Account Takeover
Account takeover is when an attacker signs in to your email, social media or banking account in your place and takes control of it. A single captured account, an email account above all, can become the key to every other account.
| In brief | Account takeover is when an attacker signs in to your online account with details they have stolen or guessed and takes control of it. |
|---|---|
| How it works |
|
| Warning signs |
|
| How to protect yourself |
|
| If it happens to you |
|
The most valuable target: email
An email account is the central lock of digital life: the 'forgotten my password' links of all the other accounts go there. That is why the most valuable target for attackers is often not a banking application but email. Once your email is taken, an attacker can reset the passwords of the accounts attached to it one by one; for that reason the strongest protections should be applied to email first.
How do passwords get captured?
Three routes stand out: the password being typed onto a phishing page by the user; a password revealed in another site's data leak being tried on every account where it is the same; and malicious software on the device stealing keystroke records. The first two do not even call for technical knowledge; leak lists and automatic trial tools are readily available. Using the same password in two places is what turns a single leak into the loss of many accounts.
The strength of two-step verification
Two-step verification means a second proof (a code, an application approval or a physical key) is asked for even if the password is captured, and on its own it prevents the great majority of account takeovers. Here is the critical detail: your approval code is a password too, and it is shared with nobody, whoever asks and on whatever grounds. A 'bank official' who asks for your code is, by definition, not an official.
Related terms: Phishing, Fake Text Messages, Malware, Remote Access Scams