Activision’s Senior Director of Game Security for Call of Duty, David Andrews, has explained how the company reviews suspected cheating, issues most bans through reviewed automated systems, and is trying to stop cheaters before they enter matches. The details come from an IGN interview published on September 10.
Andrews said the team’s strategy has shifted over time. Rather than treating large ban waves as the main answer, he now sees prevention and rapid removal as the more effective approach. That means blocking cheaters before they reach a match where possible, then removing them quickly when detection happens after play begins.
How Activision reviews suspected Call of Duty cheaters
According to Andrews, reports and detections reach the security team through several routes. The vast majority of Call of Duty bans are issued by automated systems that have been reviewed rather than by a person making every individual decision from scratch.
The review can use several types of evidence. Activision has match input data that can reveal clear outliers, while longer-term performance and behavior can show unusual changes in statistics such as kill-to-death and win-loss ratios. The company also has internal replay tools that can reconstruct a complete match for examination.
Ban waves can reveal information to cheat developers
Andrews said every ban can give cheat developers feedback about how their software was detected. That creates a trade-off: enforcement removes offenders, but it may also help cheat sellers troubleshoot their products and try to evade the same detection method.
His preferred response is continuous adaptation. The security team develops new detections and new ways to prevent or remove cheaters, while avoiding reliance on one method that can eventually be bypassed. Andrews characterized the sale of video-game cheats as a multi-billion-dollar industry whose developers have strong financial incentives.
He also said companies across the games industry talk informally about cheating and exchange experiences and possible approaches. Cheat sellers often operate across several games rather than one title, which can give publishers common ground for comparing what they are seeing.
Activision has hired people from the cheat-development world
One unusual part of Activision’s response has been recruitment. Andrews said he has successfully brought former cheat developers or people in cheat-adjacent roles onto the anti-cheat team several times. In his view, those hires contribute specialized expertise and a perspective that can be valuable when designing defenses.
The comments also addressed the gap between Activision’s internal measurements and the cheating seen by high-level players. Andrews said the company recorded a very low match-infection rate during the Black Ops 7 beta and maintained a low rate afterward. He nevertheless acknowledged that content creators and professional players at the top of ranked play encounter more cheaters than the average player.
That difference can shape the public discussion because highly visible streams may show cheating more often than a typical player experiences it. Andrews did not claim that the problem has disappeared, and Ricochet remains an active security effort.
TPM and Secure Boot remain part of the prevention strategy
Andrews credited TPM and Secure Boot requirements with a major step forward during Black Ops 7. Those controls fit the broader “shift left” strategy he described: reduce opportunities for cheats before they affect a live match, then use detection and review systems when prevention is not enough.
The interview arrives as Modern Warfare 4 approaches its October launch. Andrews said the team intends to keep making progress in the next title, but his explanation also makes clear that anti-cheat work is an ongoing contest rather than a problem solved by one requirement, detection signature, or ban wave.




