They are hard to stop because the identity details can be real, willingly shared, and individually verifiable. That means a new account may look legitimate even when it belongs to the same player or syndicate. Operators must therefore rely on device, browser, and network behaviour, not identity data alone, to uncover repeated abuse patterns.
Why the fraud problem persists even when the player is “real”
Gnoming and multi-accounting are persistent because the fraud signal is not a fake identity in the obvious sense. The operator may see a genuine person, a valid email, a working phone number, and even a clean KYC check, yet the same underlying actor can still cycle through accounts to reuse bonuses, evade limits, or conceal collusion. That makes the abuse operationally invisible if review stops at registration data.
The core issue is that identity verification and fraud detection answer different questions. Verification asks whether an account can be tied to a believable person; fraud detection asks whether this account behaves like a repeat abuser, a coordinated syndicate member, or a controlled duplicate. Those are not the same problem, so a strong onboarding flow can still leave a material abuse gap.
In practice, the weakness is that shared or legitimately borrowed identity details can be consistent enough to pass one-off checks while the abuse pattern only emerges across many events. The operator therefore needs to look for the relationship between accounts, not only the truth of each account in isolation. Behavioural correlation is what turns a series of plausible registrations into an identifiable fraud cluster.
What operators must compare instead of trusting identity data alone
To surface repeat abuse, gambling operators need to compare account behaviour across device, browser, network, and payment signals. The useful question is not simply “does this name verify?” but “does this session match a previously seen actor, route, or play pattern?” That includes device fingerprinting, IP and proxy characteristics, browser consistency, velocity of sign-up and deposit activity, bonus redemption timing, and withdrawal routing.
This is why cross-account linkage matters. If one player or syndicate can create multiple accounts that each look individually acceptable, then only the shared technical and behavioural traces reveal the pattern. Operators often get the best signal from clusters of weak indicators, especially when the same device family, network range, browser traits, or payment instrument keeps reappearing alongside repetitive promotion abuse.
That broader view is also why a broader identity and lifecycle view can be useful even in a gambling context: the lesson is that trust cannot rest on one data point, it must be sustained across repeated use, reuse, and change. For the same reason, fraud teams should also study established abuse patterns such as reused account abuse at scale and persistent access through trusted relationships, because the operational lesson is the same, repeated legitimate-looking access can still be harmful.
Why the business impact is larger than bonus abuse
The obvious loss is promotional leakage, but the real risk is broader. Repeated account cycling distorts player segmentation, defeats risk scoring, and undermines limits that were designed for a single customer relationship. It can also create compliance and disputes pressure when genuine customers are flagged inconsistently, because the operator is forced to balance fraud prevention with false-positive tolerance.
At scale, multi-accounting becomes a governance problem as much as a detection problem. If one syndicate can cheaply create many apparently valid accounts, the operator’s control assumptions weaken: bonus controls get gamed, responsible gambling interventions become less reliable, and review queues fill with borderline cases that consume analyst time without fully closing the abuse path.
This is why device and network behaviour are not just additional telemetry, they are the evidence of record for repeated misuse. When the same environment keeps reappearing under different identities, the operator should treat that as a sign of control failure, not merely as a noisy anomaly. The goal is to measure reuse, linkage, and escalation over time, not just the legitimacy of the latest signup.
Risk and Threat Considerations
Gnoming and multi-accounting create persistent exposure because they exploit a control gap between identity proofing and behavioural trust. A fraudster can present a real person, a shared identity, or a verified account and still continue the abuse through repeated registrations, shared infrastructure, or coordinated play patterns.
Failure mechanism: The operator relies too heavily on static identity attributes, so repeated abuse survives as long as each new account clears basic checks and the cross-account linkage signals are weak, delayed, or fragmented.
Impact: This enables ongoing bonus abuse, collusion, chargeback or withdrawal abuse, distorted risk scoring, and a steadily expanding review burden that can hide higher-value fraud clusters inside ordinary customer traffic.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS Control 6 — Access Control Management | Multi-account abuse is constrained by access and account governance across sessions and endpoints. |
| CIS Control 8 — Audit Log Management | Behavioural linkage depends on retaining and correlating logs across accounts, devices and sessions. | |
| Recommendation — Restrict repeated account creation paths and review access signals that indicate shared misuse. Centralise and correlate logs to detect repeated abuse patterns across multiple accounts. | ||
| NIST CSF 2.0 | DE.CM — Continuous Monitoring | Persistent fraud risk requires ongoing monitoring of device, network and session behaviour. |
| PR.AA — Identity Management, Authentication and Access Control | The issue is the gap between verified identity and actual abuse patterns. | |
| GV.RM — Risk Management Strategy | Operators must manage residual fraud risk when identity checks cannot fully prevent reuse. | |
| Recommendation — Monitor behavioural signals continuously to identify repeated abuse that passes onboarding checks. Use stronger identity and access controls alongside behavioural checks to reduce account reuse. Set fraud thresholds and review rules that reflect the residual risk of duplicate-account abuse. | ||
| OWASP Non-Human Identity Top 10 | NHI-04 — Secrets and Credential Lifecycle | Persistent reuse is enabled when controls rely on reusable trust signals instead of lifecycle-aware evidence. |
| NHI-08 — Visibility and Detection Gaps | The problem persists when repeated abuse is hidden across otherwise valid accounts and sessions. | |
| Recommendation — Rotate and invalidate any reusable trust artifacts that could support repeated abuse. Improve cross-account visibility so duplicate behaviour is surfaced as one abuse pattern. | ||
| MITRE ATT&CK | T1036 — Masquerading | Multi-accounting uses legitimate-looking identities to blend malicious activity into normal traffic. |
| T1078 — Valid Accounts | Fraud actors exploit real accounts and trusted identities rather than obvious fake ones. | |
| Recommendation — Look for normal-looking account activity that masks repeated or coordinated abuse. Treat valid-account abuse as a high-priority detection problem, not just a verification problem. | ||
Practitioner Guidance
What to prioritise: Build detection around linkage, not registration certainty. The most useful controls are the ones that reveal repeated behaviour across accounts, especially when the same device, browser profile, network path, or payment pattern keeps returning under new customer records.
What to verify: Confirm that fraud review can join events across the full customer journey, from signup through deposit, gameplay, bonus use, and withdrawal. If each step is judged in isolation, gnoming and multi-accounting will keep looking like unrelated legitimate customers.
Practitioner takeaway: The winning strategy is to treat identity data as necessary but insufficient, then force fraud decisions to rest on durable behavioural linkage and cluster analysis rather than on any single verified account.
Related resources from NHI Mgmt Group
- Why do bonus abuse and multi-accounting create such a high compliance risk for gambling businesses?
- Why do multi-accounting schemes create both fraud and compliance risk?
- Why does multi-accounting create both fraud and governance risk for online platforms?
- Why do anti-detect browsers create more fraud risk in account takeover and multi-accounting schemes?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 18, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org