Today, Cloudflare is introducing a new suite of fraud prevention capabilities designed to stop account abuse before it starts. We’ve spent years empowering Cloudflare customers to protect their applications from automated attacks, but the threat landscape has evolved. The industrialization of hybrid automated-and-human abuse presents a complex security challenge to website owners. Consider, for instance, a single account that’s accessed from New York, London, and San Francisco in the same five minutes. The core question in this case is not “Is this automated?” but rather “Is this authentic?”
Website owners need the tools to stop abuse on their website, no matter who it’s coming from.
During our Birthday Week in 2024, we gifted leaked credentials detection to all customers, including everyone on a Free plan. Since then, we’ve added account takeover detection IDs as part of our bot…
Inspect the sender’s actual email address—not just the display name—for subtle misspellings like “info@paypa1.com” or “support@nmb-bank.co” which indicate a spoofing attempt.
