
Somewhere out there in the wilderness of cyberspace, thousands of stolen credentials are being tested against unsuspecting accounts.
It’s a common threat that must be recognized – even though businesses and security teams have put a lot into cybersecurity, account takeovers still pose a persistent risk to both businesses and their customers, with thousands of attempts reported every day. So how do we stop it?
Account Takeovers
The truth is, we can’t. At least, not completely.
The thing about account takeovers is that, while we can lower the success rate, we can’t stop attempts themselves being made – if an attacker has obtained stolen credentials, they can keep trying them against a range of websites, accounts, devices, and login endpoints from wherever they are in the world.
Businesses can’t control who has access to those credentials or stop attackers from sending those requests, but what they can control is what happens when those requests reach their systems, and stop the attack before an account is compromised.
Key Challenges
To understand how a business can do that, it’s first important to understand the many forms that account takeovers can take. For businesses right now, botnet attacks are among the most difficult to defend against.
This is essentially a network of compromised devices – anything from computers and smartphones to IoT devices – that an attacker can control remotely to carry out attacks at scale.
So instead of one attacker manually attempting to log into an account, a botnet allows them to distribute thousands or even millions of automated requests across a huge number of devices and IP addresses, making it incredibly challenging to prevent botnet attacks and ensure legitimate users aren’t caught in the crossfire.
Other forms – and techniques also carried out by botnets – include social engineering, malware-based takeover, MFA bypasses, and session hijacking.
Anything and everything that might give an attacker a way into an account, botnets or even just individual attackers are going to try, so it’s the business’s job to identify these actors and try as hard as possible not to give them an in.
False Positives
This is hard, because not every unusual login is necessarily malicious. A customer might suddenly log in from a new device, or perhaps travel to another country for vacation, and thus make their visits look out of character.
From a security system’s perspective, of course, a login from an unfamiliar device or location might look suspicious, but for the customer, it would be perfectly legitimate. This creates one of the biggest problems in account takeover protection: the more aggressively a business tries to block suspicious activity, the greater the risk of blocking legitimate customers too.
And these false positives can be more than a minor inconvenience; if a customer is repeatedly challenged, or having to navigate customer support to find answers, the likelihood is they’re going to pack their things and take their business elsewhere.
Because from their point of view, the security system designed to protect their account is failing them. Yes, customers want businesses to take cybersecurity seriously in 2026, but if that security starts becoming a barrier, they’re not going to simply forgive the company ‘for the greater good’. The challenge, then, is finding the balance between security and usability, and that means looking at the context surrounding an account activity, rather than relying on a single signal in isolation.
Contextual Awareness
To give an example of this, let’s imagine a customer logging into their online banking account from a new device while abroad. On the surface, there are already two things that might raise a security alert: the device is unfamiliar and the login is coming from a country the customer doesn’t usually access their account from.
A security system relying heavily on those individual signals might decide, then, that the login is too risky and immediately block the customer as a result.
But now imagine the system has more context. It recognizes the login behavior, it knows whether the activity looks human, it knows whether the IP is reputable and the network is trusted. There are dozens upon dozens of data points that build a picture and ultimately tell the system that this is not something to be concerned about.
The customer is able to carry on with their banking uninterrupted, and when an attack does happen, the business is able to pinpoint the suspicious activity and prevent it quickly.
Conclusive Solution
It sounds like a fantastical solution, right? But the good thing is, it exists right now, and it’s already helping thousands of companies make context-aware risk decisions.
In terms of the best bot and account protection solutions, Datadome is right up there, with the company’s tech stopping over 20,000 attacks every second, but it just needs to be adopted more widely.
Last year, a security report published by the company discovered that only 2.8% of 17,000 tested websites were fully protected against simple bot attacks, and that goes to show how widespread the lack of awareness remains even today.
To deal with this problem, then, it’s crucial that more businesses recognize not only the threat, but that effective, context-aware solutions are available to help extinguish it.









Leave a Reply
You must be logged in to post a comment.