Thursday, June 18, 2026

Security Boulevard Logo

Security Boulevard

The Home of the Security Bloggers Network

Community Chats Webinars Library
  • Home
    • Cybersecurity News
    • Features
    • Industry Spotlight
    • News Releases
  • Security Creators Network
    • Latest Posts
    • Syndicate Your Blog
    • Write for Security Boulevard
  • Webinars
    • Upcoming Webinars
    • Calendar View
    • On-Demand Webinars
  • Events
    • Upcoming Events
    • On-Demand Events
  • Sponsored Content
  • Chat
    • Security Boulevard Chat
    • Marketing InSecurity Podcast
    • Techstrong.tv Podcast
    • TechstrongTV - Twitch
  • Library
  • Related Sites
    • Techstrong Group
    • Cloud Native Now
    • DevOps.com
    • Security Boulevard
    • Techstrong Research
    • Techstrong TV
    • Techstrong.tv Podcast
    • Techstrong.tv - Twitch
    • Devops Chat
    • DevOps Dozen
    • DevOps TV
  • Media Kit
  • About
    • Sponsor

  • Analytics
  • AppSec
  • CISO
  • Cloud
  • DevOps
  • GRC
  • Identity
  • Incident Response
  • IoT / ICS
  • Threats / Breaches
  • More
    • Blockchain / Digital Currencies
    • Careers
    • Cyberlaw
    • Mobile
    • Social Engineering
  • Humor
Security Bloggers Network 

Home » Security Bloggers Network » BlaBlaCar Prevents Account Takeovers with DataDome & Google Cloud

SBN

BlaBlaCar Prevents Account Takeovers with DataDome & Google Cloud

by Paige Tester on April 4, 2025

The post BlaBlaCar Prevents Account Takeovers with DataDome & Google Cloud appeared first on Blog – Datadome.

With over 100 million members, BlaBlaCar is the world’s largest car-sharing community. Hosted on Google Cloud Platform, the website and mobile app serve a large and valuable user base, which makes it a prime target for fraudsters seeking financial and personal data. The company turned to DataDome to provide highly scalable and real-time protection without impacting website performance or user experience. This successful partnership enabled the company to eliminate account takeover, carding, and other attacks with AI-powered protection. 



Datadome

Setting up DataDome is insurance. You can live without one, but you need to know that if you do, you are putting yourself at risk.

Francis Nappez
Cofounder & CTO of BlaBlaCar

The challenge: Account takeover leading to payment or stored value diversion for fraud

After observing a number of unusual and inexplicable load spikes, the BlaBlaCar team discovered the irregular traffic was due to bots trying to take control of user accounts on the site, so they began to closely monitor the behavior of the bots. Account takeover (ATO) attacks, carried out by “impersonator” type bots, usually exploit login-password databases that have been stolen from other sites.

In order to try to take control of user accounts, the bots use the “brute force” technique: they access the login forms and very rapidly test all the stolen login-password combinations, often in the hundreds of thousands. Since many people tend to use the same login-password combination on multiple sites, the success rate of ATO attacks can attain 8%.

But what, exactly, were the bots (or the fraudsters driving them) trying to achieve?

In account takeover attacks, bots have a dual objective: to collect as much personal data as possible (name, postal address, email, telephone, etc.), but also to exploit various means of payment linked to the accounts.

Carding, for example, consists of using stolen card numbers to make purchases via spoofed accounts. Attackers also try to retrieve coupons and credit coupons to use or resell. Therefore, it’s important to protect coupon sites from bots.

By closely observing the bots’ behavior, BlaBlaCar discovered that certain bots had industrialized a process to modify the transfers between community members, in order to divert them for their own benefit.

Adding to the complexity was the platform’s geographical diversity. BlaBlaCar operates in 22 countries, each with its own unique fraud landscape. In Europe for instance, attackers favored brute force credential stuffing. In Asia, the focus was on SMS pumping scams, exploiting systems to generate excessive charges. The variety and sophistication of the threats demanded a solution that could adapt to these regional challenges without compromising the seamless experience that BlaBlaCar’s users had come to expect.

BlaBlaCar managed to foil the attacks before any harm was done to its customers, but protection against the threats required constant monitoring and daily updates. The BlaBlaCar team soon realized that it would be more efficient to use a dedicated solution, and they carefully selected DataDome.

The solution: Seamless integration with Google Cloud & optimized performance for BlaBlaCar

BlaBlaCar’s revenue comes primarily from its website and mobile app, both hosted on the Google Cloud Platform. Therefore, it was crucial to find a bot and fraud mitigation solution that would integrate seamlessly with their existing Google Cloud infrastructure and services. The implementation and installation of the DataDome module were therefore carefully monitored, in order to ensure they didn’t affect site stability or user experience.

The main concern was performance. Since DataDome validates 100% of incoming traffic requests in real-time, the module is positioned at a critical point for any website or app. BlaBlaCar’s team needed assurance that DataDome’s infrastructure could handle all its traffic and scale seamlessly on Google Cloud. 

The team managed the ramp-up perfectly, especially since the chosen architecture is designed in such a way that DataDome is not a single point of failure. It’s fundamental for us to be absolutely certain that an eventual DataDome failure will not block our human users.

Francis Nappez, cofounder and CTO of BlaBlaCar

Latency is another key element of the user experience that Francis had no intention of compromising on. But thanks to the performance of 30+ global PoPs providing protection at the edge, close to users, all performance thresholds for BlaBlaCar applications have been optimized:

“Latency is extremely well managed on the DataDome side,” Francis continues. “If there is any degradation, it’s only a few milliseconds, which is largely acceptable, especially when you consider the value we get in return for the service.”

During the implementation process, it was necessary to ensure that no personal information related to users was sent to DataDome as part of the information exchange on incoming BlaBlaCar traffic.

It wasn’t just about stopping credential stuffing. DataDome’s technology could identify and neutralize more complex threats, such as bots mimicking human behavior or rotating through proxy networks to evade detection. And while stopping attacks was critical, ensuring compliance with privacy regulations like GDPR was equally important. DataDome’s design ensured that no personal user data was shared, providing BlaBlaCar with robust protection without compromising user trust.

The result: User accounts protected from known & new bot behaviors

Since the DataDome solution was activated, BlaBlaCar’s user accounts have been fully protected without any need for maintenance. DataDome’s technology, which is based on a machine learning process and pools data from all the protected sites, makes it possible to detect both known bots and new behaviors. It therefore doesn’t require any daily intervention on the part of BlaBlaCar’s technical team.

For Francis, the main challenge in a secure environment is to remain alert. In this respect, the daily report sent by the DataDome service, which presents detailed data and indicators on bot traffic to BlaBlaCar, is very useful.

“To see every day the magnitude of the threat, and to verify that it is, in this way, identified and countered, is reassuring,” Francis observes.

The true test of the partnership came during a period of intense pressure. Shortly after acquiring BusFor, a major Eastern European bus carrier, BlaBlaCar faced a wave of attacks targeting the new systems. The geopolitical situation in the region only heightened the stakes. But with DataDome already in place, BlaBlaCar was able to deploy protections rapidly, ensuring uninterrupted service during a critical time. 

As the dust settled, BlaBlaCar began leveraging the insights from DataDome to refine its own internal defenses. The team built new fraud detection models and shared learnings across departments, from engineering to customer support. Together with DataDome, BlaBlaCar wasn’t just reacting to threats—it was staying ahead of them.

More than 8 years later, BlaBlaCar continues to closely monitor the integrity of account credentials on the site, as well as the nature of bots crawling the site and mobile application. As the platform continues to grow and evolve, so too will the threats it faces. But with DataDome by its side, BlaBlaCar is ready. And for its 40 million members, that means peace of mind on every journey.

With DataDome, we benefit from the collective intelligence accumulated on all the sites protected by the technology, and this delivers great value in terms of guaranteed security.
Francis Nappez, CTO of BlaBlaCar

*** This is a Security Bloggers Network syndicated blog from DataDome authored by Paige Tester. Read the original post at: https://datadome.co/customers-stories/blablacar-account-takeover/

April 4, 2025April 14, 2026 Paige Tester Account Fraud, credential stuffing, Customer Stories, Travel & Hospitality
  • ← Securing Video Surveillance Systems with Passwordless Authentication
  • NetworkMiner 3.0 Released →

Techstrong TV

Click full-screen to enable volume control
Watch latest episodes and shows

Tech Field Day Events

Upcoming Webinars

True Agentic SecOps at Lakehouse Scale
Agentic Software Delivery in 2026: How To Bridge The Gap Between AI Ambition and Delivery Confidence
Untangling the EU Cyber Resilience Act
The Software Supply Chain Just Got Harder to See
Building a Resilient Security Culture in the AI Era with AWS & Datadog

Podcast

Listen to all of our podcasts

Secure by Design

2 weeks ago | Jack Poller

Senator Sanders Wants to Own AI Companies — and Hand America’s Adversaries the Keys

3 weeks ago | Jack Poller

NIST’s Nine: The PQC Signature Race Moves to Round Three

3 weeks ago | Jack Poller

The Quantum Arms Race: Why Washington Just Wrote a $2 Billion Check to Nine Companies

1 month ago | Jack Poller

Beyond Moore’s Law: The Hyper-Acceleration of Autonomous AI Cyber Capabilities

1 month ago | Jack Poller

The Exception Economy: When Security Teams Stop Protecting and Start Negotiating

Press Releases

GoPlus's Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

GoPlus’s Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

Subscribe to our Newsletters

Most Read on the Boulevard

Google Sues Chinese Threat Group Using Gemini AI in Phishing Scams
SailPoint Acquires Entro to Continuously Detect and Monitor Non-Human Identities
Databricks Acquires Cybersecurity Startup Panther Labs to Fortify AI Defense
Ten Great Cybersecurity Job Opportunities
Malwarebytes Finds Ad Scams Hidden in 40+ World Cup Streaming Sites
CVSS Is Officially Dead: What CISA’s BOD 26-04 Means for Everyone
Iranian Cyber Group Handala Claims Cal Water Hack
Claude Fable 5’s pricing makes Sonar Context Augmentation a potent cost lever
CISA to Require Federal Agencies to Patch Some Vulnerabilities Within 3 Days
Claude Fable 5 and Mythos 5 “abruptly disabled” after US gov. ban

Industry Spotlight

NYC Sewers Crawling With Rats and Potential Bad Actors 
Cybersecurity Featured Industry Spotlight Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threats & Breaches 

NYC Sewers Crawling With Rats and Potential Bad Actors 

June 18, 2026 Teri Robinson | Yesterday 0
Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks
Cloud Security Cybersecurity Data Privacy Data Security Featured Incident Response Industry Spotlight Malware Mobile Security Network Security News Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threats & Breaches Vulnerabilities 

Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks

April 12, 2026 Jeffrey Burt | Apr 12 Comments Off on Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks
The Day the Security Music Died
AI and Machine Learning in Security Cybersecurity Featured Industry Spotlight Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

The Day the Security Music Died

April 8, 2026 Alan Shimel | Apr 08 Comments Off on The Day the Security Music Died

Top Stories

MSG Breach: Knicks Take the NBA Championship, ShinyHunters Takes the Data 
Cybersecurity Data Security Featured News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

MSG Breach: Knicks Take the NBA Championship, ShinyHunters Takes the Data 

June 18, 2026 Teri Robinson | Yesterday 0
Trying to Control AI is Like Holding Sand
AI and Machine Learning in Security Cybersecurity Featured News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

Trying to Control AI is Like Holding Sand

June 17, 2026 Alan Shimel | 1 day ago 0
F5 Embeds Neural Network in WAF Platform to Continuously Assess Risks
Application Security Cybersecurity Featured News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

F5 Embeds Neural Network in WAF Platform to Continuously Assess Risks

June 17, 2026 Michael Vizard | 1 day ago 0

Security Humor

Randall Munroe’s XKCD 'Bottle'

Randall Munroe’s XKCD ‘Bottle’

Download Free eBook

[su_panel border="0px solid #ddd" radius="0" text_align="center" padding-top="0px" padding-bottom="0px"]
The State of Cloud Native Security 2020
[/su_panel]

Security Boulevard Logo White

DMCA

Join the Community

  • Add your blog to Security Creators Network
  • Write for Security Boulevard
  • Bloggers Meetup and Awards
  • Ask a Question
  • Email: [email protected]

Useful Links

  • About
  • Media Kit
  • Sponsor Info
  • Copyright
  • TOS
  • DMCA Compliance Statement
  • Privacy Policy

Related Sites

  • Techstrong Group
  • Cloud Native Now
  • DevOps.com
  • Digital CxO
  • Techstrong Research
  • Techstrong TV
  • Techstrong.tv Podcast
  • DevOps Chat
  • DevOps Dozen
  • DevOps TV
Powered by Techstrong Group
Copyright © 2026 Techstrong Group Inc. All rights reserved.
×

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.