Cloudflare launches Account Abuse Protection dashboard for stateful fraud investigation
Key point
The new dashboard is available first to Early Access customers, enabling fraud teams to investigate account abuse using stateful behavioral patterns rather than point-in-time identity checks.
Details
Traditional identity verification relies on point-in-time checks, which AI-enabled fraudsters can bypass using synthetic media and stolen credentials. To counter this, Cloudflare is introducing a new fraud dashboard for Account Abuse Protection (AAP), shifting security from stateless decisions to a stateful trust model that assesses account behavior over time.
Stateful Account Overviews
AAP creates privacy-preserving Hashed User IDs by cryptographically hashing identifiers like email addresses or phone numbers. These IDs anchor account activity, accumulating historical network and device signals from login and signup events. This context allows fraud teams to detect deviations from established behavior patterns, making it harder for attackers to mimic legitimate users with a single convincing interaction.
Investigative Funnel and Workflow
The dashboard is designed as an investigative funnel, moving from population visibility to individual account depth:
- Population Overview: Analysts review total login/signup volumes, unique IPs, devices, and geographic breakdowns to spot broad trends like sudden spikes in failed logins or leaked credential matches.
- Filtering and Prioritization: Teams can filter accounts by specific signal combinations, such as multiple failed logins, leaked credential matches, and activity from numerous unique IP addresses, to prioritize manual review.
- Individual Account Investigation: The view provides a detailed history of login attempts, new devices, and locations. Each event includes a Ray ID, allowing analysts to cross-reference data in Security Events to reconstruct the timeline of an attack.
- Response Actions: If an account is confirmed compromised, analysts can initiate recovery processes or use the Hashed User ID in a WAF rule to challenge or block future requests.
Access Control and Availability
The launch introduces two new roles to minimize data exposure: Account Abuse Protection (dashboard access) and Account Abuse Protection PII (access to additional account-level PII and Logpush jobs). The dashboard is currently available to Early Access customers, with Bot Management Enterprise customers able to sign up for access. This tool complements Bot detections by adding account-level context to help distinguish automated abuse from human-driven fraud.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.