# Auth Attack Runbook

Owner: Security on-call
Severity: SEV1 for active account takeover campaign, SEV2 for elevated suspicious login volume.

## Triggers

- `BankingSuspiciousLoginSpike`
- login lockout spike
- unusual refresh-token rotation failures
- session anomaly alerts or mass remote revocations

## First 15 Minutes

1. Confirm attack pattern by IP range, user agent, country, account segment and request IDs.
2. Tighten rate limits and WAF rules for affected routes.
3. Force step-up or session revocation for accounts with confirmed compromise indicators.
4. Notify support with customer-safe wording.
5. Preserve evidence for security and compliance review.

## Diagnosis

- Compare failed login identifiers, new device fingerprints and suspicious event decisions.
- Check credential stuffing indicators and leaked credential feeds if available.
- Review recent admin scope changes and MFA reset requests.

## Recovery

- Maintain heightened limits until traffic returns to baseline.
- Send customer notifications for affected accounts.
- Add detections or tuning rules for the observed pattern.
- Attach alert timeline, rule changes and impacted-account list.
