Attack outcomes
Account takeover
Also called: ATO
Account takeover is an attack in which someone gains control of a legitimate user's account, such as email, banking, payroll or social media, and uses it as their own. The attacker may change the password and recovery details to lock the owner out, then steal money or data or use the account's trust to target others.
How it works
Takeovers start with stolen credentials, phishing, SIM swaps, session theft or tricking a support agent into a reset. Once in, attackers often change the email address, phone number and MFA method so alerts go to them. Financial accounts are drained quickly, while email accounts are kept quietly for fraud.
A real example
In November 2025 the FBI said its Internet Crime Complaint Center had received more than 5,100 complaints reporting account takeover fraud since January 2025, with losses exceeding $262 million.
Source: Account Takeover Fraud via Impersonation of Financial Institution Support (I-112525-PSA) — FBI Internet Crime Complaint Center (IC3), 2025-11-25
How to stop it
Use phishing-resistant MFA, require strong verification before changing recovery details or MFA methods, and alert account owners on every such change.
Related terms
Threat actors that use it
- Scattered Spider
Profile with government sources
Sources
- Account Takeover Fraud via Impersonation of Financial Institution Support (I-112525-PSA) — FBI Internet Crime Complaint Center (IC3), 2025-11-25
Last reviewed Oct 2, 2026