Scenario library / Fraud

Large-Scale Account Takeover: a tabletop exercise scenario

Customer login success rates spike from a distributed set of addresses. Support reports unauthorised changes on customer accounts and fraudulent transactions.

60–75 min · Technical + product + comms

Abstract graphic representing large-scale account takeover

What this is modelled on

Modelled on credential stuffing campaigns that replay passwords leaked elsewhere against consumer login endpoints, producing thousands of successful takeovers without exploiting any vulnerability in the target.

Why it matters

Nothing is technically broken, which makes ownership ambiguous between security, product and fraud teams. Customer trust erodes while teams debate whose incident it is.

Exercise objectives

  • Establish incident ownership across security, fraud and product
  • Test rate limiting, bot defences and forced reset capability
  • Rehearse mass customer communication and support surge
  • Define thresholds for regulatory notification

Decision points tested

  • Force a mass reset or reset only confirmed accounts
  • Public wording when your systems were not breached
  • Whether to require stronger authentication immediately
  • Reimbursement and goodwill policy

Sample inject timeline

  1. T+0

    Traffic anomaly

    Login attempts rise tenfold with an unusual success rate.

  2. T+20

    Fraud confirmed

    Support confirms unauthorised stored-value transfers on affected accounts.

  3. T+40

    Social amplification

    Customers post screenshots publicly, accusing the company of a breach.

  4. T+60

    Reset trade-off

    A mass password reset will spike support volume beyond capacity.

What the after-action report should capture

  • Ownership and escalation clarity
  • Bot defence coverage and gaps
  • Support capacity limits
  • Authentication roadmap actions

Run this scenario with your team

Tailor it to your environment with AI, run the injects live, and export a web or PDF after-action report when the exercise ends.