It's not really about "location"
The first thing worth clearing up: this isn't GPS or physical geography. SecurynAI doesn't know where you're physically sitting, and it's not trying to guess. What it's actually looking at is what we call a new origin — a combination of a new IP address and a new device signature that hasn't logged into this account before.
That distinction matters because IP-based geolocation is often wrong or misleading — a VPN, a mobile carrier reassigning IPs, or traveling can all make a login look like it came from somewhere unexpected when nothing is actually wrong. A "new origin" check is more reliable because it's not trying to interpret geography at all — it's just noticing that this combination hasn't been seen before.
What actually gets checked
A login gets scored on a few independent signals:
- New IP address — this specific address hasn't logged into this account before
- New device — the browser/device fingerprint doesn't match previous logins
- Off-hours activity — the login happened in the middle of the night relative to typical server time
- A failed-login burst just before success — several failed attempts followed by a successful one, which can indicate credential guessing that eventually landed
These combine into a risk score. Low scores mean nothing gets flagged. Medium and above surface a finding you can review. High and critical are treated seriously enough to trigger deeper automated review.
Is this actually bad?
It depends entirely on whether the activity was you. A few honest scenarios that trigger this and are completely fine:
- You logged in from a new laptop or a fresh browser profile
- You're using a VPN or traveling
- You logged in from your phone's mobile network for the first time
- A teammate logged in for the first time from their own device
And a few that mean you should act immediately:
- You don't recognize the login at all
- It happened at a time you know you weren't at your computer
- It came right after a string of failed attempts you didn't make
What to do
- Ask "was this me or someone I gave access to?" first. Most of these alerts resolve immediately once you remember the new device or location.
- If you don't recognize it, don't wait. Revoke the session immediately and reset the password for that account.
- Check what the account did after logging in. A risky login followed by role changes, plugin installs, or file edits is a much stronger signal of compromise than the login alone.
- Turn on two-factor authentication if it isn't already on for every admin account.
The bigger point
A single flagged login, on its own, is usually not proof of a breach — it's a prompt to double-check. What actually matters is whether it lines up with other unexplained activity. Treat it as a question worth answering quickly, not an emergency by itself, unless you genuinely don't recognize the access at all.
Get every login reviewed and explained automatically.
Install free →