What it is
Account takeover is when an attacker takes control of one of your accounts (email, social, bank, work tools) using stolen credentials, stolen sessions or recovery procedures. The account is then used to scam your contacts, steal data or make purchases.
How it works
- 1The attacker obtains credentials through phishing, infostealers or credential stuffing.
- 2They get into the account and change the password and recovery address to keep it.
- 3They write to your contacts with your identity or exploit connected services.
- 4The account may be resold or used as a base for other attacks.
How to spot it
- Your password no longer works
- Sign-in alerts from unusual places or devices
- Messages or emails sent that you did not write
- Recovery address, forwarding or settings changed
How to defend
- A different password for every account, with a password manager
- Passkeys or multi-factor authentication with an app, not just SMS
- Protect your main email above all: the other accounts are recovered from it
- Check connected devices and recent sign-ins from time to time
- Keep security alerts on for the services you use
If you think you have been hit
- Try to recover the account through the service’s official process
- Change your main email’s password first, then the others
- Revoke sessions and connected apps, and warn your contacts
- Report to the platform and, if money was lost, report to the police
And there are many, many more
The attacks above are only some of the most common: there are hundreds, and new ones appear every week. If the one that concerns you is not among them, write to me: I will tell you whether it really affects you and how to defend.
Contact meOther attacks
Watch the Shorts on YouTubeMatteo Russo · Updated October 2026