Account Takeover Investigation: How to Investigate Unauthorized Access and Preserve Digital Evidence
An account takeover can begin with something as simple as an unexpected password-reset email.
Then you notice a login you do not recognize.
Your password stops working. Your recovery email has changed. Messages have been sent from your account. Security settings are different. Money or cryptocurrency has moved. Someone has contacted your customers, friends or employees while pretending to be you.
At that point, changing the password is important—but it may not answer the most important questions.
How did someone gain access?
When did the unauthorized activity begin?
What did they access after getting inside?
What did they change?
Did they download, transfer or steal anything?
Do they still have another way into the account?
An account takeover investigation examines available digital evidence to reconstruct unauthorized account activity, identify potential methods of compromise and determine the scope of the incident.
What Is an Account Takeover?
Account takeover occurs when someone obtains unauthorized access to another person’s or organization’s online account.
It can affect almost any type of account, including:
- Email accounts
- Social media accounts
- Cryptocurrency exchange accounts
- Cloud accounts
- Business accounts
- E-commerce accounts
- Financial accounts
- Website administrator accounts
- Messaging applications
- Customer portals
- Developer accounts
The attacker does not necessarily need to “hack” the service itself.
In many cases, they obtain credentials or authentication access belonging to the legitimate user.
That distinction matters because the investigation may need to extend beyond the compromised account.
How Do Account Takeovers Happen?
There is no single method.
Possible attack paths include:
Stolen Passwords
A password may have been obtained through phishing, malware, credential-stealing software, a compromised device or another data breach.
Password Reuse
If the same password is used across multiple services, credentials exposed elsewhere may be tested against additional accounts.
This is commonly associated with credential stuffing attacks.
Phishing
A victim may receive an email, text message or direct message directing them to a fake login page.
The page can be designed to imitate a legitimate service and capture credentials entered by the victim.
More sophisticated phishing attempts may also target authentication tokens or multi-factor authentication.
Compromised Email Accounts
Email accounts are especially important because they are often connected to password-reset systems for many other services.
Someone who gains access to an email account may attempt to reset passwords for other accounts.
Stolen Session Tokens
An attacker does not always need the password.
In some incidents, stolen browser cookies or authenticated session tokens can potentially allow unauthorized access to an already authenticated account.
Malware
Credential-stealing malware can collect passwords, browser data, cookies or other authentication information from a compromised device.
Social Engineering
An attacker may manipulate the victim, an employee or even a service provider into providing access or changing account information.
SIM Swapping
Where SMS is used for authentication or recovery, control of a victim’s phone number can potentially be abused to intercept verification codes.
Compromised Recovery Methods
An attacker may gain control of a recovery email address, telephone number or other account-recovery mechanism.
Determining which method was actually involved requires evidence.
An investigation should not assume the cause simply because one possibility appears likely.
Signs That an Account May Have Been Taken Over
Some account takeovers are obvious.
Others remain unnoticed while the attacker quietly monitors activity.
Possible warning signs include:
- Login alerts you do not recognize
- Password changes you did not make
- Unexpected password-reset messages
- Changes to recovery email addresses
- Changes to recovery phone numbers
- Unknown trusted devices
- New authentication methods
- Multi-factor authentication changes
- Messages you did not send
- Deleted emails
- New email-forwarding rules
- Unrecognized transactions
- Cryptocurrency withdrawals
- New API keys
- Security notifications
- Contacts receiving messages from “you”
- Account settings changing unexpectedly
- Being suddenly locked out
Several indicators appearing together can be particularly concerning.
What Should You Do After Discovering Unauthorized Account Access?
The immediate priority is usually to prevent continued unauthorized access.
But evidence preservation matters too.
Before deleting everything suspicious, document what you can safely observe.
Take note of:
- Login notifications
- Security alerts
- Unknown devices
- Suspicious IP addresses
- Changed recovery information
- Unauthorized transactions
- Messages sent by the attacker
- Password-reset emails
- Dates and timestamps
- Changes to account settings
Screenshots can help preserve what was visible at the time.
Do not publicly confront a suspected attacker or attempt to access their accounts.
Instead, preserve the information associated with the incident and use the affected service’s legitimate security and recovery procedures.
What Evidence Can Be Examined in an Account Takeover Investigation?
The available evidence varies significantly between platforms.
An investigator may examine several sources.
Login History
Login records can sometimes reveal:
- Login dates and times
- IP addresses
- Approximate locations
- Device information
- Browser information
- Successful and unsuccessful authentication attempts
These records can help construct a timeline.
However, an IP address should not automatically be interpreted as the physical location or identity of the attacker.
VPNs, proxies, mobile networks, cloud servers and compromised devices can obscure the true source of activity.
Security Notifications
Services frequently generate notifications when:
- A new device logs in
- A password changes
- Recovery information changes
- Multi-factor authentication changes
- Suspicious activity is detected
These messages can become valuable timeline evidence.
Email Records
Email can provide particularly useful evidence.
Investigators may examine:
- Password-reset messages
- Login notifications
- Security alerts
- Deleted messages
- Forwarding rules
- Filters
- Recovery requests
- Messages sent by an attacker
A compromised email account can also help explain how other accounts were subsequently accessed.
Device Evidence
Sometimes the account is only one part of the incident.
If credential theft or malware is suspected, examining the device used to access the account may become relevant.
Potential evidence can include browser artifacts, suspicious software, downloads, authentication information and other digital traces.
This is where an account takeover investigation can overlap with mobile forensics or computer forensics.
Building an Account Takeover Timeline
One of the most useful investigative techniques is reconstructing events chronologically.
For example:
Phishing message received
↓
Credentials entered into fraudulent website
↓
Unknown login detected
↓
Recovery email changed
↓
Password changed
↓
Additional accounts accessed
↓
Unauthorized transaction initiated
↓
Victim discovers compromise
The real timeline may be considerably more complicated.
Investigators can correlate evidence from emails, login records, devices, security notifications, transactions and account settings.
The goal is to understand not just what happened, but in what order it happened.
Did the Attacker Change the Account’s Security Settings?
This is an important question.
After gaining access, an attacker may attempt to make their access more persistent.
Potential changes can include:
- Adding a recovery email
- Changing the recovery phone number
- Registering another device
- Creating application passwords
- Adding authentication methods
- Creating API keys
- Changing multi-factor authentication
- Adding email-forwarding rules
- Creating administrator accounts
- Modifying account permissions
Changing the password without reviewing these settings can sometimes leave another access mechanism behind.
Email Account Takeover Can Be Especially Serious
Email deserves special attention because it often functions as the recovery mechanism for numerous other services.
If an attacker controls an email account, they may search the mailbox to identify:
- Financial services
- Cryptocurrency exchanges
- Social media accounts
- Business systems
- Cloud services
- Customer accounts
- Password-reset emails
- Personal information
They may then attempt to compromise additional accounts.
Attackers can also create forwarding rules so copies of incoming emails are silently sent elsewhere.
This is why an email compromise should not necessarily be treated as an isolated password problem.
We will cover this scenario separately in our Email Account Compromise Investigation guide.
Cryptocurrency Account Takeovers
Account takeover can become particularly serious when cryptocurrency is involved.
An attacker who gains unauthorized access to a cryptocurrency exchange account, wallet-related account or email connected to cryptocurrency services may attempt to:
- Change security settings
- Add withdrawal addresses
- Disable authentication controls
- Convert assets
- Withdraw cryptocurrency
- Delete notifications
- Compromise additional accounts
If cryptocurrency has already been transferred, the investigation may expand beyond the account itself.
Blockchain records can potentially be examined to trace transactions after funds leave an address.
This is where account takeover investigation and blockchain transaction tracing can intersect.
Can an IP Address Identify Who Accessed Your Account?
Not by itself.
An IP address can be an important investigative artifact, but it should be interpreted carefully.
An IP address may correspond to:
- A home internet connection
- A mobile carrier
- A corporate network
- A VPN
- A proxy
- A cloud server
- Public Wi-Fi
- A compromised device
Investigators can examine IP information alongside timestamps, devices, accounts, infrastructure and other evidence.
Multiple independent indicators are generally more useful than relying on one artifact.
Can You Find Out Who Hacked Your Account?
Sometimes an investigation can uncover information that helps identify or narrow down the source of unauthorized activity.
Potential indicators can include:
- IP addresses
- Email addresses
- Telephone numbers
- Usernames
- Domains
- Devices
- Cryptocurrency addresses
- Hosting infrastructure
- Related accounts
- Repeated identifiers
However, technical attribution has limitations.
Attackers can deliberately conceal their identities or use infrastructure belonging to innocent third parties.
Certain information may also only be available from service providers through appropriate legal processes.
A legitimate investigation should therefore avoid promising that every attacker can be identified.
Account Takeover vs. Identity Theft
These terms can overlap, but they are not identical.
Account takeover involves unauthorized control of an existing account.
Identity theft generally involves unauthorized use of another person’s identifying information.
An attacker may take over an account without committing broader identity theft.
Alternatively, an account takeover may become part of a larger identity-theft incident if the attacker obtains personal information and uses it elsewhere.
What If Money or Cryptocurrency Was Stolen?
Preserve the transaction information immediately.
Relevant information may include:
- Transaction IDs
- Wallet addresses
- Bank transaction records
- Cryptocurrency withdrawal records
- Recipient information
- Exchange notifications
- Confirmation emails
- Dates and timestamps
- Communications with the attacker
For cryptocurrency incidents, blockchain transaction records can sometimes provide an additional evidence source because transactions recorded on public blockchains can be analyzed after the transfer.
Tracing cryptocurrency does not automatically mean the funds can be recovered, however.
Investigation and recovery are separate questions, and anyone guaranteeing cryptocurrency recovery should be approached cautiously.
Account Recovery and Account Investigation Are Different
Recovering access to your account is important.
But recovery answers:
How do I regain control?
Investigation asks:
How was access obtained, what happened while the attacker was inside, and what evidence remains?
Sometimes recovering the account solves the immediate problem without explaining the incident.
For serious compromises, both questions may matter.
When Should You Consider an Account Takeover Investigation?
An investigation may be appropriate when:
- Someone accessed your account without permission
- You were locked out
- Recovery information was changed
- Unknown devices appeared
- Messages were sent from your account
- Financial transactions occurred
- Cryptocurrency was transferred
- Multiple accounts were compromised
- Business information may have been accessed
- You suspect malware or credential theft
- You need digital evidence preserved
- You need to understand how the compromise happened
- Unauthorized access continues after password changes
The sooner relevant records are preserved, the greater the likelihood that useful evidence will still exist.
How Cyb3rsect Approaches Account Takeover Investigations
Cyb3rsect approaches an account takeover as a digital-evidence problem.
The investigation begins by identifying the affected account, associated devices and connected services that may contain relevant evidence.
Depending on the incident, this can include:
- Authentication records
- Security notifications
- Emails
- Device artifacts
- Account changes
- IP information
- Transaction records
- Cryptocurrency addresses
- Related accounts
- Other available digital evidence
Those artifacts can then be correlated to reconstruct the sequence of suspicious activity.
The objective is not simply to confirm something went wrong.
It is to determine, as far as the available evidence allows:
When did unauthorized access begin?
How might access have been obtained?
What happened after the account was compromised?
What other accounts or systems may have been affected?
What evidence remains?
Is there evidence suggesting continued unauthorized access?
The conclusions should follow the evidence rather than assumptions.
An Account Takeover Can Be Bigger Than One Stolen Password
Changing a compromised password is important.
But serious account takeovers can extend beyond a password.
An attacker may have compromised an email account, stolen an authenticated session, changed recovery settings, accessed connected services or established another method of returning.
That is why understanding the incident matters.
A proper account takeover investigation attempts to reconstruct what happened, determine the scope of unauthorized access and preserve the digital evidence that may help explain the compromise.
If you believe an account has been accessed without authorization, preserve relevant login records, security alerts, emails, transaction information and other available evidence as early as possible.
Cyb3rsect provides digital investigation and forensic support for account takeovers, unauthorized account access and related cyber incidents.