Account takeover (ATO) is the destination most other internet scams feed into: phishing, SIM swapping, MFA fatigue, infostealer malware, and help-desk manipulation are the routes, and control of your account is the prize. Once an attacker is in, they inherit its trust, its stored data, its saved payment methods, and — critically — its recovery power over other accounts. Email is the highest-value target, because whoever controls the inbox usually controls the password resets for everything linked to it.
Several access routes recur. Credential stuffing replays username/password pairs leaked in old breaches, exploiting reuse. Credential phishing captures the login directly. MFA fatigue floods you with approval prompts until one is tapped out of annoyance. Adversary-in-the-middle phishing steals a live session token, inheriting an authenticated session even when a one-time code was used. SIM swapping intercepts SMS codes and reset links.
The compromise is often quiet at first: the attacker sets up mail-forwarding rules, adds a recovery device, or lurks before draining funds, changing your contact details, or messaging your friends with a scam. Its defining feature: your own trusted identity is turned against you and everyone who trusts it.