For a small gaming SaaS team, the least complex defensible approach is to protect the signup and login API with a captcha after a few failed attempts, then require step-up verification when risk persists. Do not lock the account. A lockout lets an attacker deny service to any player whose email address is known. TL;DR: Use per-account and per-network failure signals to decide when to show a captcha, but do not turn either signal into a permanent identity verdict. After the captcha, require an...