Account Takeover
Account takeover is the moment the attacker gains full control of an account — not only access, but the ability to change the password, the recovery mail address, the phone number and the second factor, while the real owner is shut out with no technical way back in on their own. Takeover is rarely the first stage of an attack. It is usually the destination of what came before: phishing, credential stuffing, token theft.
Term
description · examples · notesAccount takeover is the moment the attacker gains full control of an account — not only access, but the ability to change the password, the recovery mail address, the phone number and the second factor, while the real owner is shut out with no technical way back in on their own. Takeover is rarely the first stage of an attack. It is usually the destination of what came before: phishing, credential stuffing, token theft.
Description
With an account taken over, the attacker can do everything the owner can, only in their own favor: speak for the owner, buy and pay in their name, reach documents and services, steer people to malicious content, send fake invoices, deliver malware — all while the owner's contacts trust it, because the account is genuine. The most dangerous part is what follows: a taken-over mail address opens the door to password resets on every other service. The reach of the damage can be enormous, up to a complete takeover of a digital identity.
The defense rests mostly on two-factor authentication — when a password leaks, the attacker is still stopped at the second factor, with the caveat that weaker forms of it can be bypassed, so stronger ones are worth considering: phishing-resistant models and hardware keys. Alongside that, alerts have to be set up so they react to changes in recovery details (mail, phone) and to logins from new locations and devices, and any faster route to recovering a taken-over account belongs in place while there is still time. This problem is far easier to prevent than to cure.
Examples
- The attacker takes over the victim's mail account and through it sends fake invoices and payment orders to business contacts and colleagues, who usually pay without further checks because they arrive from a familiar address.
- Once an attacker changes the recovery address and phone on a social network, the owner rarely gets the account back, if at all. What usually follows is a new account and building from scratch, which is particularly painful for business accounts.
- By taking over an employee's account, the attacker already has one foot inside the organization's systems, which is worth far more than the account itself.
Notes
- Account takeover is more often a consequence than a cause. Phishing, credential stuffing and token theft are the roads that lead to it.
- The main mail account, business or private, is the attacker's key to everything: with it they can reset the passwords of every other service. Every security measure available belongs on that one.
Mentioned in the news
- 28. MAR 2026. Evropska komisija istražuje upad u AWS okruženje nakon kompromitacije naloga →
- 14. MAR 2026. Kritična ranjivost u LangSmith platformi omogućava preuzimanje naloga →
- 11. MAR 2026. Holandska vlada upozorava na otmicu naloga na Signal i WhatsApp servisima →
- 18. FEB 2026. GhostPairing: napad koji zloupotrebljava povezivanje uređaja na WhatsApp-u →
- 19. JAN 2026. Nemačka upozorava na preuzimanje Signal naloga visokih zvaničnika →
- 29. JUN 2026. Ruski akteri love Signal i WhatsApp naloge, SAD nude 10 miliona dolara za informacije →
- 19. MAJ 2026. Tycoon2FA preuzima Microsoft 365 naloge preko device-code phishinga →
- 7. MAJ 2026. Google Ads zloupotrebljen za phishing GoDaddy ManageWP naloga →
- 5. MAJ 2026. Google AppSheet zloupotrebljen u phishing kampanji za krađu Facebook naloga →
- 30. APR 2026. Nemačka sumnja na rusku Signal phishing kampanju protiv zvaničnika →
- 19. APR 2026. Još jedan učesnik napada na DraftKings osuđen na zatvor →
- 15. APR 2026. Krađa sesionih kolačića: zašto MFA nije dovoljna posle prijave →
- 14. APR 2026. Napadi na Okta naloge sve češće idu preko help deska i MFA resetovanja →
- 4. APR 2026. Device code phishing napadi eksplodirali kako se šire novi phishing kitovi →
- 2. APR 2026. EvilTokens olakšava device code phishing napade na Microsoft naloge →
- 29. MAR 2026. Iranom povezani akteri probili privatni mejl direktora FBI i pogodili Stryker wiper napadom →
- 13. MAR 2026. Meta uvodi upozorenja za sumnjive zahteve za prijateljstvo i prevare →
- 11. MAR 2026. Lažne ChatGPT i Gemini iOS aplikacije kradu Facebook naloge →
- 4. MAR 2026. Ransomver grupe sve više koriste krađu identiteta i AI alate →
- 17. FEB 2026. Zlonamerna Chrome ekstenzija krade 2FA kodove i podatke iz Facebook Business Manager-a →
Techniques
carried out with 6Techniques used to carry it out. Select one to open its page.
Defenses
countered by 6How it is defended against. Select one to open its page.