Account Takeover (ATO)

In telecommunications, Account Takeover is the unauthorized control of a subscriber or operator-portal account, often achieved via SIM swap, port-out, smishing, or vishing. It enables attackers to intercept SMS-based MFA codes and pivot into banking, email, and crypto accounts.

Categories: Identity and SubscriberThreats and Attacks

Account Takeover (ATO) in context

Subscriber identifiers (IMSI, SUPI, MSISDN, IMEI) anchor authentication, charging and lawful interception. Any protocol that leaks a permanent identifier is treated as a privacy defect, which is why 5G introduced SUCI concealment on the air interface.

Telecom threats range from opportunistic SMS phishing and SIM swap to nation-state grade location tracking. The common thread is that most attacks exploit the inherited trust model of legacy signaling protocols.

To place Account Takeover (ATO) in the wider telecom-security picture, review Artificial Traffic Inflation, UDR, Exfiltration, Insider Threat, Port-Out Fraud and Cell Phone (Mobile Phone): each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

Related topic hubs

  • SIM Swap Attack SIM swap fraud, port-out and account takeover risk.
  • Diameter Security 4G/LTE Diameter threats across IPX/roaming and DEA defenses.
  • Diameter Attacks S6a IDR/PUR/CLR abuse, subscriber tracking, LTE signaling attacks.
  • SMS Firewall SMS spam, phishing, A2P bypass and MAP-layer SMS filtering.

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.