Skip to main content

Account Fraud

TL;DR
  • Account fraud = Fake or malicious accounts created on your platform
  • Types: Bot signups, referral abuse, multi-accounting, fake reviews
  • It's infrastructure for the fraud that comes next, not the loss itself
  • Detect via: Device fingerprinting, email analysis, behavioral patterns
  • Prevent with: CAPTCHA, email verification, phone verification, rate limiting

Someone signs up who isn't a customer. They're building for later.

Definition

Account fraud is fake or abusive accounts on your site or app. They don't cost you anything directly, and that's the trap: they enable promo abuse, refund fraud, fake reviews and organized attacks.

Why Fake Accounts Matter

They EnableHow
Promo abuseNew account = new discount
Referral fraudSelf-refer across accounts
Velocity evasionSpread activity across accounts
Card testingDisposable accounts for testing
Fake reviewsBoost or attack products
Resale fraudBulk buying limited items

Common Patterns

Bot Signups

Automated signups at scale. You'll see hundreds in an hour:

  • Hundreds of accounts in hours
  • Similar registration patterns
  • Disposable email domains
  • Generic or random usernames

Referral Fraud

Gaming referral programs:

  • Self-referral across accounts
  • "Referral farms" with fake accounts
  • Quick signup → claim reward → abandon

Multi-Accounting

One person, multiple identities:

  • Evade account-level limits
  • Stack promotions
  • Bypass bans or restrictions
  • Separate fraud activity from "real" account

Fake Review Fraud

Social proof that isn't.

  • Paid review rings
  • Competitor sabotage
  • Boosting new products artificially

Detection Signals

Registration Red Flags

SignalRisk Level
Disposable email domainHigh
Email pattern matches prior fraudHigh
Device seen on multiple accountsCritical
Registration velocity (time to complete)Medium
Phone number from VoIP providerMedium
Similar usernames/passwordsHigh

Email Analysis

PatternWhat It Suggests
john+1@gmail, john+2@gmailMulti-accounting
Random string @domain.comBot-generated
Domain age < 30 daysRecently created for fraud
Known disposable domainTemporary account
Email never used elsewhereFabricated for this account

Device Signals

Device fingerprinting reveals:

  • Same device across multiple accounts
  • Emulator or automation tools
  • VPN/proxy usage
  • Device recently associated with fraud

Behavioral Indicators

BehaviorRisk
No browsing before checkoutScripted behavior
Immediate promo redemptionPromo farming
Referral link used instantlySelf-referral
Never returns after signupThrowaway account
Review posted without purchaseFake review ring

Prevention Strategies

At Registration

ControlWhat It Stops
CAPTCHABot signups
Email verificationDisposable emails
Phone verificationMulti-accounting
Rate limitingMass registration
Device fingerprintingRepeat registrations

Email Verification Best Practices

LevelMethodStops
BasicSend confirmation linkFake emails
MediumCheck domain reputationDisposable domains
StrongEmail risk scoringFraud-associated emails

Phone Verification

CheckWhy
SMS verificationTies to real phone
VoIP detectionBlock virtual numbers
Phone line typeMobile vs. landline vs. VoIP
Phone velocitySame number, many accounts

Device Controls

ControlWhat It Catches
Device fingerprintingSame device, different accounts
Emulator detectionAutomated fraud tools
VPN detectionHidden location
Device reputationKnown fraud devices

Account Linking

Here's what links accounts back together:

AttributeWhat It Links
Device fingerprintSame device = same person
IP addressSame network (less reliable)
Payment methodSame card across accounts
Shipping addressSame destination
Behavioral patternsSimilar navigation, timing

Response Playbook

Confirmed Fake Account

  1. Block the account - Prevent further activity
  2. Revoke benefits - Cancel promos, referral rewards
  3. Blacklist identifiers - Device, email, phone
  4. Check for linked accounts - Find the network
  5. Update rules - Close the registration gap

Mass Signup Attack

  1. Enable rate limiting - Slow the attack
  2. Add friction - CAPTCHA, phone verification
  3. Review recent signups - Find and remove fakes
  4. Block infrastructure - IPs, devices, email patterns

Prevention Checklist

  • CAPTCHA on registration
  • Email verification required
  • Disposable email domains blocked
  • Device fingerprinting enabled
  • Rate limiting on signup endpoints
  • Phone verification for high-value actions
  • VoIP/virtual number detection
  • Account linking across devices
  • Promo redemption limits per device

Next Steps

Preventing fake accounts?

  1. Add device fingerprinting - Catch repeat registrations
  2. Implement email verification - Block disposables
  3. Set up rate limiting - Stop mass signups

Detecting fake accounts?

  1. Check registration signals - Score risk at signup
  2. Analyze email patterns - Catch multi-accounting
  3. Link accounts - Find networks

Responding to fake accounts?

  1. Follow response playbook - Block and revoke
  2. Find linked accounts - Catch the full network
  3. Update prevention - Close gaps