[{"data":1,"prerenderedAt":118},["ShallowReactive",2],{"\u002Fglossary\u002Fimpossible-travel":3,"glossary-related-\u002Fglossary\u002Fimpossible-travel":111},{"id":4,"title":5,"body":6,"description":97,"extension":98,"meta":99,"navigation":100,"path":101,"relatedTerms":102,"seo":106,"sitemap":107,"stem":108,"term":109,"__hash__":110},"glossary\u002F6.glossary\u002Fimpossible-travel.md","What is impossible travel?",{"type":7,"value":8,"toc":90},"minimark",[9,13,23,28,31,39,43,46,59,62,70,73,77],[10,11,5],"h1",{"id":12},"what-is-impossible-travel",[14,15,16,17,22],"p",{},"Impossible travel is a fraud signal that fires when two events on the same account, usually logins, come from locations too far apart to travel between in the time that elapsed. A sign-in from Chicago followed by a sign-in from Singapore twenty minutes later implies a speed no aircraft can reach, so at least one of the two sessions deserves scrutiny. It is one of the oldest heuristics in ",[18,19,21],"a",{"href":20},"\u002Fglossary\u002Faccount-takeover","account takeover"," detection, and still one of the most useful when applied with care.",[24,25,27],"h2",{"id":26},"how-it-works","How it works",[14,29,30],{},"The mechanics are simple. Each event carries an IP address. You geolocate both IPs, compute the distance between the two points, and divide by the time between the events. That gives you an implied speed. If the speed exceeds a plausible threshold, commonly around the 550 mph cruise speed of a commercial airliner plus some margin, the pair gets flagged.",[14,32,33,34,38],{},"The signal works because attackers rarely sit in the same city as their victims. Stolen credentials get tested from datacenters and proxy networks around the world, so a successful ",[18,35,37],{"href":36},"\u002Fglossary\u002Fcredential-stuffing","credential stuffing"," hit often produces a login thousands of miles from anywhere the real user has ever signed in. Meanwhile the legitimate owner keeps using the account from home, and the two access patterns collide into an impossible pair. A velocity check catches that collision without needing to know anything else about the attacker.",[24,40,42],{"id":41},"how-to-detect-it","How to detect it",[14,44,45],{},"The naive version (IP geolocation plus a speed check) generates heavy false positives. Three sources cause most of them:",[47,48,49,53,56],"ul",{},[50,51,52],"li",{},"VPNs. A user who connects through a VPN exits the internet wherever the provider's server sits. Turning the VPN off between two requests looks like teleporting across an ocean, and switching exit nodes looks the same.",[50,54,55],{},"Corporate egress. Many companies route employee traffic through a security stack in another region, so one person can legitimately appear in two countries within minutes depending on which network their laptop joined.",[50,57,58],{},"Mobile carrier NAT. Carrier-grade NAT can assign a phone a public IP that geolocates hundreds of miles from the handset, and the assigned IP can change between sessions without the phone moving at all.",[14,60,61],{},"IP geolocation is also imprecise on its own. Databases routinely place an IP in the wrong city and occasionally the wrong country, which stretches or shrinks the computed distance.",[14,63,64,65,69],{},"The fix is corroboration, mostly with device signals. Check whether both events came from the same device: an identical ",[18,66,68],{"href":67},"\u002Fglossary\u002Fdevice-fingerprinting","device fingerprint"," on both sides of an impossible pair points at a VPN toggle rather than a second actor. Check the network type: a jump that lands on a hosting provider or a known VPN exit is far more suspicious than one that lands on a residential ISP. Check session continuity: did the second location reuse an existing authenticated session, or present a password and start fresh? And keep allowlists for corporate egress ranges your real users are known to traverse. Impossible travel plus a never-seen device plus a datacenter ASN is a strong account takeover indicator. Impossible travel alone is a prompt to look closer, not a verdict.",[14,71,72],{},"Tuning matters too. A threshold set at exactly airliner speed flags people who land and open their laptop at the gate. Adding a buffer for time zones, airport-to-city gaps, and geolocation error cuts noise without hiding real attacks, since credential stuffing pairs usually imply speeds that are absurd rather than borderline.",[24,74,76],{"id":75},"how-rupt-handles-it","How Rupt handles it",[14,78,79,80,84,85,89],{},"Rupt computes travel velocity between events as one input to a larger score, weighed against device identity, network reputation, and the account's own history on the ",[18,81,83],{"href":82},"\u002Fplatform\u002Fintelligence","intelligence layer",". An impossible pair backed by a known device can resolve quietly, while the same pair from a new device on a hosting network can trigger step-up verification or a block, the pattern described in ",[18,86,88],{"href":87},"\u002Fsolutions\u002Faccount-takeover","account takeover protection",".",{"title":91,"searchDepth":92,"depth":92,"links":93},"",2,[94,95,96],{"id":26,"depth":92,"text":27},{"id":41,"depth":92,"text":42},{"id":75,"depth":92,"text":76},"Impossible travel is when two logins on one account come from locations too far apart to reach in the time between them, a classic account takeover signal.","md",{},true,"\u002Fglossary\u002Fimpossible-travel",[103,104,105],"account-takeover","credential-stuffing","device-fingerprinting",{"title":5,"description":97},{"loc":101},"6.glossary\u002Fimpossible-travel","Impossible travel","JZsJviBBrsuEbtx1CHB-b3kD8XZG40wKNgu0q3n33Wc",[112,114,116],{"path":20,"term":113},"Account takeover",{"path":36,"term":115},"Credential stuffing",{"path":67,"term":117},"Device fingerprinting",1786669620368]