Code RoomCredential stuffing account takeover wave
MediumPrep Room Coding #2510

Credential stuffing account takeover wave

On-callReliability & on-callMid–Senior~35 min

Support tickets spike: 60+ users in 2 hours report email-change confirmations and password resets they didn't request. Your auth dashboard shows login success rate dropped (lots of failures) but a steady stream of successes from a datacenter ASN, all hitting /login then immediately POST /account/change-email. Failed-login volume is 50x baseline. A third-party 'have I been pwned' style list for a competitor leaked last week. No MFA is enforced for most accounts. How do you triage and contain this account-takeover wave?

What a strong answer looks like

Stop the bleeding first (mitigate), then form hypotheses from real signals. Separate root cause from symptom, communicate status as you go, and close with what prevents a repeat.

0:00 of about 35 min
Which questions mattered is sealed until you submit. Telling you now would just be handing over the edge cases.