Fraud & Bonus Abuse B08 / 02

Multi-accounting in iGaming: Definition, How Operators Detect It and Why Network Analysis Is Essential

Multi-accounting is the practice of one individual operating multiple accounts at the same operator (or coordinating accounts across operators), typically to exploit promotional structures, evade self-exclusion, manipulate game outcomes or commit fraud. It is one of the most common…

iGaming Glossary · Category: Fraud & Bonus Abuse · Relevant for: Risk, Fraud, Compliance

iGaming GlossaryRiskFraudCompliance

TL;DR

Multi-accounting is the practice of one individual operating multiple accounts at the same operator (or coordinating accounts across operators), typically to exploit promotional structures, evade self-exclusion, manipulate game outcomes or commit fraud. It is one of the most common abuse patterns in iGaming and one of the harder to detect because each individual account can look legitimate. Effective detection requires technical signals (device, network, behavioural) combined with KYC integration and cross-customer pattern analysis.

Mechanics 02

How it works

Multi-accounting takes several forms with varying sophistication:

  • Individual multi-accounting: one person creating multiple accounts using slight identity variations (different middle names, alternate addresses, family members' details).
  • Synthetic identity fraud: combining real and fabricated identity components to create accounts not directly linked to any specific real person.
  • Identity theft: using stolen identity documents and details to create accounts in someone else's name.
  • Account farming: organised operations creating large numbers of accounts using purchased or coordinated identity sets.
  • Self-exclusion evasion: previously self-excluded customers creating new accounts to circumvent the protection.

Detection requires multiple signal types working together:

  • Identity matching: name, date of birth, document number similarity across accounts.
  • Address analysis: shared or normalised addresses, even with formatting differences.
  • Device fingerprinting: same device across multiple accounts.
  • Network signals: shared IP addresses, related ASN, network proximity.
  • Behavioural patterns: similar play styles, timing patterns, game preferences.
  • Payment method matching: shared bank cards, e-wallets, crypto wallet addresses.
Business context 03

Why it matters in iGaming

Multi-accounting is the foundation of large-scale bonus abuse and fraud operations. A single individual abusing welcome offers across 20 fake accounts is dramatically more damaging than the same person abusing one account. More importantly, multi-accounting circumventing self-exclusion has direct regulatory consequences: operators that allow self-excluded customers to re-register through obvious multi-accounting face significant enforcement action.

Different teams have multi-accounting responsibilities:

  • Risk and Fraud teams operate the detection systems and review flagged accounts.
  • Compliance treats multi-accounting in self-exclusion contexts as a primary regulatory priority.
  • KYC vendors typically provide initial duplicate detection during onboarding.
  • Customer support handles dispute resolution when account closures or restrictions affect legitimate customers.

Multi-accounting detection is also where the line between technical sophistication and customer experience is sharpest. Aggressive detection produces false positives that close legitimate accounts (family members sharing devices, customers using VPNs, customers with similar names). Lenient detection misses real abuse and produces regulatory exposure. The right operating point requires careful threshold tuning, manual review of borderline cases and clear customer communication.

Failure modes 04

Common mistakes and how operators get multi-accounting wrong

Single-signal detection. Rules based on individual signals ("same IP address") produce excessive false positives because legitimate customers share networks (households, public WiFi). Multi-signal scoring is far more accurate.

No device fingerprinting. IP-based detection alone misses customers using mobile networks, VPNs or shared connections. Device fingerprinting captures harder-to-fake identifiers (browser configuration, screen resolution, timezone, hardware patterns) that better discriminate.

Address matching too literal. "Apt 4B 123 Main St" and "123 Main Street, Unit 4B" should match. Operators with strict-string matching miss obvious duplicates with formatting variations. Address normalisation through specialist services produces much better matching.

Self-exclusion enforcement gaps. Self-excluded customers re-registering through multi-accounting represent particularly high regulatory risk. Operators with weak detection here face direct enforcement action because the harm pattern (excluded customer continuing to gamble) is clear.

No cross-customer pattern analysis. Looking at each account in isolation misses coordinated patterns. Network analysis identifying clusters of accounts sharing signals catches organised activity that single-account review misses.

Manual review without automation. Operators relying on human review of every potentially-multi-account case can't process the volume. Automation-first frameworks with human review on borderline cases are more scalable.

Documentation gaps in enforcement. Account closures based on multi-accounting need clear documentation supporting the decision. Customer disputes and regulator queries can otherwise produce embarrassing reversals.

What good looks like 05

What good looks like

Multi-accounting detection practices observed in well-run operators:

  • Multi-signal scoring combining identity, device, network, behavioural and payment signals.
  • Address normalisation through specialist services.
  • Robust device fingerprinting that survives common evasion attempts.
  • Cross-customer pattern analysis identifying coordinated networks.
  • Differentiated response based on confidence: investigation, restriction, closure.
  • Specific focus on self-exclusion enforcement given regulatory priority.
  • Clear documentation supporting enforcement decisions.
Gamblitude 07

How Gamblitude supports multi-accounting detection

Gamblitude consumes identity, device, network and behavioural signals from operator systems and exposes them through governed analytical views. Cross-customer pattern detection identifies clusters of accounts sharing signals, supporting investigation of organised activity. Risk teams build dynamic Lists of accounts matching multi-accounting patterns, feed them into review workflows and track investigation outcomes. Insight Radar surfaces emerging patterns of related accounts before they fully develop, supporting proactive intervention.

Explore Fraud, RG, AML & Compliance ↗
Questions 08

FAQ

Through behavioural patterns over time. Genuine family members typically have different play styles, different game preferences, different stake patterns and different session timing. Multi-accounting by one person across multiple accounts shows behavioural similarity that distinguishes it. Single-snapshot detection ("same device") cannot make this distinction; behavioural pattern analysis can.

No. Households, workplaces, university dorms and many other settings have multiple legitimate customers on shared networks. Network signal alone is insufficient for blocking. Multi-signal scoring with device fingerprinting, behavioural patterns and identity matching produces much better discrimination than network-based blanket rules.

Carefully. Some customers use VPNs for legitimate privacy reasons. Some use them to circumvent geo-blocking or evade self-exclusion. Detection should focus on the geo-blocking and self-exclusion contexts (where VPN use is concerning) rather than treating all VPN traffic as fraudulent. Some operators block VPN access for regulatory reasons in specific markets.

Self-exclusion evasion is the highest priority. Operators allowing self-excluded customers to re-register through obvious multi-accounting face direct enforcement action because the harm pattern is clear. Bonus abuse-driven multi-accounting is less heavily regulator-focused but still produces customer complaints and operational losses.

Not entirely. Determined organised actors can defeat any single detection method. The realistic goal is to make multi-accounting expensive and time-consuming enough that volume-based exploitation becomes uneconomic. The combination of detection signals and enforcement consequences raises the bar high enough that the worst cases stop being commercially viable.

Explore next 09

Further reading

Keep the glossary useful

Found a mistake or want a term added to the iGaming Glossary? Let us know.

Browse the complete glossary or see how governed definitions work across dashboards, reports, alerts and AI answers.