Tag

#account takeover

32 stories taggedaccount takeover.

Illustration: A smartphone screen glowing in a darkened room shows a social media profile page with a notification badge
Identity & Access

UK Account Hijacking Fraud Up 400% as Scammers Sell Fake Tickets Through Victims' Own Profiles

Criminals are breaking into people's email and social media accounts to impersonate them, then selling counterfeit concert tickets to the victim's own friends. The UK's cybersecurity authority says one fix is already in most people's pockets.

3 min read
A smartphone screen showing an incoming call notification on the lock screen, with a subtle unauthorized account access indicator appearing simultaneously in th
Vulnerabilities

WeChat Flaw Allows Account Takeover Through Incoming Calls

Calif researchers built a worm that hijacks WeChat accounts via an incoming call. The target's phone doesn't need to be touched.

2 min read
A help desk operator's phone in their hand displaying a password reset request form, with a computer monitor behind showing multi-factor authentication dialogs,
Identity & Access

When Password Resets Become the Front Door: The Rise of Help Desk Attacks

Multi-factor authentication has pushed criminals to a softer target: the humans who reset it.

4 min read
A smartphone screen showing compromised account login alerts and unauthorized phone plan changes, Canadian mobile carrier customer service portal open in backgr
Breaches

Telus Customers Hit by Account Breach Spanning More Than a Year

Canada's second-largest phone company says criminals used stolen login details to break into customer accounts, access personal data, and in some cases quietly change people's phone plans.

3 min read
A security operations center with multiple screens showing Microsoft cloud alerts, Dropbox breach notifications, and a news ticker about the startup valuation
Cloud Security

Microsoft Cloud Fixes, 5,000 Dropbox Accounts Hijacked, and a $1.1 Billion Security Startup: This Week's Briefing

Microsoft patched flaws in its cloud platform, criminals walked into roughly 5,000 Dropbox accounts via a signup flaw, and browser-security firm Guardio hit a $1.1 billion valuation.

3 min read
A network diagram displayed on a desktop monitor showing multiple red pathways branching around a padlock symbol, representing alternative attack routes bypassi
Identity & Access

Passkeys Aren't Magic: Researchers Map 39 Ways to Sidestep Them

A new catalogue from Token shows attackers don't need to break the cryptography behind passkeys to steal accounts. They just walk around it.

4 min read
A laptop screen showing a Lenovo account signup page with email verification bypass, connected to a Dropbox login session being initiated without proper authent
Identity & Access

Dropbox accounts hijacked after attacker abused a Lenovo signup flaw

A weakness in how Lenovo verified email addresses let an attacker create fake Lenovo IDs and walk straight into around 5,000 Dropbox accounts, no password needed.

4 min read
A European government office desk with a smartphone displaying encrypted messaging apps, surrounded by classified document folders and a computer showing securi
Threat Intelligence

Russian Hackers Are Phishing EU Officials on WhatsApp and Signal

Eight serious attacks on European government staff have exposed a gap no one planned for: officials trusting consumer messaging apps with sensitive business.

4 min read
A network operations center with login session analysis dashboards, threat actors hidden behind ordinary-looking internet connections and privacy tool indicator
Identity & Access

Why Edge Security Alone Misses the Riskiest Logins

Attackers now hide behind home internet connections and privacy tools that make their sessions look ordinary. Session enrichment aims to fix that blind spot.

4 min read
A corporate network access point with multi-factor authentication confirmation displayed on screen, showing successful login while simultaneously an attacker ga
Identity & Access

Passing the Login Test Does Not Mean You Let In the Right Person

Multi-factor authentication is a genuine security win, but organisations that mistake 'logged in successfully' for 'identity confirmed' are handing attackers a very comfortable seat at the table.

3 min read
A Keycloak login interface on a screen with a password reset form, surrounded by visual indicators of vulnerability or security breach
Identity & Access

Critical Keycloak Bug Lets Anyone Reset Your Password and Log In as You

A 9.1-severity flaw in the popular open-source login server hands attackers full account takeover with no credentials required.

4 min read
A smartphone login screen showing multiple authentication methods and security badges, with a shadow figure's fingerprint attempting access in the background
Identity & Access

New Phishing Toolkit Registers Attacker Passkeys to Survive Password Resets

A tool called iAuthFlow V2 lets criminals plant a login credential they control inside your account, so changing your password does nothing to lock them out.

3 min read
An e-commerce store website displayed on a monitor with shopping cart and customer account pages, overlaid with security breach warning graphics and unauthorize
Vulnerabilities

Attackers are already probing a critical Adobe Commerce flaw that lets them hop into shoppers' accounts

CVE-2026-71362 needs no login, no admin rights and no victim clicks. Sansec says its firewall is already blocking live exploitation attempts despite Adobe seeing none.

3 min read
A computer screen showing social media account login pages and cloud storage interfaces, with digital threat graphics indicating unauthorized access attempts an
Identity & Access

FBI warns criminals are hunting nude photos in hacked accounts

The bureau says attackers are breaking into social media and cloud accounts to steal intimate images, then using them for blackmail, resale on criminal sites, and follow-on sextortion attacks against victims and their families.

4 min read
An email platform window on a monitor showing an AI assistant panel, while below it displayed messages appear to impersonate colleagues and contain financial re
AI Security

Your Email AI Assistant Could Be Turned Against You, Researchers Warn

Security researchers have shown how the AI chatbots built into modern email platforms can be hijacked to impersonate colleagues, steal account access, and set up financial fraud, all without a single suspicious link.

4 min read
© 2026 Threat Vectr