Multi-accounting detection: how device, behaviour, payment and network signals link dozens of accounts to one user and why screening at signup is cheaper.

Multi-Accounting Detection: Finding One User Behind Many Identities

A welcome bonus is priced for one person claiming it once. When one person claims it forty times, nothing visibly breaks: each account registers cleanly, meets the condition, takes the incentive, and goes quiet. Multi-accounting detection is the work of proving those forty customers were one, using data you already hold.

No stolen card, no injected script – just a person who read the promo terms closely and worked out that the cheapest input in an acquisition funnel is a new identity. Analysts who work these cases describe it the same way: it’s rarely sophisticated, but economically sensible.

So the question is whether your funnel makes the attempt profitable, and whether you find out at signup or after the money has left.


Key Takeaways:

  • Bonus abuse is a margin business: it runs while the payout per identity beats the cost of producing one.
  • Linkage signals differ in durability. Network origin and inbox addresses rotate cheaply; behavior and the destination of the money do not.
  • You pay twice for a farmed account: the incentive, plus the acquisition cost of a signup counted as new.
  • A signup check is cheaper than a post-payout investigation, but its friction lands on everyone, and suppressed conversions never appear in a report.

One Person, Many Customers: How the Cycle Repeats

The cycle has four steps, and none of them are hidden:

  1. An account registers with a fresh address and a fresh number.
  2. It does whatever the promo requires: a first deposit, a first order, a confirmed email, etc.
  3. The incentive lands, the value moves somewhere durable.
  4. The account is parked until the offer repeats.

Referral programs tighten the loop, because one operator can sit on both ends: account one refers account two, and the referral payout arrives on top of the bonus. Group-IB’s knowledge hub entry on bonus abuse walks through this family of schemes and the indicators that expose them.

The common thread is that no individual account looks wrong. Every one passes review on its own merits, because the abuse is a property of the set rather than any member of it, so detection has to be about relationships.


The Arithmetic Behind Every Farmed Identity

Whether the scheme runs is a subtraction problem. On one side is the payout per identity: welcome bonus, promo code value, referral fee, and whatever share of that converts into something the operator keeps. On the other is the cost of producing one identity that survives your checks, and it is never one item. An inbox address is effectively free; a phone number that receives codes is not. Add device or browser separation so two accounts do not look identical, a network path that does not resolve to one origin, a destination where value can land, and the operator’s own time: a one-person farm has a ceiling measured in accounts per hour.

The scheme scales while payout stays above that cost, so every layer you add either raises production cost or catches accounts before they withdraw. Neither of those requires identifying who the operator actually is.

A second loss hides in reporting. If those registrations came through a paid channel, an advertiser paid acquisition cost per identity on top of the incentive, and cohort metrics absorb it quietly: retention looks weak, and the channel gets blamed, when one user was counted many times.


Linkage Layers, Ordered by What They Cost to Defeat

Ranking these layers by how convincing they look in a review queue is the wrong order. A signal is worth what it costs the other side to break, and the cheapest to collect are the cheapest to evade.

Linkage layerWhat connects the accountsCost to break itWhere it fails you
Network originSame address or subnet, data center rangesLow: a new exit node per sessionCarrier pooling hides real users behind one address
Contact identifiersDisposable inbox domains, a reused numberLow to moderate: inboxes are free, numbers are notRecycled numbers collide honestly
Device and browserRepeating fingerprint, hardware attributesModerate: anti-detect profiles or separate devicesHomes and offices share devices
Behavior and timingSame route, same claim latency, one windowHigh: needs more humans or better automationNeeds volume and a baseline first
MoneyOne payout destination, one instrumentHigh: value must arrive somewhere reachableArrives after the incentive is granted

The top rows buy fast coverage against casual repetition. The bottom rows are where detection pays for itself, and they arrive latest.


What the Signup Surface Gives Away

Most cheap signals arrive in the first seconds, before the account has done anything. SEON’s breakdown of registration fraud detection in iGaming names the ones that carry weight there: disposable email addresses, VPN (Virtual Private Network) and data center IP (Internet Protocol) addresses, phone numbers shared across accounts, and device identifiers already linked to more than one account. They travel across verticals, because they describe the production line rather than the product.

None is conclusive alone. A data center address by itself catches a careless operator and annoys a privacy-minded customer, while that address plus a fingerprint already seen twice this week plus a claim submitted seconds after registration is a different proposition.

One more thing arrives at the same doorway and needs separating out. The 2025 Imperva Bad Bot Report puts automated traffic at 51% of all web traffic in 2024, with bad bots at 37%, up from 32% a year earlier. Account takeover is not multi-accounting: it uses stolen credentials to enter accounts that already exist, while multi-accounting manufactures new ones. They share the registration and login surface, so your signals are read in a crowded room, but they need separate responses.


Behavior is where a farm gets expensive, because the operator is imitating variety while doing the same job repeatedly. The tells are mundane: an identical route through the funnel, no wandering into pages a real new customer wanders into, fields filled by paste rather than typing, and claim latency clustered in a narrow band. Session timing carries more weight than people expect. Real signups spread across hours and days in a shape that follows the traffic source, while a farm spreads across whatever window the operator was awake. Overlay claim timing on registration timing and the clusters often separate.

These are relative signals, though: they need a baseline for your own funnel, so a brand new promo is the moment your coverage is thinnest. Across production environments, there is no correct point on that line, only a decision about who carries the cost of uncertainty.

The other expensive link is the money. Value must eventually reach somewhere the operator controls, and no proxy rotation removes that, which is why payout data produces the tightest clusters: several accounts naming one destination, one instrument funding deposits under different names, a holder name that does not match the account.

The catch is that the strongest signal arrives last. By the time a payout request reaches a queue, the incentive has been granted, the acquisition cost paid, and any commission settled. A check there protects the withdrawal.


Where the Check Belongs, and Who Pays for It

Placing checks is a resource decision more than a technical one. The same signal costs a different amount depending on when you act on it, and so does being wrong.

Passive checks at signup stay close to free for a real user, because reading device, network, and contact signals costs that user nothing. The moment a check becomes a form field, a code or a document upload, it starts subtracting real conversions. Behavioral checks after the first action are the cheapest place to add strength, since the data already exists and the reward has not been released. Hard checks at payout are the most accurate and the most expensive in trust.

Side by side, each option is strong on a different axis.

Where a Check Can Sit in the Account Lifecycle

Illustrative framework. The left color bar marks the friction profile at each checkpoint.

Comparison of signup, first action, payout request, and retrospective checks by what they catch, their cost to a real user, and their main false positive risk.
Checkpoint What It Catches Cost to a Real User Main False Positive Risk
First Action before the reward unlocks

Identical navigation paths, no exploration, pasted form fields, and claims clustered in one window.

None. It runs on event data you already collect, and the user never sees it happen.

Fast, confident returning users can look scripted.

Payout Request money about to leave

One payout destination behind many accounts, name mismatches, and reused payment instruments.

High. A hold lands at the moment the user expects trust, and support hears about it.

Joint accounts and family payment instruments can be held by mistake.

Retro Sweep cohort reviewed later

Clusters that surface only after the cohort has enough history to be compared against itself.

None up front, but a block can arrive weeks after signup on an account in good standing.

Thin logs and stale evidence can make legitimate accounts look connected.

First Action before the reward unlocks
What It Catches

Identical navigation paths, no exploration, pasted form fields, and claims clustered in one window.

Cost to a Real User

None. It runs on event data you already collect, and the user never sees it happen.

Main False Positive Risk

Fast, confident returning users can look scripted.

Payout Request money about to leave
What It Catches

One payout destination behind many accounts, name mismatches, and reused payment instruments.

Cost to a Real User

High. A hold lands at the moment the user expects trust, and support hears about it.

Main False Positive Risk

Joint accounts and family payment instruments can be held by mistake.

Retro Sweep cohort reviewed later
What It Catches

Clusters that surface only after the cohort has enough history to be compared against itself.

Cost to a Real User

None up front, but a block can arrive weeks after signup on an account in good standing.

Main False Positive Risk

Thin logs and stale evidence can make legitimate accounts look connected.

Each checkpoint is strong on a different axis, and none is strong on all three.

A workable arrangement is staged: passive linkage at signup that escalates only when a cluster forms, behavioral scoring before the incentive unlocks, manual review at payout where the money signals converge.

None of that removes the trade underneath. Every gate at registration reduces abuse and reduces genuine signups at once, and only one of those effects shows up in a report: blocked abuse is countable, while suppressed conversion is a counterfactual, because someone who saw one more required field and closed the tab leaves no row anywhere.

That asymmetry bends decisions predictably. The visible number wins the argument, so friction accumulates because nothing in the data pushes back. Then a soft quarter arrives, the gates come off quickly, and the abuse returns faster than the traffic does, because the farm was watching the offer terms and the honest user was not.

Launching an incentive and a behavioral model at the same time means the first stretch goes on recalibration. Moving friction off clean accounts and onto suspicious ones is the improvement actually available, and it turns a policy question into a classification question.


Where Multi-Accounting Detection Breaks Down

Shared context is the biggest source of honest collisions. Households, offices, campus networks, public hotspots, and mobile carrier address pooling all put unrelated people behind identifiers that look shared. Where most traffic is mobile, and addresses are pooled aggressively, network origin loses most of its value, and a rule tuned on one audience will misfire on another.

Device fingerprinting fraud is an arms race with a well-supplied other side. Anti-detect browsers exist to produce distinct, plausible fingerprints on demand, and a farm using separate physical devices defeats fingerprint matching without any cleverness at all. Treat fingerprint reuse as a filter, not a verdict.

Then there is the evidence itself. A cluster is a probability statement, not a proof, and it weakens the further you sit from the money. Punitive action on a cluster alone will catch real customers, which is why anything that confiscates value or closes an account permanently needs a human in the loop and a working appeals path.

One constraint is worth accepting rather than fighting: a block notice should not explain itself, because naming the signal that fired hands over the next iteration.


FAQ

What is multi-accounting detection?

Identifying when several accounts belong to the same person, using signals the platform already collects: device and browser attributes, network origin, contact identifiers, behavior, and payment details. The output is a cluster with a confidence level, not a verdict, and what you do with it is a policy decision.


How do platforms know that two accounts belong to the same person?

No single field proves it. Linkage comes from agreement across independent signals: a repeated device fingerprint, one payment instrument behind several deposits, matching claim timing, a shared payout destination. Any one has an innocent explanation, and four at once rarely does.


What is the difference between bonus abuse and normal promo usage?

A customer taking a welcome offer once, as intended, is the offer working. Bonus abuse is repeated extraction of a one-time incentive by one person through manufactured identities. The workable distinction is not motive, which you cannot observe, but repetition across linked accounts.


Can device fingerprinting stop multi-accounting on its own?

No. Fingerprinting catches unsophisticated repetition and is defeated by anti-detect browser profiles or by separate devices. It is cheap and immediate, but a defense resting on it alone fails against any funded operation, and it produces false matches in shared households.


Is it better to block linked accounts at signup or at payout?

Signup is cheaper, because nothing has been granted and no acquisition cost is at risk. Payout is more accurate, because payment signals are hardest to disguise, but by then the incentive and the media spend are gone. Most funnels need both.


Pricing the Check Before You Price the Bonus

The design decision arrives earlier than most teams treat it. An incentive gets approved on a growth forecast, and the linkage question gets asked after the first payout batch looks strange. By then the offer terms are public, the abuse economics are fixed, and every remaining option is a retrofit.

The better sequence is to price the bonus and the check together. If the payout per identity is worth farming, the cost of producing an identity has to rise the moment the offer goes live, and the place to raise it is the layer nobody can cheaply rotate: not the inbox address, but the behavior and the destination of the money.

Keep one column on the other side of that ledger too. Ask what the check is doing to users who are not abusing anything, because that number exists whether or not anybody measures it.

Join our Telegram for more insights and share your ideas with fellow-affiliates.