Back to Cases
VIG-2026-0918·
Account Takeover – Senior Customer Credential Stuffing
CRITICALResolvedAI: 97% confidenceAt Risk: $234,000
Case Description
Unsupervised isolation forest detected 47 accounts accessed from the same botnet IP range within 3 hours. Deep autoencoder reconstruction error exceeded threshold by 400%.
#ATO#credential-stuffing#botnet#bulk-attack
Risk Score96%
Assigned Team
Analyst
Flagged ByIsolation Forest Engine
Created6/7/2026, 10:15:00 PM
Subject
Customer Segment: 65+ Age Group, Branch 04
Industry
Banking
Amount at Risk
$234,000 USD
Escalation Level
L1 — L1 Analyst
TO
Thomas OkoroStatus Changed
Status changed: OPEN → INVESTIGATING.
SO
Sarah OkonkwoAnalyst Assigned· Banking Fraud Team
Assigned to Thomas Okoro for investigation.
SO
Sarah OkonkwoTeam Assigned· Banking Fraud Team
Assigned to Banking Fraud Team.
PN
Priya NairAlert Escalated
Alert escalated to case. Risk score 94.
AH
Ahmad HassanCase Created
Case automatically created by AI rule engine.
Evidence Locker
4 itemsBulk ATO Pattern Detected
47 accounts. 3 IPs. 3 hours.
Confirmed
Automated Mitigation Triggered
All 47 sessions terminated. MFA enforcement deployed.
Confirmed
SWIFT Transaction Log
MT103 raw transaction data export
Confirmed
GNN Entity Graph Export
Graph node-edge export — linked entities
Confirmed
Event Timeline
Bulk ATO Pattern Detected
47 accounts. 3 IPs. 3 hours.
10:15:00 PM·Isolation Forest Engine
Automated Mitigation Triggered
All 47 sessions terminated. MFA enforcement deployed.
10:17:00 PM·AI Mitigation Engine