Automatically monitor 100+ million user accounts for signs of bot fraud and other fraudulent or suspicious activities
Automatically block activities that meet a high-confidence threshold for bot or fraud activities
Significantly increase the accuracy of bot and fraud detection—while significantly decreasing staff time spent on manual fraud prevention activities
Provide invisible, frictionless account protection to pixiv users—no additional challenges or slower UX
Protect trust in the pixiv brand and foster engagement within the pixiv user community
To protect the centralized accounts of its global community of 100 million users, pixiv implemented Google reCAPTCHA Enterprise and Google reCAPTCHA Fraud Prevention to add automation and AI-powered intelligence to the fight against bot attacks and payment fraud.
Referring to Japanese-based pixiv as a social networking site is technically accurate. Still, it greatly undersells the bigger picture: Since launching in 2007, pixiv has become one of the world's largest and most popular online art communities.
The pixiv platform focuses on the sharing and exhibition of user-created art, particularly illustrations, with a significant emphasis on anime and manga-style artwork. Artists create accounts on pixiv to upload and share their artwork. The platform also has various features to support interaction and communication between artists and fans, fostering a vibrant and supportive creative community.
User trust is the foundation for any community like this. But trust is particularly critical for pixiv, because "pixiv provides all its services connected under one pixiv user account," explains Shunsuke Michii, CTO, pixiv, Inc.
We have a lot of users, so there was a lot of spam and account hijacking by bots. In particular, there were many attacks using password sprays and password lists. So, it was very important to strengthen our countermeasures against these bot attacks.
Shunsuke Michii
CTO, pixiv Inc.
It's precisely why securing and protecting those centralized user accounts is paramount to maintaining a thriving community and growing business.
pixiv has been leveraging Google Cloud solutions since 2013, hosting several of its services through Google Cloud. To maintain security on its platform and foster trust in its user community, pixiv uses Google reCAPTCHA Enterprise, Account Defender, and reCAPTCHA Fraud Prevention—among other Google Cloud security solutions—to protect user accounts against bot attacks and other fraudulent activity.
The other reason we chose reCAPTCHA Enterprise was because it had the best performance for the price.
Shunsuke Michii
CTO, pixiv Inc.
With 100 million registered users around the globe and more than 130 million artworks on the platform, pixiv is among the most significant art communities in the world. The growing popularity of new services on the platform—including VRoid, a 3D character maker, and pixivFANBOX, a dedicated platform for fostering connections between creators and fans—has fueled rapid growth in pixiv's user base. "Today, we're seeing the number of users increasing—especially overseas," says Michii.
To support and foster this growth, pixiv formed a new platform development team under Michii as CTO in 2020. "Our first priority was deciding how to manage account services as the user community grew," says Michii. The company considered outsourcing account services but built its own account services team to best protect the pixiv user experience. "As we built out our account services team, we immediately recognized that it was very important to improve the security of the login system—that was our first mission," Michii explains.
Initially, the pixiv account security initiative specifically focused on mitigating bot-related attacks—a particular issue for pixiv. "We have a lot of users, so there was a lot of spam and account hijacking by bots," says Michii. "In particular, there were many attacks using password sprays and password lists. So, it was very important to strengthen our countermeasures against these bot attacks."
pixiv is far from alone here: Since 2020, Forrester reports that 71% of companies have seen an increase in successful bot-based attacks. Cybercriminals increasingly use sophisticated bots to perpetrate credential theft schemes and other fraudulent activities, such as fake account creation, account takeover (ATO), and fraudulent transactions.
One factor in the rise of bot-related attacks is that conventional CAPTCHA (Completely Automated Public Turing test to tell Computers and Humans Apart)—the challenge-response tools traditionally used to stop bot attacks—are becoming less reliable. AI-powered bots are overcoming many CAPTCHA challenges. So-called “CAPTCHA farms” use human fraudsters to overcome CAPTCHA challenges as part of larger bot fraud schemes. Meanwhile, legitimate users/customers are growing more frustrated and less patient with completing CAPTCHA challenges—leading to poor UX, abandoned transactions, and lost revenue.
To address the many flaws of conventional CAPTCHA technologies, pixiv was already using Google's free reCAPTCHA solution. However, as the pixiv security team began to expand its focus to include broader account protection capabilities beyond just bot prevention, their partners at Google recommended an evaluation of the new account protection capabilities in reCAPTCHA Enterprise to take account protection to a future-ready level.
pixiv also evaluated other advanced anti-bot and account protection solutions, but reCAPTCHA Enterprise stood above the rest. Most notably for pixiv, reCAPTCHA Enterprise delivered elevated account security that was invisible and frictionless to pixiv users. "For pixiv, it is very important to be able to prevent bots without burdening the user—this is critical for user experience and engagement," explains Michii. "The other reason we chose reCAPTCHA Enterprise was because it had the best performance for the price."
Familiarity, ease of integration, and trust in Google as a partner also influenced pixiv's decision. "I've been using Google Cloud for quite some time," says Michii. "It was important that we were able to implement reCAPTCHA Enterprise while keeping all of our other account management and protection in place." The pixiv Platform Development team valued the certainty in Google's bandwidth and ability to support pixiv's rapidly growing global community and high volume of daily activity.
pixiv was among the earliest adopters of reCAPTCHA Enterprise, which Michii notes as a testament to their trust and collaborative partnership with Google. That partnership was on full display as pixiv rolled out reCAPTCHA Enterprise for beta testing. Michii describes the interaction with the Google team as "a two-way street: We gave them feedback that helped them to improve how the product worked for us—and it also made the product better for everyone else."
This collaborative commitment to continuous improvement makes the reCAPTCHA Enterprise solution all the more valuable for pixiv: "It's important that the product is not just a static solution, but a solution that keeps improving and evolving with our needs," says Michii.
Today, reCAPTCHA Enterprise is managing bot prevention in a way that is largely frictionless for both pixiv's user community and the pixiv account services team. Though there will always be some level of attempted bot fraud, Michii notes that reCAPTCHA Enterprise controls it to a level where he no longer worries about it daily: "I did not look at it today—which means I did not need to look at it," he explains.
Michii and the pixiv platform development team are now focusing on another major account security challenge: payment fraud. "pixiv is a global company, and fraudulent payment attacks, especially from overseas, have been a problem for a long time," says Michii.
The team recognized that the fraud prevention solution they had been using "was not enough." "We have to manually create heuristic alerts and then manually block fraud when we detect it. This requires a lot of time from our team," Michii says.
Several months ago, pixiv's partners at Google approached them about beta-testing reCAPTCHA Fraud Prevention. "We looked at it and thought, 'This is a great solution,'" says Michii. "reCAPTCHA Fraud Prevention allows pixiv to automatically block fraudulent payment activity that we previously had to identify and block manually." In addition, reCAPTCHA Fraud Prevention uses AI modeling to learn from historical fraudulent transactions and adapt the security features to continually get smarter and better at stopping fraud.
Again, pixiv did their due diligence, comparing reCAPTCHA Fraud Prevention against other fraud prevention solutions. In addition to best-in-class functionality, the ease of integration won them over: "reCAPTCHA Fraud Prevention was very easy to integrate into the current pixiv tech stack," says Michii. "If we wanted to add another [non-Google] behavioral analysis tool, we would have had to add another JavaScript tag to every page—which would mean longer page loading times that would not be user-friendly."
By comparison, reCAPTCHA Fraud Prevention integrates seamlessly with reCAPTCHA Enterprise and the other Google Cloud tools and solutions that pixiv was already using, forming what Michii calls a "single solution" to address the account security and payment fraud prevention problem.
As pixiv nurtures the exciting global growth of its community of users, the platform development team is enhancing and expanding its services on the frontend, while also working with Google Cloud to make impactful changes to the platform on the backend. "We are making big changes," says Michii.
This includes the first cloud-native service on Google Cloud, and connecting pixiv's cloud and on-premises infrastructure. "In order for pixiv to continue to grow the way our users want us to, we need to use the power of the cloud," says Michii. "We need to speed up our development, and for that, we're combining the power of Google Cloud with our existing on-premises infrastructure."
Alongside this community growth and platform expansion, the pixiv platform development team sees the Google Cloud security suite as a critical enabler: "Google's security tools like reCAPTCHA Enterprise and Fraud Prevention are also cloud-based, with very easy-to-use APIs," Michii says, which gives pixiv an agile, scalable security solution that’s ready to evolve with the company's needs.
pixiv is one of the world's largest art communities, where you can enjoy browsing and posting illustrations, manga, and novels. Community members upload a wide variety of work, organize projects, take part in official contests, and more.
Industries: Technology
Location: Japan
Products: reCAPTCHA, Google Cloud