Skip to content
hCaptcha Learning Center

Account Defense

Protect login, account recovery, account creation, and high-risk actions from takeover, credential stuffing, session hijacking, and coordinated account abuse.

Account Defense

Articles in this topic

11 articles in this collection.

Definition or guide

Account Creation Fraud: What It Is, Detection Signals, and Prevention

Learn how account creation fraud works, the signals that reveal fake registrations, and controls that prevent abusive signup without disrupting legitimate customers.

Definition or guide

Account Takeover Risk Scoring: Signals, Models, and Evaluation

Learn how account takeover risk scoring combines signals, models, and action context to protect login, recovery, sessions, and sensitive account changes.

Comparison

Credential Stuffing Protection Tools: What Enterprise Security Teams Need to Know

Compare credential stuffing protection tools by their login coverage, risk signals, response controls, session visibility, privacy design, and operating fit.

Definition or guide

Credential Stuffing vs. Brute Force: What’s the Difference?

Compare credential stuffing, brute-force attacks, and password spraying by the credentials they use, the traffic patterns they create, and the controls that reduce account risk.

Definition or guide

How Enterprise Security Teams Should Evaluate an ATO Program

Evaluate an enterprise ATO program across authentication, active sessions, sensitive actions, response controls, privacy, and measurable outcomes.

Definition or guide

How to Detect Account Abuse After Login

Detect account abuse after login by monitoring session intent, device and network changes, sensitive actions, and risk progression.

Definition or guide

How to Detect Multi-Accounting and Account Sharing Across Devices

Detect multi-accounting and account sharing by connecting device, network, behavioral, and journey evidence, then applying controls that fit the policy and risk.

Definition or guide

How to Prevent Account Takeover Before, During, and After Login

Prevent account takeover across credential use, login, active sessions, sensitive actions, and account recovery.

Definition or guide

MFA Bypass and Session Hijacking

Understand MFA bypass and session hijacking, the account-takeover paths they create, and the controls that protect recovery, active sessions, and sensitive actions.

Definition or guide

What Is Account Takeover? How ATO Attacks Work

Understand account takeover, how ATO attacks gain and keep access, the fraud they enable, and the controls that help stop them.

Definition or guide

What Is Credential Stuffing? How It Works and How to Stop It

Learn how credential stuffing attacks use stolen login pairs, how to detect them, and how layered controls can stop account abuse.

View all Learning Center topics