# What is Account Takeover (ATO)?

> Account takeover (ATO) is unauthorized control or effective use of an existing digital account by someone other than the legitimate account holder.

- Canonical URL: https://yellowcube.eu/glossary/account-takeover/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

An attacker may sign in with stolen credentials, hijack an authenticated session, abuse account recovery, persuade support staff to reset access, or change authentication and contact details after gaining an initial foothold.

ATO can affect personal, employee, administrator, service, and supplier accounts. Consequences depend on the account’s permissions and relationships: an attacker may steal data or funds, impersonate the holder, approve transactions, change security settings, scam contacts, or use one trusted account to reach other systems. Response must address both access recovery and any actions taken through the account.

### Key points

- **Warning signs:** Unrecognized sign-ins, profile or recovery changes, new authenticators, unexpected messages or transactions, access from unusual infrastructure, and unexplained loss of access.
- **Prevention:** Use phishing-resistant authentication where practical, protect recovery and help-desk processes, limit privilege, manage sessions, and notify users of sensitive changes.
- **Response:** Revoke sessions and tokens, reset or replace affected authenticators, remove unauthorized changes, review activity, preserve evidence, and check connected accounts and applications.
- **Important limitation:** A successful login is not proof that the legitimate holder is acting. Some takeovers reuse a valid session or recovery path and therefore produce no failed-password or MFA event.

### Related terms

[Identity-based attack](<https://yellowcube.eu/glossary/identity-based-attack/>) · [Login credentials](<https://yellowcube.eu/glossary/login-credentials/>) · [Multi-factor authentication (MFA)](<https://yellowcube.eu/glossary/multi-factor-authentication/>) · [Identity threat detection and response (ITDR)](<https://yellowcube.eu/glossary/identity-threat-detection-and-response/>) · [Business email compromise (BEC)](<https://yellowcube.eu/glossary/business-email-compromise/>) · [Session hijacking](<https://yellowcube.eu/glossary/session-hijacking/>) · [SIM swapping](<https://yellowcube.eu/glossary/sim-swapping/>)

### Sources

[MITRE ATT&CK T1078: Valid Accounts](https://attack.mitre.org/techniques/T1078/) · [FTC: How to Recover a Hacked Email or Social Media Account](https://consumer.ftc.gov/articles/how-recover-your-hacked-email-or-social-media-account) · [NIST SP 800-63B-4: Authentication and Authenticator Management](https://pages.nist.gov/800-63-4/sp800-63b.html)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

