#account takeover
32 stories taggedaccount takeover.

UK Account Hijacking Fraud Up 400% as Scammers Sell Fake Tickets Through Victims' Own Profiles
Criminals are breaking into people's email and social media accounts to impersonate them, then selling counterfeit concert tickets to the victim's own friends. The UK's cybersecurity authority says one fix is already in most people's pockets.

WeChat Flaw Allows Account Takeover Through Incoming Calls
Calif researchers built a worm that hijacks WeChat accounts via an incoming call. The target's phone doesn't need to be touched.

When Password Resets Become the Front Door: The Rise of Help Desk Attacks
Multi-factor authentication has pushed criminals to a softer target: the humans who reset it.

Telus Customers Hit by Account Breach Spanning More Than a Year
Canada's second-largest phone company says criminals used stolen login details to break into customer accounts, access personal data, and in some cases quietly change people's phone plans.

Microsoft Cloud Fixes, 5,000 Dropbox Accounts Hijacked, and a $1.1 Billion Security Startup: This Week's Briefing
Microsoft patched flaws in its cloud platform, criminals walked into roughly 5,000 Dropbox accounts via a signup flaw, and browser-security firm Guardio hit a $1.1 billion valuation.

Passkeys Aren't Magic: Researchers Map 39 Ways to Sidestep Them
A new catalogue from Token shows attackers don't need to break the cryptography behind passkeys to steal accounts. They just walk around it.

Dropbox accounts hijacked after attacker abused a Lenovo signup flaw
A weakness in how Lenovo verified email addresses let an attacker create fake Lenovo IDs and walk straight into around 5,000 Dropbox accounts, no password needed.

Russian Hackers Are Phishing EU Officials on WhatsApp and Signal
Eight serious attacks on European government staff have exposed a gap no one planned for: officials trusting consumer messaging apps with sensitive business.

Why Edge Security Alone Misses the Riskiest Logins
Attackers now hide behind home internet connections and privacy tools that make their sessions look ordinary. Session enrichment aims to fix that blind spot.

Passing the Login Test Does Not Mean You Let In the Right Person
Multi-factor authentication is a genuine security win, but organisations that mistake 'logged in successfully' for 'identity confirmed' are handing attackers a very comfortable seat at the table.

Critical Keycloak Bug Lets Anyone Reset Your Password and Log In as You
A 9.1-severity flaw in the popular open-source login server hands attackers full account takeover with no credentials required.

New Phishing Toolkit Registers Attacker Passkeys to Survive Password Resets
A tool called iAuthFlow V2 lets criminals plant a login credential they control inside your account, so changing your password does nothing to lock them out.

Attackers are already probing a critical Adobe Commerce flaw that lets them hop into shoppers' accounts
CVE-2026-71362 needs no login, no admin rights and no victim clicks. Sansec says its firewall is already blocking live exploitation attempts despite Adobe seeing none.

FBI warns criminals are hunting nude photos in hacked accounts
The bureau says attackers are breaking into social media and cloud accounts to steal intimate images, then using them for blackmail, resale on criminal sites, and follow-on sextortion attacks against victims and their families.

Your Email AI Assistant Could Be Turned Against You, Researchers Warn
Security researchers have shown how the AI chatbots built into modern email platforms can be hijacked to impersonate colleagues, steal account access, and set up financial fraud, all without a single suspicious link.