They return because enforcement often ends at the account boundary. If the platform does not retain and compare device, IP, payment, and identity signals across seller profiles, a banned actor can re-enter with a fresh registration. The fix is actor-level linkage, so the restriction follows the fraudster, not just the account name.
Why This Matters for Security Teams
Marketplace fraud rarely stops at the point of account suspension. When controls are limited to usernames, email addresses, or a single payment method, banned actors can reappear with new registrations, different device sessions, and rotated infrastructure. The practical risk is not just repeat abuse but escalation: counterfeit listings, chargeback exposure, seller manipulation, and trust erosion across the platform. Current guidance suggests that enforcement must be designed around the actor, not the profile, and that requires linking signals across lifecycle events rather than treating each account as isolated.
This is a security and trust problem, not only a moderation problem. Identity teams, fraud analysts, and platform security owners need shared visibility into device reputation, IP intelligence, payment instrument reuse, behavioral patterns, and document or identity verification outcomes. The control objective is closer to persistent risk attribution than one-time registration screening. NIST’s NIST SP 800-53 Rev 5 Security and Privacy Controls is useful here because it reinforces access, audit, and monitoring discipline that can be adapted to fraud enforcement workflows. In practice, many security teams encounter repeat fraud only after the same actor has already normalized re-entry through low-friction onboarding.
How It Works in Practice
Actor-level linkage works by building a correlation layer that persists across accounts and sessions. Instead of asking only whether a new signup looks legitimate, the platform asks whether the new profile resembles previously removed entities. That usually means combining several signals, each of which is weak alone but stronger in aggregate:
- Device and browser characteristics, including stable identifiers where policy permits.
- IP reputation and network patterns, especially when proxy or hosting infrastructure is reused.
- Payment instrument overlap, refund destination reuse, or payout path similarity.
- Identity verification artifacts, such as reused documents, names, addresses, or inconsistent metadata.
- Behavioral patterns, including listing cadence, pricing patterns, and account navigation timing.
The operational goal is to create a risk graph that can connect one banned marketplace actor to a later registration even when the visible account fields change. This often requires joining fraud tooling with identity governance, case management, and enforcement queues so that an analyst can see why an account is linked before taking action. Where false positives are costly, the best practice is evolving toward graduated response: step-up verification, temporary holds, manual review, then permanent restriction only when confidence is high.
MITRE’s MITRE ATT&CK is not a fraud framework, but its emphasis on adversary behavior is still useful when teams model repeat-abuse patterns and operational tradecraft. For identity proofing controls, NIST SP 800-63 Digital Identity Guidelines helps separate registration assurance from ongoing account trust. These controls tend to break down when the platform lacks durable event correlation because fraud teams cannot safely distinguish recycled actors from legitimate users sharing common attributes.
Common Variations and Edge Cases
Tighter actor-linking controls often increase review overhead, requiring organisations to balance fraud suppression against user friction and mistaken enforcement. That tradeoff becomes sharp in marketplaces with family accounts, shared devices, work networks, or high-return customer segments, where legitimate users can resemble prior bad actors. There is no universal standard for this yet, so the right threshold depends on the platform’s abuse profile, business model, and tolerance for false positives.
Some environments need heavier weighting on identity evidence, while others rely more on payment and device intelligence because identity data is sparse or privacy constrained. Privacy rules also matter: retention periods, purpose limitation, and cross-context profiling should be reviewed carefully before building persistent fraud graphs. Where human review is used, analysts need documented escalation criteria so that enforcement is consistent and defensible. In AI-assisted marketplaces, model-generated risk scores should be explainable enough to support appeal handling and audit, especially when signals are ambiguous or partially corrupted.
Edge cases are most common when a platform has frequent legitimate churn, shared checkout infrastructure, or aggressive bot activity that masks true actor identity. In those conditions, simple ban lists age poorly and enforcement becomes a moving target unless the platform preserves high-quality historical linkage.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and MITRE ATLAS address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA | Identity assurance and access decisions underpin actor-level fraud linkage. |
| NIST SP 800-63 | IAL | Identity proofing helps distinguish higher-assurance users from recycled fraud actors. |
| OWASP Agentic AI Top 10 | If AI assists enforcement, account-linking logic can be manipulated or misled. | |
| NIST AI RMF | Risk governance is needed where automated scoring drives restrictions and appeals. | |
| MITRE ATLAS | Adversaries can evade detection by changing observable attributes and reusing patterns. |
Model evasion tactics and update correlation signals when repeat actors change their surface identity.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on July 22, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org