Account Takeover

Account takeover is criminals logging into real customer accounts with stolen credentials, at bot scale.

What account takeover is

Account takeover, ATO, is a criminal logging into a real customer’s account: usually with credentials leaked from other breaches and replayed at scale, then spending saved payment methods, draining points and gift cards, or harvesting data.

Why account takeover matters

Password reuse makes every breach elsewhere your problem: bots test stolen credential lists against store logins continuously, and each success is a customer betrayed inside your walls, with the chargebacks, drained balances, and support fallout landing on the store.

How stores defend against ATO

  • Bot defense and rate limits on login endpoints
  • Breached-password checks and step-up verification on risk signals
  • Passkeys and social login shrinking the password surface
  • Alerts on the actions that matter: new address plus saved card use, balance drains

Frequently asked questions

What does an ATO wave look like in the data?

Login attempts spiking with high failure rates from rotating sources, then odd account activity: address changes, rapid redemptions, saved-card orders to fresh destinations. The login graph screams before the fraud reports arrive.

Do stores without saved cards need to care?

Yes: accounts hold order history, addresses, points, gift cards, and identity fragments worth stealing, and takeover of any account damages the customer’s trust in you regardless of what was taken.

Related terms

Loyalty Fraud · Fraud Detection · Social Login