Skip to content

Account Takeover

Account takeover is a criminal gaining control of a financial account you already have, rather than opening a new one in your name. Its defining move is not the withdrawal: it is changing the contact details and alerts of record first, so that the account's owner stops being told what is happening to it.

Last reviewed by Steven Fox, CFP®, EA on

Quick Summary

  • The account is yours and already exists. That is what separates account takeover from identity theft, where the criminal opens something new in your name.
  • The first thing changed is usually not the money. Email addresses, phone numbers and alert settings go first, which switches off the owner's own detection.
  • Regulation E does not use the phrase at all. The label carries no rights of its own; what carries rights is whether a transfer was "unauthorized" under the regulation's definition.
  • That definition turns on who started the transfer. A transfer initiated by someone other than the consumer, without authority and with no benefit to the consumer, is unauthorized.
  • The outer reporting deadline in the electronic-transfer rules runs from when the institution sends the periodic statement, not from when the customer reads it, which is precisely the assumption a takeover attacks.

Definition

Account takeover is unauthorized control of a financial account that already belongs to somebody else. The criminal logs in as the account holder, using credentials obtained through phishing, a data breach, a compromised device or a call impersonating the institution's own support line, and then operates the account: moving money, adding payees, linking an external account, or applying for credit in the owner's name from inside the relationship.

The FBI's Internet Crime Complaint Center treats it as a named pattern. Its 2025 Internet Crime Report lists "Account Takeover (ATO)" among the year's cyber-enabled fraud trends, with approximately 4,700 complaints and $359.7 million in reported losses for that year, and points readers to a public service announcement on account takeover fraud carried out by impersonating a financial institution's support staff.

Three neighboring things are frequently called by this name and are not it. Opening a new account in someone else's name is identity theft. Copying a payment card at a machine, leaving the account itself untouched, is card skimming. And persuading somebody to send money themselves is a different category again, with different legal consequences, covered on the fraud page. Each of those has its own entry here.

Advanced Explanation

The step that defines the crime is the one before the money moves. A criminal who simply drains an account is racing the owner's alerts. A criminal who first changes the email address, the phone number and the notification settings on file has removed the owner from their own account. Statements are redirected or suppressed, one-time codes go to a device the criminal controls, and the messages that would have announced a new payee or a large transfer never arrive. Only then does the money move. That sequence is why an account takeover is often discovered far later than a lost card, and why the loss is frequently much larger.

The FBI's own description of the scale within an incident is worth reading literally. In 2025, it reports, its financial fraud kill chain process "saw a rise in Tech Support and Account Takeover (ATO) initiations," and "ATO-related incidents can contain upwards of 50 or more transactions to different recipient accounts at multiple banks happening simultaneously via ACH transactions." This is not one withdrawal but a fan-out designed to be difficult to unwind, and it is why the Bureau's advice to victims is to contact the institution immediately and ask for a recall.

The label carries no legal rights, and that is a measurable fact rather than an impression. Regulation E, the federal rule governing consumer electronic fund transfers, does not use the phrase "account takeover" anywhere: the whole of 12 CFR part 1005, including the Official Interpretations in Supplement I, contains it zero times. Nothing turns on whether an incident is called a takeover. What everything turns on is whether a particular transfer was unauthorized, and that is a defined term.

Section 1005.2(m) defines an "unauthorized electronic fund transfer" as "an electronic fund transfer from a consumer's account initiated by a person other than the consumer without actual authority to initiate the transfer and from which the consumer receives no benefit." Read the whole sentence, because the final clause is routinely dropped when the definition is quoted. The operative question is who initiated the transfer. In an account takeover the criminal logs in and initiates it, so the transfer sits on the unauthorized side of the line. The regulator's official interpretation of the same definition reaches a narrower case in the same direction: a transfer initiated by a person who obtained the access device from the consumer through fraud or robbery is unauthorized too. That comment matters where the criminal got the credentials out of the victim personally rather than from a breach somewhere else, and the page on phishing sets it out in full.

Contrast the case where the account holder is talked into sending the money themselves. That is a transfer the consumer initiated, so the definition is not satisfied and the electronic-transfer protections do not reach it, however complete the deception was. The two situations feel identical to a victim and are governed differently, which is the single most important thing to understand about this area.

One feature of the reporting rules matters here more than anywhere else. The federal electronic-transfer rules set an outer reporting deadline for unauthorized transfers that appear on a periodic statement, and that deadline is measured from the financial institution's transmittal of the statement, not from the moment the customer opens it. That is an entirely reasonable rule when statements arrive where they are supposed to. It is a trap in an account takeover, because redirecting or suppressing the statement is one of the first things the criminal does, so the clock can be running while the owner has no way of seeing anything. The tiers, the two different clocks and the error-resolution timetable are set out on the debit card and bank statement pages, and the extension available where a delay was due to extenuating circumstances is covered there too. Those pages are the ones to read; the point here is only that the clock's starting gun is fired by the institution rather than by the customer.

Where the credentials come from. Usually not from the institution's own systems. The recurring sources are a phishing message or a call impersonating the bank's support line, credentials exposed in a breach elsewhere and reused on a financial account, a device compromised by malware, and, increasingly, interception of the one-time code itself by a caller who has already persuaded the victim to read it out. The last of these is why a code sent by text is a weaker second factor than one generated by an application or by a physical security key: a code can be repeated to somebody, and a key cannot.

What a reader can actually act on. Alerts are the countermeasure that maps directly onto the attack, because the attack starts by disabling them: an institution that notifies a customer through a second channel when contact details or notification settings change removes the criminal's cover. Beyond that, the durable measures are a distinct password on every financial account so that one breach elsewhere does not open a bank, a second factor stronger than a text message, and reviewing statements even in a month when nothing seems to be wrong. Where an account has already been taken over, speed matters for two independent reasons: the regulation's clocks, and the practical fact that a recall of funds has hours rather than days to work in.

How to Remember

Ask what changed first. In an account takeover the email address and the alerts are altered before a dollar moves, because the point is to make sure nobody tells you.

Used in a Sentence

“The bank's log showed the account takeover began nine days before the transfers, when the registered phone number was changed and every alert was switched off.”

How It Works

  1. Credentials are obtained, from a phishing message, a call impersonating the institution's support line, a breach elsewhere where the same password was used, or a compromised device.

  2. The criminal logs in as the account holder. Nothing about the session is unusual from the institution's point of view, which is what makes the intrusion hard to detect.

  3. The account's contact details and alert settings are changed. Email address, phone number and notification preferences go first, which redirects or silences everything that would otherwise warn the owner.

  4. Payment capability is added, in the form of new payees, a linked external account, raised transfer limits, or a card issued to a new address.

  5. Money moves, often as many transactions at once rather than one, spread across several recipient accounts at different institutions.

  6. The owner discovers it late, and the answer to who bears the loss turns on whether each transfer was unauthorized under the electronic-transfer rules and on how quickly it was reported.

A hypothetical, showing why the timeline is the problem. Nadira's password is exposed in a breach at an unrelated website. It is the same password she uses for her bank.

On day 1 someone logs in, changes the email address of record, and turns off transaction alerts. Nothing has been taken and nothing arrives to tell her. On day 3 an external account is linked. On day 12 four transfers go out, of $2,400, $3,100, $1,800 and $2,700, so the total is $2,400 + $3,100 + $1,800 + $2,700 = $10,000.

Her statement covering that period is issued on day 30, to the address the criminal set on day 1. She sees nothing.

Notice what the eleven quiet days between day 1 and day 12 accomplished. They were not idleness: they were the criminal making certain that the transfers on day 12 would go unannounced. And because the federal outer reporting deadline for items appearing on a statement runs from the institution's transmittal of that statement rather than from her reading it, a clock she cannot see is running against her. What she can recover depends on the rules set out on the debit card and bank statement pages and on how quickly she reports once she learns. All figures are hypothetical.

Pros and Cons

Account takeover has no upside, so what follows is what genuinely reduces exposure and what those measures do not reach.

What reduces exposure

  • A distinct password on every financial account, so that a breach at an unrelated site does not open a bank account.
  • A second factor stronger than a text message. A code sent by text can be read out to a convincing caller; an application-generated code is harder to hand over and a physical security key cannot be.
  • Alerts on changes to contact details and notification settings, not only on transactions, because the change is the first move and the transaction is the last.
  • Keeping a second channel of contact with the institution that a criminal cannot silence by editing the profile.
  • Reviewing statements in months when nothing appears to be wrong, since the liability clock does not wait for the customer to look.
  • Reporting within hours rather than days once something is noticed. Recall and freeze requests depend on speed, and the regulation's clocks do too.

What those measures do not reach

  • Nothing on the customer's side prevents credentials being exposed in a breach at another company.
  • Statements and alerts can be redirected by the criminal, so the ordinary detection channel is the first casualty.
  • The outer reporting clock runs from when the institution sends the statement, not from when the customer sees it, which is exactly the assumption the attack defeats.
  • The protections that reverse unauthorized transfers do not reach a payment the account holder was persuaded to make themselves.
  • A fan-out of many simultaneous transfers to accounts at several institutions is far harder to unwind than a single transfer.

People Also Asked

Answers to the most frequently asked questions.

What is the difference between account takeover and identity theft?
Which account is involved. Account takeover is control of an account you already have: the criminal logs in as you and operates it. Identity theft in the usual sense is a new account opened in your name at an institution you have never dealt with. They can overlap, since a takeover gives access to the personal information that supports opening new accounts, but the remedies differ and the identity theft page covers the statutory route for the second.
Does Regulation E cover account takeover?
Regulation E never uses the phrase. Measured across the whole of 12 CFR part 1005 including the Official Interpretations, "account takeover" appears zero times, so the label carries no rights of its own. What matters is whether a particular transfer was "unauthorized," which the regulation defines as a transfer "initiated by a person other than the consumer without actual authority to initiate the transfer and from which the consumer receives no benefit." In a takeover the criminal initiates the transfer, which is the side of the line that carries protections. The debit card and bank statement pages set out what those protections are.
Why does the criminal change my email address before taking money?
To remove you from your own account before anything is visible. Changing the address, the phone number and the alert settings redirects one-time codes, suppresses transaction notifications and can reroute the periodic statement, so the transfers that follow arrive unannounced. It is also why an alert on a change to contact details is a more useful setting than an alert on transactions alone.
I was persuaded to send the money myself. Is that account takeover?
No, and the distinction has real consequences. Account takeover means somebody else operated your account. If you initiated the transfer, even while being deceived about who you were paying or why, the federal definition of an unauthorized electronic fund transfer is not satisfied, because it requires the transfer to be "initiated by a person other than the consumer." It is still fraud, and the fraud page addresses what can be done about it.
How quickly do I have to report it?
Fast, for two separate reasons. Practically, a recall or freeze request depends on hours rather than days once money has left. Legally, more than one deadline runs, and the outer reporting deadline for transfers appearing on a periodic statement is measured from the institution's transmittal of that statement rather than from when you read it — which is a particular problem here, since redirecting the statement is part of the attack. The specific tiers, clocks and the extension available for extenuating circumstances are on the debit card and bank statement pages.

Sources

AdviceOnly maintains high editorial standards to improve the quality and accuracy of our educational content. Content is written with the assistance of artificial intelligence tools following a rigorous quality assurance process, and periodically reviewed by credentialed and experienced human financial advisors. References used include government data, academic papers, interviews with industry experts, and reputable primary sources. You can learn more about our efforts to produce accurate content in our editorial policy.

  1. Code of Federal Regulations. "12 CFR Part 1005 — Electronic Fund Transfers (Regulation E)."
  2. Consumer Financial Protection Bureau. "Regulations, 12 CFR Part 1005 (Regulation E)."
  3. Federal Bureau of Investigation, Internet Crime Complaint Center. "2025 Internet Crime Report."

Have a question a definition can't answer?

Advice-only advisors answer questions like this for a transparent flat fee — no products, no commissions, no asset management.

Find an Advisor