Skip to main content
Defentria
05

Account takeover

Accounts and accessComes in through: Passwords

Someone gets into your email with a stolen password

Reused passwords, passwords leaked from other websites or accounts without two-factor: one is enough for someone to get into the company's email or apps and act as if they were one of you.

Threat map

How it happens

  1. 1

    The password

    It's obtained through phishing, a leak from another site where the same one was used, or because it's easy to guess.

  2. 2

    The access

    The attacker gets in quietly. Without two-factor, nothing stops them.

  3. 3

    The misuse

    They read email, set rules to hide messages, ask clients for payments or steal information.

How to spot it

  • Sign-in alerts from unknown places or devices
  • Emails in "sent" that nobody wrote
  • Forwarding or deletion rules nobody created
  • Clients receiving odd messages from your account

How to protect yourself

  • Turn on two-factor for email and key apps
  • Use a password manager and never reuse passwords
  • Check whether your addresses appear in known leaks
  • Sign out sessions and change passwords when someone leaves

If it has already happened

Change the password, sign out all sessions, check the mailbox rules and turn on two-factor. Warn clients if they may have received fake messages.

Next step

How many of these risks does your company have right now?

Take the cybersecurity test and discover your exposure level in 3 minutes. You'll get your score with the highest-risk areas, no sign-up required.

Take the cybersecurity test

Free · No sign-up · 3 minutes