By NHI Mgmt Group Editorial TeamDomain: Identity Beyond IAMSource: FingerprintPublished August 3, 2026

TL;DR: Ridesharing fraud is structurally two-sided, with driver and rider abuse both exploiting identity controls that stop at onboarding while device intelligence links repeated account creation, profile rental, and referral farming across sessions, according to Fingerprint. The core lesson is that persistent device signals add a missing governance layer below identity verification, where account bans alone cannot stop re-entry or preserve regulatory due diligence.


At a glance

What this is: Fingerprint’s analysis shows that ridesharing fraud is driven by a two-sided trust problem, where driver and rider abuse exploit controls that only validate identity at onboarding.

Why it matters: It matters to IAM and fraud practitioners because identity verification alone cannot govern persistence, re-entry, and account cycling without a device-level trust layer.

By the numbers:

👉 Read Fingerprint’s analysis of ridesharing fraud, device intelligence, and re-entry risk


Context

Ridesharing fraud is an identity governance problem as much as a fraud problem, because the platform must trust two interacting populations with different incentives and different failure modes. Basic onboarding verification answers who someone was at a single moment, but it does not answer whether the same person, device, or operating pattern returns later under a new account.

That gap matters because account-level enforcement is easy to evade when bad actors can re-enter through new SIM cards, fresh email addresses, or rented profiles. Device-level persistence, cross-session linkage, and lifecycle controls become the practical bridge between identity verification, fraud detection, and regulatory accountability. This is typical of high-growth marketplace platforms, where scale often arrives before governance catches up.


Key questions

Q: How should security teams stop banned users from re-entering through new accounts?

A: They should make re-entry a lifecycle problem, not a one-time identity check. A banned user can swap email addresses, SIM cards, or even use another account holder’s profile, so the control must evaluate device history, session continuity, and linked account behaviour before allowing access. Without persistence data, bans remain easy to route around.

Q: Why do identity checks fail to stop referral and account cycling fraud?

A: Identity checks usually confirm who someone is at signup, not whether the same device keeps creating fresh accounts later. Fraudsters exploit that gap by rotating emails and phone numbers while reusing the same hardware. The result is that account-level uniqueness looks intact even when the underlying device is driving repeated abuse.

Q: What signals show that a marketplace fraud control is too blunt?

A: A control is too blunt when it blocks legitimate users from shared devices, common IP ranges, or high-risk regions while fraud still gets through with minor changes in account details. That usually means the policy relies on static identity fields instead of persistent behavioural or device-level evidence. Precision improves when the platform scores continuity, not just origin.

Q: Who is accountable when rented profiles or fake rider accounts create losses?

A: Accountability sits with the platform as well as the individual user because the platform controls onboarding, monitoring, and enforcement. In regulated environments, repeated re-entry, weak due diligence, and poor lifecycle controls can turn a fraud issue into a compliance issue. The practical test is whether the platform can show it detects and acts on repeat device history.


Technical breakdown

Why onboarding identity checks miss re-entry fraud

Document checks, selfie verification, and liveness detection are point-in-time controls. They can prove that an applicant matched a document at signup, but they do not preserve continuity across later sessions, device changes, or account handoffs. In a marketplace with weak friction and strong economic incentives, that means a banned driver or referral fraudster can return through a new email, new SIM, or borrowed account while the original verification record still looks clean. The failure is not in identity proofing itself, but in assuming proofing equals lifecycle assurance.

Practical implication: add persistent device and session linkage to onboarding decisions so re-entry attempts are evaluated against history, not just the current claim.

How device intelligence changes fraud detection

Device intelligence works by creating a durable signal from hardware, app behaviour, and session history that survives account churn. That lets fraud teams connect multiple signups, repeated credits, or account rentals back to the same physical device even when emails and phone numbers change. In effect, the device becomes the stable anchor for policy decisions. This is especially useful in two-sided marketplaces because the same platform has to defend both supply-side trust and demand-side abuse without adding visible friction to legitimate users.

Practical implication: use device history as a risk input at onboarding, during session changes, and before payout or referral release.

Why two-sided marketplaces need a dual control model

Ridesharing platforms face two different fraud economies at once. Driver-side abuse can include profile rental, deactivated-user re-entry, and account sharing, while rider-side abuse tends toward multi-accounting, referral farming, and promo extraction. These threats do not share the same incentives or controls, so a single fraud rule set will always be incomplete. The control model must separate identity proofing from persistence controls and treat both sides as linked trust domains rather than one generic user base.

Practical implication: design separate policy paths for driver and rider fraud, with different thresholds, evidence, and escalation logic for each.


NHI Mgmt Group analysis

Device persistence is the missing governance layer in marketplace fraud. Fraud teams often assume that stronger onboarding identity checks solve the problem, but ridesharing shows the real gap is continuity after signup. A device can survive SIM swaps, email churn, and account recycling, which makes it the more reliable anchor for lifecycle governance. The practitioner conclusion is straightforward: if the platform cannot recognise re-entry, it cannot enforce bans.

Two-sided marketplaces need separate trust models for supply and demand. Driver fraud and rider fraud are not mirror images. One undermines safety, supply reliability, and regulatory standing, while the other distorts incentives, refunds, and growth metrics. Treating them as a single fraud category creates blind spots in both policy design and response. The practitioner conclusion is to split controls by actor type and risk economics.

Persistent device linkage is a named control concept that closes the re-entry gap. This article makes the case for a control architecture that remembers the device, not just the account. That concept matters because account bans are only durable if they follow the actor across sessions and identities. For identity and fraud programmes, this is the difference between one-time verification and real lifecycle governance. The practitioner conclusion is to treat device intelligence as an enforcement plane, not an add-on metric.

Identity verification and fraud governance are converging, but they are not the same discipline. Verification answers whether a user presented believable evidence at the door. Fraud governance decides whether that same actor should be trusted tomorrow, on another device, or in another account. The distinction becomes critical in regulated marketplaces where due diligence and traceability matter. The practitioner conclusion is to align identity proofing with ongoing risk monitoring.

Growth metrics become more trustworthy only when fraud suppression is precise. Broad rule-based blocking can reduce abuse, but it can also suppress legitimate users in high-risk markets and distort acquisition performance. The article shows why precision matters: a control that cannot distinguish shared-device abuse from genuine onboarding will damage both trust and growth. The practitioner conclusion is to calibrate controls around behaviour and device continuity, not blunt origin checks.

What this signals

Device continuity is becoming the practical analogue of lifecycle governance in fraud-heavy marketplaces. The lesson for identity and fraud programmes is not simply to collect more signals, but to preserve continuity across sessions so bans, disputes, and payout controls are enforceable over time. Where identity proofing is a gate, device history becomes the memory. Teams can map that thinking to the NHI Lifecycle Management Guide and the control logic behind persistent access review.

Marketplace fraud control now depends on distinguishing actor classes as much as detecting bad behaviour. A platform that treats driver abuse, rider abuse, and shared-device re-entry as one problem will keep overcorrecting in one area while missing another. The operating model should look more like segmented governance than a single fraud stack. That is the same architectural shift identity teams make when they stop treating all identities as interchangeable.


For practitioners

  • Implement persistent device linkage for all account lifecycle events Tie onboarding, session changes, payout approval, and re-verification to a durable device history so re-entry attempts are compared with prior behaviour, not only with the current signup record.
  • Separate driver and rider fraud policies Create distinct rule sets for supply-side and demand-side abuse so profile rental, deactivated-user re-entry, multi-accounting, and referral farming are scored against different thresholds and escalation paths.
  • Gate high-risk promotions on uniqueness signals beyond email and phone Require device history, prior payout behaviour, and account linkage checks before releasing referral credits or first-trip bonuses, especially in markets with repeated promo abuse.
  • Use lifecycle-based review for banned-user re-entry When a previously deactivated driver or rider attempts to return, evaluate the device, session pattern, and linked accounts before allowing completion of the new onboarding flow.
  • Calibrate false-positive thresholds by market Measure how shared devices, prepaid SIM usage, and local onboarding patterns affect legitimate users so fraud controls do not block clean customers in high-risk regions.

Key takeaways

  • Ridesharing fraud exposes a lifecycle gap, not just an onboarding gap, because account bans are easy to evade when the platform cannot recognise the returning device.
  • The most useful evidence in this article is the distinction between driver-side and rider-side abuse, which shows why a single fraud policy creates both blind spots and false positives.
  • Persistent device intelligence is the control concept that turns identity verification into enforceable governance across sessions, re-entry attempts, and payout decisions.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while GDPR define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-63SP 800-63AIdentity proofing at onboarding is central, but insufficient for lifecycle fraud controls.
GDPRArt.32Device intelligence often processes personal data and must be secured proportionately.
NIST CSF 2.0PR.AC-4The article’s control gap is access continuity and account lifecycle enforcement.
NIST SP 800-53 Rev 5IA-5Re-entry fraud exposes weak authenticator and account lifecycle management.
CIS Controls v8CIS-5 , Account ManagementAccount cycling and profile rental are account management failures at scale.

Apply CIS-5 to tighten account creation, suspension, and recovery paths for high-risk marketplace users.


Key terms

  • Device Intelligence: Device intelligence is the practice of interpreting signals from a device to assess whether a session or transaction is likely legitimate. It goes beyond fingerprinting by combining device context with behavioural, identity, and payment evidence to support a risk decision.
  • Profile Rental: Profile rental is when one verified user account is used by another person who could not or should not pass verification. In marketplace environments, the account may appear legitimate while the actual operator, history, and accountability are hidden from the platform.
  • Referral Farming: Referral farming is the repeated creation of new accounts to collect promotional credits, bonuses, or payouts at scale. It is a form of account cycling that exploits growth incentives and usually requires persistence signals beyond email or phone verification to detect reliably.
  • Re-entry Gap: The re-entry gap is the control failure that allows a previously banned or deactivated actor to return through a new account without being recognised. It appears when identity proofing is treated as a one-time event rather than a lifecycle governance problem spanning devices, sessions, and linked accounts.

What's in the full article

Fingerprint's full research covers the operational detail this post intentionally leaves for the source:

  • The market-specific fraud patterns behind tenant drivers, profile rental, and referral farming.
  • How device intelligence is applied inside onboarding, session monitoring, and payout gating workflows.
  • The way persistent device signals reduce false positives in high-risk markets while preserving growth.
  • Why the compliance argument changes when platforms are treated as financial infrastructure.

👉 The full Fingerprint article covers driver-side fraud, rider-side abuse, and device-level detection examples.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, identity lifecycle, and secrets management. It gives practitioners a structured way to connect persistent trust signals to access decisions across your programme.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 15, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org