Skip to content
iGaming Times

Independent industry intelligence in your inbox. We will email you a link to confirm your subscription, and every newsletter carries a one-click unsubscribe link.

Lesson 2 of 7 · 17 min

Identity and Account Fraud

Everything downstream assumes you know who holds the account. Stolen, synthetic and farmed identities, account takeover, and the legitimate customers each control declines.

In this lesson

  • Distinguish stolen, synthetic, document and farmed identity fraud, and identify the signals for each
  • Explain why synthetic identities are harder to detect than stolen ones and what follows for detection
  • Detect account takeover from the event sequence rather than from single signals
  • Identify the legitimate populations each identity control declines, and the mitigations

The control that everything else depends on

Identity is the foundation. If an operator does not know who holds an account, every downstream control is operating on a false premise: the responsible gambling assessment is assessing the wrong person, the source of funds enquiry is asking the wrong person, and the exclusion register check is checking the wrong name.

That makes onboarding the highest-leverage point in the whole fraud stack, and it is also the point under the most commercial pressure, because every additional step costs registrations. The tension is real and it is not resolvable by choosing a side. It is managed by putting the friction where the risk is.

Stolen identity

A real person's details, used by someone else. The details are genuine, so electronic verification passes, and the fraud is that the person operating the account is not the person identified.

Where the details come from. Data breaches, phishing, and purchased datasets. The volume available is large enough that assuming rarity is a mistake.

What it is for. Sometimes extraction of a bonus, sometimes laundering, sometimes an attempt to gamble while self-excluded under another name, and sometimes as a staging step for payment fraud using instruments belonging to the same victim.

Signals. Verification data that matches but with inconsistencies: an address that verifies while the device consistently geolocates elsewhere, a date of birth inconsistent with behavioural signals, contact details registered days before signup, and details appearing in known compromised sets. Device and connection characteristics shared across supposedly unrelated registrations are among the strongest.

The control that actually works. Matching the identity to the person rather than to the data. Document capture with a liveness check binds the two, which electronic data matching cannot do. Where a market permits it, verification against a source the fraudster cannot also control, such as a bank account in the same name, is stronger still.

The victim dimension. A person whose identity was used has a legitimate grievance against the operator that accepted it, and in several frameworks a reporting obligation attaches. Treating a stolen-identity case as purely an operator loss misses that entirely.

Synthetic identity

Real and fabricated elements combined into a person who does not exist: a genuine national identifier with a fabricated name, or a real address with invented details.

Synthetic identities are harder to detect than stolen ones for a specific reason: there is no victim to complain. A stolen identity generates a dispute eventually. A synthetic one never does, so the feedback loop that trains most detection never fires.

They are also frequently cultivated. An identity used successfully across other services accumulates a history, and by the time it reaches a gambling operator it verifies cleanly against several sources.

Signals. Thin or inconsistent history relative to the claimed age. An identifier that verifies while the name and address combination appears nowhere. Clusters of identities sharing address components, contact patterns or device characteristics. Behaviour at registration inconsistent with a genuine new customer: no hesitation, no correction, form completion faster than a human filling in their own details.

The structural mitigation is cross-referencing multiple independent sources rather than accepting a single match, and treating an identity that exists in exactly one data source as unverified rather than verified.

Document fraud

Forged, altered or borrowed identity documents, presented where electronic verification failed or was unavailable.

The quality range is wide. At the low end, obvious digital manipulation detectable by automated authenticity checks. At the high end, genuine documents belonging to someone else, or high-quality forgeries that require specialist examination.

The controls, in order of strength. Automated authenticity checks on the security features of the document image. Liveness checking binding the presenter to the document. Comparison of the document data against independent sources rather than accepting it on its own. And human review of the residual cases, which is expensive and is the right answer for a small number.

The specific failure to avoid is treating a document as verification in itself. A document establishes that a document exists. Binding it to the person and corroborating its content against something else is what turns it into verification, and an operator holding a folder of document images with no corroboration has collected artefacts rather than performed checks.

Account farming

Creating accounts in volume for later use or sale. The accounts may be opened with stolen, synthetic or genuine identities, frequently recruited.

This is an industrialised activity and its signature is industrial: registrations clustered in time, shared device or connection characteristics, sequential or patterned contact details, minimal or no play, and dormancy until the accounts are needed.

Why it matters even before the accounts are used. A farmed account population sitting dormant in an operator's estate is a future promotional abuse event, a future laundering route and a future multi-accounting problem, and it is far cheaper to detect at creation than after activation. Registration-time clustering analysis is the highest-return control against it and is frequently absent, because registration controls are optimised for conversion.

Account takeover

Unauthorised access to a legitimate customer's existing account. Mechanically the simplest threat in the set, and the one with the clearest signals and the most severe customer impact.

How it happens. Overwhelmingly credential reuse: the customer used the same password elsewhere, that service was compromised, and the credentials were tried against gambling operators. Credential stuffing at the login layer is the volume attack. Phishing and SIM-swap attacks on the recovery route account for the rest.

What the attacker wants. The balance, extracted either by withdrawal to a changed payment instrument, or by transferring value through play where the product permits it, or by using a stored instrument to deposit and then withdraw elsewhere.

Signals, which are among the clearest available. Login from an unfamiliar device, location or network. A change to payout details. A change to contact details, which is frequently done first specifically to prevent the customer being alerted. A withdrawal request inconsistent with the account's history. Activity at hours unusual for that customer. Password reset followed immediately by a payout change.

The sequence matters more than any single event. Contact change followed by payout change followed by withdrawal, in one session, is close to conclusive and should be treated as such rather than generating three separate alerts nobody correlates.

Controls. Multi-factor authentication, which is the single most effective and the one most resisted for conversion reasons. Alerting on credential, contact and payout changes to the previous contact details as well as the new ones, which is the control that defeats the alert-suppression step. Step-up authentication on payout changes. Session controls. Monitoring for credential stuffing patterns at the login layer rather than at the account layer, because the attack is visible in aggregate before it succeeds anywhere.

Handling matters as much as detection. From the customer's perspective a takeover is a failure of the operator's security. How fast it is detected, whether the funds are restored, and how the account is reinstated determines whether the relationship survives. An operator that recovers the loss and leaves the customer to argue about their balance has converted a security incident into a churn event and probably a complaint.

Multi-accounting

One person operating several accounts. Treated as a breach in most operator terms, and the motivations differ enough that the response should too.

Promotional exploitation. Repeated claiming of welcome offers. The most common motivation and the least serious.

Restriction evasion. Opening a new account after the previous one was limited or closed. A commercial problem for the operator.

Exclusion circumvention. A self-excluded person opening a new account. This is the serious one: it defeats a protective measure, the operator has an obligation to take reasonable steps to prevent it, and it is a compliance failure before it is a fraud one. It should route to the responsible gambling function, not to fraud recovery.

Collusion enablement in player-versus-player products, occupying several seats.

Bonus or advantage structures where holding several accounts creates an edge unavailable to a single account.

The detection is identity resolution, and its quality determines everything. Shared device fingerprints, payment instruments, addresses, contact details, behavioural patterns and network characteristics are the linking signals. The practical limitation, stated in the first lesson and worth repeating, is that resolution across brands in the same group is frequently weaker than operators believe, and resolution across the market generally does not exist without a scheme.

Where the false positives live

Every control above declines legitimate customers, and the populations it declines are not random.

Thin-file customers fail electronic verification through no fault of their own: young adults, recent arrivals in a country, people not on credit or electoral registers. Treating that failure as a fraud signal rather than a data coverage problem produces both discrimination and wasted investigation.

Shared households and shared devices produce genuine linkage between unrelated people. Two adults at one address on one home network, each with their own account, look exactly like multi-accounting to a naive linking rule.

Travellers and VPN users trigger geolocation inconsistency legitimately.

Customers who changed their circumstances genuinely move house, change their name, replace their phone and get a new card, and doing several of those in a month is unremarkable in life and alarming to a rules engine.

Customers with a new device trigger takeover signals on an ordinary phone upgrade.

The mitigations are the same in each case: treat a single signal as weak, require corroboration before acting, tier the response so a weak signal produces a low-friction check rather than a block, and route verification failures to an alternative method rather than to an investigation queue.

And measure it. The cost of these declines is the invisible half of the trade named in the first lesson: the acquisition cost already spent, the lifetime value forgone, the complaints generated, and the customers who simply leave without saying anything. A function reporting only prevented loss is reporting one side of its own effect.

Key terms

Synthetic identity
Real and fabricated elements combined into a person who does not exist. Harder to detect than a stolen identity because no victim ever disputes it.
Liveness check
Verification binding the person presenting a document to the document itself. The step that defeats a stolen or purchased document, which document-only checks cannot.
Account farming
Creating accounts in volume for later use or sale. Detectable at registration through clustering, and far cheaper to stop there than after activation.
Credential stuffing
Automated testing of credentials compromised elsewhere against an operator’s login. Visible in aggregate at the login layer before it succeeds on any account.
Thin file
A customer with little third-party data history, common among young adults and recent arrivals. An electronic verification failure here is a data coverage problem, not a fraud signal.

Key takeaways

  • Synthetic identities are harder than stolen ones because there is no victim to complain, so the feedback loop that trains most detection never fires.
  • A document establishes that a document exists. Binding it to the person and corroborating its content is what turns it into verification.
  • Account takeover shows as a sequence: contact change, then payout change, then withdrawal. Three separate alerts nobody correlates is the failure.
  • Alert on credential, contact and payout changes to the PREVIOUS contact details as well as the new ones, which defeats the alert-suppression step.
  • Exclusion circumvention by multi-accounting is a compliance failure before it is a fraud one, and routes to responsible gambling rather than to recovery.

Check your understanding

3 questions · answer them all, then check.

  1. 1. Why are synthetic identities harder to detect than stolen ones?

  2. 2. A takeover attacker changes the contact email before changing payout details. Why?

  3. 3. Two accounts at one address share a home network and a device. What does that establish?

Sign in to track your progress through the course.

Cookie Preferences

Choose which cookies you want to accept. Essential cookies are required for the website to function properly.

Required

Necessary for the website to function. Cannot be disabled.

Help us understand how visitors interact with our website.

Used to deliver relevant advertisements and track ad performance.

Remember your preferences and settings for a better experience.