At a glance
Account compromise is when someone gets unauthorised access to your account. It can include your email, bank and social media accounts. Cybercriminals can use compromised accounts to steal personal information and money. You may notice emails missing from your folders or being sent on your behalf. It’s important to know how to identify if your account has been compromised. Learn how to protect yourself or your business from harm.
If you think your online accounts are compromised, learn how to recover from account compromise.
What is account compromise
Your account has been compromised if someone gains access your email, bank or other online accounts without your permission. With access to your accounts, the unauthorised person can steal your personal information, money and identity.
An account can become compromised if the login details are found or leaked online. This can happen if:
- you forget to log out of an account on a public computer
- you have another account with the same password that’s compromised
- your login details were in a data breach or stolen through a phishing scam.
Account compromise can cause a lot of harm. It can happen to anyone, at any time, including to businesses and organisations. You can protect yourself by securing your accounts, devices and personal information.
Warning signs of account compromise
Look out for these common warning signs:
- You can’t access your account even though you know your login details are correct.
- You’ve been logged out of your account on all devices without you doing it.
- Your account shows logins at unusual times, in unfamiliar locations or with unknown devices.
- You receive an unexpected password reset notification or attempted login from strange locations, or at unusual times.
- You notice emails marked as read, sent or deleted from your account.
- You notice payment transactions you don’t recognise or didn’t make.
- Your account provider, friends, family or colleagues alert you to suspicious activity.
- Your password recovery details are changed without your permission.
How to prevent account compromise
Here’s how to protect your accounts online.
Turn on multi-factor authentication
Multi-factor authentication (MFA) is when you need 2 or more different ways to verify you are the account owner before you can log in. For example, you may need your login details and an authentication code. Using MFA makes it harder for cybercriminals to access your accounts. Learn more about MFA.
Learn about cyber security
Cyber security is important. It helps to know what threats are and how you can protect yourself from them. Learn how you can stay secure with our personal cyber security handbook.
What is business email compromise
Business email compromise is when a cybercriminal gains unauthorised access to your business email account. This gives them access to your private communications which can be used to steal your information or damage your reputation. Cybercriminals aim to trick your contacts into sending money to bank accounts controlled by them.
Business email compromise can be used to:
- scam businesses out or money, goods or services
- get employees to share sensitive business information
- use business email accounts to contact others and appear legitimate
- target and scam customers, organisations or other contacts.
How to prevent business email compromise
Here’s how to protect your business from business email compromise.
Use multi-factor authentication
Multi-factor authentication (MFA) helps protect businesses from compromise. MFA is when you need 2 or more different ways to verify you are the account owner before you can log in. If a cybercriminal steals your login information, they still need to bypass MFA. Enable MFA on all business accounts and devices where possible. Learn more about MFA.
Register additional domain names
Cybercriminals sometimes register a domain name which appears like your business name. These look-alike domains can fool people into thinking they are contacting your business. Instead, they may end up sharing information with a cybercriminal.
Consider registering domain names that are similar to your business name. This can reduce the risk of people being tricked by look-alike domains.
Here are some common domain name tricks that a cybercriminal might use.
| Tricks to fake a domain name | Examples of fake domain names |
|---|---|
| Remove letters | pypal.com |
| Add letters | payppal.com |
| Add additional words | paypalonline.com |
| Use a different domain extension | paypal.net, paypal.au |
| Rearrange letters | payapl.com |
| Add a hyphen | pay-pal.com |
| Add www to the start of the domain name | wwwpaypal.com |
| Rearrange parts of the domain name | paypal-au.com |
Replace letters with similar characters (such as numbers, capital letters or symbols) | paypa1.com paypaI.com pàypal.com |
Set up email authentication measures
Email spoofing is when a cybercriminal sends an email and pretends it’s from your email address. It’s like sending a letter and forging who it was written by. Anyone can write a return address on an envelope – it doesn’t mean that’s where it’s truly from.
If your business uses its own domain name for email, setting up email authentication can help stop cybercriminals from sending fake emails that appear to come from your business.
If someone tries to spoof your email address, email authentication protocols will identify that the emails are fake. These protocols help prevent spoofed emails from making it to their destination. They’ll normally go to the recipient’s spam folder or won’t be delivered at all.
Have a discussion with your service provider about adding these to your domain name:
- Sender Policy Framework (SPF)
- DomainKeys Identified Mail (DKIM)
- Domain-based Message Authentication, Reporting and Conformance (DMARC).
If your DNS hosting is with a separate provider, you’ll need to contact them.
To find out more, read how to combat fake emails.
Protect your privacy
Cybercriminals can find information on someone by doing a search online. This information helps a cybercriminal appear more credible if they pretend to be you in an email.
Be careful of posting information online that identifies:
- where you work
- what your position is
- your work email address
- your personal email address.
If your email address can be found on various websites or forums, it may become a target for impersonation.
For more information about how to manage your information online, visit the Office of the Australian Information Commissioner.
Implement policies and procedures
You shouldn't action unusual or unexpected requests without verifying them. Cybercriminals can pretend to be a customer, colleague or supplier. This is how they can trick you into providing sensitive information or funds.
To keep your business secure, introduce policies and procedures to verify requests.
For example:
- have an approval process for requests that ask to change payment details or make a large transfer
- verify requests by calling and speaking to the sender on a verified phone number (not a phone number from the email)
- ensure staff have clear guidance for how to verify account details and think critically before actioning unusual requests
- have a reporting process for threatening demands for immediate action, pressure for secrecy, or requests to pass protective business processes.
Learn about cyber security
Find out how to keep your business secure by referring to our small business cyber security handbook.
Never miss a threat
Sign up to receive the latest cyber security alerts, along with information on emerging threats and how to stay secure online.