TL;DR: Akamai reported AI-powered bot traffic increased 300% in a year, while Sumsub found multi-step identity fraud rose from 10% of attacks in 2024 to 28% in 2025, showing that signup fraud is becoming more automated and coordinated, according to Sift's analysis. Single checks no longer hold up against fraud rings that combine device, network, behavioral, and identity signals.
NHIMG editorial — based on content published by Sift: Fake Account Detection: The Technical Signals That Expose Fraudulent Signups
By the numbers:
- Sumsub’s Identity Fraud Report 2025-2026 recorded an overall fraud rate of 2.2% across verified accounts in 2025.
Questions worth separating out
Q: How should security teams stop fake account creation at sign-up?
A: They should add layered friction that raises the cost of bulk registration without breaking legitimate users.
Q: Why do fake accounts remain hard to stop after identity verification passes?
A: Because verification only answers whether a document, selfie, or contact point looks valid.
Q: What do teams get wrong about fake profile detection?
A: They often focus on removing bad accounts after reports arrive, instead of measuring how trust was built in the first place.
Practitioner guidance
- Correlate registration signals across the full event Combine device fingerprinting, IP reputation, behavioural timing, email risk, and phone risk into one decision path rather than accepting any single clean signal as proof of legitimacy.
- Apply dynamic friction by risk tier Send low-risk users through quickly and trigger extra verification only when the aggregated signal profile crosses an agreed threshold, so false positives do not become a growth problem.
- Re-score accounts after onboarding Keep evaluating accounts after signup using post-registration signals such as shared infrastructure, repeated sessions, and unusual usage bursts, because many fake accounts only reveal themselves later.
What's in the full article
Sift's full post covers the operational detail this analysis intentionally leaves for the source:
- Signal-by-signal breakdowns for device, network, email, phone, and behavioural scoring during signup
- Operational examples of Dynamic Friction, Workflows, and Queue-based analyst review in fraud operations
- How the Sift Score changes as new information arrives after registration, not just at the point of signup
- Marketplace and SaaS-specific abuse patterns, including trial fraud, seller fraud, and review manipulation
👉 Read Sift's analysis of fake account detection and signup fraud signals →
Fake account detection: are layered signals enough to stop fraud?
Explore further
Layered signal analysis is now the minimum viable control for signup trust. Account creation fraud has moved beyond simple bot filtering into coordinated identity abuse that blends device spoofing, network masking, and synthetic data. That means trust decisions must be based on correlated evidence, not one-off checks that fraudsters can game. For practitioners, the governance shift is from point validation to continuous risk evaluation.
A question worth separating out:
Q: When should organisations escalate a signup for review?
A: Escalate when several moderate-risk signals line up, such as repeated device fingerprints, proxy-heavy traffic, unusually fast form completion, or multiple accounts sharing the same payment or shipping details. The point is to identify coordinated patterns, not punish one unusual field in isolation.
👉 Read our full editorial: Fake account detection depends on layered signals, not single checks