Platform Account Takeover Card Testing Payment Fraud Pricing Docs Blog
Get a Demo

Account Takeover Detection

Catch the attacker before they spend

ATO attacks don't look like failed logins. They look like a legitimate user on a new device, with a credential you've seen before, buying something plausible. Riskgrove scores the combination of signals that static rules miss.

Get a demo
device_fingerprint_match FAIL
credential_reuse_velocity_24h HIGH
session_behavior_baseline ANOMALY
geo_velocity_impossible TRUE
composite_score 0.91
recommendation BLOCK

Detection Signals

What Riskgrove reads for ATO

Each signal group targets a different phase of the account takeover lifecycle: credential acquisition, account access, and payment execution.

Device fingerprint mismatch

Compares the inbound device fingerprint against the account's 90-day device history. A first-seen device buying at high value is scored differently than a known device.

Credential reuse velocity

Tracks the rate at which a credential (email, user ID) has appeared across scoring requests in rolling 1h, 6h, and 24h windows. Credential stuffing attacks produce a recognizable density pattern.

Behavioral biometric baseline

Session behavior signals (typing rhythm, scroll pattern, tap timing from your client SDK) are compared against the account's historical baseline. A sudden shift in these patterns raises the ATO score.

Impossible geography velocity

Transaction geo is compared against the account's recent session location. Physical distance divided by time elapsed. If the speed required to travel between locations is physically impossible, the score rises sharply.

IP reputation and proxy detection

IP address checked against residential vs data-center classification, VPN/proxy/TOR exit node lists, and known anonymizing infrastructure. Attackers routinely use VPN IPs; legitimate users rarely do.

Account profile change recency

Scores transactions that follow recent profile edits (email, phone, shipping address) within a configurable lookback window. Password reset followed by immediate high-value purchase is a strong ATO indicator.

Attack Anatomy

How a typical ATO attack moves through your stack

Riskgrove intercepts at Phase 3. By then the attacker has already passed login. Transaction-level scoring is the last gate before the money moves.

Phase What happens Riskgrove
1. Credential acquisition Attacker purchases or steals valid email/password pairs from a breach list. Your login system has no record of the theft. Not yet active
2. Account access Attacker logs in. MFA may stop some attempts, but SIM-swapped or bypass-eligible accounts pass. Session now lives in attacker's browser. Not yet active
3. Payment initiation Attacker adds card or uses stored card. Creates a transaction. This is the moment Riskgrove scores before authorization. SCORED HERE
4. Chargeback window Victim notices unauthorized charge. Disputes via bank. Merchant absorbs chargeback fee plus lost goods. Prevented at Phase 3

Ready to add ATO scoring?

See how the score behaves on your transaction data

We'll run a back-test on a sample of your historical transactions and show you which ones the ATO module would have flagged.