- whether the user is privileged (depends on, or at least benefits from, T391632: Split privileged user groups to privileged / highly privileged)
- whether the user has been active (on the current wiki; globally this seems hard)
- whether the login rates are (globally) abnormally high right now (probably depends on T134953: Merge Throttler and ping limiter)
First, just log these bits of information. When we have some stats on frequency, we can consider what reaction would be appropriate.