What it means
A customer uses the same password on several sites. When one service is breached, an attacker can try the stolen credentials elsewhere, and if they work, the attacker acts through an account that looks legitimate.
This is called credential stuffing (automated attempts using stolen login pairs), and it is one route among several that also include phishing, malware and stolen sessions. Attackers go after whatever the account holds, such as rewards points, stored payment methods, private records or business controls.
The impact depends on the account's permissions, and an employee admin account can expose many customers at once. Changes such as new devices, password resets, email changes and payout-address edits often reveal a takeover, so they deserve review without making life impossible for legitimate users.
Defences work in layers. Multi-factor authentication (requiring a second proof of identity beyond the password) makes a stolen password far less useful, although codes sent by text message can still be phished, so stronger methods suit higher-risk accounts.
Rate limiting, bot detection and breached-password checks reduce automated attacks, but no single challenge stops every attacker. Safeguards should scale with risk.
A marketplace may require stronger checks before changing a seller's payout account, while a routine product-title edit needs little. Timely notifications about a new device or a changed email give customers an early warning, as long as the message explains how to secure the account without asking them to share a code.
Recovery is a weak point if an attacker can talk support into resetting access. Verify the customer with a proper process, and do not let a caller's knowledge of public facts substitute for proof.
After a suspected takeover, revoke active sessions, reset credentials, review account activity and preserve evidence for any investigation and required notifications. Measure confirmed incidents separately from suspicious attempts, because a blocked credential-stuffing attempt is not a compromised account.
State the definition whenever you report a rate, and remember that detection gaps may mean the true number is higher. Do not blame affected customers, who may have been phished or had their credentials stolen elsewhere.
In practice
Real-world examples.
Example
A stolen password is used to log in to a shopping account and change the delivery address. The retailer's risk check spots the unfamiliar location and holds the order until the customer confirms by a known channel. The genuine owner later confirms she never made the change.
Example
An intruder redirects a marketplace seller's payout account. Extra verification on payout changes pauses the transfer before any money moves, and the seller keeps the $3,500 that was due. The seller is notified through an existing contact method.
Example
A subscriber receives a login alert for a device she does not own. She reports it through the company's known support channel, and support freezes risky changes. She then resets her password and removes the unknown device.
Formula
Calculation
Confirmed takeover rate = accounts confirmed compromised in a period / active accounts in the defined population x 100
Worked example. An invented online retailer has 100,000 active accounts and confirms 50 as compromised in a quarter.
Rate = 50 / 100,000 x 100 = 0.05%
If the retailer's average loss per takeover (refunds plus handling) is $400, the quarter's direct cost is 50 x $400 = $20,000.Case study
Seen in the real world.
In this fictional case, Meadow Market, an invented online marketplace, notices a new-device login and a payout-account change on one seller profile. It pauses the transfer and contacts the seller through an established channel.
The seller confirms the change was unauthorised. The company revokes sessions, helps recover access and investigates how the intruder entered, then adds stronger verification for payout changes. This illustrative example shows that a correct password was not proof of the real owner.
Meadow Market also reports the confirmed case separately from the many blocked login attempts it sees each week, so its takeover rate reflects only real compromises. Customers also receive plain advice on using a unique password for each service and a password manager to store them. That clear definition lets management judge whether the new controls are working.
Watch out
Common mistakes.
- Treating a correct password as proof of the real account owner.
- Counting all failed login attempts as confirmed takeovers.
- Allowing account recovery without appropriate verification.
Questions
People also ask.
How do attackers gain access?
They may use stolen passwords from other breaches, phishing messages or stolen login sessions. Malware on a device can also capture credentials as they are typed, and attackers sometimes buy lists of stolen logins from other criminals.
Does MFA prevent all takeovers?
No. It reduces risk, but the method chosen and the security of the recovery process still matter. Attackers can phish codes or trick support, so layered defences remain necessary. Hardware keys and app-based approvals are generally harder to steal than text message codes.
What should a business do after one?
Protect access, investigate what was changed and help the user recover through verified steps. Fast, kind recovery support protects trust, which is often worth more than the stolen amount. Record the timeline and reverse unauthorised changes where policy allows.
From the founder's library

Take it further with the book.
Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.
25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.
View the book and save 25%