How Kiabi Cut Malicious Login Attempts & Gained Instant Threat Visibility

Last update: 24 Sep, 2026 | min
Credential stuffing attempts automatically detected and blocked,
no manual intervention
2 DDoS attempts neutralized instantly,
with zero infrastructure impact
<0.01% false positive rate,
ensuring a great customer experience
Contents
DataDome

Kiabi, the French fashion retailer operating in 30 countries, has been the target of repeated credential stuffing attacks, which led to a publicly reported incident on its second‑hand platform. Since a Web Application Firewall (WAF) alone proved too time‑consuming and reactive, the Cybersecurity team chose DataDome for its effectiveness, ease of deployment, and proactive SOC. In less than three months, Kiabi deployed DataDome across all its websites, cut malicious activity, and gained the clarity to manage both bad and “good” bots with confidence.

"Deploying DataDome was a real revelation for us. Before, we might see tens of thousands of malicious requests and correlating them to determine if they were part of the same attack required enormous manual effort. DataDome gives us a consolidated view. Even when there are thousands of different IP addresses, we can see it's actually the same attack from the same origin. Being able to characterize threats that way is a major step forward."
Patrice Martin
Cybersecurity Manager at Kiabi

The challenge: When credential stuffing becomes business-critical

In January 2025, Kiabi became one of several French retailers targeted by a coordinated credential stuffing campaign. Bots tested login credentials harvested from unrelated data breaches across the web, exploiting the widespread habit of password reuse.

For Patrice Martin, Cybersecurity Manager at Kiabi, the incident crystallized a tension that had been building for some time.

“We were under considerable pressure from credential stuffing. The WAF wasn’t enough and required a very detailed analysis that took an enormous amount of time,” he explains.

Indeed, managing bot attacks through a WAF involves manually writing and maintaining rules, analyzing requests one by one, and struggling to form a coherent picture of the attacker’s true identity. A single attacker using hundreds or even thousands of IP addresses appears, in a WAF, as that many separate issues. “We had a hard time getting an overall view of the threat,” Patrice says. “We felt that our protection wasn’t sufficient.”

After this attack, the right question was no longer whether Kiabi needed stronger bot protection, but how to implement it without slowing down the site, blocking legitimate customers, or adding layers of operational complexity.

The solution: Better protection that doesn’t impact UX and website speed

Kiabi therefore issued an RFP. Any solution had to prove itself in an environment where performance is non-negotiable. Its e-commerce sites operate in seven countries, and even minimal latency during checkout has real business consequences. False positives had to be eliminated.

The team had learned a lesson from its experience with the WAF. “In the past, our rules were sometimes too broad. We wanted to stop a potential attacker, but we ended up blocking legitimate users,” explains Patrice. Granularity was consequently essential so that his team could distinguish a bot from a human, a malicious bot from a harmless one, and adjust the response accordingly.

And even though the Security team understood the WAF’s limitations, they had no intention of getting rid of it. The chosen solution would therefore need to integrate with existing tools without requiring custom development. Furthermore, Kiabi wanted access to trend data and reports that were understandable not only to security analysts but also to the entire operations team.

Two vendors, including DataDome, made it to the final round. On paper, both offered comparable detection capabilities. The difference came down to the human factor. “It was the pre-sales team and the project team that tipped the scales,” explains Patrice. “They were extremely responsive and provided us with clear, concrete answers very quickly. That’s an important sign: if the pre-sales process isn’t smooth, there’s little chance it will be smooth later on.”

Then, the deployment of DataDome on Kiabi’s internal systems went quickly. The brand took a carefully considered approach: it started with smaller markets, the Netherlands and Portugal first, then Italy, Spain, and finally France, its highest-traffic site. Throughout the process, the DataDome teams worked closely alongside Patrice’s teams: “We weren’t the only ones monitoring the tool. DataDome was also analyzing our traffic and alerting us if anything seemed out of the ordinary. That was reassuring. You can really tell the tool is managed by experts.”

A complication arose on mobile devices. Kiabi uses a third-party partner for authentication, which meant that two SDKs (the partner’s and DataDome’s) had to coexist seamlessly. Integrating them together required close collaboration, and DataDome’s responsive support team worked hand-in-hand with Kiabi to ensure a seamless technical rollout. “We received excellent support from DataDome on this issue, even though the problems weren’t on their end,” notes Patrice.

Today, Kiabi has deployed DataDome across all its own websites and on its secondhand platform. The WAF has remained in place alongside it to provide additional protection.

The results: Less noise, more control, zero successful attacks

Malicious login attempts are now automatically detected and blocked, without requiring manual intervention from Kiabi’s teams. On Beebs (the C2C secondhand platform), where the wallet feature makes account takeover directly profitable for attackers, the decline observed since deployment is, in Patrice’s words, “spectacular and clearly noticeable.”

“Deploying DataDome was a real revelation for us. Before, we might see tens of thousands of malicious requests and correlating them to determine if they were part of the same attack required enormous manual effort. DataDome gives us a consolidated view. Even when there are thousands of different IP addresses, we can see it’s actually the same attack from the same origin. Being able to characterize threats that way is a major step forward.”

His initial concern about not affecting the site’s performance was immediately put to rest. By operating invisibly in the background, DataDome’s detection has never been noticed by Kiabi’s customers.

What the team did notice, however, on two separate occasions, was the protection it provided during two DDoS attacks that DataDome blocked in a matter of milliseconds. “This prevented the site from automatically scaling up its capacity in response to the attack. DataDome proved extremely effective, as all requests were blocked and the infrastructure was completely unaffected,” explains Patrice. The result: no traffic-related cost spikes that Kiabi should never have had to bear.

As for false positives, the team finally has the visibility it needed. “The false-positive rate is under 0.01%,” notes Patrice, who relies on DataDome’s dashboards to monitor and control this rate in real time.

The dashboards have provided Kiabi with an unexpected benefit: visibility not only into threats but also into everything that passes through the site. Harmless bots, such as SEO crawlers, AI training agents, or data aggregators, are now fully visible, with contextual information about their origin and behavior.

“DataDome made us realize that web crawling had a bigger impact on websites than we thought,” says Patrice. It wasn’t a security requirement when the project launched, but it has become one of the most appreciated features by SEO teams and web analysts.

With DataDome, automated attacks are now intercepted before they land, and the analysts who spent hours correlating IP addresses can now focus on higher-value work. “We have solid protection,” Patrice says simply. Sometimes that’s the most reassuring thing a Cybersecurity Manager can say.

Is your site protected against credential stuffing, scraping, and DDoS? Automated attacks on retail sites are growing. Test your site for free to see if you’re exposed.

DataDome
DataDome

Still exploring?

Start with an on-demand demo.