SardineCon SF/2026

Learn More
Fraud types4 min read

What is Account takeover (ATO)?

SUBSCRIBE

Account takeover is when a fraudster seizes control of a real customer's account, usually through stolen passwords, credential stuffing, a SIM swap, phishing, or by tricking support staff. Because the account is already trusted, the theft can move fast before anyone notices.

What is account takeover, in plain English?

Account takeover, usually shortened to ATO, is theft of access to an account that belongs to a real, legitimate customer. The fraudster does not create anything new; they hijack something that already exists and is already trusted. Once inside, they can drain balances, add payees, redeem rewards, order goods, or harvest the personal data needed to attack other accounts.

The reason ATO is so dangerous is that the account carries built-in trust. The customer has history, verified details, and a clean track record, so alerts that would fire on a brand-new account stay quiet. The fraudster inherits all of that reputation and uses it as cover, which is why speed matters: the goal is to cash out before the real owner or the bank realizes anything is wrong.

ATO sits at the center of the fraud world because it is a means to almost every other end. A taken-over account can fund scams, move mule money, place fraudulent orders, or serve as a launchpad for further attacks. Stopping it is less about the login itself and more about spotting the changes and actions that follow a compromised login.

How a takeover unfolds

  1. Access — Get the credentials. Stolen passwords, credential stuffing, phishing, or a SIM swap give the fraudster a way in.
  2. Enter — Log in as the victim. The login often comes from a new device or location, but with correct credentials it can look valid.
  3. Lock out — Change the details. Email, phone, or password are changed and alerts are turned off, cutting the real owner out.
  4. Cash out — Move the value. A new payee is added and funds, rewards, or goods are pushed out fast before detection.

How attackers get in

Method

How it works

Credential stuffing

Reused passwords from past breaches are replayed at scale until some accounts open.

Phishing

A fake login page or message tricks the customer into handing over credentials or a one-time code.

SIM swap

The attacker ports the victim's number to their own SIM, intercepting SMS codes and resets.

Support social engineering

The fraudster cons a call center agent into resetting access or changing contact details.

What it looks like in practice

In practice

At two in the morning, a customer's account is accessed from a device and city never seen on it before. Within minutes the account email is changed, then the phone number, and the login alerts are switched off. The real owner, asleep, gets no working notification because the contact details now point at the fraudster.

A few minutes later a new payee is added and a transfer for most of the balance is set up. This is the classic ATO signature: a changed email or phone followed almost immediately by a new payee and a cash-out. Behavioral biometrics flagged the session as not matching the owner's normal typing and navigation, and the payment is held for step-up verification, which the fraudster cannot pass.

Why it matters to operators

ATO losses are large, fast, and reputationally toxic, because the victim is a real customer who did nothing wrong and will remember how you handled it. Unlike new-account fraud, you cannot decline your way out at the door, since the login uses genuine credentials. Detection has to lean on the signals around the login and the actions after it: a new device or location, a contact change, disabled alerts, and a rapid payee-then-payment sequence.

The single most useful pattern to alert on is a changed email or phone right before a cash-out. Attackers change contact details first so the victim never sees the alerts, which means a contact change followed quickly by a payment is one of the highest-signal sequences in fraud. Layer behavioral biometrics, device fingerprinting, and step-up on risky changes, and most takeovers can be stopped between the login and the loss.

What to watch

  • New device or location at login. A first-seen device or an impossible-travel jump on an established account deserves scrutiny.
  • Contact change then payment. An email or phone change followed quickly by a new payee or transfer is the signature cash-out sequence.
  • Disabled alerts. Notifications turned off shortly after login is an attempt to keep the real owner in the dark.
  • Behavioral mismatch. Typing, navigation, and session rhythm that do not match the owner's history point to a different person.
  • SIM-swap timing. A recent number port followed by a password reset and login is a strong takeover indicator.

Quick questions

How is ATO different from new-account fraud?

New-account fraud creates a fresh account with a bad identity. ATO hijacks a real customer's existing account, inheriting its trust and history, which makes the fraudulent activity blend in far more easily.

Why change the email or phone first?

Contact details control where alerts and reset codes go. Changing them locks the real owner out of notifications and password recovery, buying the fraudster time to cash out unnoticed.

Does MFA stop account takeover?

It helps a lot but is not absolute. SMS codes can be intercepted via SIM swap, and phishing can capture one-time codes in real time, so strong MFA plus behavioral and device signals is the durable combination.

What is credential stuffing's role?

It is a common entry method. Attackers replay username and password pairs leaked in past breaches, betting that people reuse passwords, and any hits become takeover targets.

How do behavioral biometrics help?

They compare how the current session moves, types, and navigates against the genuine owner's patterns, so a valid login by the wrong person can still be flagged as anomalous.

What should happen when ATO is suspected?

Freeze risky actions, step up verification on the change or payment, and reach the real customer through a previously verified channel, not the newly changed one, to confirm what is happening.

Go deeper

  • FTC Consumer Advice: Scams ↗ — US consumer guidance on current scams and fraud, and how to report them.
  • FBI IC3 ↗ — The FBI Internet Crime Complaint Center. Fraud reporting and annual trend reports.

What to know alongside Account takeover (ATO)