Glossary

Account takeover

Also known as: ATO

Account takeover, or ATO, is fraud in which an attacker gains unauthorized control of an existing user account. They use it to steal money or data, make purchases, change account details, or lock out the legitimate user.

Account takeover is a form of identity fraud that targets an account a person already holds, such as a bank, email, retail, telecom, government-service, or social-media account. Unlike new-account fraud, the attacker does not create a false account. They impersonate the real customer to enter an existing one.

Attackers may obtain login credentials through phishing, malware, data breaches, credential stuffing, or social engineering. Credential stuffing is the automated testing of username and password pairs leaked from one service against other services where users may have reused them.

How an account takeover happens

  • A criminal acquires a password, session cookie, one-time passcode, or other authentication factor.
  • They sign in from a new device or location, or hijack an active user session.
  • They may change the email address, phone number, password, or recovery settings to retain control.
  • They use the account to transfer funds, redeem loyalty points, place orders, access personal data, or conduct further fraud.

Role of identity verification

Identity verification can help limit ATO at high-risk moments, such as account recovery, password resets, changes to contact details, new payees, or unusually large transactions. A service may ask for a document check, selfie or liveness check, or other evidence that the person is the legitimate account holder.

IDV is usually one layer of account security rather than a standalone solution. Effective ATO defenses commonly combine risk signals, multi-factor authentication, device and behavioral analysis, transaction monitoring, and clear recovery processes that do not make legitimate users unnecessarily vulnerable to lockout.