Account takeover (ATO)
Taking control of a legitimate account with stolen credentials. From inside, the attacker reads, impersonates and escalates without raising alarms.
Full definition
Account takeover (ATO) is unauthorized access to a legitimate account using stolen credentials, obtained through phishing, infostealer malware, data breaches or credential stuffing. The attacker does not break the door: they walk in with the victim's key.
Once inside, the options multiply: reading email to prepare fraud such as BEC, impersonating the victim before colleagues and vendors, stealing data, moving into other accounts, or selling the access to third parties. Because the session is legitimate, perimeter defenses see nothing unusual.
Prevention attacks the whole chain: multi-factor authentication so the credential alone is not enough, leaked credential monitoring to close the exposure before it is used, and anomaly detection inside the account to catch the intruder who already got in.
Related terms
Leaked credentials
Usernames and passwords exposed in breaches or stolen by malware, circulating on the dark web. They are the raw material of initial access to companies.
Credential stuffing
Automated testing of credentials stolen from one service against many others. It works because people reuse passwords.
Business email compromise (BEC)
Fraud where the attacker poses as an executive or vendor from a legitimate or spoofed mailbox to divert payments or data. It usually carries no malware.
Session hijacking
Stealing the cookie or token that keeps an authenticated session open. It grants entry without a password and without a second factor.
From definition to data: measure your company's human risk
Fensivo detects leaked credentials, simulates real attacks and validates with retests that behavior changed.