Attack types
계정 탈취ATO
Definition
Seizing a real account with stolen credentials to attack from the inside.
For executives (CEO·CISO)
Mail now comes from a real account, so it passes auth and reputation, then spreads internally and into VEC — the most dangerous "trusted sender" attack. Commonly missed: beyond login protection (MFA), detect post-takeover anomalies (impossible travel, mass sends, new auto-forward rules).