Cloudflare Launches Account Abuse Protection Dashboard
Cloudflare has introduced a new dashboard for Account Abuse Protection, designed to help fraud and security teams investigate and block sophisticated account attacks using stateful analysis.

The Shift Toward Stateful Trust Models
Traditionally, preventing online fraud relied on point-in-time proof of identity, such as entering a correct password or passing a liveness check. However, widespread access to AI has enabled fraudsters to fabricate or imitate legitimate identities by combining exposed credentials with synthetic media designed to evade identity verification. Consequently, identity checks are no longer sufficient because they capture only a single moment in time.
To address these evolving threats, modern fraud prevention must move beyond stateless decisions toward a stateful trust model. As detailed in the Cloudflare Blog, trust is continually earned and reassessed at each interaction against historical behavioral, network, and device patterns, making meaningful deviations easier to identify.

Introduction of the Account Abuse Protection Dashboard
Cloudflare has introduced a new fraud dashboard for Account Abuse Protection, which is available first to Early Access customers. The workspace brings together account overviews built from activity observed across a website's configured login and signup flows, giving fraud analysts a comprehensive view of their entire user population to identify suspicious trends.
Organizations interested in evaluating the new workspace can sign up for Early Access to test the capabilities within their environments and begin integrating stateful analysis into their security operations.

How Hashed User IDs Anchor Account Activity
Cloudflare's Account Abuse Protection creates stateful account overviews to help website owners detect and investigate abuse across login and signup activity. Customers configure an identifier from their existing flow, such as an email address, username, or phone number. Cloudflare then cryptographically hashes that value to create a privacy-preserving, per-domain Hashed User ID.
With each login or signup, Account Abuse Protection adds the event along with relevant network and device signals observed at Cloudflare's edge. Over time, this accumulated history establishes context for an account's typical behavior, giving designated personnel in Security Intelligence, Investigations, Trust and Safety, or Risk and Compliance a stronger foundation for investigation.
Investigative Funnel: From Population to Individual Depth
The dashboard is designed as an investigative funnel. When a suspicious event is identified, fraud teams can review the account population overview to understand the scale and shape of suspicious patterns without needing to investigate every single account individually.
Teams can review total login and signup volume, check how many accounts generated those events, and view unique IP addresses and devices. Country and ASN breakdowns provide additional context about where activity was observed, helping analysts determine campaign scope and prioritize accounts for manual review.

Investigating a Credential Stuffing Attack
When investigating unusual login activity such as a credential stuffing attack, analysts begin in the account population overview to spot anomalies. An increase in failed login activity prompts teams to examine leaked credential check results, helping them focus on accounts associated with leaked credential matches.
Analysts can narrow the field of investigation using filters to isolate specific accounts with concerning combinations of signals, such as multiple failed logins and unique IP addresses. From there, they can review individual account histories, compare clear events with suspicious activity, and decide how to respond.

Response Options and Mitigation
Once an investigation confirms that an account has been compromised, analysts can initiate established recovery processes for the user. Additionally, teams can use the Hashed User ID within a Web Application Firewall rule to challenge or block future requests associated with the compromised account.
Sources
- Cloudflare BlogFollow the thread: a new dashboard to investigate account abuse
Continue chronologically




