Table of Contents

Explore AI Summary

Share post on:

How to Detect Fake Accounts and Multi-Accounting

A single fake account rarely does much damage on its own. The real threat shows up when a fraud ring turns one playbook…

Sift Author Logo
Ben Price
black-dot
Press-Release-Tile-Image-Color-Pills_Blue

A single fake account rarely does much damage on its own. The real threat shows up when a fraud ring turns one playbook into dozens of accounts, each one built to look like a first-time buyer or seller while quietly abusing promotions or seeding fraudulent listings across your marketplace. 

This post walks through the technical signals and detection Workflows that separate a genuine new user from a coordinated multi-accounting scheme.

Why multi-accounting is a marketplace-wide problem

Most account fraud tools were built to evaluate one account at a time, missing the pattern that defines multi-accounting, which is the relationship between accounts, not the traits of any single one. A fraud ring might create 20 seller accounts across a week, each with a unique name, email, and phone number, but all connecting back to the same device, the same payout method, or the same narrow IP range.

Marketplaces are especially exposed because the incentive structure rewards new accounts. New-seller bonuses, referral credits, and first-order discounts all get replayed across every fake account a ring can stand up. TransUnion’s H1 2026 Update to its Top Fraud Trends Report found that more than 8% of account creation attempts globally were flagged as suspected digital fraud in 2025, an 18% jump from the year before, showing that fraudsters are investing more heavily in account creation.

The signals that expose fake and duplicate accounts

Detecting a fake account starts with looking past the surface-level fields a signup form collects and toward how those fields were generated. A handful of signals consistently separate synthetic and duplicate accounts from real ones:

  • Registration velocity: Tons of new accounts opening from a narrow IP range or a single device within minutes of each other is rarely organic growth. This is a huge red flag.
  • Disposable or pattern-generated emails: Addresses from throwaway domains, or emails that follow an obvious naming pattern (name1234, name1235, name1236), point to bulk account generation.
  • Phone number reputation: Virtual numbers, recently ported numbers, and numbers already tied to prior abuse carry a much greater risk than a phone number with an established history.
  • Reused payment instruments: The same card, prepaid balance, or digital wallet appearing across multiple accounts with different names is one of the strongest multi-accounting indicators out there.
  • Shipping and payout address overlap: Fraud rings often can’t fully separate the physical logistics behind their accounts, so addresses cluster even when identities don’t.

None of these signals are conclusive by themselves, but the real value comes from combining them, which is where device and network correlation take over and paint a clearer picture.

Correlating device, network, and behavioral data across accounts

Fake accounts are built to look distinct from each other on the fields a user types in. They’re much harder to separate on the technical fingerprint left behind by the device and browser used to create them. Device attributes such as screen resolution, installed fonts, browser configuration, and hardware identifiers persist across accounts even when names, emails, and phone numbers change every time.

Behavioral analytics add another layer Trust and Safety teams should not ignore. Things like device and browser information, location and IP data, page activity, navigation timing, and transaction behavior are difficult for a fraud operation to vary meaningfully across dozens of sessions, especially when the ring is running semi-automated scripts or a small team of operators cycling through accounts by hand. Link analysis that graphs these shared attributes, device, network, payment instrument, and behavior, against every account on the platform turns isolated weak signals into a visible cluster of related accounts, which is usually the moment a single suspicious signup becomes an obvious fraud ring.

Sift applies this kind of correlation continuously by assessing thousands of signals across the user journey, from registration through every subsequent login, and aggregating them into a Sift Score from 1 to 100, where 1 indicates a trustworthy user and 100 indicates likely fraud. Sift’s Global Profile intelligence resolves these identity links across the network in real time, so an account that looks brand-new in isolation can still be recognized as connected to a known cluster the moment it shares a device, payment instrument, or behavioral pattern with an existing account. That score gives fraud analysts a consistent way to compare accounts that look nothing alike on paper but behave identically underneath.

Building a real-time detection workflow

Signals only matter if they change what happens next in the user journey. A detection workflow for multi-accounting needs three components working together:

First, real-time scoring at every meaningful event, not just at signup. Account creation, first login, first listing, first payout request, and password reset all deserve a fresh look, since fraud rings often behave normally at signup and only reveal themselves a few steps later.

Second, Dynamic Friction that scales the response to the risk level: a low-risk new account moves through untouched, a moderate-risk account gets an added authentication step like one-time passcode confirmation, and a high-risk account gets held for review before it can transact.

Third, Queues that route flagged accounts to fraud analysts with the underlying evidence already attached, so a reviewer isn’t starting from zero on every case.

Sift Workflows let Trust and Safety teams configure these rules without waiting on an engineering sprint every time a new pattern emerges, and Insights gives teams a dashboard view of how account creation trends are shifting week over week, which matters because fraud rings adapt their tactics constantly.

Common evasion tactics to watch for

Fraud rings running multi-accounting operations at scale invest real effort in defeating the signals above, and detection teams should expect the following:

  • Residential proxy networks that rotate IP addresses through real home internet connections, making network-based blocking far less reliable than it was a few years ago.
  • Device emulators and virtual machines that spoof hardware fingerprints to make each session look like a distinct physical device.
  • Synthetic identities that blend real, stolen, or fabricated identity elements into a profile that passes basic identity checks but has no consistent history behind it.
  • SMS verification farms that supply large volumes of disposable phone numbers specifically to defeat one-time passcode checks.
  • Account marketplaces where aged, verified accounts with clean transaction histories are bought and sold to skip the scrutiny a brand-new account would face.

The Sift Q2 2026 Digital Trust Index found that account takeover attacks, a closely related tactic fraud rings use once fake or purchased accounts are established, rose by 8% in the internet and software sector. That trend line matters for marketplaces because a fraud ring rarely stops at account creation. Once an account exists, whether fabricated from scratch or purchased pre-aged, it becomes a target for takeover and reuse, which means detection can’t stop at the signup form.

Measuring success and iterating your defenses

One of the biggest challenges of a detection program is stopping threats without strangling legitimate growth. Trust and Safety teams should track a small set of metrics on a recurring basis: the ratio of flagged accounts confirmed as fraudulent versus false positives, the friction rate imposed on legitimate new users, the number of linked-account rings identified and shut down rather than individual accounts banned in isolation, and the time between a new evasion tactic appearing and detection catching up to it.

Ring-level takedowns matter more than single-account bans as a success metric, because banning one account in a ring of 20 accomplishes very little if the other 19 keep operating undetected. Reviewing Insights data on a monthly cadence, alongside direct feedback from the fraud analysts working Queues, is the most reliable way to catch a shift in tactics before it shows up as a spike in losses.

If your team is currently struggling with coming up with a successful detection program, then Sift may be a perfect fit for you. Sift uses advanced AI machine learning to identify and stop fraud risks before they have a chance to act. Want to try it out for yourself? Schedule a free demo with Sift today.

Frequently asked questions

What is multi-accounting fraud on an online marketplace?

Multi-accounting is when a single person or fraud ring creates multiple accounts on the same marketplace to abuse promotions, evade bans, or scale fraudulent listings. The accounts are usually built with different names, emails, and phone numbers, but share underlying technical or behavioral traits that link them together.

How is a fake account different from a duplicate or multi-accounting account?

A fake account typically relies on synthetic or stolen identity details to pass as a new, legitimate user on its own. A multi-accounting account is fake or real but is one of several accounts controlled by the same person or ring. In practice, the two overlap constantly, since most multi-accounting schemes depend on generating fake identities at scale.

Does adding fraud detection at signup slow down legitimate users?

It doesn’t have to. Dynamic Friction applies added steps like authentication only to accounts that score as risky, so the vast majority of legitimate signups move through without interruption. The goal is proportional response, not a blanket checkpoint that treats every new user as a suspect.

Can device fingerprinting alone stop multi-accounting?

No, one signal is not sufficient on its own. Device fingerprinting is defeated by emulators and virtual machines when used in isolation, which is why it needs to be combined with network, payment, behavioral, and identity signals through link analysis to reliably expose ring activity.

Dare to grow differently.

Flip the switch on fraud-fueled fear. Make risk work for your business and scale securely into new markets with Sift’s AI-powered platform.

see sift in action
  • remitly
  • swan
  • yelp-white
  • taptap
  • remitly
  • swan
  • yelp-white
  • taptap