Account takeover is one of the biggest threats to social-network users — an attacker who steals a password (via phishing or a leaked credential list) tries to log in from their own location and device, which looks nothing like the real owner's normal pattern. This simulator visualizes a real defensive technique: every synthetic login event for one account lands on a 3D globe and is scored live with a composite risk formula that combines geographic velocity ("impossible travel" between two logins too far apart in too little time), whether the device is new, how many failed attempts preceded it, and whether the login hour is unusual. Switch between a normal-traffic scenario, a simulated impossible-travel takeover, and a credential-stuffing burst, tune the auto-lock threshold, and watch which events get silently escalated to step-up verification versus fully blocked — exactly the kind of trust-and-safety pipeline that protects real social accounts.