A few days each year, sportsbooks get exactly what every acquisition team dreams about: a flood of new signups arriving at once, drawn in by an event too big to ignore.
During events like the US Sports Equinox – the rare overlap of NFL, NBA, NHL and MLB action on the same weekend – or the Melbourne Cup, Australia's "race that stops a nation," betting volume spikes, welcome offers get pushed harder and new accounts pour in by the thousands.
But fraudsters watch the calendar just as closely as sportsbooks and fans.
Every spike in genuine signups doubles as cover for a less welcome kind of traffic: the same person or coordinated group opening account after account to claim a bonus meant for one new customer.
As a sports betting operator, this puts you in a tough spot. If you slow the journey down to interrogate every new player, you’ll frustrate the genuine users who are ready to use your platform. But leave the doors wide open, and bonus abuse eats into the margins of the very promotions designed to win those players over.
Finding the right balance requires understanding what multi-account fraud actually looks like, why major sporting events leave you especially exposed, and how to build a signup journey capable of telling a genuine new customer from someone who's already been through the door a dozen times before.
We’ll cover:
Curious how multi-account fraud detection looks in practice? Request a demo to see how our GBG Go solution flags resurfacing identities and suspicious patterns during signup.
Multi-account fraud occurs when a single individual or group creates and controls multiple accounts on the same platform while attempting to make each registration look like a distinct customer.
In sports betting, this often means abusing promotional signup bonuses: fraudsters open multiple accounts to repeatedly collect welcome bonuses, free bets and deposit matches that were designed as one-time acquisition incentives.
This issue isn't unique to gaming operators, though. Any business offering signup incentives faces similar exposure. In banking, for instance, when opening a new account includes a cash reward, bad actors have financial motivation to present themselves as new customers again and again.
Identifying sophisticated multi-account fraud during registration is difficult because bad actors alter their details across attempts. They routinely rotate:
Fraudsters can also use stolen or synthetic identity details alongside deepfake technology, automated bots, virtual private networks (VPNs) and device-masking tools.
An important point to keep in mind is that multi-account detection isn't the same thing as preventing an account takeover or verifying whether an individual identity is genuine. An applicant can pass an individual identity check while still operating a duplicate account within a broader multi-account ring.
So, rather than asking only if a single registration passes verification, you should evaluate what patterns appear when that registration is considered alongside other recent signup attempts.
Read more: Synthetic identity fraud detection: How to identify fake identities
Major events increase multi-account risks in a few different ways:
Stopping bonus abusers and repeat fraudsters takes more than matching names and addresses. It takes the right signals, in the right order, backed by authoritative data beyond a single database.
Here are some strategies:
Multi-account detection should look beyond exact matches against existing customer records.
This is where velocity monitoring comes in: it tracks how often the same or similar information (names, emails, devices, addresses) shows up across registration attempts within a given time frame, instead of just checking for exact duplicates. The key is identifying what stays constant and what changes between attempts.
For instance, the same name appearing twice with identical information might simply be a genuine player who abandoned a form and restarted. On the other hand, the same identity appearing repeatedly while the address, phone number, or email address changes every time indicates an elevated risk profile.
To be effective, velocity rules should:
You should also set a separate baseline for expected traffic during major events. Build this baseline ahead of time using historical data so you know what normal activity looks like. That way, when traffic spikes on event days, it’s easier to tell a genuine surge from a suspicious one.
Multi-account fraud is a pattern-recognition problem, not just a duplicate-data issue. The information a user submits at signup is only part of the picture: to catch coordinated fraud, you also need to evaluate the signals your systems generate about that applicant behind the scenes. Combine diverse signals to build an accurate picture of each applicant, such as:
Distinguish between an isolated unusual signal and a broader suspicious pattern. A newly created email address or an IP change can happen for legitimate reasons, after all. However, when several weak signals appear together across repeated signup attempts, that's usually a red flag.
Layering signals can also help prevent false positives. Evaluating multiple attributes together allows you to make confident decisions without blocking genuine players over a minor discrepancy.
When acquiring a new player, you know the least about that customer at the exact moment you need to decide whether to trust them.
An applicant might look completely new inside your database while maintaining a long, suspicious history across other platforms.
Relying solely on internal database history leaves your platform vulnerable to bad actors who rotate basic details. Incorporating external fraud intelligence provides the broader context you need to verify whether an applicant is truly new.
For example, the GBG Trust network draws on millions of identity insights across 28+ sectors to help surface patterns and connections that wouldn't necessarily be visible from the information submitted during an individual application.
Instead of asking if an account exists in your database, external intelligence like what GBG Trust provides lets you ask if broader digital signals and the applicant’s digital footprint suggest they are cycling through fake details or creating fake accounts to claim another welcome bonus.
Avoid responding to multi-account fraud by adding another verification requirement to every signup – that punishes genuine players with unnecessary friction and drives drop-off at registration. Instead, establish clear risk thresholds that dictate when additional assurance is actually necessary.
Low-risk applicants move through registration quickly without added friction. Higher-risk players step up to document or biometric verification, while significant-risk applications route directly to manual review or immediate rejection.
And if you define these threshold rules and escalation paths before peak traffic hits, you can ensure your system automatically handles traffic spikes without requiring too much manual intervention from your compliance or fraud teams.
The order you run checks isn’t just a technical detail: it shapes your costs and how fast genuine players get through signup.
Order your checks by how much risk they rule out relative to what they cost. A check like GBG Trust might cost more per signup than a basic email signal, but catching multi-accounting early can save you more than it costs since that traffic never reaches your more expensive verification steps.
This way, you’re not spending extra funds on document authentication or biometric liveness checks for registrations that were fraudulent from the start.
So, it may be a good idea to save higher-cost verification steps for signups that clear initial risk screening or those that specifically call for step-up verification.
Fraud tactics don’t stand still, so your onboarding controls can’t either – they need regular testing and tuning. What’s more, controls that perform well during normal traffic levels may behave differently once volume spikes.
Monitor key performance metrics on an ongoing basis:
Run A/B tests on different verification paths, risk thresholds, check sequences and escalation rules to see what actually works.
Before a major sporting event, set clear performance baselines, pinpoint where your current bottlenecks are and map out how your system should respond if specific fraud signals spike.
During and after the event, compare results against your baselines so you can sharpen your velocity rules before the next big game rolls around.
Preparing your sportsbook for major events like the Sports Equinox or the Melbourne Cup doesn't mean you should add more verification to every new signup.
Rather, the key is to have enough intelligence to spot suspicious patterns and enough flexibility to respond differently depending on the risk.
Our identity orchestration platform, GBG Go, brings these capabilities together in one unified system. It connects you to more than 110 verification modules through a single API across 195 countries.
Here are three reasons Lottoland, Atlantic Lottery and Betway choose to work with us:
Seeing the same first and last name pop up three times in your registration queue in a week isn't necessarily alarming: players abandon forms and mistype details all the time, then just try again. But if the address or phone number changes each time, that's a different story.
This is exactly the kind of pattern our GBG Trust solution is built to catch, across industries, before an account ever gets approved. It analyzes anomalies against a global consortium network, reaching a 96% identity fraud detection accuracy rate, and assigns every digital identity that touches your signup flow a real-time Trust Score from 1 to 100.
And our velocity monitoring lets you set your own rules of engagement: how many times an identity can resurface, and in what window, before it warrants a second look. That's what makes it possible to tell the difference between someone picking up an abandoned signup and someone cycling through new details to claim a fresh welcome bonus.
Run GBG Trust alongside your identity checks, and multi-accounting gets flagged early, reducing the risk of it slipping through undetected. From there, you can layer on email verification, phone intelligence, address verification or additional fraud signals to add context to whatever GBG Trust flags.
With GBG Go, you control the exact order and logic of your onboarding flow using a visual, drag-and-drop journey builder.
Low-cost checks, such as verifying whether an email address is disposable or a phone number is active, run first. More expensive verifications are earned only when they're actually needed.
By running pattern and velocity checks as an initial step, you flag resurfacing identities with shifting details before you've spent anything on other checks.
Clean registrations pass through to standard onboarding, while flagged attempts trigger targeted step-up checks or manual review.
You can also A/B test different journey configurations to optimize conversion rates. A genuine bettor signing up minutes before the Melbourne Cup gets approved instantly, while a multi-account pattern gets pulled aside.
Even the best-designed signup journey won't stop every multi-accounter.
Some fraudulent accounts look completely legitimate on their own. It's only once they start behaving that the connection between them becomes visible, which is exactly where ongoing fraud and transaction monitoring come into play.
Our iGaming transaction monitoring watches wagering, bonus redemption, deposits and withdrawals in real time. It looks for the kind of activity that often shows up after signup: unusual bonus redemption, wagering patterns that mirror suspiciously across accounts, or deposit and withdrawal behavior that doesn't add up.
Behavior like this builds up evidence over time, something a single point-in-time check can’t do. That’s what makes post-signup monitoring a necessary backstop for anything that slips through onboarding.
You set your own risk thresholds, fraud rules, alerts and workflows, so the response fits how your business actually operates.
Major sporting events are huge growth opportunities, but unmanaged multi-accounting can eat away at the profitability of your welcome promotions.
Lean too hard on rigid, manual checks and you’ll frustrate genuine bettors, while ignoring registration patterns makes your marketing budget a target for systematic bonus abuse.
The way through is combining real-time velocity monitoring, cross-industry intelligence and dynamic orchestration so you can protect your margins without slowing down the players who are actually there to play.
To see how GBG Go can help you detect multi-account fraud during signup, request a demo today.
Sports betting fraud covers deceptive or illegal activity targeting sportsbooks or sports bettors. This can include multi-accounting and bonus abuse, account takeover, identity and payment fraud, sports betting scams and, in a different category, match-fixing designed to manipulate betting outcomes.
For online sports betting operators, signs of suspicious activity can appear throughout the customer journey. These might include repeated registrations using similar details, unusual bonus redemption, linked accounts displaying identical wagering patterns or unusual deposit and withdrawal behavior.
Effective fraud protection therefore needs to extend beyond signup and monitor how accounts behave once customers begin placing a bet, claiming bonuses and moving funds.
Common signs include multiple signups coming from the same IP address or device fingerprint within a short timeframe, as well as registrations using variations of the same name or email structure.
Other indicators include repeated use of similar payment details, sudden spikes in signup velocity and accounts displaying identical betting or bonus redemption behaviors immediately after registration.
Sportsbooks can detect multi-account fraud by combining velocity monitoring, device fingerprinting and risk-based signals during registration. Using a cross-industry intelligence network like GBG Trust allows operators to spot resurfacing identity patterns and data anomalies across multiple platforms in real time, catching repeat registrants before bonuses are awarded.
Standard identity verification confirms whether an individual's data matches official records, but on its own, it may not stop multi-accounting if a fraudster uses valid or stolen details across multiple accounts.
Preventing multi-accounting requires combining identity verification with velocity rules, device intelligence and cross-industry pattern recognition to evaluate how a registration fits into broader sign-up trends.