Every fraud scheme begins with an account that should never have been created. For marketplaces and B2B/B2C SaaS platforms with self-serve signup and free trials, registration is the widest open door in the product, and fake account detection is the discipline of closing it without turning away real customers.
Why fake account creation is accelerating
Account creation fraud is no longer a manual, low-volume nuisance. Advanced AI technology has made it easier than ever for fraudsters, and the data backs that up. Akamai’s 2026 State of the Internet research found that AI-powered bot traffic increased 300% over a single year, much of it built specifically to pass as human during signup flows.
Sumsub’s Identity Fraud Report 2025-2026 recorded an overall fraud rate of 2.2% across verified accounts in 2025, with online media and dating platforms seeing rates as high as 6.3%, and found that multi-step identity fraud, where fraudsters chain several tactics together instead of relying on one trick, rose from 10% of attacks in 2024 to 28% in 2025.
In the FBI’s Internet Crime Complaint Center’s 2026 annual report, they estimated there to be about 453,000 cyber-enabled fraud complaints, with reported losses exceeding $17.7 billion.
None of this is abstract for trust and safety teams. It means the fake accounts hitting your registration flow today are more automated, more disguised, and more likely to be part of a coordinated campaign than the ones you saw two years ago.
How fraudsters manufacture fake accounts at scale
Understanding the supply chain behind fake accounts makes detection far more tractable. Digital criminals rarely build accounts one at a time anymore. Common tactics include:
- Synthetic identities that blend real data (a stolen Social Security number or address) with fabricated details to pass basic verification checks.
- Disposable email addresses and virtual or VoIP phone numbers that satisfy a form field but cannot be tied back to a real person.
- Device farms and emulators that spin up hundreds or thousands of unique-looking sessions from a small number of physical machines.
- Residential proxy networks that mask the true origin of traffic, making a fraud ring in one location look like organic signups spread across a country.
- Generative AI tools that produce realistic selfies and matching identification documents to defeat photo-based identity verification.
- CAPTCHA-solving services, often staffed by low-wage human workers, that clear the checks designed specifically to stop bots.
Each of these tactics leaves a trace. The work of fake account detection is knowing where to look for it.
The technical signals that expose fake accounts
No single data point reliably separates a fraudulent signup from a legitimate one. Effective detection comes from combining signals across the entire registration event, not just checking a box at the form level.
Device intelligence matters first. Fingerprinting a device across sessions reveals when the same physical or emulated device is behind dozens of “unique” accounts, even when IP addresses and browser headers are spoofed. Network and IP reputation add another layer, flagging traffic from known proxy or VPN exit nodes, data center ranges masquerading as residential connections, or IP blocks already tied to prior abuse.
Email and phone risk scoring catches disposable domains, recently created addresses, and numbers sourced from bulk SMS-verification services. Behavioral signals, like how quickly a form is filled out, whether mouse movement looks human or scripted, or whether fields are populated in an order no person would use, catches bots that have gotten past the surface-level checks.
Velocity and link analysis tie these together: if 50 new accounts share the same device fingerprint, payment instrument, or shipping address, that pattern is worth flagging even if every individual signup looks clean in isolation.
Marketplaces and SaaS face the same problem with different shapes
The underlying mechanics of fake account creation are similar across industries, but the damage looks different depending on the platform.
On marketplaces, fake accounts show up as fraudulent seller profiles built to list counterfeit or non-existent goods, buyer accounts created to abuse promotions or manipulate reviews, and duplicate accounts used to evade a ban after a previous account was shut down. Because marketplaces connect two sides of a transaction, a single fake account can generate harm on both sides at once, damaging buyer trust and seller reputation simultaneously.
For B2B/B2C SaaS platforms, the risk concentrates around free trials and self-serve onboarding. Fraudsters and competitors alike create fake company accounts to extend trial periods, inflate seat counts to test pricing limits, or harvest gated content and API credits without ever intending to pay. Beyond direct cost, fake signups corrupt the metrics product and growth teams rely on, including activation rates, trial-to-paid conversion, and seat expansion forecasts which all get skewed when a meaningful share of “new users” were never real prospects.
Building a fake account detection strategy that scales
A durable approach treats fake account detection as a continuous process, rather than just a one-time gate at the signup form.
Start by assessing signals across the full user journey instead of a single moment in time. Sift assesses thousands of signals, including device, network, behavioral, and identity data, and aggregates them into a Sift Score from 1 to 100, where 1 indicates a trustworthy user and 100 indicates likely fraud. That score updates as new information arrives, so a signup that looks clean at registration but starts behaving suspiciously afterward gets re-evaluated rather than permanently trusted.
Apply friction dynamically instead of uniformly. Dynamic Friction routes low-risk signups straight through while directing higher-risk ones to additional Verification steps, such as email or phone confirmation, only when the signal data warrants it. That protects conversion rates for the vast majority of legitimate signups while still slowing down the accounts that need a second look.
Automate the decisioning with Workflows, and route gray-area accounts to a review Queue where fraud analysts can make the final call with full context on the signals that triggered it. Insights should feed back continuously, surfacing a new proxy range, a fresh wave of synthetic identities, or a spike from a specific device cluster, so analysts can adjust before a pattern becomes a large-scale campaign.
Where fake account detection breaks down
Even well-resourced trust and safety teams undermine their own defenses in predictable ways:
- Relying on a single signal, such as email domain checks or CAPTCHA alone, without combining it with device and network data. Fraudsters have automated their way past nearly every standalone check that exists.
- Treating verification as binary. Blocking every signup that trips a rule, or approving everything that doesn’t, ignores the middle ground where most of the decision-making value lives.
- Evaluating risk only at registration, rather than watching for suspicious behavior in the days and weeks that follow an approved signup.
- Working in isolation. A fraud ring rarely targets one platform, and sharing signal intelligence, internally across product lines or through a broader fraud network, catches patterns a single company’s data never would.
Fake account detection is not a problem trust and safety teams solve once. It is a moving target that requires layered signals, adaptive friction, and a feedback loop that gets faster as fraud tactics evolve.
Is your fraud team struggling with detecting fake accounts? If so, Sift is the perfect solution. It utilizes advanced machine learning technology to identify fraud signals and stops them before they cause financial harm to your business. Schedule a free consultation with Sift today.
Frequently asked questions
Fake account detection is the process of identifying fraudulent or automated signups, such as those created with synthetic identities, disposable contact information, or bots before they can be used for downstream abuse like promo fraud, fraudulent listings, or account takeover. It combines device, network, behavioral, and identity signals to distinguish real users from manufactured ones.
Identity verification confirms that a specific piece of identity information, such as a document or a selfie, is authentic and belongs to the person presenting it. Fake account detection is broader, because it evaluates the entire signup context, including device history, network reputation, and behavior, to catch fraud that identity verification alone would miss, including accounts built with real but stolen identity data.
Yes. CAPTCHA-solving services and generative AI tools that create realistic selfies and matching documents have made many standalone checks far less reliable on their own. That is why layered signal analysis, rather than any single check, has become necessary for reliable detection.
As little as possible for legitimate users. Applying the same verification steps to every signup slows down real customers and still misses sophisticated fraud. Dynamic, risk-based friction that only escalates to additional verification for higher-risk signups protects conversion while still catching fraudulent ones.
Yes. Fake trial signups and inflated seat counts distort activation rates, trial-to-paid conversion, and expansion forecasts. Product and growth teams making decisions off of those numbers end up optimizing for a population of users that was never going to convert in the first place.





