Friday, June 12, 2026

Security Boulevard Logo

Security Boulevard

The Home of the Security Bloggers Network

Community Chats Webinars Library
  • Home
    • Cybersecurity News
    • Features
    • Industry Spotlight
    • News Releases
  • Security Creators Network
    • Latest Posts
    • Syndicate Your Blog
    • Write for Security Boulevard
  • Webinars
    • Upcoming Webinars
    • Calendar View
    • On-Demand Webinars
  • Events
    • Upcoming Events
    • On-Demand Events
  • Sponsored Content
  • Chat
    • Security Boulevard Chat
    • Marketing InSecurity Podcast
    • Techstrong.tv Podcast
    • TechstrongTV - Twitch
  • Library
  • Related Sites
    • Techstrong Group
    • Cloud Native Now
    • DevOps.com
    • Security Boulevard
    • Techstrong Research
    • Techstrong TV
    • Techstrong.tv Podcast
    • Techstrong.tv - Twitch
    • Devops Chat
    • DevOps Dozen
    • DevOps TV
  • Media Kit
  • About
    • Sponsor

  • Analytics
  • AppSec
  • CISO
  • Cloud
  • DevOps
  • GRC
  • Identity
  • Incident Response
  • IoT / ICS
  • Threats / Breaches
  • More
    • Blockchain / Digital Currencies
    • Careers
    • Cyberlaw
    • Mobile
    • Social Engineering
  • Humor
Application Security Security Bloggers Network 

Home » Cybersecurity » Application Security » The Ugly Truth of Retail Fraud and Account Takeovers

SBN

The Ugly Truth of Retail Fraud and Account Takeovers

by Matt Vanderpol on May 17, 2019

Human nature can be very ugly to witness, especially when the resulting damage is self-inflicted. The reality behind the prevalence of account takeover is simple human nature: despite the availability of password managers that can generate strong passwords, store them, and enter them at time of login, consumers continue to reuse the same password across many different websites. Therein lies the Achilles Heel for any organization that relies on a web app as the gateway to products and services they provide: no matter how well the underlying application is designed and maintained, website authentication pages are the doors beckoning to attackers with the siren call, “Go ahead. Try to break through.”

Account takeover (ATO) continues to be a business challenge our customers repeatedly tell us they must defend against—and one that cuts across nearly every vertical. The second in a series of three entries, this blog focuses on key scenarios that organizations with a public-facing e-commerce or retail presence should monitor to defend against ATO. For a refresher on how utilizing a threshold-based approach enables organizations to identify irregular request patterns to spot fraudulent authentication and account activity, check out the first entry in this series on ATO.

Account Takeover Overview

Account takeover is also referred to as “credential stuffing”— here’s a breakdown of the process of automatically testing the validity of stolen credentials against various websites:

  1. A third-party breach occurs and the username and password pairs are exfiltrated
  2. The exfiltrated credentials are then posted to public paste sites, sold in bulk, or traded on Dark Web marketplaces
  3. A threat actor acquires the leaked usernames and credentials
  4. The attacker uses automated credential stuffing tools like Sentry MBA to test the stolen credentials against sites with user bases that store high-value data and personally identifiable information (PII).

VerizonWebApBreachChartThe above happens very quickly because attackers know they are not alone in their attempt to leverage the same dump of stolen credentials for illicit gain.

Malicious actors have three primary goals with account takeovers:

  • Sell validated login credential pairs on the Dark Web
  • Gain access to account information such as stored credit card data and personally identifiable information (PII) and then sell it to other threat actors, usually for the purposes of identity theft, applying for credit in the victim’s name etc.
  • Leverage the account for their own gain such as transfer money, purchase goods, spread an agenda, or abuse website functions

The value of stolen accounts is readily apparent, so it’s no surprise that Verizon’s latest Data Breach Investigation Report for 2019 lists web apps as the top threat vector leading to data breaches, especially when combined with stolen credentials. It’s easy to walk through a bank vault door when you already have the keys and the proper credentials.

 

Know Your Sites’ Expected Traffic Thresholds

AccountTakeoverUICardIdentifying malicious activity requires your organization to define an expected baseline level of web request activity for each of the key authentication events over a defined time frame: any web request traffic patterns outside of what is normally expected should be flagged as abnormal. Depending on how the attacker deploys their credential testing, there are two types of ATO types: “Volumetric” and Low and Slow”:

Volumetric credential stuffing: the login requests are attempted in high volume bursts at easily identified spikes above the expected baseline

 

Low and Slow: these login requests are continual and consistent and run 24/7 at a slow pace that has no easy-to-discern start or stop and do not stand out readily from overall valid login requests.

Both ATO types are typically distributed from a wide range of IP addresses. Sophisticated account takeover attacks are very highly distributed with the attacker goal being to resubmit their requests from many different locations so as to appear legitimate. Think of this as obfuscation through dispersion.

 

Retail ATO and App Abuse Examples

If you work in an organization with an online retail presence or allow customers to transact with stored value units for real merchandise or services (example: loyalty programs, coupon “deal” sites), there are several forms of web app abuse to monitor and take action on. Below are examples of attacks specific to retail and e-commerce that Signal Sciences can detect and block.

Fraudulent purchases result when attackers use a combination of approaches with the immediate goal of completing fraudulent purchases:

  • Stolen Credentials: after acquiring stolen username-password pairs, attackers will do the following to manipulate an account for their own gain:
    • Change the address so they can have merchandise delivered to a different address
    • Change email address so they can lock out the valid account owner and reset the account password if necessary (this is where out-of-band authentication becomes ineffective once an account is compromised)
    • Brute force of CVV many retailers require valid CVV to complete purchases
  • Creation fake accounts with the primary goal to test stolen credit cards with fraudulent transactions, no matter how small the value.

Gift Card Cracking occurs when attackers attempt to brute force the API that enables users to check their gift card balances with the end goal of determining the validity of gift card numbers. A higher than normal number of requests against the Gift Card API and failures from a single IP indicates a brute force attempt.

ecomm abuse | Signal SciencesProduct and Price Scraping is executed via automated bot requests:

  • Bad Bots constantly visit product pages, performing searches and scrape data. These can be identified by known signatures including known bad IP ranges from various sources like SANS. Signal Sciences customers also get the benefit of our Network Learning Exchange (NLX) that identifies malicious traffic across our customer based. This collective data provides insight that can be leveraged to stop attacks happening to all customers.
  • SearchBot Imposters advertise themselves as search engine bots but are actually fake. These can be identified based on a reverse DNS lookup of the bots’ source IP addresses.

Check out flow abuse:

  • Scalping with bots is the common modus operandi here: bots are deployed against the purchase flow and attempt to buy discounted or limited edition items using stolen credit or stored value cards for merchandise and then sold at a premium. An indicator to monitor for here is higher than expected “Add to Cart” activity from a single IP.

The above is academic, so here’s a real-world example of detecting and stopping ATO: Glossier, an e-commerce beauty brand, uses the Signal Sciences Console for visibility into the origin source of malicious traffic. They can also see and block web requests originating from an entire geographic range of IP address that target specific endpoints and attempt to cycle through username and password combinations. In sum, Signal Sciences empowers Glossier to detect and block account takeover attempts, all without a dedicated security team.

Detect and Prevent Account Takeover with Signal Sciences

Signal Sciences provides real-time, automated visibility not only into login and account creation activity, but also the web request values and context behind those requests that can reveal fraud with easy configuration and no performance impact on the apps protected. Other solutions in the market add significant latency and can adversely impact customer experience and require significant ramp up time—and that’s time you could be using to defeat the adversary. With Signal Sciences, you get visibility when it counts, not later when it’s too late. See for yourself with a live demo or download and read more about our brute force and ATO prevention capabilities.

 

The post The Ugly Truth of Retail Fraud and Account Takeovers appeared first on Signal Sciences.


Recent Articles By Author
  • Championing Visibility and Reducing Uncertainty with Effective Product Design
  • Securing Technology Innovators’ Web Layer Assets
  • Virtual Patching the Signal Sciences Way
More from Matt Vanderpol

*** This is a Security Bloggers Network syndicated blog from Signal Sciences authored by Matt Vanderpol. Read the original post at: https://www.signalsciences.com/blog/account-takeover-ecommerce-retail/

May 17, 2019May 17, 2019 Matt Vanderpol account takeover, Web Application Security
  • ← WhatsApp, Microsoft and Intel Chip Vulnerabilities
  • Zero Trust: Fortifying the Security Landscape →

Techstrong TV

Click full-screen to enable volume control
Watch latest episodes and shows

Tech Field Day Events

Upcoming Webinars

Building a Resilient Security Culture in the AI Era with AWS & Datadog
Toxic Flows: When Your Agent Skill Becomes a Supply Chain Attack
The Future of Agentic Software Delivery: Unifying Source & Binaries
35 Million Lines, Zero Build-Breakers: How Adyen Scaled DevSecOps
How to Conduct AI-Native Bug Discovery & Triage

Podcast

Listen to all of our podcasts

Secure by Design

1 week ago | Jack Poller

Senator Sanders Wants to Own AI Companies — and Hand America’s Adversaries the Keys

2 weeks ago | Jack Poller

NIST’s Nine: The PQC Signature Race Moves to Round Three

2 weeks ago | Jack Poller

The Quantum Arms Race: Why Washington Just Wrote a $2 Billion Check to Nine Companies

4 weeks ago | Jack Poller

Beyond Moore’s Law: The Hyper-Acceleration of Autonomous AI Cyber Capabilities

1 month ago | Jack Poller

The Exception Economy: When Security Teams Stop Protecting and Start Negotiating

Press Releases

GoPlus's Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

GoPlus’s Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

Subscribe to our Newsletters

Most Read on the Boulevard

Ex-IBM Exec Accuses Big Blue and AT&T of Covering Up Foreign Data Breaches
Google Patches 429 Chrome Vulnerabilities in Major Browser Update
Anthropic’s Mythos Can Serve Up N-Day Exploits in Minutes or Hours
Zscaler Launches Industry-First Zero Trust Security for Agentic AI
ShinyHunters Secret to Success: Breaking the Trust Barrier
7 Best Local LLMs You Can Run for Coding
8 Self-Evolving Skills Hermes Agent Writes on Its Own
10 Best AI Models for Coding in 2026
12 AI Coding Agents Compared in 2026: Claude Code vs Antigravity vs Codex vs Cursor vs OpenCode vs Hermes
8 Claude Code Alternatives Compared (2026)

Industry Spotlight

Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks
Cloud Security Cybersecurity Data Privacy Data Security Featured Incident Response Industry Spotlight Malware Mobile Security Network Security News Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threats & Breaches Vulnerabilities 

Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks

April 12, 2026 Jeffrey Burt | Apr 12 Comments Off on Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks
The Day the Security Music Died
AI and Machine Learning in Security Cybersecurity Featured Industry Spotlight Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

The Day the Security Music Died

April 8, 2026 Alan Shimel | Apr 08 Comments Off on The Day the Security Music Died
The Lock, Not the Alarm: How Palo Alto’s Koi Acquisition Rewrites Endpoint Security
Featured Industry Spotlight Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Uncategorized 

The Lock, Not the Alarm: How Palo Alto’s Koi Acquisition Rewrites Endpoint Security

February 18, 2026 Jack Poller | Feb 18 Comments Off on The Lock, Not the Alarm: How Palo Alto’s Koi Acquisition Rewrites Endpoint Security

Top Stories

ServiceNow Fixes Flaw That Could Lead to Unauthorized Access to Instances
Cloud Security Cybersecurity Data Privacy Data Security Featured Identity & Access Incident Response Mobile Security Network Security News Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Vulnerabilities 

ServiceNow Fixes Flaw That Could Lead to Unauthorized Access to Instances

June 11, 2026 Jeffrey Burt | Yesterday 0
Zscaler Launches Industry-First Zero Trust Security for Agentic AI
AI and ML in Security Cybersecurity Featured News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Zero-Trust 

Zscaler Launches Industry-First Zero Trust Security for Agentic AI

June 10, 2026 Jon Swartz | 1 day ago 0
Anthropic’s Mythos Can Serve Up N-Day Exploits in Minutes or Hours
Cloud Security Cybersecurity Data Privacy Data Security Featured Incident Response Malware Mobile Security Network Security News Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threat Intelligence Vulnerabilities 

Anthropic’s Mythos Can Serve Up N-Day Exploits in Minutes or Hours

June 9, 2026 Jeffrey Burt | 2 days ago 0

Security Humor

Randall Munroe’s XKCD 'Husband and Wife'

Randall Munroe’s XKCD ‘Husband and Wife’

Download Free eBook

[su_panel border="0px solid #ddd" radius="0" text_align="center" padding-top="0px" padding-bottom="0px"]
The Dangers of Open Source Software and Best Practices for Securing Code
[/su_panel]

Security Boulevard Logo White

DMCA

Join the Community

  • Add your blog to Security Creators Network
  • Write for Security Boulevard
  • Bloggers Meetup and Awards
  • Ask a Question
  • Email: [email protected]

Useful Links

  • About
  • Media Kit
  • Sponsor Info
  • Copyright
  • TOS
  • DMCA Compliance Statement
  • Privacy Policy

Related Sites

  • Techstrong Group
  • Cloud Native Now
  • DevOps.com
  • Digital CxO
  • Techstrong Research
  • Techstrong TV
  • Techstrong.tv Podcast
  • DevOps Chat
  • DevOps Dozen
  • DevOps TV
Powered by Techstrong Group
Copyright © 2026 Techstrong Group Inc. All rights reserved.
×

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.