Account takeover happens when a criminal gains control of an existing account—email, bank, social media, shopping, investment or another online service—and uses that access to steal money, impersonate the victim or reset access to other accounts. Because email often functions as a password-reset hub, one compromised login can quickly become several.
What to do in the first hour
- Contact the financial institution or platform through a trusted channel. Do not use a phone number or link supplied by the suspected attacker.
- Reset the password from a clean device. Use a new, unique password that is not reused elsewhere.
- Sign out other sessions. Many services let you revoke devices or active sessions.
- Enable multifactor authentication. Prefer a stronger method supported by the service and secure the recovery options.
- Check email forwarding and recovery settings. Attackers may add a hidden forwarding rule, recovery address or phone number.
- Preserve evidence. Save screenshots, transaction IDs, messages, login alerts and timestamps before they disappear.
- Report financial fraud quickly. The FBI’s Internet Crime Complaint Center (IC3) directs victims to contact their financial institution and file a complaint when appropriate.
Identity theft insurance vs. personal cyber insurance
| Coverage concept | What it may provide | Common misunderstanding |
|---|---|---|
| Identity theft coverage | Recovery services and eligible expenses such as certain legal, document, communication or lost-wage costs, subject to the policy | It generally should not be assumed to reimburse the stolen account balance itself |
| Personal cyber coverage | Depending on form: cyber extortion, data restoration, cyberattack response, online fraud or cyber-crime benefits | There is no universal personal-cyber policy; triggers differ |
| Bank/card protections | Separate statutory, contract or institution dispute rights may apply to unauthorized activity | Those rights are not the same as an insurance benefit |
The NAIC specifically tells consumers that identity theft insurance generally does not reimburse money stolen from accounts. That is why it is important to distinguish recovery expense coverage from a fraud-loss benefit.
Could personal cyber insurance reimburse stolen money?
Possibly under some forms—but never assume it. Personal cyber endorsements and standalone policies can define “cyber crime,” “online fraud,” “unauthorized access,” “funds transfer” or “social engineering” differently. A loss where a criminal directly accesses an account can be treated differently from a loss where the victim is tricked into voluntarily sending money.
Read the definitions and exclusions for authorized vs. unauthorized transfers, voluntary parting, cryptocurrency, investment scams, social engineering, family-member actions and business activity. Limits can be much lower than the total policy limit.
Our guide to online scam losses and personal cyber insurance explores those distinctions.
What identity theft coverage is often designed to do
Identity theft recovery can involve replacing documents, disputing fraudulent accounts, contacting credit bureaus and merchants, obtaining records and sometimes hiring professional help. Policies or endorsements may pay specified recovery expenses and provide a case manager or restoration service.
For the recovery-focused model, see identity theft insurance: what it covers and what to do first.
Do not overlook the email account
If an attacker controls your email, changing a bank password without securing email can leave the reset channel exposed. The Federal Trade Commission recommends changing the hacked account password, signing out of other devices, turning on two-factor authentication and checking account recovery information. Apply the same discipline to every account that reused the compromised password.
When to contact the insurer
Once urgent containment steps are underway, report the incident within the time required by the policy. Some cyber policies provide a hotline or approved service providers. Ask before hiring expensive forensic, legal or restoration help if the policy requires insurer consent.
Our broader personal cyber insurance guide explains common personal coverage modules and exclusions.
Build a clean evidence file
- Bank or payment-provider dispute confirmation
- Fraudulent transaction list with dates and amounts
- Platform security alerts and login history
- Emails, texts or messages used in the attack
- IC3 or police report number if filed
- Credit bureau or identity-restoration records
- Receipts for eligible recovery expenses
- Policy declarations and cyber/identity endorsements
Prevention after recovery
Account takeover recovery is a good time to eliminate password reuse, turn on multifactor authentication and review account recovery options. Consider a password manager and enable transaction/login alerts on high-value accounts. Security improvements do not replace insurance, but they reduce the chance that one stolen password becomes a chain of losses.
Frequently asked questions
Does identity theft insurance replace money stolen from my bank account?
Do not assume so. NAIC consumer guidance says identity theft insurance generally does not reimburse stolen money itself; it is often designed around recovery services and eligible expenses. Broader cyber products can differ.
Should I call the insurer before the bank?
No. If money or account access is at risk, contact the financial institution or platform immediately. Then follow the insurance reporting requirements as soon as practical.
Is a phishing loss always covered by personal cyber insurance?
No. Coverage depends on the policy’s fraud definitions, whether the transfer was authorized, exclusions, limits and other conditions.
Sources & further reading
Reviewed October 6, 2026. Cyber and identity-theft policy forms vary materially. Contact affected financial institutions immediately when money or credentials may be compromised.
