S.M.M.

Stop Manipulating Me · A Field Guide to Psychological Influence

ENTRY No. T24.10
CATEGORY Internet Scams
CLEARANCE Public / Essential
EDITION 01
Dossier · Manipulation Tactic

Account Takeover

Access Fraud · Trusted-Identity Hijack · Ubiquitous
Red Flag
How It WorksSEC 01

Account takeover (ATO) is the destination most other internet scams feed into: phishing, SIM swapping, MFA fatigue, infostealer malware, and help-desk manipulation are the routes, and control of your account is the prize. Once an attacker is in, they inherit its trust, its stored data, its saved payment methods, and — critically — its recovery power over other accounts. Email is the highest-value target, because whoever controls the inbox usually controls the password resets for everything linked to it.

Several access routes recur. Credential stuffing replays username/password pairs leaked in old breaches, exploiting reuse. Credential phishing captures the login directly. MFA fatigue floods you with approval prompts until one is tapped out of annoyance. Adversary-in-the-middle phishing steals a live session token, inheriting an authenticated session even when a one-time code was used. SIM swapping intercepts SMS codes and reset links.

The compromise is often quiet at first: the attacker sets up mail-forwarding rules, adds a recovery device, or lurks before draining funds, changing your contact details, or messaging your friends with a scam. Its defining feature: your own trusted identity is turned against you and everyone who trusts it.

Warning SignsSEC 02
  • Unexpected login alerts. "New device or location" notifications for sign-ins you didn't make.
  • Resets you didn't request. Password-reset or MFA-enrollment emails arriving unprompted.
  • A burst of MFA prompts. Repeated push approvals you didn't initiate — push-bombing in progress.
  • Silent settings changes. New mail-forwarding rules, filters, linked devices, or recovery emails/phones you didn't add.
  • Being logged out or locked out. Suddenly unable to sign in to your own account.
  • Contacts flagging odd messages. Friends report strange messages "from you," or funds and payout details have changed.
Frequently Paired WithSEC 03
  • SIM Swapping · T24.11
    Intercepts the SMS codes that enable it
  • Phishing · T14.2
    The credential-harvest route
  • Malware Delivery · T24.25
    Infostealers scrape logins and tokens
  • MFA Fatigue · T14.18
    Push-bombing wears down approval
How the Scam UnfoldsSEC 04
  • Stage 01 · Access
    A stolen or reused password, a phished login, a fatigued MFA approval, or a hijacked session defeats the account's authentication.
  • Stage 02 · Entrenchment
    The attacker lurks — adding forwarding rules and a recovery device, quietly altering settings to keep control and lock you out.
  • Stage 03 · Exploitation
    Funds are drained, linked accounts are cascaded via email resets, and scams are sent to your trusted contacts.
Counter-ProtocolSEC 05
Defense: Your email is the master key — harden authentication before a loss, not after.
  • Unique, long, random passwords per account via a password manager — this kills credential stuffing and refuses to autofill on look-alike phishing domains.
  • Adopt phishing-resistant MFA (passkeys or FIDO2 keys), especially on email and finances, in preference to SMS or push-approval.
  • Treat any unrequested MFA prompt as an attack. Deny it and change the password; use number-matching where only push exists.
  • Turn on login and transaction alerts, and periodically review active sessions, forwarding rules, and recovery settings.
  • If taken over: from a clean device reset the password, revoke all sessions, remove rogue rules and devices, re-enroll MFA, notify contacts, and report to IdentityTheft.gov and IC3.