Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Multi-accounting rings: what Trust and Safety teams need to catch


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19453
Topic starter  

TL;DR: Fraud rings can turn one playbook into dozens of accounts, and Sift says more than 8% of global account creation attempts were flagged as suspected digital fraud in 2025, showing why single-account review misses coordinated abuse. The real control challenge is linking device, network, payment, and behavioural signals before fake accounts are used for promotions, listings, or takeover.

NHIMG editorial — based on content published by Sift: How to Detect Fake Accounts and Multi-Accounting

By the numbers:

Questions worth separating out

Q: How can teams reduce multi-accounting without blocking legitimate users?

A: Use relationship analysis across devices, payment methods, and behaviour so the platform can detect coordinated abuse without relying on a single brittle rule.

Q: Why do fake accounts evade single-account fraud controls?

A: Single-account controls miss the relationship that defines multi-accounting.

Q: How do you know if account fraud detection is actually working?

A: Look for fewer linked rings operating over time, faster detection of new evasion tactics, and a stable false-positive rate for legitimate users.

Practitioner guidance

  • Correlate accounts into rings, not cases Join device fingerprints, payment instruments, shipping or payout addresses, and network attributes into a shared entity graph so analysts can see coordinated abuse patterns.
  • Score at every monetisable event Recompute risk at first login, first listing, first payout request, and password reset instead of stopping at account creation.
  • Apply dynamic friction by risk tier Use step-up verification for medium-risk accounts and hold high-risk accounts for review before they can transact or receive benefits.

What's in the full article

Sift's full article covers the operational detail this post intentionally leaves for the source:

  • Step-by-step signal correlation across registration, login, listing, and payout events
  • Examples of how Sift Score and Global Profile intelligence are applied in workflow decisions
  • Operational guidance on tuning Dynamic Friction to balance fraud reduction and user experience
  • Dashboard-oriented trend review methods for weekly and monthly fraud operations

👉 Read Sift's analysis of how to detect fake accounts and multi-accounting →

Multi-accounting rings: what Trust and Safety teams need to catch?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19044
 

Multi-accounting is really identity graph abuse. The core failure is treating each signup as a standalone trust decision when the attacker is building a connected identity cluster. That shifts the security problem from verification of one record to detection of repeated relationships across records. For practitioners, the lesson is that fraud rings win when the platform has no graph-level view of identity reuse.

A question worth separating out:

Q: What should Trust and Safety teams do when one account looks suspicious?

A: Investigate the surrounding identity cluster before deciding on a single-account action. Check whether the same device, payment method, address, or behaviour appears elsewhere, because the real threat is often a ring that can replace one account quickly. Containment should focus on the shared pattern, not just the latest signup.

👉 Read our full editorial: Multi-accounting detection depends on linked identity signals, not single accounts



   
ReplyQuote
Share: