Account Takeover (ATO)


Back


Definition
Account takeover, or ATO, happens when an attacker gains control of a user’s account by stealing or guessing login credentials. This can happen through phishing, credential stuffing, malware, social engineering, or exposed passwords from a data breach.

Why it matters
Account takeover matters because it can lead to identity theft, financial loss, data exposure, and unauthorized transactions. For businesses, ATO can also increase support costs, damage trust, and create security risks across connected systems.

Example use case
An attacker uses a stolen email and password from a previous data breach to log in to a shopping account. Once inside, they change the shipping address and attempt to make purchases using saved payment details.