Announcing Cloudflare Account Abuse Protection: prevent fraudulent attacks from bots and humans (opens in new tab)
Cloudflare’s new Account Abuse Protection suite targets fraud from both bots and humans, focusing on whether activity is authentic rather than merely automated. It combines leaked-credential detection and account-takeover signals with new tools for identifying risky signups and suspicious identities. The capabilities are in Early Access for Bot Management Enterprise customers at no additional cost temporarily. ## Leaked Credentials and Account Takeover - Cloudflare reports that 41% of network logins use leaked credentials, with password reuse allowing old breaches to compromise valuable accounts. - Its leaked credential check compares hashed passwords against known breach data without storing or accessing plaintext passwords. - More than 60% of login-page traffic during the 2024 Black Friday analysis was automated, enabling attackers to test stolen credentials at scale. - Account takeover (ATO) detections identify customer-specific suspicious login behavior and expose attempted attacks in the Security analytics dashboard. - These detections caught an average of 6.9 billion suspicious login attempts per day across Cloudflare’s network during the referenced week. ## Fraud Requires More Than Bot Detection - Modern abuse combines automation, human fraud farms, device and location spoofing, and synthetic identities. - Attackers may use valid credentials, operate at human speed, or employ AI agents, making simple bot classification insufficient. - Common customer problems include fake users exploiting free trials, attackers logging in with correct passwords, and human-paced account draining. - Effective protection must evaluate intent, identity, and authenticity alongside automation. ## Detecting Suspicious Account Creation - Disposable email addresses allow attackers to create large numbers of accounts for promotions or other abuse without maintaining real email infrastructure. - Cloudflare’s disposable email check provides a binary signal that customers can use in security rules. - Organizations can block disposable addresses outright or challenge users who register with them. - Cloudflare also introduces email-risk assessment based on suspicious email patterns and infrastructure, helping identify potentially fraudulent signups. ## Privacy-Preserving User Identification - Hashed User IDs are per-domain identifiers created by cryptographically hashing usernames. - They help customers correlate suspicious activity and mitigate fraudulent traffic without exposing users’ original identifiers. - The feature is intended to identify risky account behavior while preserving end-user privacy. Cloudflare recommends enabling leaked-credential checks and using the new signup, identity, and behavioral signals together. This layered approach is better suited to fraud campaigns that blend valid credentials, human activity, and automated tools.