Edge Rewrite
// HTMLRewriter · presentation

This page was redesigned at the edge.

Cloudflare fetched the original article and streamed it through HTMLRewriter to apply an entirely new visual system without rebuilding the source page.

Jump to content

Account takeover

From Wikipedia, the free encyclopedia

Account takeover (ATO) is when an attacker uses vulnerabilities to take control of a victim's account allowing the attacker to preform functions on the victim's behalf.[1] Account takeover can be the result of theft of session tokens, credential stuffing, malware, insecure design of access controls, or social engineering.[2][3][4]

References

[edit]
  1. ↑ Doerfler, Periwinkle; Thomas, Kurt; Marincenko, Maija; Ranieri, Juri; Jiang, Yu; Moscicki, Angelika; McCoy, Damon (2019-05-13). "Evaluating Login Challenges as aDefense Against Account Takeover". The World Wide Web Conference. ACM: 372–382. doi:10.1145/3308558.3313481. ISBN 978-1-4503-6674-8.{{cite journal}}: CS1 maint: periodical has ISBN (link)
  2. ↑ "Account Takeover Attack (ATO) | Types, Detection & Protection | Imperva". Learning Center. Retrieved 2026-10-05.
  3. ↑ "What Is Account Takeover (ATO)? Definition & Fraud Protection". Fortinet. Retrieved 2026-10-05.
  4. ↑ "Account Takeover Fraud - Internet Crime Complaint Center (IC3)". www.ic3.gov. Retrieved 2026-10-06.