Technique
Account Takeover
Also known as: ATO, ATO Fraud, Account Hijacking, Credential Stuffing Attack, Account Compromise
EXPLOITATION
Gaining unauthorized access to victim's online accounts using stolen credentials.
Common attack flows
How it fits in a scam
This technique shows up duringEXPLOITATION
Defense
How to defend against this
How to spot it
- Unexpected password change or recovery email notifications
- Login alerts from unfamiliar devices or locations
- Unauthorized transactions or account changes
- Unprompted MFA/2FA requests you didn't initiate
- New email forwarding rules you didn't create
- Missing expected notifications (attacker deleting alerts)
- Unable to log in with known-good password
- Unfamiliar linked devices or sessions in account settings
Seen in the wild
Where we’ve seen it
Commonly targets
Further reading