By NHI Mgmt Group Editorial TeamDomain: Identity Beyond IAMSource: SiftPublished July 31, 2026

TL;DR: Akamai reported AI-powered bot traffic increased 300% in a year, while Sumsub found multi-step identity fraud rose from 10% of attacks in 2024 to 28% in 2025, showing that signup fraud is becoming more automated and coordinated, according to Sift's analysis. Single checks no longer hold up against fraud rings that combine device, network, behavioral, and identity signals.


At a glance

What this is: This is an analysis of why fake account detection now requires layered signal analysis across registration and post-signup behavior.

Why it matters: It matters to identity and IAM practitioners because fraudulent signups distort trust decisions, weaken verification models, and create downstream abuse that can affect account governance, access controls, and lifecycle management.

By the numbers:

👉 Read Sift's analysis of fake account detection and signup fraud signals


Context

Fake account detection sits at the boundary between identity verification and fraud prevention. The core governance problem is that registration flows are now easy to automate, easy to disguise, and easy to chain into larger abuse campaigns, so a single check rarely provides enough confidence to separate legitimate users from manufactured ones.

For identity programmes, the intersection matters because bad signups do not stop at the login screen. They can distort verification outcomes, pollute trust scores, and feed account takeover, promo abuse, and ban evasion. That makes fake account detection a lifecycle problem as much as an onboarding problem, especially where self-serve access is the default.


Key questions

Q: How should security teams stop fake account creation at sign-up?

A: They should add layered friction that raises the cost of bulk registration without breaking legitimate users. Combine device reputation, behavioural analysis, identity verification, and step-up checks at the point of enrolment. The goal is to make account creation expensive enough that industrialised fraud loses scale, while preserving a predictable journey for real customers.

Q: Why do fake accounts remain hard to stop after identity verification passes?

A: Because verification only answers whether a document, selfie, or contact point looks valid. It does not prove the account is legitimate in context. Fraudsters can pass one check with stolen or synthetic data while still using the same device, network, or behaviour patterns across many accounts.

Q: What do teams get wrong about fake profile detection?

A: They often focus on removing bad accounts after reports arrive, instead of measuring how trust was built in the first place. Fraud prevention has to look at early intent signals, not just obvious policy violations. If the platform only reacts after harm, it is already operating behind the attacker’s timeline.

Q: When should organisations escalate a signup for review?

A: Escalate when several moderate-risk signals line up, such as repeated device fingerprints, proxy-heavy traffic, unusually fast form completion, or multiple accounts sharing the same payment or shipping details. The point is to identify coordinated patterns, not punish one unusual field in isolation.


Technical breakdown

Why single-signal signup checks fail

Fake account detection fails when organisations treat one control, such as CAPTCHA, email domain checks, or selfie verification, as a sufficient test of legitimacy. Fraudsters now combine synthetic identities, disposable contact points, proxy networks, and automation to make each individual signal look normal. The detection problem is therefore probabilistic, not binary. The useful question is not whether one field looks valid, but whether the full registration event fits a believable identity pattern across device, network, and behaviour.

Practical implication: teams should replace single-pass approval rules with multi-signal risk scoring.

How device, network, and behavioural signals work together

Device intelligence identifies repeated physical or emulated environments across supposedly unique signups. Network reputation highlights data centre ranges, residential proxy exit nodes, and other traffic sources that do not fit legitimate customer acquisition patterns. Behavioural signals add another layer by measuring interaction speed, field order, mouse movement, and other timing cues that often expose scripted activity. None of these signals is decisive on its own, but together they create a more reliable picture of whether a signup was created by a person, a bot, or a fraud workflow.

Practical implication: build correlation logic that weighs signals together instead of scoring them in isolation.

Why post-signup monitoring matters as much as signup screening

A common governance mistake is treating registration as the only decision point. In practice, a fake account may look clean at creation and only reveal itself later through impossible velocity, shared payment or shipping data, or repeated interactions from the same device cluster. This is where continuous assessment matters. Risk that was acceptable at signup can become unacceptable as soon as the account begins behaving like part of a ring, a trial abuse operation, or a credential harvesting campaign.

Practical implication: extend detection beyond onboarding and re-score accounts as new signals arrive.


Threat narrative

Attacker objective: The attacker’s objective is to create believable accounts at scale that can be monetised, reused, or leveraged for downstream abuse without triggering early controls.

  1. Entry begins with automated signup attempts that use synthetic identities, disposable emails, virtual phone numbers, or AI-generated verification artifacts to pass the first gate.
  2. Escalation follows when the same infrastructure reuses devices, proxy ranges, payment instruments, or shipping details across many accounts, making the fraud ring visible in aggregate.
  3. Impact occurs when fraudulent accounts are used for promo abuse, counterfeit listings, review manipulation, trial extension, or later account takeover activity.

NHI Mgmt Group analysis

Layered signal analysis is now the minimum viable control for signup trust. Account creation fraud has moved beyond simple bot filtering into coordinated identity abuse that blends device spoofing, network masking, and synthetic data. That means trust decisions must be based on correlated evidence, not one-off checks that fraudsters can game. For practitioners, the governance shift is from point validation to continuous risk evaluation.

Fraud rings exploit the verification boundary between identity and access. Fake account creation is not just a fraud operations issue when the same account primitives later feed entitlement, promotion, and lifecycle abuse. Identity verification can confirm a document or selfie, but it does not by itself establish whether the account belongs in the environment. Practitioners should treat onboarding assurance and access governance as connected controls, not separate problems.

Behavioral velocity is the clearest named concept here: the speed and coordination of signups reveal what individual fields hide. When many accounts share the same device fingerprint, timing pattern, or linked data, the pattern matters more than any one validated attribute. This is especially relevant for marketplaces and SaaS platforms where fake users distort both trust and product metrics. Practitioners should design controls that detect cluster behaviour, not just field-level validity.

Dynamic friction is better governance than uniform friction. Forcing every user through the same verification path damages conversion and still leaves sophisticated fraud untouched. Risk-based escalation lets low-risk users move quickly while applying extra checks only where the signal set justifies it. That is the practical middle ground between open signup and overblocking, and it is the right operational model for mature identity and fraud programmes.

Fake account detection should be managed as a lifecycle control, not a signup feature. The strongest fraud programmes do not stop at admission decisions. They re-evaluate accounts as new signals appear, because fraud often becomes visible only after the first interaction, not before it. Practitioners should align this with lifecycle governance so that suspicious accounts can be throttled, reviewed, or closed before they become durable abuse channels.

What this signals

Verification trust gap: the biggest programme risk is assuming that a passed onboarding check means the account is trustworthy for its entire lifecycle. In reality, fraud teams need to connect identity verification, device intelligence, and ongoing behaviour analysis so that trust can be revoked when later signals contradict the initial decision.

Where fake account creation intersects with IAM, the lesson is simple: account admission and account governance cannot be separated cleanly. Practitioners should watch for repeated device clusters, proxy-heavy traffic, and identity reuse patterns, then route those cases into controls aligned to the NIST Cybersecurity Framework 2.0 and NHI Lifecycle Management Guide where account lifecycle decisions are involved.


For practitioners

  • Correlate registration signals across the full event Combine device fingerprinting, IP reputation, behavioural timing, email risk, and phone risk into one decision path rather than accepting any single clean signal as proof of legitimacy.
  • Apply dynamic friction by risk tier Send low-risk users through quickly and trigger extra verification only when the aggregated signal profile crosses an agreed threshold, so false positives do not become a growth problem.
  • Re-score accounts after onboarding Keep evaluating accounts after signup using post-registration signals such as shared infrastructure, repeated sessions, and unusual usage bursts, because many fake accounts only reveal themselves later.
  • Use cluster analysis for fraud rings Look for repeated devices, payment instruments, shipping addresses, and proxy ranges across apparently unrelated accounts, then route clusters to analyst review instead of judging each account alone.
  • Connect fraud review to identity governance Feed high-confidence fake account cases into account lifecycle controls so suspicious identities can be throttled, reviewed, or removed before they generate more abuse.

Key takeaways

  • Fake account detection now requires correlated evidence across device, network, behavioural, and identity signals.
  • Fraudsters increasingly use AI, synthetic identities, and proxy infrastructure to make each individual signup look legitimate.
  • The strongest control model is continuous, risk-based, and linked to account lifecycle governance rather than a one-time registration gate.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63 and NIST CSF 2.0 set the technical controls, while GDPR define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-63SP 800-63AIdentity proofing and enrollment are central to fake account detection.
NIST CSF 2.0PR.AC-1Authentication and identity management map directly to signup trust decisions.
GDPRArt.32Fraud signals and identity data handling can involve personal data protections.

Limit collection to what is needed, secure identity data, and document processing safeguards for fraud detection under Art.32.


Key terms

  • Duplicate Account Detection: Duplicate account detection is the process of identifying when one person or fraud ring controls multiple player accounts. The strongest versions connect device data, payment methods, behavioural similarity, and referral relationships so teams can stop repeat abuse before bonuses are converted into losses.
  • Synthetic Identity: A synthetic identity is a software-based actor that can authenticate, request access, and execute actions without being a human user. In practice, this includes AI agents, bots, service accounts, tokens, and other machine identities that need clear ownership, scope, and revocation.
  • Dynamic Friction: Dynamic friction is the practice of adding more user challenge only when risk rises. Rather than forcing every user through the same experience, the system adapts its response to context, which helps preserve conversion while still reducing fraud exposure in higher-risk scenarios.
  • Device fingerprint: A bundle of client signals used to recognise the same browser, app, or device across sessions. It often includes user agent, platform traits, and other stable characteristics. For impossible travel, fingerprinting helps separate a real attacker on a different device from a user switching networks.

What's in the full article

Sift's full post covers the operational detail this analysis intentionally leaves for the source:

  • Signal-by-signal breakdowns for device, network, email, phone, and behavioural scoring during signup
  • Operational examples of Dynamic Friction, Workflows, and Queue-based analyst review in fraud operations
  • How the Sift Score changes as new information arrives after registration, not just at the point of signup
  • Marketplace and SaaS-specific abuse patterns, including trial fraud, seller fraud, and review manipulation

👉 The full Sift post covers layered detection logic, fraud-ring patterns, and operational workflow detail

Deepen your knowledge

NHI Mgmt Group's NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, secrets management, and identity lifecycle. It helps security practitioners connect identity controls to the broader governance decisions their programmes depend on.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 1, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org