SardineCon SF/2026

Learn More
Account & access fraud4 分で読めます

Account farmingとは?

SUBSCRIBE

Account farming is the mass creation of accounts, usually with bots, emulators, and throwaway phone numbers and emails, to stockpile them for later fraud, promo abuse, or resale. One farmed batch can fuel many separate attacks, so catching the batch early stops a lot of downstream harm at once.

What is account farming, in plain English?

Account farming is fraud's supply chain. Rather than opening one account to abuse, an operator mass-produces hundreds or thousands of them using automation: bots to fill signup forms, emulators to fake devices, and disposable phone numbers and emails to clear verification. The accounts are not used right away; they are stockpiled as inventory.

That inventory feeds many purposes. Some accounts are aged and sold, some are used for promotion and bonus abuse where each account claims a signup reward, some become mule accounts, and some are held in reserve for future scams. Because the accounts come off the same production line, a single farm can supply a wide range of downstream attacks.

The strategic point for defenders is leverage. Farmed accounts are created in batches that share tells, so if you can spot the batch, you can take down a whole cohort at once instead of fighting the resulting fraud account by account. Farming sits upstream of account aging, account selling, and much promo abuse.

How an account farm operates

  1. Tooling — Set up automation. Bots, emulators, and proxies are configured to run signups at scale and look like many devices.
  2. Identities — Feed in throwaway details. Disposable emails, virtual phone numbers, and copy-paste profile data clear the registration steps.
  3. Create — Mass-produce accounts. Accounts are opened in rapid batches, sometimes hundreds in a short window from shared infrastructure.
  4. Deploy — Stockpile, sell, or abuse. The batch is aged, sold, or used for promo abuse, mule activity, or coordinated fraud.

Who is involved?

Who

Their role

The farmer

Runs the automation and produces accounts in bulk as a product or as raw material for their own fraud.

Infrastructure suppliers

Provide proxies, virtual numbers, disposable emails, and emulator tooling that make scale possible.

The buyers

Fraudsters who purchase farmed accounts for takeover-free access, promo abuse, or mule use.

The platform

Bears the signup load and the downstream abuse, and is where the batch tells are visible.

What it looks like in practice

In practice

Over one evening, a service sees a spike of new signups: several hundred accounts in a few hours. On inspection, they share more than volume, many resolve to the same handful of device fingerprints, cycle through a narrow band of proxy IPs, and use profile names that follow the same template with minor tweaks.

Individually each account looks passable. Clustered, the batch is obvious. The farm intended to hold them for a bonus promotion launching that week, planning to claim one reward per account. Because the cohort was spotted on shared device and IP traits, the whole batch is closed before a single bonus is paid.

Why it matters to operators

Farming is where a lot of downstream fraud is cheapest to stop. If you only react to the eventual abuse, promo losses, mule activity, resold takeovers, you are fighting the same operator one incident at a time. Catch the batch at creation and you remove the ammunition before it is ever fired.

That is why the workflow here is cluster first, act at the batch level. Device intelligence, signup velocity limits, and phone and email reputation checks surface the shared infrastructure. Grouping accounts by common device fingerprints, IP ranges, funding sources, or templated profile data lets you take down the whole cohort in one move rather than chasing individuals as they surface.

What to watch for

  • Signup spikes. Bursts of new accounts clustered tightly in time, especially outside normal patterns.
  • Shared device fingerprints. Many accounts resolving to the same handful of devices or emulators.
  • Narrow IP and proxy ranges. Signups concentrated in a small set of IPs, data-center ranges, or proxy pools.
  • Disposable contacts. Virtual phone numbers and throwaway email domains with poor reputation.
  • Templated profiles. Copy-paste names and details with small variations across many accounts.

Quick questions

Why farm accounts instead of using one?

Scale and resilience. A stockpile lets an operator run many attacks, absorb takedowns, and sell surplus. Individual accounts get burned; a farm keeps producing more.

How is farming different from account aging?

Farming is the mass creation of accounts. Aging is deliberately keeping some of them quiet so they look established. Farms often age a portion of their inventory before selling or using it.

What makes farmed accounts detectable?

They are made on shared infrastructure at speed, so they cluster on device fingerprints, IP ranges, disposable contacts, and templated data. Those shared traits are the seam to pull on.

Why is batch-level action so valuable?

Because one farm feeds many attacks. Closing the whole cohort at once removes downstream promo abuse, mule accounts, and resold takeovers in a single move instead of one at a time.

What controls slow farming down?

Device intelligence, signup velocity limits, phone and email reputation checks, and challenges that are cheap for real users but costly for automation at scale.

Does emulator use always mean farming?

Not always, but a cluster of emulated devices behind a wave of signups is a strong signal. Combined with shared IPs and disposable contacts, it points firmly at a farm.

Go deeper

Account farmingと併せて知っておきたい用語