Corporate account takeover (CATO) is account takeover aimed at a business — most damagingly its online banking, treasury, or identity-provider accounts — enabling attackers to initiate payments, change payroll, or grant themselves access while appearing to be the company.

How it works

Entry comes via credential theft or helpdesk-style social engineering against employees with banking access; attackers persist while studying payment patterns; then transfers are styled to look routine — often ACH batches and wires sized under review thresholds (see dual authorization).

Warning signs

  • Unfamiliar payees appearing in templates.
  • Changed contact details or alert settings on bank accounts.
  • MFA resets nobody remembers requesting.
  • Small "test" transactions preceding larger ones.

Controls

  • Dedicated devices or hardened access for banking.
  • Dual authorization on payment release.
  • ACH positive pay filters (see ACH positive pay).
  • Verified out-of-band confirmation for new payees and limit changes.
  • Verification on the reset flows that guard all of it — see account takeover prevention.