Definition
Account takeover happens when an attacker obtains credentials and gains access to an email account without authorisation. In marketing, compromised accounts are a common source of spam and phishing because the attacker uses a trusted address to send malicious mail.
The damage is twofold: recipients lose trust in your brand, and the sending reputation of your domain is damaged by the spam, hurting future deliverability.
Account takeover is both a security incident and a deliverability disaster, because spam sent from your account destroys the reputation you built. Prevention and monitoring are cheap compared with recovery. Responding quickly limits the damage.
How Takeovers Happen
Credential reuse, phishing, and password breaches are the most common entry points. Once inside, attackers typically scan for sensitive data, reset passwords, and send phishing mail from the account.
Detection relies on monitoring unusual login and sending behaviour.
Why It Matters
Account takeover is both a security incident and a deliverability disaster, because spam sent from your account destroys the reputation you built. Prevention and monitoring are cheap compared to the recovery cost.
Best Practices
- Enforce strong passwords and multi-factor authentication.
- Watch for unusual login and sending patterns.
- Suspend and secure compromised accounts promptly.
- Enforce strong, unique passwords and multi-factor authentication on all accounts.
- Monitor for unusual logins, sent-volume spikes, and new forwarding rules.
- Suspend and secure compromised accounts immediately.
- Audit third-party app access to email accounts.
- Train staff to recognise phishing that targets credentials.
Was this useful?
Related Glossary Terms
Abuse Complaint
An abuse complaint is a report from a recipient who marks an email as spam, which negatively affects sender reputation and deliverability.
Alt Text
Alt text is the written alternative to an image in an email, displayed when images are blocked, slow to load, or consumed by screen readers.
Anonymized Data
Anonymized data is email subscriber or interaction data that has been stripped of personally identifiable information so individuals cannot be re-identified.
AOL Mail for Email Marketers
AOL Mail is a legacy email provider with specific deliverability requirements and rendering quirks, now operating as part of the Yahoo+AOL network under shared infrastructure.
Apple App Password (Email)
An Apple app password is a generated, app-specific password used to sign into an email account through clients that do not support two-factor authentication.
Australia Spam Act 2003
The Australian Spam Act 2003 bans unsolicited commercial email, requiring consent, accurate sender information and a clear, working unsubscribe facility on every message.
Frequently Asked Questions
An attacker gaining unauthorised access to an email account, typically to steal data or send malicious mail. Account takeover is both a security incident and a deliverability disaster, because spam sent from your account destroys the reputation you built.
Spam or phishing sent from your account damages your domain reputation and triggers blocks. Prevention and monitoring are cheap compared with recovery.
Unusual logins, unexpected sent mail, new forwarding rules, and password reset emails you did not request. Responding quickly limits the damage.
Use strong unique passwords, enable multi-factor authentication, and monitor account activity. Account takeover is both a security incident and a deliverability disaster, because spam sent from your account destroys the reputation you built.
Secure the account, revoke sessions and app access, notify affected parties, and alert your ESP or provider. Prevention and monitoring are cheap compared with recovery.