Account Takeover
Account Takeover and One-Time Code Fraud
Account takeover happens when a criminal gains access to one of your accounts, often by persuading you to share a one-time code or by reusing a leaked password.
Overview
What is it
Account takeover is the loss of control of an account to someone else. Criminals get in by reusing passwords exposed in data breaches, by guessing weak passwords, or by persuading you to read out a one-time code during a fake support call. Once inside, they change the password and recovery details, lock you out, and use the account to target your contacts. One-time codes are the last line of defence, which is why no genuine organisation will ever ask you to share one.
Entry point
How does it usually begin
The takeover begins with a leaked password, a phishing page, or a phone call that asks for a code. Sometimes a criminal requests a password reset on your account, then calls you pretending to be support and asks you to confirm the code that was just sent to you.
Psychology
The psychological play
The deception exploits helpfulness and authority. A caller who sounds like support and already knows your name makes sharing a code feel like a normal security step. The genuine code message often warns you not to share it, but the caller talks over that warning.
Warning signs
What to watch for
- You receive a one-time code you did not request.
- Someone calls and asks you to read out a code.
- You are unexpectedly logged out or your password stops working.
- You receive alerts about sign-ins from unfamiliar devices.
- Contacts say they got strange messages from your account.
- Recovery email or phone details have been changed without your knowledge.
Victim perspective
What the victim usually sees
Your phone shows a code you did not ask for, followed by a call from someone claiming to be support. They say the code is needed to secure your account and ask you to read it out.
Anatomy
The anatomy of the deception
- 01
Contact
You receive an unexpected one-time code, then a call.
Defender move
Never share a code, even with someone who sounds official.
- 02
Trust
The caller knows your name and account details.
Defender move
Remember that leaked data can supply those details.
- 03
Pressure
You are told your account is at risk right now.
Defender move
End the call and check your account yourself.
- 04
Request
You are asked to read out the code.
Defender move
Treat any request for a code as an attempt at takeover.
- 05
Payment or Information
The code is used to reset your password.
Defender move
Change the password and recovery details immediately.
- 06
Consequence
You are locked out and your contacts are targeted.
Defender move
Use account recovery, warn contacts, and report it.
Verification
What to verify
- 1Never share a one-time code with anyone, including support staff.
- 2Check for unfamiliar sign-ins in your account security settings.
- 3Verify that your recovery email and phone number are still correct.
- 4Use a unique password for every important account.
Protection
How to protect yourself
- Use an authenticator app rather than text-message codes where possible.
- Never reuse passwords across accounts.
- Review active sessions and remove devices you do not recognise.
- Treat unsolicited calls about your account as hostile until verified.
If it happened
If you already responded
Act quickly, and don't blame yourself.
- 1Start account recovery with the provider immediately.
- 2Change the password and recovery details once you regain access.
- 3Warn your contacts about messages sent from your account.
- 4Report the incident to the provider and your national fraud service.
Examples
Real-world examples
Examples include fake support calls that request a code, password reuse after a breach, and fake password-reset emails that lead to a look-alike login page.
Sources
Where this comes from
Claims are labelled by verification status. Treat reported, alleged and unresolved claims as exactly that.
- Verified factINSTITUTIONAL
Guidance on phishing and account protection
Microsoft Security · 01 Oct 2024
View source - Verified factGOVERNMENT
Guidance on personal data and identity theft
UK Information Commissioner's Office (ICO) · 18 Mar 2024
View source
Spotted this pattern? Help others by reporting it.