# Account Takeovers

## Identify both bots and human attacks

Use a combination of scores and heuristics to highlight suspicious or hijacked accounts.

### Real-time blocking

Rules execute in milliseconds to block account takeovers inline without noticeable delay.

### Custom definitions

Define account takeovers your way using advanced filtering and real-time velocity queries.

### Granular analytics

Leverage BI-grade analytics to expose account takeovers and fraud rings at scale.

### Data enrichment

Enriched with device intelligence, risk scores, velocity metrics, and much more.

## Segmentation

### Define account takeovers using custom logic

Castle lets you use advanced filtering, real-time velocity queries, and custom lists to segment out account takeovers with high precision.

- deny  
- ATO Score is > 90  
- and Device Age is < 5 min  
- and Proxy IP is true  
- and Count of events Login Failed by ISP in the last 10 min is > 20  
- or Signals include Reported Devices

## Automation

### Action on account takeovers in real-time

Rules execute in milliseconds and can be used to adapt the user experience based on risk in real-time.

- deny  
- Abuse Score is > 90  
- and Disposable Email is true  
- and Count events Registration by Device Fingerprint in the last day is > 3  
- or Signals include Blocked country
  
- Add User ID Warned Account Sharers  
- Remove User ID Allowed Users  
- Send webhook https://hooks.zapier.com/hooks/catch/4378238094/ch3dka  
- Send to Slack #security-alerts

### Real-time decisions

Assessments of data like user count per device or hourly failed logins executed in the blink of an eye.

### Inline blocking

Initiate request blocks or step-up verifications anywhere in your app without disrupting the user experience.

### Alerts & notifications

Ensure your team and users stay informed with triggered Slack notifications or webhooks.

## Analytics

### A holistic view of account takeovers

Harness the power of BI-grade analytics to expose account takeover attacks and unravel fraud rings with precision.

### Explore

- **Event Name**: Registration Attempted, Login Attempted, …
- **Policy Action**: deny, challenge

| Timestamp          | Policy    | Event                     | User                                    | Location                     | Connection               | Device               | Lists | Signals                               |
|--------------------|-----------|---------------------------|-----------------------------------------|------------------------------|--------------------------|----------------------|-------|---------------------------------------|
| Sat, Aug 8 07:59:08| Challenge | Medium Abuse Score        | 732496                                  | Spain 33204, Gijón          | Telefonica de Espana     | Chrome on Windows 10 |       | Disposable email domains, New device  |
| Sat, Aug 8 07:59:08| Deny      | Bad email                 | 471896                                  | Ukraine 29000, Khmelnytskyi | Kyivstar                 | Chrome on Windows 10 |       | Trusted user devices                   |
| Sat, Aug 8 07:59:08| Deny      | [ScAuth] Attempted Login  | 956616                                  | South Africa 8001, Cape Town| Starlink                 | Chrome on Windows 10 |       | Challenged IPs, Timezone Area Mismatch, Multiple Accounts Per Device |
| Sat, Aug 8 07:59:08| Deny      | Password Reset Policy      | 849676                                  | India 400001, Mumbai       | Jio                      | Chrome on Windows 10 |       | Multiple Accounts Per Device           |
| Sat, Aug 8 07:59:08| Challenge | Trusted Device Policy      | 753516                                  | Russian Federation 672000, Chita| Rostelecom          | Chrome on Windows 10 |       | Disposable email domains, Multiple Accounts Per Device |

## Enrichment

### All the data you need to pinpoint account takeovers

Every interaction is enriched with comprehensive device intelligence, risk scores, location data, and much more.

- Battery State: Charging  
- Emulator: Rooted  
- Device Fingerprint: mXZ29K2RRXeDDkdX  
- Memory: Storage 256GB  
- ATO Score: 76  
- Bot Score: 32  
- Carrier: AT&T  
- Headless Browser: Signups per IP over 1h 5  
- Timezone: Europe/Berlin (UTC+1)

### Risk Scores

Out of the box risk scores for account abuse, account takeover, and bot abuse.

### Velocities

Compute personalized signals based on real-time metrics like counts, sums, averages, and more.

### Device fingerprinting

Persistent device identifiers resilient to storage resets and resistant to privacy plug-ins.

### Bot detection

Identify bot actions via bot scores, headless indicators, or velocity and rate limit checks.

## Get started

### Create your free account today

Start with a free quota, with transparent pricing that scales when you do.
