166 terms · 75/46/45
Threat № 021 · class: identity

Account Takeover

Account takeover is the moment the attacker gains full control of an account — not only access, but the ability to change the password, the recovery mail address, the phone number and the second factor, while the real owner is shut out with no technical way back in on their own. Takeover is rarely the first stage of an attack. It is usually the destination of what came before: phishing, credential stuffing, token theft.

Term

description · examples · notes

Account takeover is the moment the attacker gains full control of an account — not only access, but the ability to change the password, the recovery mail address, the phone number and the second factor, while the real owner is shut out with no technical way back in on their own. Takeover is rarely the first stage of an attack. It is usually the destination of what came before: phishing, credential stuffing, token theft.

Description

With an account taken over, the attacker can do everything the owner can, only in their own favor: speak for the owner, buy and pay in their name, reach documents and services, steer people to malicious content, send fake invoices, deliver malware — all while the owner's contacts trust it, because the account is genuine. The most dangerous part is what follows: a taken-over mail address opens the door to password resets on every other service. The reach of the damage can be enormous, up to a complete takeover of a digital identity.

The defense rests mostly on two-factor authentication — when a password leaks, the attacker is still stopped at the second factor, with the caveat that weaker forms of it can be bypassed, so stronger ones are worth considering: phishing-resistant models and hardware keys. Alongside that, alerts have to be set up so they react to changes in recovery details (mail, phone) and to logins from new locations and devices, and any faster route to recovering a taken-over account belongs in place while there is still time. This problem is far easier to prevent than to cure.

Examples

  • The attacker takes over the victim's mail account and through it sends fake invoices and payment orders to business contacts and colleagues, who usually pay without further checks because they arrive from a familiar address.
  • Once an attacker changes the recovery address and phone on a social network, the owner rarely gets the account back, if at all. What usually follows is a new account and building from scratch, which is particularly painful for business accounts.
  • By taking over an employee's account, the attacker already has one foot inside the organization's systems, which is worth far more than the account itself.

Notes

  • Account takeover is more often a consequence than a cause. Phishing, credential stuffing and token theft are the roads that lead to it.
  • The main mail account, business or private, is the attacker's key to everything: with it they can reset the passwords of every other service. Every security measure available belongs on that one.

Mentioned in the news

Composite
MITRE ATT&CK

Techniques

carried out with 6

Defenses

countered by 6