TL;DR: Fraud rings can turn one playbook into dozens of accounts, and Sift says more than 8% of global account creation attempts were flagged as suspected digital fraud in 2025, showing why single-account review misses coordinated abuse. The real control challenge is linking device, network, payment, and behavioural signals before fake accounts are used for promotions, listings, or takeover.
NHIMG editorial — based on content published by Sift: How to Detect Fake Accounts and Multi-Accounting
By the numbers:
- 8% of account creation attempts globally were flagged, re flagged as suspected digital fraud in 2025, an 18% jump from the year before.
- Sift scores users from 1 to 100, where 1 indicates a trustworthy user and 100 indicates likely fraud.
Questions worth separating out
Q: How can teams reduce multi-accounting without blocking legitimate users?
A: Use relationship analysis across devices, payment methods, and behaviour so the platform can detect coordinated abuse without relying on a single brittle rule.
Q: Why do fake accounts evade single-account fraud controls?
A: Single-account controls miss the relationship that defines multi-accounting.
Q: How do you know if account fraud detection is actually working?
A: Look for fewer linked rings operating over time, faster detection of new evasion tactics, and a stable false-positive rate for legitimate users.
Practitioner guidance
- Correlate accounts into rings, not cases Join device fingerprints, payment instruments, shipping or payout addresses, and network attributes into a shared entity graph so analysts can see coordinated abuse patterns.
- Score at every monetisable event Recompute risk at first login, first listing, first payout request, and password reset instead of stopping at account creation.
- Apply dynamic friction by risk tier Use step-up verification for medium-risk accounts and hold high-risk accounts for review before they can transact or receive benefits.
What's in the full article
Sift's full article covers the operational detail this post intentionally leaves for the source:
- Step-by-step signal correlation across registration, login, listing, and payout events
- Examples of how Sift Score and Global Profile intelligence are applied in workflow decisions
- Operational guidance on tuning Dynamic Friction to balance fraud reduction and user experience
- Dashboard-oriented trend review methods for weekly and monthly fraud operations
👉 Read Sift's analysis of how to detect fake accounts and multi-accounting →
Multi-accounting rings: what Trust and Safety teams need to catch?
Explore further
Multi-accounting is really identity graph abuse. The core failure is treating each signup as a standalone trust decision when the attacker is building a connected identity cluster. That shifts the security problem from verification of one record to detection of repeated relationships across records. For practitioners, the lesson is that fraud rings win when the platform has no graph-level view of identity reuse.
A question worth separating out:
Q: What should Trust and Safety teams do when one account looks suspicious?
A: Investigate the surrounding identity cluster before deciding on a single-account action. Check whether the same device, payment method, address, or behaviour appears elsewhere, because the real threat is often a ring that can replace one account quickly. Containment should focus on the shared pattern, not just the latest signup.
👉 Read our full editorial: Multi-accounting detection depends on linked identity signals, not single accounts