Account compromise and fraud activation look different from each other in session data, but they share a common characteristic: both produce behavioral patterns that are inconsistent with the account's own history. This post describes the specific behavioral indicators that distinguish compromised accounts from their owners, and fraudulent accounts from legitimate ones, based on the pattern families that show up most reliably in production fraud detection systems.
These are not exhaustive or definitive indicators. Fraud tactics evolve, and any single indicator has a false positive rate that makes it unreliable on its own. But these pattern families appear in a large majority of cases and form the core signal basis for behavioral trust scores that detect high-risk accounts.
Keystroke and input dynamics: the hardest signal to fake
Input dynamics are the timing patterns of keyboard and touchscreen interactions: how quickly a person types, the intervals between keystrokes, the duration of key holds, the error rate and correction patterns. These dynamics are a function of motor habits that develop over years and are consistent enough across sessions to serve as a behavioral signature.
Account compromise shows up in input dynamics because the attacker's motor habits are different from the account owner's. A fraudster who has stolen credentials and is manually operating the account types differently: different inter-key interval distributions, different key hold patterns, different error and backspace rates. The divergence from the account's historical input signature is detectable even when credential checks pass.
Automation shows a more pronounced and different signature: machine-generated input has timing distributions that are either too regular (constant inter-key intervals) or randomized in a pattern that lacks the natural autocorrelation of human typing. The absence of correction behavior, the consistency of typing speed across structurally different fields, and the statistical properties of the IAT distribution are all distinguishing features.
Session warm-up: what precedes the sensitive action
Legitimate users approach sensitive actions (payment changes, account settings modifications, high-value purchases) with a session context that reflects a genuine user journey: browsing from a landing point, navigating through the relevant product area, arriving at the sensitive action after some time on the platform. This warm-up behavior is characteristic of someone using the platform for its intended purpose.
Compromised account sessions and fraud-intent sessions typically show minimal warm-up. The session begins close to the sensitive action endpoint. There is little or no browsing behavior preceding the high-value action. The navigation path is direct and purposeful in a way that doesn't match the browsing pattern the account owner typically shows.
The absence of warm-up is a strong signal specifically because it is hard to fake without generating it: you cannot add artificial warm-up browsing without spending additional time in the session and generating additional behavioral signal that itself needs to match the account owner's patterns.
Navigation and interaction pattern shifts
Beyond individual sessions, accounts show consistent navigation patterns over time: which pages they visit, in what order, for what duration. A user who consistently browses a specific category, visits account settings on a regular cadence, and spends predictable time on product pages develops a navigation fingerprint as characteristic as their input dynamics.
When an account is taken over, the new operator has different goals and different knowledge of the platform. They navigate to areas the account owner rarely visited. They skip areas the account owner regularly used. They spend different amounts of time on pages. The shift in navigation pattern, measured against the account's own history, is a distinctive indicator.
This pattern shift is also detectable at a single-session level for accounts with sufficient history. A session where the navigation sequence matches known attack paths (direct to payment method settings, payment method change, immediate high-value purchase) is a concerning pattern regardless of the individual-action risk scores.
Device environment inconsistency
Fraudulent sessions often originate from device environments that are inconsistent with the account's history. The indicators include: browser user agent changes inconsistent with software update cycles, hardware metrics that diverge from the account's historical profile, timezone-location inconsistency relative to the account's typical access geography, and browser configuration characteristics associated with automation or sandboxing.
Device inconsistency alone has a moderate false positive rate: legitimate users travel, change devices, and update software. The value is in the combination of device inconsistency with behavioral indicators. A session from a new device type with different input dynamics and minimal session warm-up is a much stronger signal than any of those indicators in isolation.
Temporal anomalies: when the session happens
Account owners access their accounts at predictable times. A user who consistently accesses their account during business hours on weekdays from one timezone is an anomaly if they suddenly produce a session at 3 AM from a different timezone. The anomaly is not the time itself, but the divergence from the account's own timing distribution.
Fraud operations often run on schedules driven by their operators' own work patterns and by the operational windows of the payment systems they exploit. These schedules create clustering patterns in session timing that can be identifiable at the platform level across multiple accounts even when no individual account's timing divergence is large enough to trigger per-account anomaly detection.
Behavioral indicators after account modification events
Account modification events (password reset, email change, phone number update, payment method addition) are legitimate but also a common precursor to fraud. The session behavior in the period immediately following an account modification is highly diagnostic. An account that modifies its payment method and immediately initiates a high-value purchase, with session behavior that diverges from the account's historical patterns, is showing the behavioral signature of account takeover that the attacker chose to complete before the actual fraud event rather than during it.
Monitoring the behavioral indicators in the sessions following modification events, rather than only at the time of the modification itself, catches a class of fraud that would otherwise appear as a clean session at the point of the fraud action.