Account takeover
A criminal seizing control of your email, banking or shopping account and acting as you.
Account takeover is when a criminal gains control of an account that belongs to you — email, banking, shopping, social media — and uses it as though they were you. Email is the prize target, because whoever holds it can reset the passwords to everything else. Attackers get in with credentials leaked in a data breach, guessed from reused passwords via credential stuffing, or captured by phishing.
Once inside they may drain funds, make purchases, harvest personal data for identity theft, or message your contacts to spread the scam further. Signs include being logged out unexpectedly, password-reset or login-alert emails you did not request, unfamiliar transactions, or friends receiving odd messages from you. The two habits that block most takeovers are a unique password for every important account, ideally kept in a password manager, and turning on two-factor authentication so a stolen password alone is not enough. If an account is taken, act fast: regain control, change the password, sign out other sessions, and check what else used the same login. Our guide to identity-theft warning signs covers the clean-up.
Related terms
Data breach
An incident exposing stored personal data, which is then reused to fuel further fraud.
Credential stuffing
Automated attacks that try leaked passwords across many sites, exploiting password reuse.
Phishing
Fraudulent messages that impersonate a trusted brand to steal your passwords, card details or money.
Identity theft
Misuse of your personal details to impersonate you, open credit or commit fraud in your name.