Account takeover means someone else gains control of one of your online accounts. By the time you notice, they may have changed the password, recovery email, phone number, or security settings to keep you out.
Does this affect you?
Use this for any online account, including email, banking, social media, shopping, gaming, and work tools, when you want to understand how takeovers happen and what warning signs to watch for.
The most common ways accounts get taken over
Most cases come from a few repeatable patterns.
- Reused passwords: a password leaked from one service is tried automatically on other popular sites, a technique called credential stuffing.
- Phishing: a fake email, text, or direct message sends you to a lookalike login page that captures the real password.
- SIM swapping: an attacker moves your phone number to a SIM they control so they can receive text-message codes.
- Malware: infected software can log keystrokes or steal saved browser passwords.
- Weak passwords: short, common, or personal-detail passwords are easier to guess or crack, especially without two-factor authentication.
Early warning signs
Catching a takeover quickly limits the damage.
- You receive a new sign-in, password-changed, or recovery-changed alert you did not trigger.
- You are suddenly logged out and the normal password no longer works.
- Contacts receive strange messages or emails from you.
- The recovery email or phone number changed without your knowledge.
- Unfamiliar purchases, posts, transfers, or account activity appear.
More control
Turn on two-factor authentication
Even if an attacker gets the password, two-factor authentication blocks most account takeovers because they still need your authenticator app, security key, or phone.
Check breach exposure
Services such as Have I Been Pwned can show whether an email address appeared in known breaches. Use that as a clue for which old passwords need replacement.
Recover from a clean device
Change the affected password from a device you trust, then review recovery email, phone number, active sessions, forwarding rules, and connected apps.
Fix reused passwords everywhere
If the stolen password was reused, change it on every other account that used it. A password manager makes unique passwords realistic.
Sources
- FTC Consumer Advice – How to recognize and avoid phishing scams (2025)
- CISA – Avoiding social engineering and phishing attacks (2025)
- FTC – Identity theft (2025)
