Skip to content

Account Takeover

Account Takeover and One-Time Code Fraud

Account takeover happens when a criminal gains access to one of your accounts, often by persuading you to share a one-time code or by reusing a leaked password.

High riskSafeGlobalCurrent
Last verified 9 February 2025
account-takeoverotp2fapasswords

Overview

What is it

Account takeover is the loss of control of an account to someone else. Criminals get in by reusing passwords exposed in data breaches, by guessing weak passwords, or by persuading you to read out a one-time code during a fake support call. Once inside, they change the password and recovery details, lock you out, and use the account to target your contacts. One-time codes are the last line of defence, which is why no genuine organisation will ever ask you to share one.

Entry point

How does it usually begin

The takeover begins with a leaked password, a phishing page, or a phone call that asks for a code. Sometimes a criminal requests a password reset on your account, then calls you pretending to be support and asks you to confirm the code that was just sent to you.

Psychology

The psychological play

The deception exploits helpfulness and authority. A caller who sounds like support and already knows your name makes sharing a code feel like a normal security step. The genuine code message often warns you not to share it, but the caller talks over that warning.

Warning signs

What to watch for

  • You receive a one-time code you did not request.
  • Someone calls and asks you to read out a code.
  • You are unexpectedly logged out or your password stops working.
  • You receive alerts about sign-ins from unfamiliar devices.
  • Contacts say they got strange messages from your account.
  • Recovery email or phone details have been changed without your knowledge.

Victim perspective

What the victim usually sees

Your phone shows a code you did not ask for, followed by a call from someone claiming to be support. They say the code is needed to secure your account and ask you to read it out.

Anatomy

The anatomy of the deception

  1. 01

    Contact

    You receive an unexpected one-time code, then a call.

    Defender move

    Never share a code, even with someone who sounds official.

  2. 02

    Trust

    The caller knows your name and account details.

    Defender move

    Remember that leaked data can supply those details.

  3. 03

    Pressure

    You are told your account is at risk right now.

    Defender move

    End the call and check your account yourself.

  4. 04

    Request

    You are asked to read out the code.

    Defender move

    Treat any request for a code as an attempt at takeover.

  5. 05

    Payment or Information

    The code is used to reset your password.

    Defender move

    Change the password and recovery details immediately.

  6. 06

    Consequence

    You are locked out and your contacts are targeted.

    Defender move

    Use account recovery, warn contacts, and report it.

Verification

What to verify

  1. 1Never share a one-time code with anyone, including support staff.
  2. 2Check for unfamiliar sign-ins in your account security settings.
  3. 3Verify that your recovery email and phone number are still correct.
  4. 4Use a unique password for every important account.

Protection

How to protect yourself

  • Use an authenticator app rather than text-message codes where possible.
  • Never reuse passwords across accounts.
  • Review active sessions and remove devices you do not recognise.
  • Treat unsolicited calls about your account as hostile until verified.

If it happened

If you already responded

Act quickly, and don't blame yourself.

  1. 1Start account recovery with the provider immediately.
  2. 2Change the password and recovery details once you regain access.
  3. 3Warn your contacts about messages sent from your account.
  4. 4Report the incident to the provider and your national fraud service.

Examples

Real-world examples

Examples include fake support calls that request a code, password reuse after a breach, and fake password-reset emails that lead to a look-alike login page.

Sources

Where this comes from

Claims are labelled by verification status. Treat reported, alleged and unresolved claims as exactly that.

  • Verified factINSTITUTIONAL

    Guidance on phishing and account protection

    Microsoft Security · 01 Oct 2024

    View source
  • Verified factGOVERNMENT

    Guidance on personal data and identity theft

    UK Information Commissioner's Office (ICO) · 18 Mar 2024

    View source

Spotted this pattern? Help others by reporting it.