Device fingerprint mismatch
Compares the inbound device fingerprint against the account's 90-day device history. A first-seen device buying at high value is scored differently than a known device.
Account Takeover Detection
ATO attacks don't look like failed logins. They look like a legitimate user on a new device, with a credential you've seen before, buying something plausible. Riskgrove scores the combination of signals that static rules miss.
Get a demoDetection Signals
Each signal group targets a different phase of the account takeover lifecycle: credential acquisition, account access, and payment execution.
Compares the inbound device fingerprint against the account's 90-day device history. A first-seen device buying at high value is scored differently than a known device.
Tracks the rate at which a credential (email, user ID) has appeared across scoring requests in rolling 1h, 6h, and 24h windows. Credential stuffing attacks produce a recognizable density pattern.
Session behavior signals (typing rhythm, scroll pattern, tap timing from your client SDK) are compared against the account's historical baseline. A sudden shift in these patterns raises the ATO score.
Transaction geo is compared against the account's recent session location. Physical distance divided by time elapsed. If the speed required to travel between locations is physically impossible, the score rises sharply.
IP address checked against residential vs data-center classification, VPN/proxy/TOR exit node lists, and known anonymizing infrastructure. Attackers routinely use VPN IPs; legitimate users rarely do.
Scores transactions that follow recent profile edits (email, phone, shipping address) within a configurable lookback window. Password reset followed by immediate high-value purchase is a strong ATO indicator.
Attack Anatomy
Riskgrove intercepts at Phase 3. By then the attacker has already passed login. Transaction-level scoring is the last gate before the money moves.
Ready to add ATO scoring?
We'll run a back-test on a sample of your historical transactions and show you which ones the ATO module would have flagged.