Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Device intelligence and ridesharing fraud: what IAM teams miss


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15737
Topic starter  

TL;DR: Ridesharing fraud is structurally two-sided, with driver and rider abuse both exploiting identity controls that stop at onboarding while device intelligence links repeated account creation, profile rental, and referral farming across sessions, according to Fingerprint. The core lesson is that persistent device signals add a missing governance layer below identity verification, where account bans alone cannot stop re-entry or preserve regulatory due diligence.

NHIMG editorial — based on content published by Fingerprint: LLMjacking is not the topic here; this ridesharing fraud analysis focuses on device intelligence and the re-entry gap

By the numbers:

Questions worth separating out

Q: How should security teams stop banned users from re-entering through new accounts?

A: They should make re-entry a lifecycle problem, not a one-time identity check.

Q: Why do identity checks fail to stop referral and account cycling fraud?

A: Identity checks usually confirm who someone is at signup, not whether the same device keeps creating fresh accounts later.

Q: What signals show that a marketplace fraud control is too blunt?

A: A control is too blunt when it blocks legitimate users from shared devices, common IP ranges, or high-risk regions while fraud still gets through with minor changes in account details.

Practitioner guidance

  • Implement persistent device linkage for all account lifecycle events Tie onboarding, session changes, payout approval, and re-verification to a durable device history so re-entry attempts are compared with prior behaviour, not only with the current signup record.
  • Separate driver and rider fraud policies Create distinct rule sets for supply-side and demand-side abuse so profile rental, deactivated-user re-entry, multi-accounting, and referral farming are scored against different thresholds and escalation paths.
  • Gate high-risk promotions on uniqueness signals beyond email and phone Require device history, prior payout behaviour, and account linkage checks before releasing referral credits or first-trip bonuses, especially in markets with repeated promo abuse.

What's in the full article

Fingerprint's full research covers the operational detail this post intentionally leaves for the source:

  • The market-specific fraud patterns behind tenant drivers, profile rental, and referral farming.
  • How device intelligence is applied inside onboarding, session monitoring, and payout gating workflows.
  • The way persistent device signals reduce false positives in high-risk markets while preserving growth.
  • Why the compliance argument changes when platforms are treated as financial infrastructure.

👉 Read Fingerprint’s analysis of ridesharing fraud, device intelligence, and re-entry risk →

Device intelligence and ridesharing fraud: what IAM teams miss?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 15322
 

Device persistence is the missing governance layer in marketplace fraud. Fraud teams often assume that stronger onboarding identity checks solve the problem, but ridesharing shows the real gap is continuity after signup. A device can survive SIM swaps, email churn, and account recycling, which makes it the more reliable anchor for lifecycle governance. The practitioner conclusion is straightforward: if the platform cannot recognise re-entry, it cannot enforce bans.

A question worth separating out:

Q: Who is accountable when rented profiles or fake rider accounts create losses?

A: Accountability sits with the platform as well as the individual user because the platform controls onboarding, monitoring, and enforcement. In regulated environments, repeated re-entry, weak due diligence, and poor lifecycle controls can turn a fraud issue into a compliance issue. The practical test is whether the platform can show it detects and acts on repeat device history.

👉 Read our full editorial: Device intelligence closes the re-entry gap in ridesharing fraud



   
ReplyQuote
Share: