Now onboarding businesses across Leeds & Yorkshire — book a free IT & security review
← All resources

Account Takeover: How It Happens and How to Stop It

In short

Account takeover is when a criminal gets into one of your online accounts and uses it as if they were you. It usually starts with a stolen or reused password, or a phishing email. The warning signs are subtle — unexpected login alerts, missing emails, changed settings. The defences are simple: MFA everywhere, unique passwords in a password manager, and login alerts switched on.

Some links on this page are affiliate links: if you sign up or buy through them, Dacros may earn a commission, at no extra cost to you. We only recommend tools we use and rate. Full disclosure.

What “account takeover” really means

Account takeover is exactly what it sounds like: a criminal gets into one of your online accounts and starts using it as though they were you. That might be your email, your Microsoft 365 login, your online banking, your social media, or a supplier portal.

Once they’re in, they can read your messages, reset your other passwords, send emails in your name, steal data, or redirect payments. Because they’re logged in as a legitimate user, nothing looks obviously “hacked” — and that’s what makes it so damaging.

How criminals get in

Almost every account takeover starts with a stolen password. There are two very common routes.

Phishing. You receive an email or text that looks genuine — a fake Microsoft login, a “your mailbox is full” warning, a delivery notice. You click, you land on a convincing copy of a real login page, and you type your password straight into the criminal’s hands. Learning how to spot a phishing email is one of the most useful skills your team can have.

Credential stuffing. When another company suffers a data breach, the leaked email addresses and passwords end up on criminal forums. Attackers then take those combinations and try them automatically against hundreds of other services. If you reused the same password anywhere, those accounts fall too. This is why one reused password can quietly put a dozen accounts at risk.

Other routes exist — malware that captures what you type, or SIM-swapping to intercept text codes — but stolen and reused passwords are the overwhelming majority.

The warning signs

Account takeover is often quiet, but it usually leaves traces. Watch for:

  • Login alerts you didn’t trigger — a sign-in from an unfamiliar location, device or time.
  • Password-reset or MFA emails you didn’t request — criminals probing to get in, or covering their tracks after they have.
  • Emails missing from your inbox, or messages marked as read that you never opened. Attackers often set up hidden rules that auto-delete or forward your mail so you don’t see their activity.
  • Sent items you don’t recognise, or colleagues asking about emails you never sent.
  • Changed settings — a new forwarding rule, a different recovery phone number or email, or unfamiliar connected apps.
  • Being logged out unexpectedly, or your password suddenly not working.

Any one of these deserves a closer look. Several together mean act now.

How to stop it — three controls that do the heavy lifting

You don’t need to be technical to shut down the common routes. Three measures cover most of the risk.

1. Turn on multi-factor authentication (MFA) everywhere

MFA means a password alone isn’t enough to log in. After the password, the account also asks for a second proof — usually a code or a tap-to-approve on your phone. Even if a criminal has your correct password, they’re stopped dead without that second factor.

This is the single highest-value change you can make, and it’s now a baseline requirement under Cyber Essentials. Switch it on for email first, then banking, then everything else that offers it. Our guide to multi-factor authentication walks through it in plain English.

2. Give every account a strong, unique password

Unique passwords break credential stuffing completely: a password leaked from one site is useless everywhere else. Nobody can memorise dozens of strong, unique passwords, which is exactly what a password manager is for. It generates them, stores them encrypted, and fills them in for you. A tool like Proton Pass means your team can have a different strong password for every service without writing anything on a sticky note. See our roundup of the best password managers for small business for more.

3. Switch on login and security alerts

Most services — Microsoft 365, Google, banks — can email or notify you when there’s a new sign-in or a settings change. Turn these on so an intrusion tells on itself. An alert you can act on within the hour is worth far more than discovering a breach weeks later.

What to do if an account is taken over

Speed matters. Work through this quickly:

  1. Change the password on the affected account — and anywhere the same password was used.
  2. Sign out all active sessions (most services have a “log out everywhere” option), so the criminal is kicked off even if they’re still connected.
  3. Turn on MFA if it wasn’t already enabled.
  4. Check the settings — remove any unfamiliar forwarding rules, filters, recovery addresses or connected apps the attacker may have added.
  5. Warn anyone affected — contacts who may have received scam emails from you, and your IT provider if it’s a work account.
  6. Report it to Action Fraud if money or business data is involved.

Be especially thorough with email. If a criminal controls your mailbox, they can reset the passwords of almost everything else linked to it — so your email account is the one to lock down hardest.

The bottom line

Account takeover isn’t usually the work of a genius hacker. It’s the predictable result of a stolen or reused password meeting an account with no second line of defence. Add MFA, give every account a unique password through a password manager, and switch on alerts — and you remove the conditions the attack depends on.

If you’d like a hand rolling out MFA and a password manager across your team, or checking whether any accounts are already exposed, talk to DACROS. We help small businesses across Leeds and Yorkshire close these gaps without the jargon — see our cyber-security services for the full picture.

Frequently asked questions

How do criminals get my password in the first place?

Two main routes. First, phishing — a fake login page tricks you into typing your password. Second, data breaches at other companies: if a site you used was breached and you reused that password elsewhere, criminals try the same email-and-password combination across hundreds of services. That second technique is called credential stuffing, and it's why reused passwords are so dangerous.

Does multi-factor authentication really stop account takeover?

It stops the vast majority of it. Even if a criminal has your correct password, MFA means they still need a second factor — usually a code or approval on your phone — that they don't have. It's the single most effective control for the effort involved, and it's a baseline requirement under Cyber Essentials. It isn't magic, but it defeats almost all password-only attacks.

I've had a login alert from a country I've never visited. What do I do?

Treat it seriously. Change that account's password straight away, sign out all active sessions, and confirm MFA is switched on. Then check whether the same password was used anywhere else and change those too. If it's a work account, tell your IT provider so they can check for wider access.

Is a password manager safe? Isn't it risky to keep everything in one place?

A reputable password manager encrypts your passwords so only you can unlock them, and it lets every account have a strong, unique password — which removes the far bigger risk of reuse. In practice, the alternative (memorising passwords, so reusing simple ones) is what actually gets people taken over. A password manager is a large net improvement.

Who writes this

Dacros — led by Jordan Gilbert

Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.

Want this handled for you?

Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.