Credential stuffing account takeover wave
Support tickets spike: 60+ users in 2 hours report email-change confirmations and password resets they didn't request. Your auth dashboard shows login success rate dropped (lots of failures) but a steady stream of successes from a datacenter ASN, all hitting /login then immediately POST /account/change-email. Failed-login volume is 50x baseline. A third-party 'have I been pwned' style list for a competitor leaked last week. No MFA is enforced for most accounts. How do you triage and contain this account-takeover wave?
What a strong answer looks like
Stop the bleeding first (mitigate), then form hypotheses from real signals. Separate root cause from symptom, communicate status as you go, and close with what prevents a repeat.
0:00 of about 35 min
Which questions mattered is sealed until you submit. Telling you now would just be handing over the edge cases.
Run or narrate your approach, then ask the coach.