1. Enter attack volume
Use observed or forecast automated credential stuffing attempts per month.
2. Set successful login rate
Enter the percentage of attempts that result in unauthorized access.
3. Set harmful abuse rate
Estimate the share of unauthorized logins that lead to fraud, data access, loyalty theft, or another loss event.
4. Enter loss severity
Use the average direct and operational loss per abused account.
5. Choose the period
Set the number of months represented by the scenario.
6. Review expected loss
Compare expected unauthorized logins, abused accounts, monthly loss, and total loss.