Use case

Account Takeover

22% of US adults have fallen victim to ATO fraud. Blockdash detects the key tells of adversaries who are taking over user accounts at scale to commit acts of fraud — and stops them in milliseconds.

Start blocking bots

Free Test on your site

Quick facts

  • 22% of US adults have fallen victim to ATO fraud
  • Attackers try to appear human to bypass defenses during credential stuffing attacks
  • Attacks occur in waves
  • Evasion techniques include residential IPs and clean browser sessions
  • Adversaries time attacks to mimic real user traffic patterns
  • Layered defenses to stop ATO are absolutely vital

What is account takeover (ATO), and how do attacks work?

Attacker typing username and password into a computer to break into an account

Account takeover occurs when cybercriminals gain access to user accounts with stolen credentials. How do bad actors get those credentials? Credential stuffing: automation that tests stolen usernames and passwords against hundreds or thousands of websites at a time. It has a low barrier to entry, a high cost to businesses, and nasty repercussions for people's lives.

Fraudsters take advantage of the fact that many people reuse the same email and password combination across platforms — everything from banking accounts to subscription services. After breaking into an account, attackers will do one or more of the following:

  • Sell the information
  • Sell the related rewards or loyalty points
  • Break into other accounts that use the same credentials, then sell that info
  • Use linked payment methods or credit cards for unrelated purchases
  • Gather additional personal information for further attacks

Blockdash observes credential stuffing attacks arrive in waves. A recent campaign we detected and defeated for a retailer looked like this:

01Wave one — standard tooling

A surge in traffic using a worldwide proxy network and browser session hijacking.

02Wave two — first retooling

A full-force attack using localized residential IPs and clean browser sessions.

03Wave three — second retooling

A slower attack using the same tools as wave two, but starting in the morning to mimic real human traffic.


What's the impact of account takeover on your business?

From your revenue to your customer experience to your very brand itself, credential stuffing attacks have a range of harmful effects:

  • Increased fraud claims and costs
  • High password authentication and other infrastructure costs
  • Potential for expensive regulatory fines
  • Loss of customer loyalty — and customers themselves
  • Damage to your reputation and brand equity
378%

Account takeover (ATO) fraud climbed 378% over the past three years.

ATO fraud growth index (3 years)

Why is Blockdash effective for stopping ATO?

Blockdash looks for immutable evidence of automation from the very first request, instead of relying on contextual data from the past — which takes time and ongoing maintenance. Malicious login requests are stopped before they ever enter your infrastructure, where damage can be done. Traditional tools simply take too long to decide and get tricked when bots hide behind residential proxy networks.

Blockdash makes bots, not humans, do the work: an invisible proof-of-work challenge makes attacks arduous and expensive for bots to continue while requiring no action from real users. That makes brute-force methods like credential stuffing impractical to conduct at scale.

Deep visibility into application traffic is critical to identifying and isolating attack traffic. Using it, Blockdash produces highly accurate indicators of compromise shared across customers — so if the same group visits any of your applications, they are monitored closely and blocked.



Latest research