Resources Docs Free Blog Contact
Log inGet started
Attack Playbooks

How these attacks
are actually built

Six playbooks across e-commerce, fintech, SaaS, iGaming, travel and creator platforms. Each one takes an attack apart — the tooling, the control it defeats, what the verdict returns — and models the exposure with inputs you replace with your own. No customer names, because these are not customer reports.

6
Attack playbooks broken down step-by-step
Full
Live detection signals per request
1 call
One API call to a verdict — live the same day
0
CAPTCHAs added to legitimate users
Network Intelligence
VPNs, residential proxies, datacenter IPs, Tor exit nodes, ASN reputation and routing pattern analysis
Device Intelligence
Headless browsers, antidetect spoofing (Kameleo, GoLogin, Dolphin Anty), emulators, canvas and WebGL fingerprint
Behavioral Signals
Velocity patterns, device clustering, session anomalies, account linkage graphs, superhuman timing
E-Commerce
Card Testing
0
Blocklist hits on the order

Stolen cards routed through residential proxies arrive from a real consumer ISP near the billing address. IP reputation is clean, AVS matches, geolocation agrees — and the disputes land six weeks later.

Residential ProxyDevice FingerprintVelocity Signals
Read case study
Fintech
Fake Signups
4
Layers in the farming stack

A signup bonus is a published price for a fake account. Antidetect browser, residential proxy, catch-all email, scripted fill — each layer defeats one control, and together they leave nothing for a rules engine to count.

VPN DetectionAntidetect BrowserAccount Velocity
Read case study
SaaS
Trial Farming
1
New identity per trial

A new email, a new IP, a cleared browser, and the fourteen days start again. Every trial is individually unremarkable, which is exactly why the cohort never shows up in a per-account check.

Canvas FingerprintDevice ClusteringBrowser Identity
Read case study
Creator Economy
Pledge Fraud
1
Operator behind many backers

Hundreds of plausible backers, no shared card, email or address. What they share is infrastructure — and the payout usually clears before the disputes arrive.

Residential ProxyASN PatternNetwork Clustering
Read case study
iGaming
Bonus Abuse
0
KYC failures — the documents are real

Rented identities pass onboarding truthfully, and an antidetect profile per account means the fingerprints never repeat. A fully compliant KYC process is not an obstacle to this attack.

Antidetect BrowserResidential ProxyDevice Spoofing
Read case study
Travel & Ticketing
Scalper Bots
<1s
Bot time-to-hold on release

Direct API calls, one residential IP per session, solved CAPTCHAs at a fraction of a cent. Every control aimed at the bots lands hardest on your customers, who are the ones least able to pay the toll.

Headless BrowserAutomation SignalsDevice Velocity
Read case study

Have results from your own integration?

These playbooks are worked examples, not customer results. Used Maskbreak on your own site? Share what you measured — positive, mixed or no change.

Include what changed, dates and traffic volume, your comparison method, measured results and limitations. Send aggregate figures only; do not include visitor data, credentials or API keys.

Submitting starts a private conversation, not permission to publish. We will ask you to approve the final wording, figures and whether your organisation is named before publication. Participation is optional and does not affect access.

Share your experience

Ready to protect your platform?

Free during open beta: 1,000 visitor checks/hour per API key. No card. At least 30 days’ notice before paid changes. Live in minutes.

Get Free API Key
Fraud BriefOnce a month · no spam · unsubscribe anytime
Get the new VPN, proxy & bot patterns we see each month
Short, technical breakdowns of what fraudsters changed last month — written for engineers, not marketers.