How do bot operators take over marketplace buyer accounts?
Credential stuffing at scale
The cheapest attack is also the most common. Breached email-password pairs from other sites are tested against the marketplace login in huge volumes, spread across residential IPs and headless browsers so no single source trips a rate limit. The operators do not hammer one account. They test one credential per account across millions of accounts, staying under the lockout threshold everywhere. A hit rate of a fraction of a percent still yields thousands of working logins when the credential list is large enough.
The defense is not a tougher CAPTCHA on the login page, since the traffic is deliberately kept slow and human-looking. What works is breach-correlation at login time: checking the presented credential against known breach compilations and forcing a reset or step-up before the session proceeds, plus velocity analysis across the fleet, not the account. One account failing once is nothing. Ten thousand accounts each failing once from the same infrastructure is an attack.
Session theft that skips the login
More sophisticated operators skip credentials entirely. Malware, malicious browser extensions, and phishing pages that proxy the real login steal the authenticated session cookie after the buyer logs in legitimately. The attacker imports that cookie and browses as the buyer with no password and no 2FA challenge. To the marketplace, it looks like the real user on a new device.
This is why login-time defenses are not enough. Session binding matters: tie the session to device and network fingerprints and re-verify when they change sharply. A session that logged in from Chicago on an iPhone and suddenly buys from a datacenter IP on a headless browser is not the same user, even if the cookie is valid. Re-authentication on anomalous session changes catches what the login page never sees.
Farmed accounts that age into trust
The patient operators create accounts themselves and age them. The accounts browse, wishlist, make small legitimate purchases, and build the history that risk systems reward. Months later they are sold or activated for fraud: fake reviews, reseller purchases, payment fraud, or chargeback schemes. Aged accounts sail through new-account screening because they are not new.
Detection has to look at behavior continuity, not account age. An account that bought phone cases for six months and suddenly buys ten high-value gift cards for resale is a changed account regardless of its age. Velocity and category shifts relative to the account's own history are the signal. Fraud teams that only score new accounts are screening the front door while the back door walks in with seniority.
What the takeover buys the operator
Taken-over buyer accounts are infrastructure, not the end goal. They place orders with stolen payment methods that look legitimate because the account history is real. They post reviews that look organic for the same reason. They drain loyalty points and stored balances, which converts directly to goods. And they serve as mules for reseller operations: the bot buys the limited drop through a real account, and the marketplace's own fraud data shows a trusted buyer, not a bot.
What actually reduces takeover fraud
No single control does it. The working stack is layered: breach-credential checks at login, session binding with re-verification on anomaly, behavioral scoring across the full session rather than the login moment, and step-up authentication scaled to risk instead of applied to everyone. Rate limits and lockouts still matter for the crude attacks, but the professional pipeline is designed around them. The marketplaces that cut takeover fraud are the ones that score the session continuously and treat a changed session as a changed user, even when the cookie is valid and the account is old.
How do you detect account takeover without blocking real buyers?
Score the session, not just the login. Look for device and network changes, impossible travel, password resets followed by immediate high-value purchases, and behavior that does not match the account's history. Step up authentication on risk, do not block on a single signal.
Does two-factor authentication stop account takeover?
It stops basic credential stuffing, but attackers phish codes, abuse SIM swaps, and steal authenticated sessions to skip the login entirely. Treat 2FA as one layer in a session-scoring system, not as the whole defense.