Breaches & Passwords

What Is Account Takeover Fraud? Signs and the Recovery Window

By the RedactZero Team · September 16, 2026 · 9 min read

The short version

Account takeover fraud is what happens after a stolen login works. The attacker changes your recovery email and phone so you cannot get back in, then uses the account to spend, to reset passwords elsewhere, or to scam your contacts. The way in can be a leaked password, a phishing page, malware, or a hijacked phone number. Federal rules give you a short window to limit losses on bank accounts: report within two business days and your liability is capped at $50. Recover your email first, then money accounts, then everything else.

What account takeover fraud actually is

Account takeover fraud, often shortened to ATO, is when someone gains control of an account you legitimately own and operates it as you. The distinguishing feature is control, not just access. A peek at your inbox is a breach of privacy. Changing your recovery phone, locking you out, and moving money is a takeover.

The phrase covers any account type: email, banking, payment apps, shopping sites with a saved card, social media, mobile carrier accounts, and loyalty programs with points that can be cashed out. What unites them is that the attacker is not pretending to be you to a third party, as in identity theft. They are literally logged in as you, with every permission the account grants.

How it differs from credential stuffing

Credential stuffing is one door into an account. Account takeover is what happens once any door opens. Stuffing is the automated attempt to log in with leaked email and password pairs; takeover is the occupation that follows a success. We covered the attempt side in our guide to credential stuffing. This post is about the aftermath.

The distinction matters because the defenses differ. Unique passwords stop stuffing. They do nothing once an attacker is inside and has already changed the password on you. Stopping stuffing is about preventing entry. Limiting takeover damage is about how fast you notice, how fast you act, and whether your most important accounts are walled off from each other.

The four ways attackers get in

Almost every takeover starts one of four ways: a reused password from an old breach, a phishing page that captured your login, malware that copied saved passwords from your device, or a SIM swap that moved your phone number to the attacker's handset. None of these require targeting you personally. Most are run at scale against lists.

Stolen logins are the leading way in at the organizational level too. Verizon's 2025 Data Breach Investigations Report, published April 23, 2025, analyzed over 22,000 security incidents including 12,195 confirmed breaches, and found credential abuse was the top initial access vector at 22 percent, ahead of vulnerability exploitation at 20 percent.

The SIM swap route deserves special mention because it defeats text-message codes. If your carrier can be talked into moving your number, every SMS verification code goes to the attacker. Our guide on SIM swap protection explains how to add a carrier PIN.

What happens in the first hour after a successful login

The first thing a competent attacker does is not steal. It is to lock you out. They change the recovery email, swap the phone number, add their own device as trusted, and set up an auto-forwarding rule so they keep receiving your mail even after you change the password. Only then do they look for value.

This is why the FTC's October 29, 2024 consumer alert on hacked accounts tells people to check for auto-forwarding rules they did not set up. A forwarding rule survives a password change and keeps feeding the attacker your reset links and bank alerts.

The next moves depend on the account. In an email account, they search for messages from banks, brokerages, and crypto exchanges, then trigger resets there. In a shopping account, they change the delivery address and buy with the saved card. In a social account, they message your contacts with a plea for money or a link to the same phishing page that caught you.

Which accounts attackers go after first

Email is the prize, every time. It is the recovery channel for nearly everything else, so controlling it means controlling accounts whose passwords the attacker never learned. After email comes anything holding money or a saved payment method, then your mobile carrier account, because that unlocks SMS codes for everything else.

A simple way to rank your own exposure: which accounts, if taken over, would let someone reset the others? Email and phone carrier accounts sit at the top of that tree. Bank, payment app, and password manager accounts sit just below.

Our guide on recovering a hacked email account walks through the email case step by step. Do that one first, before anything else, because every other recovery depends on it.

The recovery window: what federal law says about your money

For bank accounts and debit cards, how much you can lose depends on how fast you report. The Consumer Financial Protection Bureau explains that reporting within two business days caps your liability at $50, waiting longer can raise it to $500, and missing the 60-day statement window can leave you responsible for later transactions in full.

When you report a lost or stolen card or unauthorized withdrawalMost you can be held responsible for
Within 2 business days of discovering the lossThe unauthorized amount or $50, whichever is less
After 2 business daysUp to $500
More than 60 days after the statement showing the withdrawalPotentially the full amount of transactions after the 60-day period

Source: Consumer Financial Protection Bureau, "How do I get my money back after I discover an unauthorized transaction or money missing from my bank account?", last reviewed August 28, 2026.

Once you report, the CFPB says the bank generally has ten business days to investigate, or twenty if the account is under 30 days old, and must resolve the matter within 45 days, or up to 90 days for foreign, new-account, or debit point-of-sale transactions. Credit cards are simpler: the FTC states that federal law limits your responsibility for unauthorized credit card charges to $50.

One detail worth knowing if you were tricked rather than hacked. The CFPB's Electronic Fund Transfer FAQs state that when a consumer is fraudulently induced into sharing account access information with a third party, and that third party uses it to make a transfer, the transfer is unauthorized under Regulation E. Handing over a login to a convincing fake support agent does not forfeit the protection. Transfers you sent yourself are treated differently, so describe exactly what happened when you report.

Signs it is happening to you

Takeover is noisy if you know the sounds. The FTC lists three tip-offs: a notification that your email address or phone number changed, a message that someone tried to log in or did log in and it was not you, and being unable to log in at all.

The dangerous version is the quiet one, where the attacker only reads and waits. That is why checking forwarding rules and trusted devices periodically matters even when nothing seems wrong. Our overview of the signs your identity was stolen covers the wider pattern beyond a single account.

How to take an account back, in order

Order matters more than speed on any single step. Secure the account that controls the others before you chase the one where the damage showed up. If your bank alerted you but your email is also compromised, fixing the bank first is pointless: the attacker will reset it again through your inbox.

  1. Email first. Change the password to something unique. The FTC suggests aiming for 12 to 15 characters. Turn on two-factor authentication. Verify the recovery email and phone are yours. Delete any forwarding rules and filters you did not create. Sign out of all other sessions.
  2. Phone carrier second. Log in to your carrier account, confirm no SIM change or port request is pending, and add an account PIN or port-freeze.
  3. Money accounts third. Call the bank or app using the number on your card, not one from an email. Report the unauthorized activity in writing so the deadlines above start running. Ask for new card numbers.
  4. Everything that shared the password. Change it everywhere it was reused, starting with anything that stores a payment method.
  5. Tell people. The FTC advises warning contacts not to click links or send money in response to messages from you.
  6. Report. If personal information was misused, file at IdentityTheft.gov for a recovery plan. Report losses to the FBI's Internet Crime Complaint Center at ic3.gov.

If you cannot log in at all, go through the provider's official account recovery flow rather than a support number found in a search result. The wider response order, including credit freezes, is in our guide on what to do after a data breach.

What the numbers say about scale

Account takeover is rarely reported as its own category, which hides its size. It shows up inside phishing, identity theft, and payment fraud figures. The FBI's Internet Crime Complaint Center received 1,008,597 complaints in 2025 with $20.877 billion in reported losses, a 26 percent increase from 2024, and phishing led every category by volume.

IC3 crime type, 2025Complaints
Phishing / spoofing191,561
Personal data breach67,456
Identity theft31,675
Credit card / check fraud18,774

Source: FBI Internet Crime Complaint Center, 2025 Internet Crime Report, "2025 Crime Types by Complaint Count."

The FTC's figures point the same direction. Its Consumer Sentinel Network received 6.5 million reports in 2024, including more than 1.1 million identity theft reports through IdentityTheft.gov, with fraud losses of $12.5 billion. On June 15, 2026 the agency reported that about $16 billion was lost to fraud in 2025, the highest on record and roughly 25 percent above 2024.

How to make takeover much harder

The single most effective step is a second factor that does not depend on a password. Google's May 2019 research with New York University and UC San Diego measured this on real accounts: on-device prompts prevented 100 percent of automated bot attacks, 99 percent of bulk phishing attacks, and 90 percent of targeted attacks. Security keys did even better.

No user who relied only on security keys fell to targeted phishing during the study. Even the weakest option helped substantially. Simply adding a recovery phone number blocked up to 100 percent of automated bots, 99 percent of bulk phishing, and 66 percent of targeted attacks in the same study. Strongest to weakest: passkeys or hardware keys, then authenticator app prompts and codes, then SMS.

Beyond the second factor: use a different password on every site so one leak cannot cascade, keep recovery details current so the legitimate recovery path is yours, and review trusted devices and forwarding rules a couple of times a year. Our password manager and 2FA guide covers the setup.

Why your public data makes takeover easier

Takeover attempts get past support desks and security questions using facts about you that are already public. Your mother's maiden name, past addresses, phone numbers, and relatives sit on people-search sites for anyone to read. Reducing that exposure removes the raw material for the social-engineering half of the attack.

Two checks are worth doing now. First, find out whether your email address has appeared in a known breach, which tells you whether your old passwords are in circulation. Have I Been Pwned is the standard database for this, and our explainer on how Have I Been Pwned works shows how to read its results. Second, see what people-search sites publish about you and opt out using the free opt-out guides.

RedactZero's free exposure scan does both in one step: it checks an email against known breaches and lists the data brokers likely to list a US adult, and nothing you scan is stored.

Find out what an attacker could already use

Run a free exposure scan to see whether your email appears in known breaches, plus which data brokers and public profiles reference you. No account, nothing stored.

Run a free exposure scan

Frequently asked questions

What is account takeover fraud in simple terms?

Account takeover fraud is when someone else gains control of an account you own and uses it as if they were you. The login might come from a leaked password, a phishing page, or a stolen phone number. The fraud is everything that happens after that login works: changed recovery details, drained balances, and access to your other accounts.

How is account takeover different from credential stuffing?

Credential stuffing is one way in: software tries leaked email and password pairs on many sites. Account takeover is the result once any method works. Stuffing is the attempt; takeover is the occupation. Phishing, SIM swapping, and malware also lead to takeover without any stuffing involved.

How long do I have to report unauthorized bank transactions?

Under federal rules explained by the CFPB, reporting a lost or stolen card within two business days caps your liability at $50. After two business days it can rise to $500. If you do not report an unauthorized withdrawal within 60 days of the statement that shows it, you could owe the full amount of transactions made after that window.

Am I covered if I was tricked into giving someone my login details?

For bank and payment app transfers, the CFPB's Electronic Fund Transfer FAQs say that when a consumer is fraudulently induced into sharing account access information and a third party uses it to make a transfer, that transfer is unauthorized under Regulation E. Transfers you initiated yourself are treated differently, so report quickly and describe exactly what happened.

What is the first thing to do if my account was taken over?

Secure your primary email first, because password resets for everything else flow through it. Change its password, turn on two-factor authentication, check the recovery email and phone, and look for auto-forwarding rules you did not create. Then move to bank and payment accounts, then everything else that shared the password.

What are the signs my account has been taken over?

The FTC lists three: a notification that your email address or phone number changed, a message that someone tried to log in or did log in and it was not you, and being unable to log in at all. Unrequested password-reset emails, verification codes arriving on their own, and sent messages you did not write are also strong signs.

Does two-factor authentication stop account takeover?

It stops most of it. Google research published in May 2019 with New York University and UC San Diego found that on-device prompts prevented 100 percent of automated bot attacks, 99 percent of bulk phishing attacks, and 90 percent of targeted attacks, and no user relying only on security keys fell to targeted phishing during the study. SMS codes help but are the weakest form.

Where do I report account takeover fraud in the US?

Report it to the company that runs the account first. If money was lost or your personal information was misused, file at IdentityTheft.gov to get a recovery plan, and file an internet crime complaint with the FBI at ic3.gov. Report unauthorized bank or card transactions directly to the bank in writing so the federal deadlines start running.

Sources: Consumer Financial Protection Bureau, "How do I get my money back after I discover an unauthorized transaction or money missing from my bank account?" (last reviewed August 28, 2026) and the CFPB Electronic Fund Transfers FAQs (Regulation E, unauthorized EFTs); FTC Consumer Advice, "Using Credit Cards and Disputing Charges" and "Email or social media hacked? Here's what to do," October 29, 2024; Google Online Security Blog, "New research: How effective is basic account hygiene at preventing hijacking," May 17, 2019, with New York University and UC San Diego; Verizon 2025 Data Breach Investigations Report, April 23, 2025; FBI Internet Crime Complaint Center, 2025 Internet Crime Report; FTC press releases of March 10, 2025 (2024 Consumer Sentinel data) and June 15, 2026 (2025 fraud losses); Have I Been Pwned.