Account Takeover (ATO) is an attack in which an unauthorized party gains control of a legitimate user account.
It often follows credential theft, phishing, password spraying, or session hijacking and it can bypass perimeter defenses because activity appears to come from a real account.