How an account takeover really unfolds (hidden inbox rules, forwarding, and the debit-delay window)
Most people picture an account takeover as a dramatic lock-out. The costly ones are the opposite: quiet, tidy, and designed so your inbox looks completely normal while someone works in the background. Here's how it actually unfolds, and the handful of settings to check on your own account today.
Last reviewed: 21 July 2026
This is de-identified, general mechanics, not a how-to, and not about any one person. It is the quiet cousin of the recovery gap: the weak point is rarely your password, it is the recovery channel around it.
Step one: quiet access
The attacker gets your email password, usually through phishing or a password reused from another site that was breached. Email is the target because it's the master key: it's where password resets for your bank, your shopping, and your social accounts all land.
Crucially, they often don't change your password. A changed password tips you off. Silent access lets them stay for days.
Step two: hiding their tracks
This is the part people miss. To keep the inbox looking untouched, an attacker sets up rules so you never see what they're doing:
- Auto-forwarding: a copy of every incoming email is quietly sent to their address.
- Inbox rules and filters: messages containing words like "security", "password", "receipt", or your bank's name get automatically marked read and moved to Archive or Trash. Reset confirmations and fraud alerts arrive and vanish before you'd ever notice.
- RSS feed rules: an old Outlook trick that quietly siphons mail out through a feed.
From your side, the inbox looks normal. Behind it, everything sensitive is being redirected and hidden.
Step three: resetting the linked accounts
With your email under their control and alerts suppressed, they work down the list of accounts tied to that address and trigger "forgot password" on the valuable ones: banking, buy-now-pay-later, shopping accounts with stored cards, other email. Each reset link lands in your inbox, gets caught by their rule, and is deleted before you see it.
Step four: the payment-change lag
The money doesn't always move instantly, and that's deliberate. Some banking and payment systems apply a delay, often around 24 hours, before a change like a new payee, a raised limit, or a new direct debit takes full effect, or before certain transactions clear. Attackers use that window: make the change, wait out the lag, and move funds before the account holder notices anything is off. By the time an odd transaction appears, the tracks were covered days ago.
None of this needs sophistication; it's mostly settings and patience.
What to check on your own account right now
You can audit your own account calmly in a few minutes. If any of these is set and you didn't set it, treat that as your signal to change your password and turn on two-factor authentication immediately.
- Mail forwarding: in your email settings, confirm there's no forwarding address you don't recognise.
- Rules and filters: look for filters that delete, archive, or mark-as-read anything mentioning security, passwords, receipts, or banks. Delete any you didn't create.
- Recovery email and phone: check the recovery address and phone number on the account are still yours. Attackers add their own so they can re-take it.
- Connected or authorised apps: review third-party apps and devices with access, and revoke anything unfamiliar.
- Recent security activity: most providers show recent logins, locations, and devices. Unfamiliar sign-ins are worth acting on.
As a baseline: turn on two-factor authentication on your email first (it protects everything downstream), and stop reusing passwords across sites.
If you find signs of it
- Change your email password from a device you trust, and turn on 2FA.
- Remove the forwarding, the rules, and any unknown recovery details.
- If money is involved, contact your bank first: they can freeze payments and sometimes reverse transactions if you're quick.
- Report it: ReportCyber at cyber.gov.au for the cybercrime; Scamwatch; and IDCARE (1800 595 160) if your identity may have been misused.
If the account is already fully taken over, our hacked email recovery help walks through getting it back.
The short version: a smart takeover keeps your inbox looking normal: forwarding and inbox rules hide the reset emails while linked accounts get drained, sometimes timed around a payment-change delay. Check your email's forwarding, rules, recovery details, connected apps, and recent logins; turn on 2FA on your email; and if money's moving, contact your bank first.
This is general, educational information, not a diagnosis or a guarantee. safe2recover doesn't access your accounts or recover funds; for money already moved, your bank and the police (via ReportCyber) are where to start.