What email account takeover is#
Account takeover (ATO) is unauthorized access to a legitimate mailbox, typically via phished credentials, password reuse, or OAuth consent phishing.
Why it matters#
A taken-over mailbox bypasses every authentication control and becomes a launchpad for BEC and internal phishing.
How mailbox providers use it#
Gmail, Microsoft, and Yahoo combine authentication results, sender reputation, and recipient engagement into a placement decision made per message. Email account takeover feeds directly into that model, and weaknesses compound with other signals.
How to measure the impact#
- Baseline inbox placement with seed tests before any change.
- Make one change at a time and hold volume steady.
- Re-test after 48 to 72 hours; provider models need time to update.
- Track Postmaster Tools and SNDS alongside your seed results.
Improving it#
- Enforce phishing-resistant MFA (FIDO2 keys or passkeys) for admins and finance.
- Review third-party OAuth grants monthly and restrict user consent.
- Alert on impossible-travel logins and mass downloads.
- Have a documented response: revoke sessions, reset, audit rules and forwards, notify affected parties.
Frequently asked questions#
What are signs of a compromised email account?
Unknown sent items, new forwarding rules, missing mail, login alerts from unfamiliar locations, and contacts reporting odd messages.