Appearance
Description
Restricted region detection identifies access that originates from a country or region that is considered high-risk or is not expected for legitimate users of the organization. Rather than comparing the reported location against a specific user's history, this check evaluates whether the origin falls within regions commonly associated with fraud, sanctions, or organized attack activity.
Key indicators include:
- High-risk or sanctioned regions
Access originating from countries or regions associated with elevated fraud risk or subject to organizational or regulatory restrictions.
- Unexpected geographies
Connections from regions where the organization has no legitimate users or operations.
- Concentration of risk signals
Access from a restricted region combined with other anonymization or device signals, which strengthens the overall risk assessment.
Relevance to Social Engineering Attacks
In social engineering campaigns, attackers frequently operate from regions outside the target organization's normal footprint. Because a genuine employee or candidate is unlikely to connect from a restricted or unexpected region, access from these locations is a strong indicator that the person behind the session is not who they claim to be.
Common attacker objectives include:
Concealing origin - operating from a region that the organization cannot easily investigate or act against.
Impersonation - claiming to be a local employee or candidate while connecting from a high-risk region.
Evading regional controls - attempting access from regions the organization would normally block or scrutinize.
By flagging access from restricted or unexpected regions, this check surfaces sessions whose origin is inconsistent with a legitimate user.