Hijacking, like it's aviation namesake, refers to the unauthorized takeover of someone else's online account. It typically involves gaining unauthorized access to the account by exploiting weak or reused passwords, though more advanced techniques like social engineering, sim swapping and other techniques are also potential vectors for hijacking. Once the attacker has access, they often will change the password, preventing the user from accessing their account. In addition the attacker may then go on to use the account for a wide range of malicious purposes, including identity theft, fraud, spreading malware, account resale, or accessing sensitive information.
Since the problem of weak and reused passwords is such a dominant cause of account hijacking the design of authentication systems has an enormous impact on how often users will get hijacked on a platform. The two best strategies are to either: