CLOUDFLARE has expanded its Account Abuse Protection (AAP) offering with a new stateful dashboard designed to help website owners investigate abuse across login and signup activity. Moving beyond traditional stateless identity checks, AAP anchors activity to a privacy-preserving Hashed User ID per domain, created from an identifier such as an email or phone number.
Each login or signup adds the event and relevant network and device signals observed at Cloudflare’s edge, building a historical context for an account and enabling fraud teams to identify deviations from normal behaviour over time.
The dashboard supports an investigative funnel, starting with an overview of population-level activity and narrowing down to individual accounts. Analysts can view total login and signup volume, unique IPs and devices, and country/ASN breakdowns to gauge the scope of any suspected campaign. From there, they can apply filters to isolate accounts with troubling signal combinations—e.g., multiple failed logins and leaked credential matches across several unique IPs—to prioritise manual reviews.
An individual account view aggregates activity like login success rates and frequently seen networks, locations, and devices, with the ability to drill into events (each tagged with a Ray ID) to reconstruct how activity unfolded and determine appropriate responses, such as recovery steps or blocking future requests tied to the Hashed User ID.
The system is designed to minimise unnecessary data exposure, introducing dedicated access roles for dashboard and PII data, and is currently available to Account Abuse Protection Early Access customers, with enterprise options for Bot Management.