The new tool helps participating website owners review unusual login and signup patterns. Cloudflare says it is initially available to Account Abuse Protection Early Access customers.
In 60 seconds
- Organizations using Account Abuse Protection should ask whether the new dashboard is available to them.
- Check with the Cloudflare administrator, then review recent login and signup patterns if access is enabled.
- Have the designated security or fraud team investigate unusual activity before changing accounts.
- Do not treat a leaked-credential result as proof that an account was taken over.
Who should care and what to do now
This announcement concerns website owners using Cloudflare’s Account Abuse Protection service. Cloudflare says the new dashboard is initially available to Account Abuse Protection Early Access customers. It also says Bot Management Enterprise customers interested in these capabilities can sign up for Early Access.
To check, ask the organization’s Cloudflare administrator whether Account Abuse Protection Early Access is enabled. If it is, the designated security or fraud team can review recent login and signup activity in the dashboard.
The proportionate step today is to compare recent activity with the organization’s usual patterns. If that review confirms an account was compromised, Cloudflare says the customer can begin its established recovery process.
Do not install software or follow an unexpected message that claims to provide dashboard access. Do not reset every account or block users based on one warning signal.
What the dashboard shows
Cloudflare says the dashboard brings activity from configured login and signup flows into one investigative workspace. Teams can review total event volume, the number of accounts involved, and the internet addresses and devices seen across those accounts. An internet address, often called an IP address, identifies a connection on a network.
The dashboard also provides country and network details. Cloudflare refers to one type of network detail as an ASN, or Autonomous System Number. It identifies a network on the internet and can add context during an investigation.
Teams can review failed logins and leaked-credential results. A leaked-credential result means the service found a username or password match associated with leaked information. Cloudflare says this is an investigative lead, not proof that every related account was compromised.
The tool is designed to move from broad patterns to individual account reviews. Analysts can filter for combinations such as repeated failed logins, several leaked-credential results, and activity from many internet addresses. They can then decide which accounts need manual review.
How Cloudflare describes an investigation
Cloudflare’s example starts with a rise in failed login activity. The team checks leaked-credential results, then looks for shared internet addresses, networks, locations, or devices. These connections can help define the possible scope of a credential stuffing attack. Credential stuffing is the repeated use of stolen usernames and passwords against another service.
In the example, about 2,400 events produced a leaked username or password result, while 11,700 events were classified as clean. Cloudflare says this comparison is a lead for investigation, not confirmation that every related account was compromised.
An individual account view includes login and signup history, login success rate, leaked-credential results, and commonly associated networks, locations, and devices. Analysts can compare earlier activity with later events to see when a change began and whether attempts were repeated.
Each event includes a timestamp and a Ray ID. Cloudflare describes a Ray ID as an identifier for a request that passed through its service. Teams can use it to look up related information in Security Events. If a review confirms compromise, Cloudflare says the customer can follow its established recovery process. It also says a Hashed User ID can be used in a web application firewall rule to challenge or block later requests associated with that identifier.
Account details and access controls
Cloudflare says it cryptographically hashes an identifier from an existing login or signup flow, such as an email address, username, or phone number, into a per-domain Hashed User ID. Hashing changes the original value into another value used by the service. Within Account Abuse Protection, the Hashed User ID anchors activity to an account.
Separate permissions control access to additional account-level personal information, such as an email address. Cloudflare says one role controls access to the dashboard, while another controls access to that additional information. The second role is also required to create or update Logpush jobs containing personal information.
Cloudflare recommends assigning these roles according to what each team member needs to investigate. That access guidance comes from the company’s announcement. Decisions about account recovery or blocking remain part of each customer’s own process.
Does this affect me?
- Who may be affected
- Website owners and organizations using Cloudflare Account Abuse Protection should care. Cloudflare says the dashboard is initially available to Account Abuse Protection Early Access customers.
- How to check
- Ask the organization’s Cloudflare administrator whether Account Abuse Protection Early Access is enabled, then review recent login and signup trends if the dashboard is available.
- What to do
- Have the designated security or fraud team investigate unusual activity and use the organization’s established recovery process only when its review confirms compromise.
- What to avoid
- Do not install an alleged dashboard tool, reset every account, block users, or treat a leaked-credential result as proof of compromise without reviewing the surrounding activity.
Common questions
Does this announcement report a Cloudflare breach?
No. Cloudflare’s announcement describes a new investigation dashboard and does not report a breach of a specific customer or account.
Who can use the new dashboard?
Cloudflare says it is initially available to Account Abuse Protection Early Access customers. Bot Management Enterprise customers interested in the capabilities can sign up for Early Access.
What does a leaked-credential result mean?
It means Cloudflare identified a leaked username or password result. Cloudflare says the result is a lead for investigation, not proof that an account was compromised.
What should an organization do if its review confirms compromise?
Cloudflare says the customer can begin its established recovery process. The announcement does not provide one password-reset or recovery sequence for every organization.
Primary source
Evidence source: Cloudflare, “Follow the thread: a new dashboard to investigate account abuse,” published October 2, 2026: https://blog.cloudflare.com/account-abuse-protection-dashboard/. The announcement describes a product launch and does not report a breach of a specific customer. Read the complete original source.
Get the important updates without the noise
Choose the devices and topics you care about in Cyber Alerts.
Article history: Published Oct 2, 2026 at 6:05 pm EDT. Updates and corrections are noted here when material facts change.
