Account takeover means someone gains access to an online account without permission. A stolen password is one route, but a stolen session, approved sign-in prompt or malicious connected app can also grant access. A login notification is not by itself proof that access succeeded.
A useful example
You find a new forwarding rule in email and a recovery address you do not recognize. Changing the password is necessary, but the forwarding rule and recovery setting must be removed too. Review active sessions, connected apps, sent messages and recent transactions. Secure the recovery email before resetting other accounts.
What to do
Use the real provider's recovery process from a trusted device. End unfamiliar sessions, change to a unique password, correct recovery details and turn on MFA. If the account affects other people, warn them about suspicious messages. Google's
compromised-account checklist illustrates the kinds of persistence to check. Recovery is complete when control and settings are restored, not merely when a new password works.
Practical distinction
Treat an unknown recovery address or mail-forwarding rule as evidence of account changes. Remove them after regaining access so the intruder cannot quietly return.