POST /signupBlockedScripted signup from a phone emulator
- Android emulator, spoofed model
- Part of a 300-signup surge
- Disposable email domain
Solution
Fake account creation is the bulk registration of accounts that do not belong to real, distinct customers, made by bots, device farms or synthetic identities and later used for spam, promo abuse, fake reviews, mule activity or resale. Kavra assesses each signup for automation, spoofed devices and shared infrastructure before the account exists.
POST /signupBlockedScripted signup from a phone emulator
A fake account is any account registered without a real, distinct person or business behind it who intends to use the service as designed. Some are created by scripts in the thousands. Some are created by hand in phone farms. Some carry a convincing but invented identity. What they share is that the account is a tool for something else.
Fake accounts are the raw material of most online abuse. They are cheap to make in bulk, stored until needed, and often sold as aged accounts that look more trustworthy than fresh ones. Stopping them at signup is far cheaper than finding them later by what they do.
The signup is rarely the goal. Knowing the end use tells you where the damage will land.
| Use | What happens next | Who feels it |
|---|---|---|
| Promo and referral farming | Welcome offers and referral rewards claimed once per fake account | Growth and finance teams |
| Spam and scams | Messages, comments and fake listings pushed to real users | Trust and safety, users |
| Fake reviews and ratings | Products, sellers or apps boosted or attacked | Marketplaces and their buyers |
| Mule and payment fraud | Accounts receive and move stolen funds or test stolen cards | Fintech compliance and payments |
| SMS and OTP abuse | Signups trigger verification texts to premium numbers | Telecom budget, see SMS pumping |
| Free tier and API farming | Trials, credits and API keys multiplied | SaaS and AI product costs |
| Resale | Aged or verified accounts sold to other fraudsters | Every team, later |
Fake account operations run like small factories, with each stage bought or automated.
Emails come from disposable or bulk-registered domains, phone numbers from virtual number services, and names from generators or leaked data. For regulated products, synthetic identities mix real and invented details to pass onboarding checks.
Scripts run in headless browsers on servers, Android emulators imitate phones, and device farms run racks of real handsets for apps that check hardware.
Each signup exits through a different residential or mobile proxy so that no single IP address stands out.
Bots fill the signup form, click email links, read codes from virtual numbers and pass CAPTCHAs through solving services. Human workers handle the steps that bots fail.
Accounts are left to sit, warmed up with light activity, then used in a campaign or sold. Aged accounts slip past rules that only distrust brand-new users.
Every product with open registration gets fake signups. The cost depends on what a new account can do. On marketplaces and social products, fake accounts erode trust in listings, reviews and messages. In fintech, they open the door to mule networks and regulatory scrutiny. In SaaS and AI, each fake account consumes compute, credits and support time. In retail and iGaming, they turn marketing budgets into payouts for fraud rings.
Fake accounts give themselves away by what they share and how they are made.
Sudden spikes of new accounts with no matching campaign, often at night in your main market.
Phones that run on desktop hardware and browsers inside virtual machines.
Headless browsers, automation frameworks and forms completed with no real typing.
Disposable domains, sequential usernames or random strings on free providers.
Many signups sharing a device, proxy provider or network range.
Accounts that verify, then go quiet until a campaign or a sale.
Signup checks often validate the details, not the actor typing them.
| Defense | What it proves | What it misses |
|---|---|---|
| Email verification | The inbox exists | Disposable and bulk-registered inboxes verify fine |
| SMS verification | The number receives texts | Virtual numbers, and each text costs you money |
| CAPTCHA | Someone solved a puzzle | Solving services and farm workers solve them at scale |
| IP rate limits | Few signups per address | Proxy pools give every signup its own address |
| Document checks | An ID was presented | Synthetic and stolen identities, plus friction for real customers |
The best time to stop a fake account is before it exists. That needs a decision at the signup request, based on who is really submitting it, with extra checks saved for the uncertain middle.
Measure the result by what fake accounts stop doing, not only by how many signups you reject. Fewer spam reports, lower SMS spend per real customer, fewer referral payouts to linked accounts and cleaner activation numbers are the signs the filter is working. If rejections rise but downstream abuse does not fall, the fakes are getting through a door you are not watching, such as the mobile app or a partner API.
How Kavra helps
Kavra assesses each signup with 3,000+ data points and returns a clear recommendation before your backend creates the account.
Headless browsers, automation frameworks and HTTP clients imitating browsers are caught by contradictions between layers.
Emulators, virtual machines, device farms and spoofed devices are flagged on web and through native iOS and Android SDKs.
Surges of new devices, shared infrastructure and velocity anomalies are grouped, so one operator's burst shows up as one campaign.
Kavra measures real exit IPs of commercial residential and mobile proxy networks, on top of 30+ public reputation feeds.
No CAPTCHA, puzzle or slider, ever. Extra invisible checks run when evidence is unclear, with nothing for the visitor to solve.
Choose cautious, balanced or strict presets, start in observe-only mode, and let your backend allow, verify or reject.
FAQ
Something else? Talk to our team.
Look at how the account was made, not only at the details entered. Automation, emulated devices, proxy networks and many signups sharing one device or network are strong signs. Kavra checks these layers on every signup and groups related signups, so a bulk campaign stands out even when each account looks plausible alone.
Mostly for money or reach. Fake accounts farm signup bonuses and referrals, post spam and scams, write fake reviews, move stolen funds, test stolen cards, multiply free trials and API quotas, and inflate follower or vote counts. Many are also sold to other fraudsters, especially once they have aged or passed verification.
A synthetic identity combines real and invented details, such as a real identification number with a made-up name and date of birth, to create a person who does not exist. It can pass basic onboarding checks and build a credit or trust history over time. It matters most in fintech and lending, where it is used to obtain credit that is never repaid.
It slows casual abuse but not organized operations. Virtual number services supply codes cheaply, and each verification text costs you money. Attackers can even abuse the SMS step itself for toll fraud. Assessing the signup first and sending codes only to low-risk requests cuts both fake accounts and messaging costs.
Block when the evidence is clear, such as automation from an emulator in a signup surge. When it is mixed, let the account exist with limits: no rewards, no messaging or lower limits until it shows normal activity. Starting in observe-only mode shows which approach suits your traffic before you enforce anything.
Run Kavra on your own traffic in observe-only mode. No risk to your customers, and a clear report of the fraud it finds.