Account takeover (ATO)
Also known as: ATO · Account takeover fraud · Account hijacking · Account compromise
Fraud in which a criminal seizes control of a legitimate user's account — through a leaked password, phishing or a SIM swap — and operates it as if they were the real owner.
Legal basis
OWASP — Credential stuffing (common ATO vector)
Unlike opening a fake account, account takeover (*ATO*) attacks a real, good account. The criminal signs in with credentials harvested from breaches, phishing or a SIM swap, changes the contact and security details, then drains the account or uses it to defraud others. Because the access comes through the correct login, onboarding controls see nothing wrong.
What gives ATO away is the change in behavior, not the credential: a new device, a login from another region, a different typing rhythm, a password change followed by a transfer. That is why the defense combines device intelligence, behavioral biometrics and step-up authentication at moments of risk, rather than trusting that the right password means the right person.
Frequently asked questions
What is account takeover (ATO)?
It is when a fraudster seizes control of a legitimate user's account using leaked credentials, phishing or a SIM swap, and operates it as if they were the owner. Unlike a fake account, the account here is real — what changes is who is in control.