← Back to glossary

Unauthorized control over a user account.

Definition

ATO is unauthorized access and control of an account, often via compromised credentials, session tokens, social engineering, or recovery-channel abuse.

In plain English Unauthorized control over a user account.

Why this matters

Why it matters: It enables direct access to private data and can facilitate fraud, data exfiltration, and further compromise.

Example

Example: Credential stuffing leads to successful login followed by changing MFA settings.