Skip to main content

Account Fraud

TL;DR
  • Account fraud = Fake or malicious accounts created on your platform
  • Types: Bot signups, referral abuse, multi-accounting, fake reviews
  • Creates infrastructure for future fraud and policy abuse
  • Detect via: Device fingerprinting, email analysis, behavioral patterns
  • Prevent with: CAPTCHA, email verification, phone verification, rate limiting

Fraudulent accounts created on your platform for abuse.

Definition

Account fraud occurs when someone creates fake or abusive accounts on your website or app. These accounts become infrastructure for other fraud types: promo abuse, refund fraud, fake reviews, and organized attacks.

Why Fake Accounts Matter

They EnableHow
Promo abuseNew account = new discount
Referral fraudSelf-refer across accounts
Velocity evasionSpread activity across accounts
Card testingDisposable accounts for testing
Fake reviewsBoost or attack products
Resale fraudBulk buying limited items

Common Patterns

Bot Signups

Automated account creation at scale:

  • Hundreds of accounts in hours
  • Similar registration patterns
  • Disposable email domains
  • Generic or random usernames

Referral Fraud

Gaming referral programs:

  • Self-referral across accounts
  • "Referral farms" with fake accounts
  • Quick signup → claim reward → abandon

Multi-Accounting

One person, multiple identities:

  • Evade account-level limits
  • Stack promotions
  • Bypass bans or restrictions
  • Separate fraud activity from "real" account

Fake Review Fraud

Manufactured social proof:

  • Paid review rings
  • Competitor sabotage
  • Boosting new products artificially

Detection Signals

Registration Red Flags

SignalRisk Level
Disposable email domainHigh
Email pattern matches prior fraudHigh
Device seen on multiple accountsCritical
Registration velocity (time to complete)Medium
Phone number from VoIP providerMedium
Similar usernames/passwordsHigh

Email Analysis

PatternWhat It Suggests
john+1@gmail, john+2@gmailMulti-accounting
Random string @domain.comBot-generated
Domain age < 30 daysRecently created for fraud
Known disposable domainTemporary account
Email never used elsewhereFabricated for this account

Device Signals

Device fingerprinting reveals:

  • Same device across multiple accounts
  • Emulator or automation tools
  • VPN/proxy usage
  • Device recently associated with fraud

Behavioral Indicators

BehaviorRisk
No browsing before checkoutScripted behavior
Immediate promo redemptionPromo farming
Referral link used instantlySelf-referral
Never returns after signupThrowaway account
Review posted without purchaseFake review ring

Prevention Strategies

At Registration

ControlWhat It Stops
CAPTCHABot signups
Email verificationDisposable emails
Phone verificationMulti-accounting
Rate limitingMass registration
Device fingerprintingRepeat registrations

Email Verification Best Practices

LevelMethodStops
BasicSend confirmation linkFake emails
MediumCheck domain reputationDisposable domains
StrongEmail risk scoringFraud-associated emails

Phone Verification

CheckWhy
SMS verificationTies to real phone
VoIP detectionBlock virtual numbers
Phone line typeMobile vs. landline vs. VoIP
Phone velocitySame number, many accounts

Device Controls

ControlWhat It Catches
Device fingerprintingSame device, different accounts
Emulator detectionAutomated fraud tools
VPN detectionHidden location
Device reputationKnown fraud devices

Account Linking

Connect related accounts using:

AttributeWhat It Links
Device fingerprintSame device = same person
IP addressSame network (less reliable)
Payment methodSame card across accounts
Shipping addressSame destination
Behavioral patternsSimilar navigation, timing

Response Playbook

Confirmed Fake Account

  1. Block the account – Prevent further activity
  2. Revoke benefits – Cancel promos, referral rewards
  3. Blacklist identifiers – Device, email, phone
  4. Check for linked accounts – Find the network
  5. Update rules – Close the registration gap

Mass Signup Attack

  1. Enable rate limiting – Slow the attack
  2. Add friction – CAPTCHA, phone verification
  3. Review recent signups – Find and remove fakes
  4. Block infrastructure – IPs, devices, email patterns

Prevention Checklist

  • CAPTCHA on registration
  • Email verification required
  • Disposable email domains blocked
  • Device fingerprinting enabled
  • Rate limiting on signup endpoints
  • Phone verification for high-value actions
  • VoIP/virtual number detection
  • Account linking across devices
  • Promo redemption limits per device

Next Steps

Preventing fake accounts?

  1. Add device fingerprinting – Catch repeat registrations
  2. Implement email verification – Block disposables
  3. Set up rate limiting – Stop mass signups

Detecting fake accounts?

  1. Check registration signals – Score risk at signup
  2. Analyze email patterns – Catch multi-accounting
  3. Link accounts – Find networks

Responding to fake accounts?

  1. Follow response playbook – Block and revoke
  2. Find linked accounts – Catch the full network
  3. Update prevention – Close gaps