Skip to content
E-commerce Development

Account Takeover Prevention: What Actually Works

Protecting customer accounts from attackers using stolen or reused passwords.

Marcus Adeyemi Technical Director 2 min read 24 views
Account Takeover Prevention: What Actually Works

What is at stake

Compromised accounts mean stolen loyalty points, fraudulent orders and saved payment details at risk.

The playbook

  1. Offer and encourage multi-factor authentication
  2. Rate limit and monitor login attempts
  3. Check passwords against known breach lists
  4. Alert customers to new device sign-ins
  5. Require re-authentication for sensitive changes

Where it goes wrong

Avoid:

  • Unlimited login attempts
  • No alerts on password or email changes
  • Saved payment methods with weak authentication
  • Ignoring spikes in failed logins
What to do and what to avoid with account takeover prevention, side by side
Good practice against the usual mistakes, from the sources listed below.

The numbers behind it

Published figures for Account Takeover Prevention
MeasureFigure
Credential stuffingattackers reuse leaked passwords at scale
Rate limitingslows automated login attempts
Multi-factor authenticationblocks most credential reuse
Monitoringunusual login patterns can be detected

Getting outside help

When to hand it over: Bring in help when stores hold accounts with stored value.

Where this comes from

The figures and practices above come from the sources listed.

Working on something like this?

We take on E-commerce Development work for teams who want it done once, properly. Tell us what you are building and we will tell you honestly whether we are the right studio for it. Start a project.

Where to go next

Spotted something wrong? Report an error on this page. We correct on the page and say what changed.

All services

The work behind this article, and what it costs.

Marcus Adeyemi

Builds and maintains the web work. Writes about front-end architecture, performance, accessibility and the unglamorous parts of keeping a site alive.

Keep reading

More in E-commerce Development