An attacker already has the city treasurer's mailbox password and now enrolls a new MFA method and creates hidden mailbox rules. Which term best describes this stage?
Select an answer to reveal the explanation.
Short Explanation
The thief already has the treasurer's keys and is changing the locks — new MFA, sneaky inbox rules. That is account takeover: control of a real civic identity, not a DDoS, not a vendor implant, not a Windows registry trick.
Full Explanation
Account takeover is control of a legitimate civic identity, typically shown by password use plus identity changes such as MFA enrollment and mailbox-rule persistence. DDoS is an availability flood, supply chain is vendor/component tampering, and registry persistence is a host technique — none describe seizing the treasurer mailbox. Defense Analysts should hunt Entra/M365 audit, MFA registration, and inbox-rule events in Splunk rather than treating the incident as a network flood or a clerk-PC registry hunt.