OFICIAL Cloudflare Blog

Follow the thread: a new dashboard to investigate account abuse

What happened
Based on Cloudflare Blog · Oct 02, 2026

Cloudflare launched a new fraud dashboard for Account Abuse Protection to help teams investigate suspicious account activity using stateful trust models and hashed identifiers, replacing point-in-time identity checks.

Follow the thread: a new dashboard to investigate account abuse
Cloudflare Blog — Cloudflare
Key points
·
Cloudflare’s Account Abuse Protection replaces one-time identity checks with stateful behavioral analysis using hashed identifiers and historical signals.
·
The new dashboard aggregates login and signup activity to help fraud teams detect suspicious trends and prioritize accounts for review.
·
Fraud teams can filter accounts by signals like failed logins and leaked credentials to isolate high-risk cohorts for investigation.

Traditional fraud prevention relied on one-time identity checks like passwords or biometrics, but AI now allows fraudsters to fabricate identities by combining stolen credentials with synthetic media. This makes stateless verification insufficient, as even passing a check does not guarantee trust in the account. Cloudflare’s Account Abuse Protection (AAP) shifts to a stateful model that evaluates behavior over time, using hashed identifiers to track accounts without exposing personal data. Each login or signup event is recorded alongside network and device signals, building a behavioral profile that flags deviations.

The new dashboard aggregates account activity across login and signup flows, enabling fraud teams to view user populations, detect suspicious trends, and drill down into specific accounts. It functions as an investigative funnel, allowing analysts to assess the scale of suspicious patterns before reviewing individual accounts. Metrics include total login and signup volumes, unique IP addresses, devices, countries, and ASNs, helping teams prioritize accounts for manual review and reconstruct events.

Investigations begin with anomaly detection in the account population overview, where teams can identify broader campaigns like credential stuffing. For example, a leaked credential summary might show thousands of events with compromised credentials versus clean ones, guiding analysts to focus on affected accounts. Filters narrow the field by combining signals such as failed logins, leaked credentials, and multiple IP addresses, isolating accounts for urgent review.

Analysts can then examine individual accounts to trace login attempts, identify new devices or locations, and determine the scope of suspicious activity. Each event includes a Ray ID for cross-referencing in Security Events, and compromised accounts can be blocked or challenged using WAF rules tied to the hashed identifier. The dashboard also introduces role-based access controls, separating dashboard access from PII exposure to enforce least privilege principles.

Original source → Deals on Clipraptor.com →