Account takeover in plain terms
In account takeover, nothing about the account is fake. It belongs to a real customer, with a real payment method, a purchase history and often a stored balance. That is exactly what the attacker wants: an account the business already trusts. Once inside, they act fast, before the owner notices.
- Change the email, phone or password to lock the owner out.
- Spend stored value: wallet balances, loyalty points, gift cards, airline miles.
- Buy with saved cards and ship to a new address.
- Withdraw funds or send them to a money mule.
- Harvest personal data or use the account's reputation to scam others.
How attackers get in
| Route | How it works |
|---|---|
| Credential stuffing | Bots try passwords leaked from other sites, relying on reuse |
| Phishing | A fake login page or message collects the password and often the one-time code |
| Session theft | Malware on the victim's device steals login cookies, skipping the password entirely |
| SIM swap and OTP interception | The attacker moves the victim's number to a new SIM to receive codes |
| Social engineering of support | A caller convinces an agent to reset access |
Why account takeover matters
The direct loss is only the start. The business refunds the customer, pays for support and investigation, and often absorbs a chargeback when saved cards were used. The customer loses trust in the brand, not in the attacker, and many close their account after a takeover even when they are made whole.
Taken-over accounts also feed other fraud. Attackers use aged, trusted accounts to post scams on marketplaces, launder money through fintech apps, or pass as long-time customers when they commit payment fraud. Because the account has a clean history, the rules that catch new fake accounts rarely fire. The earlier in the session the takeover is spotted, at login or at the first change of contact details, the less there is to clean up.
What ATO looks like in traffic
A takeover usually looks like the right person on the wrong device. The password is correct, but the login comes from a device the account has never used, often a spoofed browser or an emulator, through a proxy placed near the owner's usual city. It is followed within minutes by a change of contact details or a large transaction. Each of those events alone is normal; together they tell the story.
Kavra keeps a list of trusted devices per account and checks every login and sensitive action against it: new device, new network, impossible travel, known-bad device. It then recommends allow, step up or block, so the real owner is rarely interrupted. The full prevention playbook is on the account takeover prevention page, with industry detail for fintech and banking.