Account Defense

For marketplaces and apps, where the attacker usually has a valid account and the abuse looks like use.

The problem is not the login page

On a marketplace, the expensive attacks do not break in. They sign up. A seller account with a short history and a sudden change in listing behaviour, a buyer account created eleven minutes ago running a card test, a legitimate account taken over and used to move value out through a payout channel you built on purpose.

None of that trips a perimeter control, because none of it is an intrusion. It is your product being used exactly as designed by someone you would rather not have.

What we watch

Credential stuffing at platform scale

Distributed attempts across thousands of accounts from residential addresses, at rates deliberately set below anything a per-IP rule would catch. We score the population, not the request.

Account takeover, after the fact

Most takeovers are visible in the minutes that follow: a device that has never been seen, a payout detail changed, a burst of activity at an hour the account has never been active. Individually, each is normal. Together, they are not.

API abuse

The endpoints that matter on a marketplace are rarely the ones documented as sensitive. Search, availability and pricing endpoints get scraped hardest, and the traffic arrives with a valid token because it belongs to a real account.

Signals, not verdicts

We return scores and the reasons behind them to your own risk logic. We do not make the block decision, and we are suspicious of vendors who want to. You know what a false positive costs on your platform in a way we never will — for a two-sided marketplace, wrongly freezing a high-volume seller during their peak week is more expensive than the fraud you prevented.

Fit

Account Defense is built for platforms with accounts on both sides and money moving between them. If you run a single-sided storefront, Checkout Monitor is almost certainly the product you want, and we would rather say so than sell you both.