Skip to main content
Blog
Blog

Multi-accounting detection software: stop bonus abuse and referral fraud

Multi-accounting detection software links accounts to the same device fingerprint, catching bonus abuse and referral fraud before payouts go out.

Aug 04, 2026 5 min read
Multi-accounting detection software: stop bonus abuse and referral fraud
Table of Contents

TL;DR: multi-account detection stack for aged accounts

  • Identity checks are cheap: Email and SIM verification is a low bar to clear. Disposable inboxes and prepaid SIMs are cheap enough that fifty accounts with fifty different identifiers still trace back to one laptop.
  • What cside returns: cside builds a device fingerprint from 250+ browser signals that survives cookie clearing, incognito windows and VPN swaps, and returns both a stable device ID and the count of accounts already tied to it inside your chosen time window.
  • How to act on it: If iGaming welcome bonuses or SaaS referral payouts are quietly funding one operator's coffee habit, wire the signal into a delayed-eligibility rule. If IP-based linking is still on your roadmap, cancel it.

Short on time? See cside's real-time signup-fraud detection. It covers everything below in one deployment.

Multi-accounting is one person running several accounts on the same platform to claim a bonus, referral reward, or promo offer more than once. Multi-accounting detection software links those accounts back to a single operator so you can catch the abuse before the payout goes out.

The attacker uses a fresh email, phone number, and payment method for every account, which is why identity checks alone miss the pattern. The device fingerprint is different. It comes from hardware and browser signals the attacker cannot swap by rotating credentials, so it stays constant across all fifty accounts and links them together.

ToolSignal usedCatches same-device multi-accountingWorks across incognito sessionsFree tier
csideBrowser-layer hardware fingerprintYesYesYes, 1,000 API calls/mo
Email/phone verificationIdentity document validationNo, disposable identifiers bypass itN/AVaries
IP-based linkingIP address correlationPartial, shared IPs cause false positivesNoVaries

Where multi-accounting causes the most damage

iGaming and online casinos are the highest-exposure vertical. Welcome bonuses, free spins, and deposit match offers exist to acquire new customers. A single operator creating dozens of accounts to claim each welcome offer multiple times turns an acquisition cost into a direct loss. The economics are simple: if the bonus is worth more than the cost of creating an account, multi-accounting turns a profit.

SaaS with referral programs face a different version of the same attack. If a referral bonus pays $50 per new user referred, one person creating accounts to refer to themselves and collect on each referral is pulling money straight out of the referral budget.

Fintech and neobanks with new-account bonuses (sign-up credits, cashback on first transactions) face multi-accounting from organized groups that treat account creation as a revenue operation.

In every one of these cases the attacker's play is identity rotation: a new email, a new phone number, a new payment method for each account. Verification that only checks whether an email or phone is valid has no way to tell that the same person on the same laptop opened fifty accounts.

cside: device fingerprinting for multi-account linking

cside multi-accounting detection builds a stable device fingerprint from over 250 browser signals during each registration session. That fingerprint holds up across cookie clearing, incognito windows, and VPN use, the evasion tricks multi-accounters lean on, because it comes from physical hardware: GPU rendering output, font metrics, canvas entropy, WebGL behavior, and audio context.

When the same fingerprint shows up on more than one account, cside flags the link. It returns a stable device fingerprint ID for the session, a signal for whether that fingerprint has already been seen on other accounts, and the number of accounts tied to it within a time window you set.

Your platform decides what to do with that signal: delay bonus eligibility for new accounts on linked devices, ask for extra verification before a high-value promotion, or block registration outright when the device is already linked to a flagged account.

The detection runs passively. A legitimate user opening a single account from their own device sees no extra friction. Only registrations from devices already tied to other accounts surface in the signal.

Email and phone verification

Email and phone verification confirm that the person registering controls the email address or phone number they entered. They are a useful baseline against low-effort multi-accounting from casual bad actors who use obviously fake identifiers.

They do nothing against anyone with a supply of disposable email addresses or prepaid SIM cards, both cheap and widely used by multi-accounting operations. Someone who registers fifty accounts with fifty different emails from one laptop walks straight past email verification. Device fingerprinting is the control that catches that scenario.

IP-based account linking

IP-based linking flags accounts that register from the same IP address. It catches some cases, mainly attacks run from a single machine on a static IP, but it produces both false positives and false negatives in practice.

False positives: households, offices, and student dorms share IP addresses. Flag every account from one IP and you catch multi-accounters along with legitimate users who happen to share a connection.

False negatives: VPNs and residential proxies change the apparent IP with every session. An operator rotating VPN connections gets a fresh IP for each registration and slips past IP-based linking completely.

Device fingerprinting avoids both failure modes. The fingerprint changes only when the physical device changes.

Mike Kutlu
Client-Side Security Consultant

Client-side security consultant at cside. 10+ years of experience implementing technology solutions for enterprises (previously at Oracle, Cloudflare, and Splunk). Now helping teams use client-side intelligence to catch & reduce fraud.

FAQ

Frequently Asked Questions

Multi-accounting fraud is one person creating multiple accounts on a platform to claim bonuses, referral rewards, or promotional offers more than once. It shows up most in iGaming, SaaS with referral programs, and fintech with new-account bonuses.

The attacker rotates identity credentials (email addresses, phone numbers, payment methods) to look like different users while operating from one physical device.

Device fingerprinting builds a stable identifier from browser hardware signals (GPU rendering, font metrics, canvas entropy, WebGL output) that persist across email changes, cookie clearing, incognito mode, and VPN use. When several registrations produce the same fingerprint, they link back to one physical operator no matter which identity credentials were used.

cside surfaces the linked-account signal through its API at registration time, so your platform can act on it before the account is approved.

Sophisticated operators can try to evade fingerprinting by using a different physical device per account, such as a pool of cheap smartphones or virtual machines. That raises the operational cost sharply, because every device that yields a distinct fingerprint needs its own physical machine or a properly isolated virtual environment.

For the many multi-accounting operations that run at scale from a handful of machines, device fingerprinting stays highly effective.

It depends on the context. For bonus eligibility, delaying or adding verification for new accounts on linked devices is usually enough to break the economics of the attack without blocking real users.

For higher-risk cases, such as a device already tied to a flagged or banned account, blocking registration outright is appropriate. cside returns the signal; your platform sets the response policy.

Monitor and Secure Your Third-Party Scripts

Gain full visibility and control over every script delivered to your users to enhance site security and performance.

Start free, or try Business with a 14-day trial.

cside dashboard interface showing script monitoring and security analytics
Related Articles
Book a demo

Want to walk through this with an engineer?

Thirty minutes, on your own site. Not a slide deck.

We'll show you:

Which third-party scripts are running on your site right now
Where you stand on PCI DSS 6.4.3 and 11.6.1
How much of your traffic is bots and AI agents

Rather just send a question?

Finding open slots…

Real humans only. We'd know.

Having trouble booking? Open scheduler in a new tab

What are you trying to solve?

Tell us in a line and we'll come back with something useful, not a generic pitch.

We usually help with:

Seeing which third-party scripts run on your site
PCI DSS 6.4.3 and 11.6.1 evidence
Bots, AI agents and account takeover

Prefer to just book a time? Pick a slot instead