ScamsIdentity theftAccount takeover: the five doors criminals use to get in — and how to lock each one first
High

Account takeover: the five doors criminals use to get in — and how to lock each one first

Criminals don't need to 'hack' you to take over your email, bank, or social accounts — they walk through one of five doors: a reused password, a fake login page, a stolen verification code, a SIM swap, or infostealer malware. Every one of those doors has a free lock. Here's the priority order, starting with the one move that matters most.

Sources checked:FBI IC3CISAFTCNIST

Account takeover is rarely a movie-style hack. Nobody breaks the encryption on your bank. Instead, someone walks in through one of five well-worn doors — a password you reused, a login page that wasn’t real, a six-digit code you read aloud, a phone number that got moved, or malware that vacuumed up your saved logins. The FBI’s Internet Crime Complaint Center said in a November 2025 alert that it had received more than 5,100 complaints of account takeover fraud with losses exceeding $262 million since January 2025. The alert’s focus: criminals who get in by impersonating your own bank’s support staff or website.

Here’s the good news, and the point of this guide: every one of those five doors has a free lock, and you can install the most important one — strong multifactor authentication on your email account — before dinner. This is the prevention playbook. If you’re already locked out or watching a stranger post as you, go straight to the recovery steps, in order.

Why your email is the account behind your accounts

When criminals get to choose a target, they choose email — because your inbox is where every other account sends its “reset your password” link. Control of your email is effective control of everything downstream: bank, social media, shopping, identity paperwork. Lock the inbox first; everything else inherits the protection.

The five doors

Door 1: the reused password. Data breaches leak email-and-password pairs by the millions, and criminals feed those lists into automated tools that try each pair on banks, email providers, and retailers — an attack called credential stuffing. If you reuse a password, a breach at some forum you forgot about becomes a working key to your bank. The cleanup steps after your data leaks are in what to do after a data breach.

Door 2: the fake login page. A convincing email or text warns of an “unusual sign-in” or a failed payment and links you to a pixel-perfect copy of the real login page. Whatever you type there goes to the criminal — sometimes relayed to the real site in real time, so even your one-time code gets stolen in the same breath. The FBI’s 2025 account-takeover alert adds a wrinkle worth knowing: fraudulent websites are one of the two main routes criminals use to get into accounts, and its advice includes avoiding clicking on internet search results or advertisements to reach your bank at all. The full anatomy is in the phishing email guide.

Door 3: the stolen verification code. The criminal already has your password and needs the six-digit code your bank just texted you — so they call, posing as the fraud department, with a helpful reason you should read it back. The FBI’s guidance in that same 2025 PSA is flat: companies generally do not contact you to ask for your username, password, or one-time passcode. The person asking for the code is the takeover, in progress. The one rule that stops it is in the verification-code scam.

Door 4: the SIM swap. Instead of stealing a code, the criminal steals the phone number the codes go to — convincing your carrier to move your number onto their SIM. From that moment, your texts (including login codes) ring on their phone, and your own device drops to “SOS only.” The carrier PIN that blocks it is free and takes ten minutes: SIM-swap protection.

Door 5: the infostealer. Malware built specifically to raid what your browser has saved — logins, cookies, and autofill data — no guessing required. In a May 2025 joint advisory, CISA and the FBI described the LummaC2 infostealer spreading through spearphishing links and through fake CAPTCHA pages that instruct you to “verify you’re human” by pasting a command into your computer — the paste is what installs the malware. If a “verification” step ever asks you to open a Run box or terminal, stop: that’s the fake CAPTCHA “ClickFix” scam.

Notice what all five have in common: none of them is defeated by having a “strong” password. That’s why the defense below is a system, not a password tip.

The defense, in priority order

This is Lock the Front Door — the named protocol this site recommends for account security — applied as a ranked to-do list. Do them in order; the first two carry most of the weight.

1. Turn on MFA — and climb the ladder

CISA’s headline number, from its More than a Password campaign (launched in 2022), is that “the use of MFA on your accounts makes you 99% less likely to be hacked.” The FTC’s consumer version is just as concrete — with two-factor on, a hacker who steals your password can’t log in without the second factor.

But not all second factors are equal, and CISA publishes the ranking. Its phishing-resistant MFA fact sheet puts it this way: “any form of MFA is better than no MFA,” but phishing-resistant MFA — passkeys and physical security keys — is “the gold standard,” while a code texted to your phone provides the weakest protection. So climb as high as each account allows:

  • Best: a passkey or security key. NIST’s consumer guidance describes the passkey advantage plainly: it’s a private digital key on your device, you log in as easily as you unlock your phone, and it can’t easily be stolen through phishing — there’s nothing to type into a fake page.
  • Good: an authenticator app. Free, works offline, immune to SIM swaps.
  • Better than nothing: SMS codes. Vulnerable to doors 3 and 4 — but still turn them on where nothing better exists.

Start with your email, then bank, then anything holding a card number.

2. Get a password manager and stop reusing passwords

This single habit closes door 1 entirely. The FTC and NIST both point consumers to password managers, which generate and remember a long, unique password for every site — NIST’s benchmark for any password you must create yourself is at least 15 characters. Unique passwords mean a breach at one site opens exactly one door, which you can re-lock with one reset.

There’s a bonus feature nobody advertises: your manager autofills only on the exact domain it saved. When it refuses to fill on what looks like your bank’s login page, it has spotted a fake before you did. Treat autofill silence as an alarm, not an inconvenience.

3. Adopt the two never-rules

They cost nothing and defeat doors 2 and 3. Never log in through a link, a search ad, or an attachment — open the app or type the address yourself. MFA can’t save you on a page built to relay your code, which is why the FBI pairs its MFA advice with a warning that it won’t protect you on a fraudulent login page. And never share a verification code with any person, for any reason. Real companies generate codes for you to type into their site — never to recite to a caller.

4. Lock your phone number

Ask your carrier for an account PIN and port-out protection so your number can’t be moved without it. Ten minutes, free, and it turns door 4 into a wall — the full walkthrough is in SIM-swap protection.

5. Tidy your recovery settings

Once a year, open the security page of your email and bank accounts and check the recovery email and phone number on file. An old number you gave up years ago may now belong to a stranger — which makes it a back door into your account that no password strength can fix. While you’re there, review connected devices and sessions, and remove what you don’t recognize.

The early warnings

A takeover attempt usually announces itself: reset emails you didn’t request, codes arriving unprompted, login alerts from unfamiliar devices, a phone that suddenly loses service. Any of these means someone is at one of your doors right now — change that account’s password, check its recovery settings, and if your phone went dark, call your carrier from another phone immediately.

If they’re already inside

Prevention has a time limit; if you’re past it, move to the recovery sequence — regain access, evict the intruder, then lock the door behind them — in our hacked-account recovery guide. Nothing on this page requires spending a dollar: the locks are free, the criminals count on you not installing them, and an afternoon of setup beats a month of cleanup. For the rest of the free arsenal, browse the named defense moves — or test how well you’d spot doors 2 and 3 in the wild with the 60-second quiz.

Warning signs
  • Password-reset emails or verification codes arrive that you didn't request — a sign someone already has your password and is working on the second lock.
  • Login or new-device alerts from places and devices you don't recognize, or an MFA push prompt appears when you aren't logging in.
  • Your phone suddenly drops to 'no service' or 'SOS only' for no reason — the classic opening of a SIM swap, where your number (and your text codes) now ring on someone else's device.
  • A 'verification' page asks you to prove you're human by pasting a command into a Windows Run box — that's not a CAPTCHA, it's an infostealer installing itself.
Defense move — Lock the Front Door
  • Start with your email account, today: it's the account that resets every other account. Add the strongest second factor it offers — a passkey or security key first, an authenticator app second, SMS codes only if nothing else exists. CISA says MFA makes you 99% less likely to be hacked (More than a Password campaign, 2022).
  • Use a password manager and let it generate a unique password for every account. One breach then opens one door instead of twenty — and a manager that refuses to autofill on a login page is quietly telling you the page is fake.
  • Adopt the two never-rules: never log in through a link or a search ad (open the app or type the address yourself), and never read a verification code to anyone. The FBI notes companies generally do not contact you to ask for your username, password, or OTP.
  • Lock your phone number with a carrier PIN and port-out protection, so a SIM swap can't quietly reroute your text codes to a criminal's phone.
  • Tidy your recovery settings once a year: make sure the backup email and phone number on file are current and yours, and remove old ones — an ex-phone number is a back door you forgot you left open.
Editor's note

Everyone asks me which antivirus to buy, and almost no one asks the question that decides whether they get taken over: what happens if someone gets my email password? That inbox is the account behind your accounts — every reset link for everything you own lands there. So my honest priority list is short: put a passkey on your email first, put your passwords in a manager second, and only then worry about the rest of this page.

Frequently asked

Which type of two-factor authentication should I actually use — and is SMS good enough?

Use the strongest option each account offers, in this order: a passkey or physical security key, then an authenticator app, then SMS codes. CISA's guidance is blunt about the ranking — 'any form of MFA is better than no MFA,' but phishing-resistant MFA (the passkey/security-key tier) is 'the gold standard,' while a texted code 'provides the weakest protection.' The FTC gives the same advice to consumers: an authenticator app or a security key are the more secure types, and you should pick one of them when you have the option. SMS codes can be phished in real time and rerouted by a SIM swap — but if SMS is all an account supports, turn it on anyway. A weak lock still beats an open door.

Isn't putting every password in one password manager just creating one big target?

It concentrates risk in one place, but it removes a much bigger risk everywhere else: reuse. When a breached site leaks your password, criminals immediately try that same email-and-password pair on banks, email providers, and stores — so one reused password quietly becomes twenty compromised accounts. NIST's consumer guidance recommends using a password manager to generate and store long, unique passwords, and the FTC's advice is the same. Protect the manager itself with a long passphrase (15+ characters) and the strongest MFA it offers. There's also a hidden bonus: a manager autofills only on the exact site it saved, so when it goes silent on a look-alike login page, treat that silence as an alarm.

What exactly is a passkey, and should I switch to one?

A passkey replaces your password with a private digital key stored on your device — you approve a login the same way you unlock your phone, with a fingerprint, face, or PIN. NIST's guidance highlights the two properties that matter here: passkeys can't easily be stolen through phishing, and each one works only for the site that created it, so there's nothing to reuse, leak, or type into a fake page. That kills the two biggest takeover doors — credential stuffing and fake logins — at the root. Yes, switch where it's offered: start with your primary email account, then banking. Most major email, bank, and social platforms now support passkeys, and you can usually keep your password as a backup while you get comfortable.

RY
Ryon — Founder & Editor
Consumer-safety advocate · Scamblare

Scamblare researches scams every day so you don't have to. Every article is checked, claim by claim, against primary sources like the FTC and FBI IC3 under our published editorial standard. How we fact-check ›