The step that defines the crime is the one before the money moves. A criminal who simply drains an account is racing the owner's alerts. A criminal who first changes the email address, the phone number and the notification settings on file has removed the owner from their own account. Statements are redirected or suppressed, one-time codes go to a device the criminal controls, and the messages that would have announced a new payee or a large transfer never arrive. Only then does the money move. That sequence is why an account takeover is often discovered far later than a lost card, and why the loss is frequently much larger.
The FBI's own description of the scale within an incident is worth reading literally. In 2025, it reports, its financial fraud kill chain process "saw a rise in Tech Support and Account Takeover (ATO) initiations," and "ATO-related incidents can contain upwards of 50 or more transactions to different recipient accounts at multiple banks happening simultaneously via ACH transactions." This is not one withdrawal but a fan-out designed to be difficult to unwind, and it is why the Bureau's advice to victims is to contact the institution immediately and ask for a recall.
The label carries no legal rights, and that is a measurable fact rather than an impression. Regulation E, the federal rule governing consumer electronic fund transfers, does not use the phrase "account takeover" anywhere: the whole of 12 CFR part 1005, including the Official Interpretations in Supplement I, contains it zero times. Nothing turns on whether an incident is called a takeover. What everything turns on is whether a particular transfer was unauthorized, and that is a defined term.
Section 1005.2(m) defines an "unauthorized electronic fund transfer" as "an electronic fund transfer from a consumer's account initiated by a person other than the consumer without actual authority to initiate the transfer and from which the consumer receives no benefit." Read the whole sentence, because the final clause is routinely dropped when the definition is quoted. The operative question is who initiated the transfer. In an account takeover the criminal logs in and initiates it, so the transfer sits on the unauthorized side of the line. The regulator's official interpretation of the same definition reaches a narrower case in the same direction: a transfer initiated by a person who obtained the access device from the consumer through fraud or robbery is unauthorized too. That comment matters where the criminal got the credentials out of the victim personally rather than from a breach somewhere else, and the page on phishing sets it out in full.
Contrast the case where the account holder is talked into sending the money themselves. That is a transfer the consumer initiated, so the definition is not satisfied and the electronic-transfer protections do not reach it, however complete the deception was. The two situations feel identical to a victim and are governed differently, which is the single most important thing to understand about this area.
One feature of the reporting rules matters here more than anywhere else. The federal electronic-transfer rules set an outer reporting deadline for unauthorized transfers that appear on a periodic statement, and that deadline is measured from the financial institution's transmittal of the statement, not from the moment the customer opens it. That is an entirely reasonable rule when statements arrive where they are supposed to. It is a trap in an account takeover, because redirecting or suppressing the statement is one of the first things the criminal does, so the clock can be running while the owner has no way of seeing anything. The tiers, the two different clocks and the error-resolution timetable are set out on the debit card and bank statement pages, and the extension available where a delay was due to extenuating circumstances is covered there too. Those pages are the ones to read; the point here is only that the clock's starting gun is fired by the institution rather than by the customer.
Where the credentials come from. Usually not from the institution's own systems. The recurring sources are a phishing message or a call impersonating the bank's support line, credentials exposed in a breach elsewhere and reused on a financial account, a device compromised by malware, and, increasingly, interception of the one-time code itself by a caller who has already persuaded the victim to read it out. The last of these is why a code sent by text is a weaker second factor than one generated by an application or by a physical security key: a code can be repeated to somebody, and a key cannot.
What a reader can actually act on. Alerts are the countermeasure that maps directly onto the attack, because the attack starts by disabling them: an institution that notifies a customer through a second channel when contact details or notification settings change removes the criminal's cover. Beyond that, the durable measures are a distinct password on every financial account so that one breach elsewhere does not open a bank, a second factor stronger than a text message, and reviewing statements even in a month when nothing seems to be wrong. Where an account has already been taken over, speed matters for two independent reasons: the regulation's clocks, and the practical fact that a recall of funds has hours rather than days to work in.