VIG-2026-0918

Back to Cases
VIG-2026-0918·

Account Takeover – Senior Customer Credential Stuffing

CRITICALResolvedAI: 97% confidenceAt Risk: $234,000
Case Description

Unsupervised isolation forest detected 47 accounts accessed from the same botnet IP range within 3 hours. Deep autoencoder reconstruction error exceeded threshold by 400%.

#ATO#credential-stuffing#botnet#bulk-attack
Risk Score96%
Assigned Team
Analyst
Flagged ByIsolation Forest Engine
Created6/7/2026, 10:15:00 PM
Subject
Customer Segment: 65+ Age Group, Branch 04
Industry
Banking
Amount at Risk
$234,000 USD
Escalation Level
L1 — L1 Analyst
TO
Thomas OkoroStatus Changed

Status changed: OPEN → INVESTIGATING.

SO
Sarah OkonkwoAnalyst Assigned· Banking Fraud Team

Assigned to Thomas Okoro for investigation.

SO
Sarah OkonkwoTeam Assigned· Banking Fraud Team

Assigned to Banking Fraud Team.

PN
Priya NairAlert Escalated

Alert escalated to case. Risk score 94.

AH
Ahmad HassanCase Created

Case automatically created by AI rule engine.

Evidence Locker
4 items
Bulk ATO Pattern Detected
47 accounts. 3 IPs. 3 hours.
Confirmed
Automated Mitigation Triggered
All 47 sessions terminated. MFA enforcement deployed.
Confirmed
SWIFT Transaction Log
MT103 raw transaction data export
Confirmed
GNN Entity Graph Export
Graph node-edge export — linked entities
Confirmed
Event Timeline
Bulk ATO Pattern Detected

47 accounts. 3 IPs. 3 hours.

10:15:00 PM·Isolation Forest Engine
Automated Mitigation Triggered

All 47 sessions terminated. MFA enforcement deployed.

10:17:00 PM·AI Mitigation Engine
ARIA Copilot
Forensic Intelligence Agent
Config API →

ARIA ready

🔧 Demo Mode · Enter to send