By NHI Mgmt Group Editorial TeamBased on SumSub: “iGaming Fraud Insights – ICE Barcelona Part 2” (June 8, 2026)

TL;DR: Fraud in iGaming is reshaping operator growth, regulatory pressure and investor due diligence, with the SumSub-hosted panel at ICE Barcelona highlighting tension between acquisition and prevention, unlicensed operators, Brazil’s evolving framework, and World Cup-driven fraud angles. The core issue is that fraud is no longer a side control problem, it is now a market and governance constraint.


At a glance

What this is: This is a panel recap on how iGaming fraud is affecting growth, regulation and investment decisions, with AI-driven abuse and event-linked fraud among the risks discussed.

Why it matters: It matters because operator identity, fraud and compliance teams have to govern acquisition, due diligence and player abuse as one connected control problem rather than separate functions.


Context

iGaming fraud is no longer just a loss-prevention issue. In this discussion, the focus is on how fraud now changes growth strategy, regulatory scrutiny and capital allocation in a market where player acquisition and abuse often collide.

The governance gap is that operators cannot treat fraud as a downstream exception. When unlicensed competitors, bonus abuse, multi-accounting and AI-driven abuse all sit in the same operating model, identity, onboarding and due-diligence controls become part of market resilience.


Key questions

Q: What breaks when iGaming operators prioritise acquisition over fraud prevention?

A: Friction-free growth can create a control environment where multi-accounting, bonus abuse and payment abuse scale faster than review can catch them. When acquisition and fraud teams work separately, the business may optimise conversion while quietly expanding loss, regulatory exposure and investor risk. The result is not just more fraud, but weaker confidence in the operator’s overall governance.

Q: Why does fraud due diligence matter for iGaming investors and partners?

A: Because fraud maturity is now part of business quality, not just security quality. Investors and partners need to know whether an operator can detect abuse, manage licensed and unlicensed market pressure, and respond to escalation without relying on manual heroics. Weak fraud governance can distort valuation, increase compliance risk and undermine trust in reported growth.

Q: What are the signs that bonus abuse and multi-accounting are outpacing controls?

A: Look for repeated account creation patterns, unusual referral or promotion uptake, rapid value extraction after onboarding and inconsistent identity behaviour across linked accounts. If those signals rise during campaigns or events while review queues stay flat, the control set is likely too static for the abuse pattern.

Q: How should operators respond when major events create new fraud angles?

A: Treat the event as a risk multiplier, not just a demand spike. Increase monitoring thresholds, validate identity and payment patterns more aggressively, and compare event-period behaviour with normal baselines. The main goal is to distinguish legitimate surge from coordinated abuse before losses compound.


Technical breakdown

Player acquisition and fraud prevention are now coupled controls

In iGaming, acquisition and abuse prevention often pull in opposite directions. Lower-friction onboarding can improve conversion, but it also widens exposure to bonus abuse, multi-accounting and synthetic behaviour. That makes fraud controls part of the customer journey architecture, not just a back-office fraud function. The technical challenge is to verify identity, behavioural integrity and account uniqueness without destroying conversion. For operators, the control question is not whether to block fraud, but where to place friction so it reduces abuse without collapsing growth.

Practical implication: tune onboarding, verification and step-up checks around abuse thresholds instead of applying a single blanket friction model.

Why unlicensed operators distort the trust boundary

Unlicensed operators change the fraud equation because they sit outside the same compliance, monitoring and recourse structures as regulated firms. That weakens market-wide trust signals and can make it harder for players, partners and investors to distinguish legitimate scale from unsafe growth. In practice, this creates a broader governance problem: fraud analysis is no longer just about bad accounts, but about the integrity of the operating environment itself. When the market includes actors that do not follow the same rules, due diligence has to include licensing status, control maturity and the credibility of abuse handling.

Practical implication: include licensing and control maturity checks in partner, acquisition and counterparty due diligence, not only in customer risk scoring.

AI-driven abuse expands the fraud surface beyond familiar playbooks

AI-driven threats matter because they can industrialise behaviours that once depended on manual effort, such as scaling account creation, evading pattern-based detection or coordinating abuse across multiple touchpoints. That does not make every automated attack autonomous in the strict identity sense, but it does raise the speed and variability of fraud operations. Operators that rely only on static rules will miss the shift from isolated suspicious events to adaptive abuse campaigns. The control gap is not just detection volume, but detection adaptability across identity, behaviour and payment flows.

Practical implication: use layered anomaly detection and human review for abuse patterns that adapt faster than rules can be tuned.


NHI Mgmt Group analysis

Fraud has become a governance variable, not only an operational loss vector. The article shows that iGaming fraud now influences growth, regulatory response and investor diligence at the same time. That changes how identity and fraud programmes should be framed, because control maturity is now part of market credibility. The practitioner conclusion is that fraud operations must be owned as a board-level trust issue, not a narrow detection function.

The tension between acquisition and prevention is the real control design problem. Operators do not fail because they lack fraud tools alone. They fail when onboarding, bonus policy and risk scoring are optimised in silos and create openings for multi-accounting, bonus abuse and fast-moving abuse patterns. The implication is that identity signals, account creation logic and abuse controls need to be designed together.

Unlicensed competition distorts the governance baseline. When some operators are outside the same regulatory and assurance expectations, regulated teams compete against a market signal that rewards speed over control depth. That makes licensing, due diligence and abuse handling part of the same trust model. The practitioner takeaway is that fraud governance increasingly has to be evaluated as an ecosystem problem, not just an internal control set.

Event-linked abuse: seasonal peaks such as the World Cup create concentrated fraud opportunity because high-volume attention and betting demand compress review windows. The article points to sports events as moments when fraud angles expand, which means rate changes, novelty and volume spikes can all mask abuse. For practitioners, the lesson is that seasonal surge planning has to include fraud governance, not just capacity planning.

From our research library:

What this signals

iGaming fraud now functions as a market-shaping control issue. For operators, that means abuse handling can no longer sit only inside fraud operations or payments teams. It has to inform product design, player onboarding, partner assessment and regulatory response because the same weak points create loss, compliance pressure and trust erosion.

Bonus abuse, multi-accounting and event-linked spikes are governance signals, not edge cases. When those patterns increase, they show that controls are being tested at the exact points where revenue and identity assurance meet. Teams should treat those signals as evidence that risk ownership is too fragmented across growth, compliance and fraud functions.


For practitioners

  • Strengthen onboarding friction points Insert verification and step-up checks where account creation, bonus enrolment and payment behaviour indicate abuse risk. The goal is to slow multi-accounting and bonus abuse without creating unnecessary conversion loss.
  • Tie fraud controls to due diligence Include control maturity, licensing status and abuse-response capability in partner and investment reviews. Fraud exposure should affect commercial decisions before capital is committed.
  • Tune seasonal fraud monitoring Raise scrutiny during major sports events and other volume spikes, when coordinated abuse can hide inside legitimate traffic surges. Review thresholds should change with the event calendar.
  • Expand detection beyond static rules Use behavioural signals, anomaly review and analyst triage to catch abuse that adapts faster than fixed policy logic. Static rule sets are not enough when fraud actors change tactics quickly.

Key takeaways

  • iGaming fraud is now shaping how operators grow, how they are regulated and how they are valued by investors.
  • The article ties the risk to familiar abuse patterns such as bonus abuse, multi-accounting, unlicensed operators and event-driven exploitation.
  • Operators need to align onboarding, due diligence and fraud response so that commercial growth does not outrun trust controls.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKTA0006 — Credential AccessFraud abuse in iGaming often depends on account compromise and identity misuse.
Recommendation — Map abuse patterns to credential access behaviours and strengthen detection around account takeover indicators.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsPlayer and partner access decisions shape how fraud controls enforce trust boundaries.
Recommendation — Apply PR.AA-05 to align account permissions and entitlement checks with fraud risk signals.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementAuthenticator lifecycle controls matter where account reuse and abuse depend on weak credential governance.
Recommendation — Use IA-5 to govern credential issuance, renewal and revocation for high-risk account flows.
CIS Controls v8CIS-5 — Account ManagementAccount sprawl and weak lifecycle control are central enablers for multi-accounting and abuse.
Recommendation — Use CIS-5 to tighten account lifecycle governance and remove unused or suspicious accounts promptly.

Key terms

  • Multi-accounting: Multi-accounting is the practice of one actor creating or controlling multiple identities to evade limits, gain incentives, or hide coordinated behaviour. In betting and fraud environments, it matters because the platform may see each account as separate unless identity signals are correlated across devices, payments, and sessions.
  • Bonus Abuse: Bonus abuse is the exploitation of promotional incentives through repeated sign-ups, account farming or coordinated behaviour that drains value from the platform. It is not a single tactic but a pattern of identity misuse that distorts acquisition economics and weakens the trust model behind customer growth.
  • Fraud Due Diligence: Fraud due diligence is the evaluation of an operator, partner or investment target for fraud exposure, control maturity and governance quality. In practice, it looks beyond headline growth to ask whether abuse patterns, licensing status and response capability are credible under real operating pressure.
  • Event-Driven Fraud: Event-driven fraud is a scam pattern that intensifies around major announcements, technical transitions, or market-moving moments. The fraudster uses public attention and uncertainty to manufacture urgency. In crypto, this often means fake upgrade instructions, recovery offers, or investment prompts that sound time-sensitive and credible.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org