Back to Glossary

Entry · Business

Account Takeover

Account takeover is unauthorised control of someone else's online account, often after their credentials or a login session are stolen. The intruder may make purchases, access private data or change account settings. A successful login alone does not prove the rightful user was present.

From the Money Master HQ dictionary, founded by Shihan Sheriff (FCMA, VP of Finance at Nomod, CFO at Esanjo Ventures). How these definitions are written.

What it means

A customer uses the same password on several sites. When one service is breached, an attacker can try the stolen credentials elsewhere, and if they work, the attacker acts through an account that looks legitimate.

This is called credential stuffing (automated attempts using stolen login pairs), and it is one route among several that also include phishing, malware and stolen sessions. Attackers go after whatever the account holds, such as rewards points, stored payment methods, private records or business controls.

The impact depends on the account's permissions, and an employee admin account can expose many customers at once. Changes such as new devices, password resets, email changes and payout-address edits often reveal a takeover, so they deserve review without making life impossible for legitimate users.

Defences work in layers. Multi-factor authentication (requiring a second proof of identity beyond the password) makes a stolen password far less useful, although codes sent by text message can still be phished, so stronger methods suit higher-risk accounts.

Rate limiting, bot detection and breached-password checks reduce automated attacks, but no single challenge stops every attacker. Safeguards should scale with risk.

A marketplace may require stronger checks before changing a seller's payout account, while a routine product-title edit needs little. Timely notifications about a new device or a changed email give customers an early warning, as long as the message explains how to secure the account without asking them to share a code.

Recovery is a weak point if an attacker can talk support into resetting access. Verify the customer with a proper process, and do not let a caller's knowledge of public facts substitute for proof.

After a suspected takeover, revoke active sessions, reset credentials, review account activity and preserve evidence for any investigation and required notifications. Measure confirmed incidents separately from suspicious attempts, because a blocked credential-stuffing attempt is not a compromised account.

State the definition whenever you report a rate, and remember that detection gaps may mean the true number is higher. Do not blame affected customers, who may have been phished or had their credentials stolen elsewhere.

In practice

Real-world examples.

1

Example

A stolen password is used to log in to a shopping account and change the delivery address. The retailer's risk check spots the unfamiliar location and holds the order until the customer confirms by a known channel. The genuine owner later confirms she never made the change.

2

Example

An intruder redirects a marketplace seller's payout account. Extra verification on payout changes pauses the transfer before any money moves, and the seller keeps the $3,500 that was due. The seller is notified through an existing contact method.

3

Example

A subscriber receives a login alert for a device she does not own. She reports it through the company's known support channel, and support freezes risky changes. She then resets her password and removes the unknown device.

Formula

Calculation

Confirmed takeover rate = accounts confirmed compromised in a period / active accounts in the defined population x 100 Worked example. An invented online retailer has 100,000 active accounts and confirms 50 as compromised in a quarter. Rate = 50 / 100,000 x 100 = 0.05% If the retailer's average loss per takeover (refunds plus handling) is $400, the quarter's direct cost is 50 x $400 = $20,000.

Case study

Seen in the real world.

In this fictional case, Meadow Market, an invented online marketplace, notices a new-device login and a payout-account change on one seller profile. It pauses the transfer and contacts the seller through an established channel.

The seller confirms the change was unauthorised. The company revokes sessions, helps recover access and investigates how the intruder entered, then adds stronger verification for payout changes. This illustrative example shows that a correct password was not proof of the real owner.

Meadow Market also reports the confirmed case separately from the many blocked login attempts it sees each week, so its takeover rate reflects only real compromises. Customers also receive plain advice on using a unique password for each service and a password manager to store them. That clear definition lets management judge whether the new controls are working.

Watch out

Common mistakes.

  • Treating a correct password as proof of the real account owner.
  • Counting all failed login attempts as confirmed takeovers.
  • Allowing account recovery without appropriate verification.

Questions

People also ask.

How do attackers gain access?

They may use stolen passwords from other breaches, phishing messages or stolen login sessions. Malware on a device can also capture credentials as they are typed, and attackers sometimes buy lists of stolen logins from other criminals.

Does MFA prevent all takeovers?

No. It reduces risk, but the method chosen and the security of the recovery process still matter. Attackers can phish codes or trick support, so layered defences remain necessary. Hardware keys and app-based approvals are generally harder to steal than text message codes.

What should a business do after one?

Protect access, investigate what was changed and help the user recover through verified steps. Fast, kind recovery support protects trust, which is often worth more than the stolen amount. Record the timeline and reverse unauthorised changes where policy allows.

Was this explanation helpful?

From the founder's library

Accounting Fundamentals: A Non-Finance Manager's Guide to Finance and Accounting, by Shihan Sheriff

Take it further with the book.

Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.

US$2.24US$2.99

25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.

View the book and save 25%
Last updated · October 8, 2026
Browse all terms →

Disclaimer

The information provided in this finance dictionary is for educational and informational purposes only. It should not be construed as financial, investment, legal, or tax advice. Always consult with a qualified professional before making any financial decisions. Money Master HQ makes no representations or warranties about the accuracy, completeness, or suitability of this information. Use of this content is at your own risk.