ML Account Takeover Risk Assessment
Google's site-specific behavioural model produces account-risk judgements. Customer-configured policy can use the numerical account-takeover risk score or suspicious-login label to trigger protective responses. The numerical score requires Enterprise. Score and label enforcement triggers are not to be combined on the same assessment. Google does not independently disable accounts.
Recorded characteristics
- Function
- Account defense works by "creating a site-specific model for your website to detect a trend of suspicious behavior". It returns account-risk judgements: the numerical account takeover risk score (accountDefenderAssessment.accountTakeoverVerdict.risk, Enterprise only) or the SUSPICIOUS_LOGIN_ACTIVITY label. "You can configure your enforcement logic either based on the risk score exceeding your threshold or based on the label's presence." "Do not use both the risk score and the label to trigger enforcement on the same assessment." Documented customer responses include "Restrict or disable fraudulent accounts", blocking suspicious requests and challenging risky logins. Google does not independently disable accounts; protective actions are implemented in the customer's backend.
- Data access
- Account activity reported by the customer's site: horizontal telemetry from the reCAPTCHA script on pages in the user workflow, critical user actions and a stable account identifier. "Account defense requires you to provide a stable account identifier". Customers annotate events to tune the site-specific model.
- Actions
- Can take actions
- External actions
- Conditional
- Human confirmation
- Not required
- Permission basis
- Not established
- Administrative control
- Setup requires a score-based site key, the reCAPTCHA script on every page in the user workflow, a stable account identifier and event annotation. The customer chooses the threshold or label check and the protective response. Google recommends evaluating the score's performance "with an appropriate threshold on your platform's traffic before you use it for enforcement".
- Default state
- Not established
- Availability
- Account defense is not available on Essentials; Premium provides basic explainability reasons; Enterprise provides the account takeover risk score and advanced explainability reasons.
- Licensing
- "You must have an Enterprise subscription to use the ATO risk score feature." Other commercial terms are not publicly established.
- External model or provider
- Not established
- Limitations and uncertainty
- The threshold check is a documented integration pattern; it does not establish that every customer uses numerical account-risk scoring. Without Enterprise only the label route is available. An empty accountDefenderAssessment means Account defense "did not have anything to add to the score". Activation requires setup; no documented disabled-by-default setting exists, so default state is not established. No platform-enforced per-action human approval is documented. Permission basis is not publicly established. No monitor is active.
Evidence
- Detect and prevent account-related fraudulent activities on websites
Supports: Limitations · Licensing · Data access · Human confirmation · Actions · Function · Primary source
"Do not use both the risk score and the label to trigger enforcement on the same assessment." Google recommends evaluating the score on the customer's own traffic before using it for enforcement.
"You must have an Enterprise subscription to use the ATO risk score feature."
"Account defense requires you to provide a stable account identifier to make the assessment and to attribute user activity".
The documented check compares accountTakeoverVerdict.risk to the customer's chosen threshold and then implements protective actions; no platform-enforced per-action approval is documented.
"You can configure your enforcement logic either based on the risk score exceeding your threshold or based on the label's presence." Listed responses include "Restrict or disable fraudulent accounts."
Account defense works by "creating a site-specific model for your website to detect a trend of suspicious behavior or a change in activity."
- Interpret assessments for websites
Supports: General · Primary source
"After you receive the score from reCAPTCHA, you must interpret the score and take appropriate actions for your site."
- Google Cloud Fraud Defense overview
Supports: General · Primary source
"reCAPTCHA has become a part of Google Cloud Fraud Defense" and "The verdict includes a risk score from 0.0 to 1.0 and reason codes."
- Compare features between Google Cloud Fraud Defense tiers
Supports: Availability · Primary source
Feature table, Account defense: Essentials N/A; Premium "Basic explainability reasons"; Enterprise "Account takeover risk score, and advanced explainability reasons".
- Fraud Defense release notes
Supports: General · Primary source
15 February 2023: "reCAPTCHA Enterprise account defender is now generally available"; 28 March 2024: GA for mobile applications.