Back to the glossary
    Credentials & identityCybersecurity glossary

    Account takeover (ATO)

    Taking control of a legitimate account with stolen credentials. From inside, the attacker reads, impersonates and escalates without raising alarms.

    Full definition

    Account takeover (ATO) is unauthorized access to a legitimate account using stolen credentials, obtained through phishing, infostealer malware, data breaches or credential stuffing. The attacker does not break the door: they walk in with the victim's key.

    Once inside, the options multiply: reading email to prepare fraud such as BEC, impersonating the victim before colleagues and vendors, stealing data, moving into other accounts, or selling the access to third parties. Because the session is legitimate, perimeter defenses see nothing unusual.

    Prevention attacks the whole chain: multi-factor authentication so the credential alone is not enough, leaked credential monitoring to close the exposure before it is used, and anomaly detection inside the account to catch the intruder who already got in.

    Related terms

    From definition to data: measure your company's human risk

    Fensivo detects leaked credentials, simulates real attacks and validates with retests that behavior changed.