Sportsbook fraud: Detecting multi-account fraud during signup

A few days each year, sportsbooks get exactly what every acquisition team dreams about: a flood of new signups arriving at once, drawn in by an event too big to ignore.

During events like the US Sports Equinox – the rare overlap of NFL, NBA, NHL and MLB action on the same weekend – or the Melbourne Cup, Australia's "race that stops a nation," betting volume spikes, welcome offers get pushed harder and new accounts pour in by the thousands.

But fraudsters watch the calendar just as closely as sportsbooks and fans.

Every spike in genuine signups doubles as cover for a less welcome kind of traffic: the same person or coordinated group opening account after account to claim a bonus meant for one new customer.

As a sports betting operator, this puts you in a tough spot. If you slow the journey down to interrogate every new player, you’ll frustrate the genuine users who are ready to use your platform. But leave the doors wide open, and bonus abuse eats into the margins of the very promotions designed to win those players over.

Finding the right balance requires understanding what multi-account fraud actually looks like, why major sporting events leave you especially exposed, and how to build a signup journey capable of telling a genuine new customer from someone who's already been through the door a dozen times before.

We’ll cover:

  • What is multi-account fraud?
  • Why sportsbooks face greater multi-account fraud exposure around major sporting events
  • How to build an effective signup flow for multi-account fraud detection
  • How to prepare for multi-account fraud with GBG

Curious how multi-account fraud detection looks in practice? Request a demo to see how our GBG Go solution flags resurfacing identities and suspicious patterns during signup.

What is multi-account fraud?

Multi-account fraud occurs when a single individual or group creates and controls multiple accounts on the same platform while attempting to make each registration look like a distinct customer.

In sports betting, this often means abusing promotional signup bonuses: fraudsters open multiple accounts to repeatedly collect welcome bonuses, free bets and deposit matches that were designed as one-time acquisition incentives.

This issue isn't unique to gaming operators, though. Any business offering signup incentives faces similar exposure. In banking, for instance, when opening a new account includes a cash reward, bad actors have financial motivation to present themselves as new customers again and again.

Identifying sophisticated multi-account fraud during registration is difficult because bad actors alter their details across attempts. They routinely rotate:

  • Email addresses and phone numbers
  • Residential addresses
  • Payment methods and banking credentials
  • Device fingerprints and IP addresses

Fraudsters can also use stolen or synthetic identity details alongside deepfake technology, automated bots, virtual private networks (VPNs) and device-masking tools.

An important point to keep in mind is that multi-account detection isn't the same thing as preventing an account takeover or verifying whether an individual identity is genuine. An applicant can pass an individual identity check while still operating a duplicate account within a broader multi-account ring.

So, rather than asking only if a single registration passes verification, you should evaluate what patterns appear when that registration is considered alongside other recent signup attempts.

Read more: Synthetic identity fraud detection: How to identify fake identities

Why sportsbooks face greater multi-account fraud exposure around major sporting events

Major events increase multi-account risks in a few different ways:

  • Higher promotional value increases the financial incentive for abuse. Welcome bonuses drive signups during major events, but any offer meant for one-time use gives bad actors a financial reason to pose as multiple new customers. The bigger the offer, the bigger the payout for opening dozens of accounts.
  • Fraudulent registrations hide inside legitimate signup spikes. A surge in signups on Melbourne Cup day or during the Sports Equinox is normal, but it makes fraud harder to spot. Hundreds of registrations per hour are expected, but one person generating 30 of them isn’t.
  • Time-sensitive bettors won’t tolerate friction. Someone signing up 20 minutes before kickoff wants to bet immediately. Adding manual reviews or extra verification for every applicant drives genuine players to abandon signup. Therefore, the goal is to increase scrutiny on risky signups while keeping the path fast for everyone else.

How to build an effective signup flow for multi-account fraud detection

Stopping bonus abusers and repeat fraudsters takes more than matching names and addresses. It takes the right signals, in the right order, backed by authoritative data beyond a single database.

Here are some strategies:

1. Look for combinations of repeated and changing information

Multi-account detection should look beyond exact matches against existing customer records.

This is where velocity monitoring comes in: it tracks how often the same or similar information (names, emails, devices, addresses) shows up across registration attempts within a given time frame, instead of just checking for exact duplicates. The key is identifying what stays constant and what changes between attempts.

For instance, the same name appearing twice with identical information might simply be a genuine player who abandoned a form and restarted. On the other hand, the same identity appearing repeatedly while the address, phone number, or email address changes every time indicates an elevated risk profile.

To be effective, velocity rules should:

  • Focus on combinations of attributes, not single data points alone
  • Define clear time windows (how many signups per hour or day)
  • Set thresholds for how many repeats are acceptable before triggering an intervention

You should also set a separate baseline for expected traffic during major events. Build this baseline ahead of time using historical data so you know what normal activity looks like. That way, when traffic spikes on event days, it’s easier to tell a genuine surge from a suspicious one.

2. Don't expect one signal to expose a multi-accounter

Multi-account fraud is a pattern-recognition problem, not just a duplicate-data issue. The information a user submits at signup is only part of the picture: to catch coordinated fraud, you also need to evaluate the signals your systems generate about that applicant behind the scenes. Combine diverse signals to build an accurate picture of each applicant, such as:

  • Identity information and public records
  • Email age, activity and risk history
  • Phone number type and line stability
  • Device fingerprints, emulators and network attributes
  • IP addresses, geolocation and proxy indicators
  • Physical address deliverability and location data
  • Payment method history and account details
  • Behavioral analysis during the registration session

Distinguish between an isolated unusual signal and a broader suspicious pattern. A newly created email address or an IP change can happen for legitimate reasons, after all. However, when several weak signals appear together across repeated signup attempts, that's usually a red flag.

Layering signals can also help prevent false positives. Evaluating multiple attributes together allows you to make confident decisions without blocking genuine players over a minor discrepancy.

3. Look beyond your own customer history

When acquiring a new player, you know the least about that customer at the exact moment you need to decide whether to trust them.

An applicant might look completely new inside your database while maintaining a long, suspicious history across other platforms.

Relying solely on internal database history leaves your platform vulnerable to bad actors who rotate basic details. Incorporating external fraud intelligence provides the broader context you need to verify whether an applicant is truly new.

For example, the GBG Trust network draws on millions of identity insights across 28+ sectors to help surface patterns and connections that wouldn't necessarily be visible from the information submitted during an individual application.

Instead of asking if an account exists in your database, external intelligence like what GBG Trust provides lets you ask if broader digital signals and the applicant’s digital footprint suggest they are cycling through fake details or creating fake accounts to claim another welcome bonus.

4. Make suspicious players prove more – not everyone else

Avoid responding to multi-account fraud by adding another verification requirement to every signup – that punishes genuine players with unnecessary friction and drives drop-off at registration. Instead, establish clear risk thresholds that dictate when additional assurance is actually necessary.

Low-risk applicants move through registration quickly without added friction. Higher-risk players step up to document or biometric verification, while significant-risk applications route directly to manual review or immediate rejection.

And if you define these threshold rules and escalation paths before peak traffic hits, you can ensure your system automatically handles traffic spikes without requiring too much manual intervention from your compliance or fraud teams.

5. Put your checks in an order that lets you act early

The order you run checks isn’t just a technical detail: it shapes your costs and how fast genuine players get through signup.

Order your checks by how much risk they rule out relative to what they cost. A check like GBG Trust might cost more per signup than a basic email signal, but catching multi-accounting early can save you more than it costs since that traffic never reaches your more expensive verification steps.

This way, you’re not spending extra funds on document authentication or biometric liveness checks for registrations that were fraudulent from the start.

So, it may be a good idea to save higher-cost verification steps for signups that clear initial risk screening or those that specifically call for step-up verification.

6. Test the journey before fraudsters test it for you

Fraud tactics don’t stand still, so your onboarding controls can’t either – they need regular testing and tuning. What’s more, controls that perform well during normal traffic levels may behave differently once volume spikes.

Monitor key performance metrics on an ongoing basis:

  • Form completion and drop-off rates
  • Automated verification pass rates
  • Manual review and escalation volumes
  • Where suspected fraud tends to get flagged
  • False positive rates across different customer segments

Run A/B tests on different verification paths, risk thresholds, check sequences and escalation rules to see what actually works.

Before a major sporting event, set clear performance baselines, pinpoint where your current bottlenecks are and map out how your system should respond if specific fraud signals spike.

During and after the event, compare results against your baselines so you can sharpen your velocity rules before the next big game rolls around.

How to prepare for multi-account fraud with GBG

Preparing your sportsbook for major events like the Sports Equinox or the Melbourne Cup doesn't mean you should add more verification to every new signup.

Rather, the key is to have enough intelligence to spot suspicious patterns and enough flexibility to respond differently depending on the risk.

Our identity orchestration platform, GBG Go, brings these capabilities together in one unified system. It connects you to more than 110 verification modules through a single API across 195 countries.

Here are three reasons Lottoland, Atlantic Lottery and Betway choose to work with us:

Spot patterns that individual signup checks can miss

Seeing the same first and last name pop up three times in your registration queue in a week isn't necessarily alarming: players abandon forms and mistype details all the time, then just try again. But if the address or phone number changes each time, that's a different story.

This is exactly the kind of pattern our GBG Trust solution is built to catch, across industries, before an account ever gets approved. It analyzes anomalies against a global consortium network, reaching a 96% identity fraud detection accuracy rate, and assigns every digital identity that touches your signup flow a real-time Trust Score from 1 to 100.

And our velocity monitoring lets you set your own rules of engagement: how many times an identity can resurface, and in what window, before it warrants a second look. That's what makes it possible to tell the difference between someone picking up an abandoned signup and someone cycling through new details to claim a fresh welcome bonus.

 

Run GBG Trust alongside your identity checks, and multi-accounting gets flagged early, reducing the risk of it slipping through undetected. From there, you can layer on email verification, phone intelligence, address verification or additional fraud signals to add context to whatever GBG Trust flags.

Spend more on verification only when the signals say to

With GBG Go, you control the exact order and logic of your onboarding flow using a visual, drag-and-drop journey builder.

Low-cost checks, such as verifying whether an email address is disposable or a phone number is active, run first. More expensive verifications are earned only when they're actually needed.

 

By running pattern and velocity checks as an initial step, you flag resurfacing identities with shifting details before you've spent anything on other checks.

Clean registrations pass through to standard onboarding, while flagged attempts trigger targeted step-up checks or manual review.

You can also A/B test different journey configurations to optimize conversion rates. A genuine bettor signing up minutes before the Melbourne Cup gets approved instantly, while a multi-account pattern gets pulled aside.

Prevent future fraud with transaction monitoring

Even the best-designed signup journey won't stop every multi-accounter.

Some fraudulent accounts look completely legitimate on their own. It's only once they start behaving that the connection between them becomes visible, which is exactly where ongoing fraud and transaction monitoring come into play.

Our iGaming transaction monitoring watches wagering, bonus redemption, deposits and withdrawals in real time. It looks for the kind of activity that often shows up after signup: unusual bonus redemption, wagering patterns that mirror suspiciously across accounts, or deposit and withdrawal behavior that doesn't add up.

 

Behavior like this builds up evidence over time, something a single point-in-time check can’t do. That’s what makes post-signup monitoring a necessary backstop for anything that slips through onboarding.

You set your own risk thresholds, fraud rules, alerts and workflows, so the response fits how your business actually operates.

 

 

Final thoughts

Major sporting events are huge growth opportunities, but unmanaged multi-accounting can eat away at the profitability of your welcome promotions.

Lean too hard on rigid, manual checks and you’ll frustrate genuine bettors, while ignoring registration patterns makes your marketing budget a target for systematic bonus abuse.

The way through is combining real-time velocity monitoring, cross-industry intelligence and dynamic orchestration so you can protect your margins without slowing down the players who are actually there to play.

To see how GBG Go can help you detect multi-account fraud during signup, request a demo today.

FAQs

What is sports betting fraud, and what suspicious activity should sportsbooks look for?

Sports betting fraud covers deceptive or illegal activity targeting sportsbooks or sports bettors. This can include multi-accounting and bonus abuse, account takeover, identity and payment fraud, sports betting scams and, in a different category, match-fixing designed to manipulate betting outcomes.

For online sports betting operators, signs of suspicious activity can appear throughout the customer journey. These might include repeated registrations using similar details, unusual bonus redemption, linked accounts displaying identical wagering patterns or unusual deposit and withdrawal behavior.

Effective fraud protection therefore needs to extend beyond signup and monitor how accounts behave once customers begin placing a bet, claiming bonuses and moving funds.

What are the signs of multi-account fraud?

Common signs include multiple signups coming from the same IP address or device fingerprint within a short timeframe, as well as registrations using variations of the same name or email structure.

Other indicators include repeated use of similar payment details, sudden spikes in signup velocity and accounts displaying identical betting or bonus redemption behaviors immediately after registration.

How can sportsbooks detect multi-account fraud during signup?

Sportsbooks can detect multi-account fraud by combining velocity monitoring, device fingerprinting and risk-based signals during registration. Using a cross-industry intelligence network like GBG Trust allows operators to spot resurfacing identity patterns and data anomalies across multiple platforms in real time, catching repeat registrants before bonuses are awarded.

Can identity verification prevent multi-accounting?

Standard identity verification confirms whether an individual's data matches official records, but on its own, it may not stop multi-accounting if a fraudster uses valid or stolen details across multiple accounts.

Preventing multi-accounting requires combining identity verification with velocity rules, device intelligence and cross-industry pattern recognition to evaluate how a registration fits into broader sign-up trends.