# Multi-accounting detection that sees one person behind many accounts

Source: https://kavralab.com/solutions/multi-accounting/

**Multi-accounting** is when one person or group creates and runs several accounts on the same platform to claim repeat bonuses, bypass limits, manipulate outcomes or return after a ban. Kavra links those accounts back to the device, network and behavior they share, even when each one looks new.

- **Who it hits:** iGaming, fintech, marketplaces, SaaS, e-commerce
- **What it costs:** Bonus budgets, referral payouts, skewed data
- **Tools used:** Antidetect browsers, proxies, emulators, scripts
- **Where to stop it:** At signup, before the first reward

## What is multi-accounting?

Multi-accounting means one real person, or one organized group, controlling more than one account on a service that expects one account per person. On its own, a second account is not always fraud. It becomes fraud when the extra accounts exist to take something the rules give only once: a welcome bonus, a free trial, a referral reward, a first-order discount, a voting right or a fresh start after a ban.

Modern multi-accounting is rarely manual. Operators run tens or hundreds of accounts from one laptop with an [antidetect browser](https://kavralab.com/detect/antidetect-browsers/), route each one through a different [residential proxy](https://kavralab.com/detect/residential-proxies/), and script the signup flow. Every account looks like a different person, on a different device, in a different city.

## How a multi-accounting attack works

Most campaigns follow the same playbook, whether the target is a sportsbook bonus or a SaaS free tier.

1. **Build identities**: The operator buys or generates emails, phone numbers and sometimes documents. Disposable inboxes and virtual numbers make each identity cheap.
2. **Mask the device**: Each account gets its own browser profile with a spoofed device: different screen, graphics card, fonts, timezone and language. Emulators and virtual machines do the same on mobile.
3. **Mask the network**: Traffic for each profile exits through a different residential or mobile IP address, usually in the same country as the target audience.
4. **Automate the flow**: Scripts or automation frameworks fill in forms, verify emails and claim the reward, often in bursts timed around a promotion.
5. **Cash out**: Rewards are withdrawn, consolidated into one account, resold, or used to tilt a result, such as matched bets, fake reviews or ranking manipulation. By the time the pattern shows up in reports, the budget is already spent.

## Who it hits and what it costs

Any business that gives something of value to a new account is a target. In **iGaming**, it drains welcome bonuses and free bets through what the industry calls bonus abuse and [gnoming](https://kavralab.com/glossary/gnoming/). In **fintech**, duplicate accounts collect signup rewards and hide mule activity. On **marketplaces**, they post fake listings, leave fake reviews and return after bans. In **SaaS and AI products**, they farm free credits and trials. In **e-commerce**, they stack first-order discounts.

- Direct losses: bonuses, credits, referral payouts and discounts paid to the same person many times.
- Polluted data: inflated signup and activation numbers that mislead marketing and product decisions.
- Unfair outcomes: manipulated rankings, votes, raffles and limited drops that real customers lose.
- Operational load: manual reviews, support tickets and chargebacks from accounts that should never have existed.

## Multi-accounting by industry

The technique is the same everywhere. What the operator is after changes.

| Industry | What multi-accounters farm | Where to check |
|---|---|---|
| [iGaming and betting](https://kavralab.com/industries/igaming/) | Welcome bonuses, free bets, odds boosts, arbitrage limits | Signup, bonus claim, withdrawal |
| [Fintech and banking](https://kavralab.com/industries/fintech/) | Signup rewards, referral payouts, mule accounts | Onboarding, first transfer |
| [Marketplaces](https://kavralab.com/industries/marketplaces/) | Fake listings, fake reviews, ban evasion | Seller signup, listing, review |
| [SaaS and AI products](https://kavralab.com/industries/saas-ai/) | Free trials, free credits, API quotas | Signup, trial start, API key creation |
| [E-commerce and retail](https://kavralab.com/industries/ecommerce/) | First-order discounts, limited drops, loyalty points | Account creation, checkout |
| [Travel and ticketing](https://kavralab.com/industries/travel/) | Ticket limits per customer, fare holds | Account creation, cart, checkout |

## Warning signs of multi-accounting

No single signal proves it. Patterns across accounts do.

- **Devices that do not add up**: A browser claims one graphics card and screen, but renders like another. Profiles that differ on the surface behave identically underneath.
- **Clean IPs from proxy networks**: Every signup comes from a different home IP address in the right country, yet the addresses belong to commercial proxy pools.
- **One device, many fingerprints**: The same returning visitor shows up with a new fingerprint on each visit. Rotation is itself a signal.
- **Identical behavior**: Forms filled in the same order at the same speed, with pasted values and no hesitation, across many new accounts.
- **Bursts around promotions**: Spikes of new accounts right after an offer launches, clustered by time, network or email pattern.
- **Shared destinations**: Different accounts withdraw to the same wallet or card, or refer each other in chains.

## Why common defenses miss it

Each classic check covers one layer. Multi-accounting tools are built to pass exactly that layer.

| Defense | What it checks | How multi-accounters get past it |
|---|---|---|
| Email and phone verification | That the contact exists | Disposable inboxes and virtual numbers cost cents |
| IP blocklists | Known bad addresses | Residential proxies rotate through real home IPs |
| Cookies and local storage | A returning browser | Each antidetect profile starts with empty storage |
| Basic device fingerprinting | What the browser reports | Antidetect browsers rewrite every reported value |
| CAPTCHA | That a human is present | Solving services and a human operator pass it easily |
| KYC at signup | A real identity document | Adds friction for everyone, and stolen or borrowed identities still pass |

## How to prevent multi-accounting

The goal is to recognize the same actor across accounts without adding friction for the honest majority. That takes evidence from several layers at once, checked for contradictions, and a decision at the moment it matters: before the reward is granted.

- Assess every signup, not a sample. The first account in a ring looks clean; the tenth one shares its evidence.
- Look past what the browser says about itself. Compare the claimed device with how it actually behaves and with the network it uses.
- Treat a changing fingerprint on a returning device as a warning, not a new visitor.
- Recognize proxy and VPN traffic by what it is, not only by where it appears to come from.
- Delay or verify the reward, not the signup, when evidence is mixed. Step up only the risky few.
- Link accounts by shared device, network and behavior, and review clusters instead of single users.

## A real new customer vs a multi-accounter

**Real new customer**

- Device and browser are consistent on every layer
- Home broadband or mobile carrier that matches the device
- Hesitates, corrects typos, reads the terms
- No link to existing accounts

**Multi-accounter**

- Spoofed device that contradicts itself
- Residential proxy exit, new IP for every account
- Pasted values, identical timing across signups
- Shares device, network or payout with other accounts

> **Key takeaway:** Multi-accounting beats checks that look at one layer at a time. Stop it by linking accounts through the evidence they cannot easily change together, and decide **before** the bonus or credit is paid. See how the same approach stops [bonus abuse](https://kavralab.com/solutions/bonus-abuse/) and [fake account creation](https://kavralab.com/solutions/fake-accounts/).

## How Kavra stops multi-accounting

Kavra analyzes 3,000+ data points on every visit and links accounts that share an actor, then tells your backend what it found, in plain language.

- **Identity and device linking**: Returning devices are recognized across visits and accounts, so one actor behind many signups shows up as one cluster.
- **Rotation is a signal**: When a device changes its fingerprint but stays the same actor, Kavra keeps one identity and flags the rotation.
- **Spoofed environments exposed**: Antidetect profiles, emulators and virtual machines are caught by the contradictions between what they claim and how they behave.
- **Proxy intelligence**: Kavra measures real exit IPs of commercial residential and mobile proxy networks, on top of public reputation feeds.
- **AI/ML risk engine**: Every layer is weighed together, and models keep learning from new fraud patterns without adding friction for real users.
- **You decide the outcome**: Allow, verify or block with your own rules. Start in observe-only mode to see every linked account before acting.

## FAQ

### Is multi-accounting illegal?

Usually it is not a crime by itself, but it breaks the terms of service of most platforms that offer bonuses, trials or one-account-per-person rules. It can become fraud when accounts are used to obtain money, rewards or credit under false pretenses, which is why operators close the accounts and withhold the rewards.

### How do you detect multiple accounts from the same person?

By linking accounts through evidence they share and cannot easily change together: the real device behind a spoofed profile, the network it uses, how it behaves and its history. Kavra checks these layers for contradictions on every visit and groups accounts that belong to the same actor.

### Can antidetect browsers hide multi-accounting?

They hide it from checks that trust what the browser reports. They rewrite the device values a page can read, but they struggle to keep every layer consistent at once. Kavra looks for those inconsistencies, so a profile that looks new on the surface can still be linked to the actor behind it.

### Does multi-accounting detection hurt real customers?

It should not. Families sharing a home network or a device are normal, so good detection weighs many signals instead of blocking on one. Kavra runs invisibly, never shows CAPTCHA puzzles, and lets you verify or delay only the risky few while everyone else signs up without friction.

### Should I block multi-accounting at signup or at withdrawal?

Assess at signup and act before value leaves. Checking at signup stops rewards from being granted to linked accounts, while a second check at bonus claim or withdrawal catches accounts that looked clean at first and later joined a ring.

### What is the difference between multi-accounting and bonus abuse?

Multi-accounting is the technique: many accounts run by one actor. Bonus abuse is one of the main reasons to do it: claiming a welcome offer, free bet or promo code many times. Most bonus abuse relies on multi-accounting, but multi-accounting is also used for ban evasion, review fraud and vote manipulation.

---
Kavra Lab: bot and fraud detection that explains every decision. Book a demo: https://kavralab.com/contact/
