Account takeover (ATO) is unauthorized access to a legitimate mailbox, typically via phished credentials, password reuse, or OAuth consent phishing.
What are signs of a compromised email account?
Unknown sent items, new forwarding rules, missing mail, login alerts from unfamiliar locations, and contacts reporting odd messages.
Why does email account takeover matter for deliverability?
A taken-over mailbox bypasses every authentication control and becomes a launchpad for BEC and internal phishing.
What is the first step to get started with email account takeover?
Enforce phishing-resistant MFA (FIDO2 keys or passkeys) for admins and finance.
What is the most common email account takeover mistake?
SMS-based MFA for high-value accounts.