last reviewed: 2026-08-12Editorial status: working editionReport an error