Scenario library / Fraud
Large-Scale Account Takeover: a tabletop exercise scenario
Customer login success rates spike from a distributed set of addresses. Support reports unauthorised changes on customer accounts and fraudulent transactions.
60–75 min · Technical + product + comms

What this is modelled on
Modelled on credential stuffing campaigns that replay passwords leaked elsewhere against consumer login endpoints, producing thousands of successful takeovers without exploiting any vulnerability in the target.
Why it matters
Nothing is technically broken, which makes ownership ambiguous between security, product and fraud teams. Customer trust erodes while teams debate whose incident it is.
Exercise objectives
- Establish incident ownership across security, fraud and product
- Test rate limiting, bot defences and forced reset capability
- Rehearse mass customer communication and support surge
- Define thresholds for regulatory notification
Decision points tested
- Force a mass reset or reset only confirmed accounts
- Public wording when your systems were not breached
- Whether to require stronger authentication immediately
- Reimbursement and goodwill policy
Sample inject timeline
- T+0
Traffic anomaly
Login attempts rise tenfold with an unusual success rate.
- T+20
Fraud confirmed
Support confirms unauthorised stored-value transfers on affected accounts.
- T+40
Social amplification
Customers post screenshots publicly, accusing the company of a breach.
- T+60
Reset trade-off
A mass password reset will spike support volume beyond capacity.
What the after-action report should capture
- Ownership and escalation clarity
- Bot defence coverage and gaps
- Support capacity limits
- Authentication roadmap actions
Run this scenario with your team
Tailor it to your environment with AI, run the injects live, and export a web or PDF after-action report when the exercise ends.
