Account Takeover Prevention: What Actually Works
Protecting customer accounts from attackers using stolen or reused passwords.
What is at stake
Compromised accounts mean stolen loyalty points, fraudulent orders and saved payment details at risk.
The playbook
- Offer and encourage multi-factor authentication
- Rate limit and monitor login attempts
- Check passwords against known breach lists
- Alert customers to new device sign-ins
- Require re-authentication for sensitive changes
Where it goes wrong
Avoid:
- Unlimited login attempts
- No alerts on password or email changes
- Saved payment methods with weak authentication
- Ignoring spikes in failed logins
The numbers behind it
| Measure | Figure |
|---|---|
| Credential stuffing | attackers reuse leaked passwords at scale |
| Rate limiting | slows automated login attempts |
| Multi-factor authentication | blocks most credential reuse |
| Monitoring | unusual login patterns can be detected |
Getting outside help
When to hand it over: Bring in help when stores hold accounts with stored value.
Where this comes from
- OWASP — Credential Stuffing Prevention Cheat Sheet
- National Institute of Standards and Technology — Digital Identity Guidelines
The figures and practices above come from the sources listed.
Working on something like this?
We take on E-commerce Development work for teams who want it done once, properly. Tell us what you are building and we will tell you honestly whether we are the right studio for it. Start a project.
Where to go next
Spotted something wrong? Report an error on this page. We correct on the page and say what changed.