TL;DR: Fraud rings can turn one playbook into dozens of accounts, and Sift says more than 8% of global account creation attempts were flagged as suspected digital fraud in 2025, showing why single-account review misses coordinated abuse. The real control challenge is linking device, network, payment, and behavioural signals before fake accounts are used for promotions, listings, or takeover.
At a glance
What this is: This is an analysis of how marketplace fraud rings use multi-accounting and which linked signals expose coordinated fake accounts.
Why it matters: It matters because Trust and Safety and IAM-adjacent teams need to move from isolated account checks to relationship-based detection across identity, device, and payment signals.
By the numbers:
- 8% of account creation attempts globally were flagged, re flagged as suspected digital fraud in 2025, an 18% jump from the year before.
- Sift scores users from 1 to 100, where 1 indicates a trustworthy user and 100 indicates likely fraud.
👉 Read Sift's analysis of how to detect fake accounts and multi-accounting
Context
Multi-accounting is a fraud pattern in which one person or ring creates many accounts that appear independent but share hidden links. The security gap is that most controls still evaluate a signup in isolation, while the real risk sits in relationships across device, payment, network, and behaviour patterns. For identity and fraud teams, the question is not whether a single account looks valid, but whether the account belongs to a coordinated identity cluster.
In marketplace environments, incentives such as referral credits, first-order discounts, and seller bonuses make account creation itself the attack surface. That pushes this topic into the overlap between fraud prevention, identity verification, and access governance, because a fake account often becomes a reusable identity primitive for later abuse. The pattern described here is typical of modern marketplace fraud rather than an edge case.
Key questions
Q: How can teams reduce multi-accounting without blocking legitimate users?
A: Use relationship analysis across devices, payment methods, and behaviour so the platform can detect coordinated abuse without relying on a single brittle rule. Then calibrate thresholds against real customer journeys and review false positives regularly. The goal is targeted friction for risky patterns, not blanket restrictions.
Q: Why do fake accounts evade single-account fraud controls?
A: Single-account controls miss the relationship that defines multi-accounting. Fraud rings can vary names, emails, and phones while preserving the same device, wallet, or IP cluster. Once those hidden links are visible, a set of ordinary-looking accounts becomes a clearly coordinated abuse pattern.
Q: How do you know if account fraud detection is actually working?
A: Look for fewer linked rings operating over time, faster detection of new evasion tactics, and a stable false-positive rate for legitimate users. If analysts are only banning individual accounts, the programme may be busy but still ineffective because the broader cluster remains intact.
Q: What should Trust and Safety teams do when one account looks suspicious?
A: Investigate the surrounding identity cluster before deciding on a single-account action. Check whether the same device, payment method, address, or behaviour appears elsewhere, because the real threat is often a ring that can replace one account quickly. Containment should focus on the shared pattern, not just the latest signup.
Technical breakdown
How multi-accounting differs from ordinary account fraud
Multi-accounting is not just fake identity creation. It is coordinated account reuse at scale, where each profile is designed to pass isolated checks while the fraud ring exploits platform incentives across multiple accounts. The key technical distinction is that the threat is relational: different names, emails, and phone numbers can still map to the same device, payment instrument, or behavioural pattern. That means a valid-looking signup can still be part of a larger abuse cluster if the backend scoring model only inspects a single identity record.
Practical implication: move detection from account-level review to cluster-level correlation across identity attributes and shared infrastructure signals.
Why device, network, and payment correlation exposes fake account clusters
Device fingerprints, browser configuration, IP geography, and payment reuse are harder to vary consistently than names or inboxes. Fraud rings can rotate visible fields, but they often leave stable technical residues such as screen resolution, hardware traits, wallet reuse, or a narrow IP range. Link analysis turns those residues into a graph, which is far more useful than checking each field independently. This is why isolated weak signals become decisive when they are combined into a single relationship view, especially when the ring uses semi-automated scripts or repeatable human workflows.
Practical implication: build graph-based correlation that joins device, network, and payment signals before deciding whether an account is legitimate.
Real-time scoring and dynamic friction are the control layer
Detection is only useful when it changes the next step in the user journey. Real-time scoring at signup is necessary but insufficient, because many fraud rings behave normally until first listing, first payout, or password reset. Dynamic friction provides the response layer by applying more verification only when the risk score rises, rather than slowing every user. Queueing suspicious cases with evidence attached helps analysts work faster and makes the program operationally sustainable. Without those controls, fraud teams can identify abuse but still fail to interrupt it before monetisation.
Practical implication: combine event-based scoring with graduated friction and analyst queues at the points where fraud becomes monetisable.
NHI Mgmt Group analysis
Multi-accounting is really identity graph abuse. The core failure is treating each signup as a standalone trust decision when the attacker is building a connected identity cluster. That shifts the security problem from verification of one record to detection of repeated relationships across records. For practitioners, the lesson is that fraud rings win when the platform has no graph-level view of identity reuse.
Identity verification and IAM controls converge in marketplace fraud. This is not only a Trust and Safety issue, because fake accounts become persistent access paths into promotions, listings, messaging, and payouts. Where an organisation has strong onboarding checks but weak post-registration monitoring, the fraud surface stays open after the account is created. Practitioners should treat lifecycle visibility as part of fraud governance, not an optional extra.
Named concept: relationship-based account risk. The article illustrates a governance gap in which risk is measured per account instead of per relationship between accounts, devices, and payment methods. That gap matters because coordinated abuse often looks low risk in isolation and high risk only when clustered. The practical conclusion is that fraud programmes need entity resolution, not just point-in-time identity checks.
AI-assisted fraud will keep pushing beyond static rules. As rings use automation, proxy infrastructure, and synthetic identities, static pattern matching degrades quickly. The broader market signal is that fraud prevention is becoming an adaptive identity problem rather than a rules-only detection problem. Practitioners should expect more pressure to unify identity verification, behavioural analytics, and access governance in one operating model.
What this signals
Relationship-based account risk is the practical shift this article points to. Fraud teams that still optimise around isolated signups will keep missing the fraud ring until money moves, while teams that graph identity, device, and payment reuse can intervene earlier. The same logic applies to IAM-adjacent programmes: lifecycle visibility matters when reuse becomes the attack path.
Multi-accounting is also a reminder that verification controls must be paired with runtime monitoring. One-time checks at onboarding do not hold when the attacker can create twenty identities in a week and reuse them across promotions or listings. That is why relationship analysis, not just form validation, should inform fraud thresholds and case prioritisation.
For practitioners
- Correlate accounts into rings, not cases Join device fingerprints, payment instruments, shipping or payout addresses, and network attributes into a shared entity graph so analysts can see coordinated abuse patterns.
- Score at every monetisable event Recompute risk at first login, first listing, first payout request, and password reset instead of stopping at account creation.
- Apply dynamic friction by risk tier Use step-up verification for medium-risk accounts and hold high-risk accounts for review before they can transact or receive benefits.
- Measure ring takedowns, not only bans Track how many linked-account clusters are dismantled, how long new evasion patterns take to detect, and how often legitimate users are over-fricted.
Key takeaways
- Multi-accounting succeeds when fraud teams evaluate one account at a time instead of the relationships that bind many accounts into a ring.
- Device, network, and payment correlation are the signals that turn isolated suspicions into a defensible abuse cluster.
- Real-time scoring and dynamic friction matter because fraud only becomes costly when the account is allowed to transact.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while GDPR define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 | Identity and access management is relevant where fake accounts are created and reused. |
| NIST SP 800-53 Rev 5 | IA-5 | Authenticator management matters when accounts are spun up and reused at scale. |
| GDPR | Art.32 | Personal-data processing in identity verification and fraud scoring can trigger security obligations. |
Use IA-5 to strengthen credential issuance, verification, and revocation for suspicious accounts.
Key terms
- Multi-accounting: Multi-accounting is the practice of one actor creating or controlling multiple identities to evade limits, gain incentives, or hide coordinated behaviour. In betting and fraud environments, it matters because the platform may see each account as separate unless identity signals are correlated across devices, payments, and sessions.
- Entity Graph: An entity graph is a structured model of identities, devices, applications, and relationships across a security environment. It lets teams resolve different identifiers to the same actor, preserving continuity across systems so investigations can follow activity without manual field matching.
- Dynamic Friction: Dynamic friction is the practice of adding more user challenge only when risk rises. Rather than forcing every user through the same experience, the system adapts its response to context, which helps preserve conversion while still reducing fraud exposure in higher-risk scenarios.
- Link Analysis: Link analysis is the practice of connecting events, entities, and relationships so investigators can see behaviour in context. In security operations, it turns isolated logs into a traceable sequence that reveals who or what acted, how systems are connected, and why an activity matters.
What's in the full article
Sift's full article covers the operational detail this post intentionally leaves for the source:
- Step-by-step signal correlation across registration, login, listing, and payout events
- Examples of how Sift Score and Global Profile intelligence are applied in workflow decisions
- Operational guidance on tuning Dynamic Friction to balance fraud reduction and user experience
- Dashboard-oriented trend review methods for weekly and monthly fraud operations
Deepen your knowledge
NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, IAM, and secrets management. It gives practitioners the governance foundation that modern identity-heavy security programmes depend on.
Published by the NHIMG editorial team on August 25, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org