AI Briefing
KO

Cloudflare Announces Account Abuse Protection: Blocking Fraudulent Attacks by Bots and Humans

·2026.03.12 14:00

Key point

It blocks account fraud and ATO with Disposable email, email risk, and Hashed User IDs.

Details

Cloudflare has unveiled Account Abuse Protection, a new defense system that blocks not only bots but also human-involved fraudulent account abuse. It is currently available in Early Access at no additional cost to Bot Management Enterprise customers, and the full Cloudflare Fraud Prevention is expected to be released later this year.

There are now three core defense mechanisms. Disposable email check identifies accounts signed up with disposable emails, and email risk provides low, medium, and high risk levels based on email patterns and infrastructure. Added to this is Hashed User IDs, which uses domain-specific identifiers created by cryptographically hashing usernames to track and mitigate suspicious behavior at the account level.

Cloudflare also addresses the underlying problem. As of last year, 41% of all logins across its network used leaked credentials, and in a Black Friday 2024 analysis, over 60% of login page traffic was automated traffic. Last week, ATO detection features caught an average of 6.9 billion suspicious login attempts per day, and Cloudflare presents this as part of a strategy to more precisely block attacks spanning account creation, login, and account takeover.

The core features are as follows.

  • Disposable email check: Blocks or applies a challenge to disposable emails commonly used for promotion abuse and fake account creation
  • Email risk: Assesses risk at the signup stage based on the email's patterns and infrastructure
  • Hashed User IDs: Analyzes account-level behavioral patterns using hashed identifiers instead of storing usernames in plaintext

Cloudflare emphasizes that network/IP-centric defense alone is no longer sufficient, and that authenticity and identity must now be considered together. These features can be used in Security analytics, Security rules, and Managed Transforms, and focus on better surfacing repetitive and targeted fraudulent behavior while preserving privacy.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.