Darktrace stitches together subtle signs of a cloud or email account takeover, locks out the attacker, and makes sure they stay out
Stop account takeovers before damage is done
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.
- Item A
- Item B
- Item C

10,000
Darktrace customers




































Account takeover trends
ATOs are getting stealthier and more costly
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.
- Item A
- Item B
- Item C
$4.81m
$4.81m
Mollit ad ea labore aute deserunt commodo sit amet ut. Ut ad labore veniam ea. Voluptate in eu sunt excepteur duis culpa.
is the average cost of an attack using compromised credentials
Cost of a Data Breach Report
292 days
292 days
Mollit ad ea labore aute deserunt commodo sit amet ut. Ut ad labore veniam ea. Voluptate in eu sunt excepteur duis culpa.
average time to identify and contain attacks using stolen or compromised credentials
IBM
Why Darktrace?
Understanding people, rather than attacks
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.
- Item A
- Item B
- Item C
Build behavioral profiles unique to your organization
Darktrace ingests live data from across your digital environment to continuously learn and adapt to each user, while integrating with third-party alerts to provide a comprehensive view of emerging account takeover threats
Real-time account takeover detection
Instead of blanket rules prone to false positives, Darktrace’s AI provides seamless, end-to-end visibility into user activities, continuously monitoring for suspicious login behavior, administration activity, file transfers, and lateral movement
Targeted autonomous response
Darktrace's cloud-native response mechanisms ensure the attacker is locked out while allowing normal business operations to continue
Accelerate your investigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.
- Item A
- Item B
- Item C

Threat story: Account takeover
How AI-led security stops account hijack
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.
- Item A
- Item B
- Item C
Threat story: Account takeover
How AI-led security stops account hijack
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.
- Item A
- Item B
- Item C
Initial SaaS account compromise
A threat actor gained access to a manufacturing customer’s SaaS account using compromised credentials. As a result, legacy security solutions did not flag the login as malicious.
Darktrace recognized the login as rare for the account, flagged the absence of MFA, and identified the IP as suspicious, triggering an alert.
Establishing persistence: Hidden email rule
The attacker created an inconspicuous email rule (“….,,,”) to divert emails from a specific domain into ‘Conversation History,’ ensuring phishing attempts remained unseen. Security tools did not detect the subtle manipulation of email settings, as rule creation is common in SaaS platforms.
Darktrace identified the unusual rule, linking it to the suspicious login and a newly registered typosquat domain.
Phishing attempt
Shortly after gaining access, the attacker sent a phishing email from the same rare IP, likely to escalate privileges or compromise additional accounts. The email bypassed signature-based detection, as it did not contain known malware or flagged URLs.
Darktrace’s anomaly-based detection identified the sender’s unusual behavior, marking the email as suspicious.
SOC intervention
Without proactive monitoring, security teams would have noticed the attack only after damage was done.
Darktrace correlated the login, rule change, and phishing attempt in real time, enabling rapid human intervention before further escalation.

3,092
3,092
Mollit ad ea labore aute deserunt commodo sit amet ut. Ut ad labore veniam ea. Voluptate in eu sunt excepteur duis culpa.
behaviors controlled by Darktrace’s autonomous response in the first 3 months
$2,520
$2,520
Mollit ad ea labore aute deserunt commodo sit amet ut. Ut ad labore veniam ea. Voluptate in eu sunt excepteur duis culpa.
saved in analyst resources in first 13 days

Recommended resources
Insights, case studies, and strategies to protect your business
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.
- Item A
- Item B
- Item C

White paper
Tackling the 11 Biggest Cloud Threats with AI-Powered Defense
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.
Bold text
Emphasis
Take a closer look at the the top 11 threats arising in modern cloud deployments, including account-based attacks.


Customer Story
Customer Story: How Digimax augmented their small security team with Darktrace
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.
Bold text
Emphasis
See how this Italian consumer electronics firm brought email, network, and SaaS application security together for extended visibility with context.


Blog
Detecting and containing account takeover with Darktrace
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.
Bold text
Emphasis
Learn how Darktrace detects deviations in user behavior to autonomously stop account-based threats before they escalate.

See Darktrace in action
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.
- Item A
- Item B
- Item C


ActiveAI Security Platform
Cyber resilience across the entire business
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.
- Item A
- Item B
- Item C
Account takeover
Frequently asked questions
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.
- Item A
- Item B
- Item C
What are different types of account takeover attacks?
Account takeover is used to describe any scenario in which a malicious actor gains unauthorized access to a user’s account. There are several ways an adversary can gain access to a legitimate user account:
Credential stuffing: Attackers use stolen login credentials from previous breaches to access accounts where users have reused usernames and passwords.
Malware: Malicious software like keyloggers or spyware captures login details and enables silent account takeover attacks.
Phishing: Phishing attacks trick users into revealing credentials through fake login pages or deceptive emails posing as trusted sources.
Brute-force attacks: Attackers rapidly guess password combinations to break into accounts, often targeting weak or common passwords.
SIM swapping: Cybercriminals hijack a victim’s phone number to intercept 2FA codes and take control of protected accounts.
Exploiting vulnerabilities: Targeting outdated software or weak security practices, such as unsecured passwords.
Man-in-the-Middle (MitM) attacks: In MitM attacks, credentials are stolen by intercepting user traffic over insecure networks during login sessions.
Once an attacker gains access to a corporate account, they’ll generally aim to exploit it for strategic, financial, or operational advantage. Theiy will try and escalate privileges or pivot to other systems within the organization, and may exfiltrate sensitive data like intellectual property, customer information, financial records, or internal communications.
If the account belongs to an employee with access to critical systems, attackers might deploy malware, ransomware, or create backdoors for persistent access. They can also impersonate the user to conduct business email compromise (BEC) scams, tricking colleagues or partners into transferring funds or revealing confidential information. In some cases, attackers monitor communications silently to gather intelligence or prepare for larger attacks.
Is multi-factor authentication (MFA) enough to stop account takeovers?
While MFA is a strong security measure, it’s not foolproof. Attackers are increasingly finding ways to bypass or exploit MFA, making it essential to have behavioral detection in place as well.
Even with robust security mechanisms like MFA there are advanced techniques attackers can use like AitM phishing kits that bypass MFA, see this blog for a full threat story on how this is done and stopped by Darktrace. Similarly, the misuse of legitimate services such as Milanote for malicious purposes can help attackers evade traditional email security solutions by blurring the distinction between legitimate and malicious content.
This is why security tools based on anomaly detection are crucial for defending against such attacks. However, user awareness is equally important. Delays in processing can impact the speed of response, making it essential for users to be informed about these threats.
Why are SaaS environments increasingly targeted by cyber attackers?
SaaS environments are attractive to cyber-criminals for a number of reasons.
1. High Concentration of Data: SaaS platforms often store vast amounts of sensitive corporate data, including customer information, financial records, and intellectual property, making them attractive targets.
2. Widespread Adoption: As more organizations move to cloud-based services for scalability and convenience, the attack surface expands. This widespread use increases the chances of misconfigurations or weak security practices.
3. User-Centric Access: SaaS applications are typically accessed via the internet using credentials, making them vulnerable to account takeover attacks, phishing, and credential stuffing.
4. Third-Party Dependencies: SaaS environments often integrate with other tools and services, creating complex ecosystems where a vulnerability in one component can compromise the entire system.
5. Inconsistent Security Posture: Organizations may assume that security is fully handled by the SaaS provider, leading to gaps in user-side configurations, such as weak access controls or lack of multi-factor authentication (MFA).
How do attackers maintain persistence in a SaaS account takeover?
Threat actors often compromise multiple accounts within the same organization, using one account to launch attacks (e.g. phishing) while keeping another dormant to maintain access and evade detection.
What happens after a SaaS account is hijacked?
Once a SaaS account is compromised, attackers may:
• Alter email rules to hide their activities or misdirect communications.
• Access sensitive internal data or steal confidential information.
• Launch additional social engineering attacks to compromise more accounts or escalate privileges.
• Cause service disruptions or damage to the organization's reputation.
How can SaaS account hijacking be detected?
Detection relies on spotting unusual behaviors and login patterns that deviate from the norm:
• Unusual login locations: For example, logins from unexpected geographic locations or multiple locations simultaneously.
• Uncommon login devices or endpoints: Accessing the account from devices or network locations that are not typically used.
• Suspicious email activity: The creation of new email rules or suspicious outbound emails that were not initiated by the user.
Can Darktrace stop attackers once they have compromised an account?
Darktrace detects account takeovers with high confidence by stitching together unusual behavior that indicates a compromise, such as unusual login time and location, unusual inbox rule creation, and many more subtle signs of attack. It then takes autonomous action to lock the attacker out of the account and makes sure they stay out. Autonomous Response is highly configurable and can be set to human confirmation mode to avoid any unwanted responses.





