TL;DR: Fraud in iGaming is reshaping operator growth, regulatory pressure and investor due diligence, with the SumSub-hosted panel at ICE Barcelona highlighting tension between acquisition and prevention, unlicensed operators, Brazil’s evolving framework, and World Cup-driven fraud angles. The core issue is that fraud is no longer a side control problem, it is now a market and governance constraint.
Editorial analysis by NHI Mgmt Group, based on content published by SumSub: “iGaming Fraud Insights – ICE Barcelona Part 2”.
Key questions
Q: What breaks when iGaming operators prioritise acquisition over fraud prevention?
A: Friction-free growth can create a control environment where multi-accounting, bonus abuse and payment abuse scale faster than review can catch them.
Q: Why does fraud due diligence matter for iGaming investors and partners?
A: Because fraud maturity is now part of business quality, not just security quality.
Q: What are the signs that bonus abuse and multi-accounting are outpacing controls?
A: Look for repeated account creation patterns, unusual referral or promotion uptake, rapid value extraction after onboarding and inconsistent identity behaviour across linked accounts.
Practitioner guidance
- Strengthen onboarding friction points Insert verification and step-up checks where account creation, bonus enrolment and payment behaviour indicate abuse risk.
- Tie fraud controls to due diligence Include control maturity, licensing status and abuse-response capability in partner and investment reviews.
- Tune seasonal fraud monitoring Raise scrutiny during major sports events and other volume spikes, when coordinated abuse can hide inside legitimate traffic surges.
Bottom line: iGaming fraud is now shaping how operators grow, how they are regulated and how they are valued by investors.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Fraud in iGaming is now an identity governance problem, not a narrow abuse problem. The panel makes clear that player trust, payment integrity and regulatory compliance now move together. When operators treat fraud as only a detection issue, they miss the lifecycle question: who is allowed to create value, extract value and repeat that pattern at scale? The practitioner conclusion is that fraud controls now belong in the same governance conversation as access, onboarding and account lifecycle management.
A few things that frame the scale:
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface, according to the Ultimate Guide to NHIs.
- Only 5.7% of organisations have full visibility into their service accounts, which means most identity programmes still cannot see their non-human estate clearly.
A question worth separating out:
Q: What should compliance and security teams do when fraud risk affects investor due diligence?
A: They should report fraud as a business assurance metric, not only a loss-prevention metric. That means linking identity controls to bonus abuse, payout integrity, market exposure and control coverage by jurisdiction. Investors will read the quality of those controls as evidence of operational discipline, so the reporting model has to show more than incident counts.
👉 Read our full editorial: iGaming fraud is reshaping growth, regulation and due diligence
Fraud has become a governance variable, not only an operational loss vector. The article shows that iGaming fraud now influences growth, regulatory response and investor diligence at the same time. That changes how identity and fraud programmes should be framed, because control maturity is now part of market credibility. The practitioner conclusion is that fraud operations must be owned as a board-level trust issue, not a narrow detection function.
A few things that frame the scale:
- Nearly 60% of companies reported that fraud losses were still increasing in 2025.
A question worth separating out:
Q: How should operators respond when major events create new fraud angles?
A: Treat the event as a risk multiplier, not just a demand spike. Increase monitoring thresholds, validate identity and payment patterns more aggressively, and compare event-period behaviour with normal baselines. The main goal is to distinguish legitimate surge from coordinated abuse before losses compound.
👉 Read our full editorial: iGaming fraud is reshaping growth, regulation and due diligence