Solution

Fake account detection that stops bot signups at the front door

Fake account creation is the bulk registration of accounts that do not belong to real, distinct customers, made by bots, device farms or synthetic identities and later used for spam, promo abuse, fake reviews, mule activity or resale. Kavra assesses each signup for automation, spoofed devices and shared infrastructure before the account exists.

POST /signupBlocked

Scripted signup from a phone emulator

  • Android emulator, spoofed model
  • Part of a 300-signup surge
  • Disposable email domain
Risk95
Your actionReject the signup
Who it hits
Marketplaces, social, fintech, SaaS, retail
What it costs
Spam, fraud, SMS fees, polluted metrics
Tools used
Signup bots, emulators, device farms, proxies
Where to stop it
At signup, before the account is live

What is fake account creation?

A fake account is any account registered without a real, distinct person or business behind it who intends to use the service as designed. Some are created by scripts in the thousands. Some are created by hand in phone farms. Some carry a convincing but invented identity. What they share is that the account is a tool for something else.

Fake accounts are the raw material of most online abuse. They are cheap to make in bulk, stored until needed, and often sold as aged accounts that look more trustworthy than fresh ones. Stopping them at signup is far cheaper than finding them later by what they do.

What fake accounts are used for

The signup is rarely the goal. Knowing the end use tells you where the damage will land.

UseWhat happens nextWho feels it
Promo and referral farmingWelcome offers and referral rewards claimed once per fake accountGrowth and finance teams
Spam and scamsMessages, comments and fake listings pushed to real usersTrust and safety, users
Fake reviews and ratingsProducts, sellers or apps boosted or attackedMarketplaces and their buyers
Mule and payment fraudAccounts receive and move stolen funds or test stolen cardsFintech compliance and payments
SMS and OTP abuseSignups trigger verification texts to premium numbersTelecom budget, see SMS pumping
Free tier and API farmingTrials, credits and API keys multipliedSaaS and AI product costs
ResaleAged or verified accounts sold to other fraudstersEvery team, later

How bulk fake account creation works

Fake account operations run like small factories, with each stage bought or automated.

  1. 01

    Source identities

    Emails come from disposable or bulk-registered domains, phone numbers from virtual number services, and names from generators or leaked data. For regulated products, synthetic identities mix real and invented details to pass onboarding checks.

  2. 02

    Provision devices

    Scripts run in headless browsers on servers, Android emulators imitate phones, and device farms run racks of real handsets for apps that check hardware.

  3. 03

    Rotate networks

    Each signup exits through a different residential or mobile proxy so that no single IP address stands out.

  4. 04

    Automate the form

    Bots fill the signup form, click email links, read codes from virtual numbers and pass CAPTCHAs through solving services. Human workers handle the steps that bots fail.

  5. 05

    Age and deploy

    Accounts are left to sit, warmed up with light activity, then used in a campaign or sold. Aged accounts slip past rules that only distrust brand-new users.

Who it hits and what it costs

Every product with open registration gets fake signups. The cost depends on what a new account can do. On marketplaces and social products, fake accounts erode trust in listings, reviews and messages. In fintech, they open the door to mule networks and regulatory scrutiny. In SaaS and AI, each fake account consumes compute, credits and support time. In retail and iGaming, they turn marketing budgets into payouts for fraud rings.

  • Direct fraud: rewards, credits and payments captured through accounts that should not exist.
  • Variable costs: SMS verification, email sending, compute and storage for accounts with no customer behind them.
  • Bad data: inflated signup, activation and user counts that mislead planning and investors.
  • Cleanup: moderation, bans and appeals for accounts that could have been refused in a single step.

Warning signs of fake signups

Fake accounts give themselves away by what they share and how they are made.

  • Signup surges

    Sudden spikes of new accounts with no matching campaign, often at night in your main market.

  • Emulated or virtual devices

    Phones that run on desktop hardware and browsers inside virtual machines.

  • Automation traces

    Headless browsers, automation frameworks and forms completed with no real typing.

  • Patterned emails

    Disposable domains, sequential usernames or random strings on free providers.

  • Shared infrastructure

    Many signups sharing a device, proxy provider or network range.

  • Dormant after signup

    Accounts that verify, then go quiet until a campaign or a sale.

Why common signup defenses fall short

Signup checks often validate the details, not the actor typing them.

DefenseWhat it provesWhat it misses
Email verificationThe inbox existsDisposable and bulk-registered inboxes verify fine
SMS verificationThe number receives textsVirtual numbers, and each text costs you money
CAPTCHASomeone solved a puzzleSolving services and farm workers solve them at scale
IP rate limitsFew signups per addressProxy pools give every signup its own address
Document checksAn ID was presentedSynthetic and stolen identities, plus friction for real customers

How to prevent fake account creation

The best time to stop a fake account is before it exists. That needs a decision at the signup request, based on who is really submitting it, with extra checks saved for the uncertain middle.

  • Assess every signup on web, mobile app and API, not only the website form.
  • Detect automation, emulators, virtual machines and device farms directly.
  • Link signups by device and network so a surge from one operator shows up as one campaign.
  • Recognize residential and mobile proxy exits even when the IP looks like a home connection.
  • Send SMS codes only after the signup passes a risk check, to avoid paying for fake verifications.
  • Verify or limit uncertain new accounts, for example by delaying rewards or messaging, instead of rejecting them outright.
  • Recheck accounts when they first do something valuable, so aged fakes are caught too.

Measure the result by what fake accounts stop doing, not only by how many signups you reject. Fewer spam reports, lower SMS spend per real customer, fewer referral payouts to linked accounts and cleaner activation numbers are the signs the filter is working. If rejections rise but downstream abuse does not fall, the fakes are getting through a door you are not watching, such as the mobile app or a partner API.

A real signup vs a fake account

Real signup

  • A real phone or computer that behaves like one
  • Home or carrier network that fits the device
  • Typing, pauses and the odd mistake
  • Uses the product after signing up

Fake account

  • Emulator, virtual machine or farm handset
  • Proxy exit, new IP for every signup
  • Form filled by script or at machine speed
  • Idle, then used for one job

Sources

  1. OWASP Automated Threats to Web Applications: OAT-019 Account Creation
  2. OWASP Automated Threats to Web Applications: OAT-017 Spamming
  3. OWASP Automated Threats to Web Applications: OAT-009 CAPTCHA Defeat
  4. Federal Reserve FedPayments Improvement: Synthetic Identity Fraud
  5. OWASP API Security Top 10: API4:2023 Unrestricted Resource Consumption

How Kavra helps

How Kavra stops fake account creation

Kavra assesses each signup with 3,000+ data points and returns a clear recommendation before your backend creates the account.

  • Signup bots exposed

    Headless browsers, automation frameworks and HTTP clients imitating browsers are caught by contradictions between layers.

  • Emulators and farms

    Emulators, virtual machines, device farms and spoofed devices are flagged on web and through native iOS and Android SDKs.

  • Coordinated campaigns

    Surges of new devices, shared infrastructure and velocity anomalies are grouped, so one operator's burst shows up as one campaign.

  • Proxy intelligence

    Kavra measures real exit IPs of commercial residential and mobile proxy networks, on top of 30+ public reputation feeds.

  • Invisible to real users

    No CAPTCHA, puzzle or slider, ever. Extra invisible checks run when evidence is unclear, with nothing for the visitor to solve.

  • Your policy, your call

    Choose cautious, balanced or strict presets, start in observe-only mode, and let your backend allow, verify or reject.

FAQ

Frequently asked questions

Something else? Talk to our team.

How do you detect fake accounts?

Look at how the account was made, not only at the details entered. Automation, emulated devices, proxy networks and many signups sharing one device or network are strong signs. Kavra checks these layers on every signup and groups related signups, so a bulk campaign stands out even when each account looks plausible alone.

Why do people create fake accounts?

Mostly for money or reach. Fake accounts farm signup bonuses and referrals, post spam and scams, write fake reviews, move stolen funds, test stolen cards, multiply free trials and API quotas, and inflate follower or vote counts. Many are also sold to other fraudsters, especially once they have aged or passed verification.

What is a synthetic identity?

A synthetic identity combines real and invented details, such as a real identification number with a made-up name and date of birth, to create a person who does not exist. It can pass basic onboarding checks and build a credit or trust history over time. It matters most in fintech and lending, where it is used to obtain credit that is never repaid.

Does phone verification stop fake accounts?

It slows casual abuse but not organized operations. Virtual number services supply codes cheaply, and each verification text costs you money. Attackers can even abuse the SMS step itself for toll fraud. Assessing the signup first and sending codes only to low-risk requests cuts both fake accounts and messaging costs.

Should I block suspicious signups or let them in and watch?

Block when the evidence is clear, such as automation from an emulator in a signup surge. When it is mixed, let the account exist with limits: no rewards, no messaging or lower limits until it shows normal activity. Starting in observe-only mode shows which approach suits your traffic before you enforce anything.

See who is really on your site.

Run Kavra on your own traffic in observe-only mode. No risk to your customers, and a clear report of the fraud it finds.