Start with Identity
← Glossary
Threat

Account Takeover (ATO)

When an attacker gains control of a legitimate account, often via stolen credentials, phishing, or session theft. A leading cause of breaches and fraud.

The distinguishing feature of ATO is that nothing looks broken: the login succeeds, the log line is normal, and detection has to come from behavior rather than from a failure. The three supply chains feeding it are infostealer logs, credential dumps replayed against unrelated sites, and real-time relay kits that capture a valid session. Each defeats a different control, which is why layered detection plus phishing-resistant credentials beats any single fix.

See also: credential stuffing, session hijacking, what is ITDR, infostealer session hijacking teardown

Last reviewed By SWI Community TeamSuggest a correctionHow we research