# What is account takeover?

Source: https://kavralab.com/glossary/account-takeover/

**Account takeover** (ATO) is a form of fraud in which a criminal gets into a real customer's online account, usually with stolen or phished login details, and then uses it to steal money, points, data or goods. The account's history makes the attacker look trusted. Kavra compares each login with the account's own devices and habits.

## Account takeover in plain terms

In account takeover, nothing about the account is fake. It belongs to a real customer, with a real payment method, a purchase history and often a stored balance. That is exactly what the attacker wants: an account the business already trusts. Once inside, they act fast, before the owner notices.

- Change the email, phone or password to lock the owner out.
- Spend stored value: wallet balances, loyalty points, gift cards, airline miles.
- Buy with saved cards and ship to a new address.
- Withdraw funds or send them to a [money mule](https://kavralab.com/glossary/money-mule/).
- Harvest personal data or use the account's reputation to scam others.

## How attackers get in

| Route | How it works |
|---|---|
| [Credential stuffing](https://kavralab.com/glossary/credential-stuffing/) | Bots try passwords leaked from other sites, relying on reuse |
| Phishing | A fake login page or message collects the password and often the one-time code |
| Session theft | Malware on the victim's device steals login cookies, skipping the password entirely |
| SIM swap and OTP interception | The attacker moves the victim's number to a new SIM to receive codes |
| Social engineering of support | A caller convinces an agent to reset access |

## Why account takeover matters

The direct loss is only the start. The business refunds the customer, pays for support and investigation, and often absorbs a chargeback when saved cards were used. The customer loses trust in the brand, not in the attacker, and many close their account after a takeover even when they are made whole.

Taken-over accounts also feed other fraud. Attackers use aged, trusted accounts to post scams on marketplaces, launder money through fintech apps, or pass as long-time customers when they commit [payment fraud](https://kavralab.com/solutions/payment-fraud/). Because the account has a clean history, the rules that catch new fake accounts rarely fire. The earlier in the session the takeover is spotted, at login or at the first change of contact details, the less there is to clean up.

## What ATO looks like in traffic

A takeover usually looks like the right person on the wrong device. The password is correct, but the login comes from a device the account has never used, often a spoofed browser or an emulator, through a proxy placed near the owner's usual city. It is followed within minutes by a change of contact details or a large transaction. Each of those events alone is normal; together they tell the story.

Kavra keeps a list of trusted devices per account and checks every login and sensitive action against it: new device, new network, impossible travel, known-bad device. It then recommends allow, step up or block, so the real owner is rarely interrupted. The full prevention playbook is on the [account takeover prevention](https://kavralab.com/solutions/account-takeover/) page, with industry detail for [fintech and banking](https://kavralab.com/industries/fintech/).

## FAQ

### What does ATO stand for in fraud?

ATO stands for account takeover. Fraud, risk and security teams use it for any case where someone other than the rightful owner gains control of an account and uses it. You will also see it in phrases like ATO attack, ATO rate and ATO protection.

### Is account takeover the same as identity theft?

They overlap but are not the same. Identity theft uses a person's details to open new accounts or credit in their name. Account takeover hijacks an account the person already has. Data stolen in a takeover, such as addresses and ID numbers, is often reused later for identity theft.

### Who is liable when an account is taken over?

It depends on the product and the country. In banking and payments, rules often protect consumers from unauthorized transactions, so the provider carries much of the loss. In e-commerce, gaming and loyalty programs, businesses usually restore balances to keep customers. Either way, the business pays for support time, refunds and lost trust.

---
Kavra Lab: bot and fraud detection that explains every decision. Book a demo: https://kavralab.com/contact/
