Account Takeover Scam

In this scam, a fraudster gains access to your email, bank, or shopping accounts, often after phishing or a data breach, then changes details, makes purchases, or uses the account to attack others.

Quick verdict

Risk level
High risk
Scam type
Account takeover (identity)
Main red flag
Unexpected password resets, logins, or changes to your accounts.
What to do first
Secure your email first, then change passwords and enable two-factor authentication.

Understanding this scam

In this scam, a fraudster gains access to your email, bank, or shopping accounts, often after phishing or a data breach, then changes details, makes purchases, or uses the account to attack others.

Identity theft uses stolen personal data, from phishing, data breaches, or mail theft, to open accounts, claim benefits, or take over existing accounts in your name. It can go undetected for months, which is why early monitoring and credit freezes matter.

If you take one thing from this guide, make it this: Unexpected password resets, logins, or changes to your accounts. Secure your email first, then change passwords and enable two-factor authentication.

If your message looks slightly different, check the MFA Fatigue Scam or the Email Storage Full Scam, both are close cousins of this pattern. Every related guide lives in the Identity Theft & Data Scams guides, and the scam checker can scan the text you received.

A typical example

Example pattern, not a real report
Example pattern: You get password-reset emails you did not request, are logged out unexpectedly, or see orders and changes you did not make.

This is a fictional, anonymised example used to illustrate the pattern. It is not a verified real message, and any names are used only to show how the scam typically reads.

The tell here: Unexpected password resets, logins, or changes to your accounts.

What the data shows

1M+
identity-theft reports are made to the FTC each year
$10.3B
total reported US fraud losses in 2023

Warning signs

  • Password-reset emails or codes you did not request
  • Being logged out or locked out unexpectedly
  • Changed recovery email, phone, or details
  • Orders, messages, or transfers you did not make
  • Logins from unfamiliar devices or locations

Your safest response

  • Secure your email account first, as it controls other resets
  • Change passwords and enable two-factor authentication
  • Review and remove unknown devices and sessions
  • Contact affected providers and your bank

If you have already engaged

  • Regain access through official recovery and lock the account down
  • Check for changed recovery details and undo them
  • Review transactions and report fraud
  • Warn contacts if your account messaged them

What to avoid

  • Do not reuse passwords across accounts
  • Do not ignore unexpected reset emails or logins
  • Do not delay securing your email

You might also see

Questions people ask

Why secure my email first?
Email controls password resets for many accounts. If a scammer holds your email, they can take over others, so lock it down first.
How did they get in?
Often through phishing, reused passwords exposed in a breach, or intercepted codes. Unique passwords and two-factor authentication make takeover much harder.
My account was taken over. What now?
Regain access through official recovery, change passwords, enable two-factor authentication, remove unknown sessions, undo changed recovery details, and report fraud.
How do I prevent it?
Use strong unique passwords, enable two-factor authentication, and be wary of phishing links and unexpected reset requests.

Last reviewed June 2026 · Written & reviewed by the

Disclaimer: This page provides educational information only to help you recognise common scam patterns. It is not legal, financial, cybersecurity, or law enforcement advice, and it does not confirm whether any specific message, company, or person is genuine or fraudulent. When in doubt, contact the official organisation directly and report concerns to your local authorities.