Account takeover
Accounts and accessComes in through: Passwords
Someone gets into your email with a stolen password
Reused passwords, passwords leaked from other websites or accounts without two-factor: one is enough for someone to get into the company's email or apps and act as if they were one of you.
Threat mapHow it happens
- 1
The password
It's obtained through phishing, a leak from another site where the same one was used, or because it's easy to guess.
- 2
The access
The attacker gets in quietly. Without two-factor, nothing stops them.
- 3
The misuse
They read email, set rules to hide messages, ask clients for payments or steal information.
How to spot it
- Sign-in alerts from unknown places or devices
- Emails in "sent" that nobody wrote
- Forwarding or deletion rules nobody created
- Clients receiving odd messages from your account
How to protect yourself
- Turn on two-factor for email and key apps
- Use a password manager and never reuse passwords
- Check whether your addresses appear in known leaks
- Sign out sessions and change passwords when someone leaves
If it has already happened
Change the password, sign out all sessions, check the mailbox rules and turn on two-factor. Warn clients if they may have received fake messages.
How we help
Training
Passwords and two-factor
A practical course so your team recognises it in time.
Audit
We check whether this door is open in your company and how to close it.
Full guide · in Spanish
Autenticación en dos pasos (MFA): por qué debería ser obligatoria en tu empresa
Other threats through this door
See all threatsHow many of these risks does your company have right now?
Take the cybersecurity test and discover your exposure level in 3 minutes. You'll get your score with the highest-risk areas, no sign-up required.
Free · No sign-up · 3 minutes