SardineCon SF/2026

Learn More
Identity verification4 分で読めます

Duplicate account detectionとは?

SUBSCRIBE

Duplicate account detection finds multiple accounts run by one party. That is a classic sign of promo and bonus abuse, ban evasion, mule networks, or synthetic clusters, so linking hidden accounts back to a single controller is a core fraud control.

What is duplicate account detection, in plain English?

Duplicate account detection is the work of spotting when many accounts are really controlled by one person or one operation. On the surface each account looks separate, with its own name and email, but underneath they share the same hand on the controls. That single controller is often up to something: promo and bonus abuse, ban evasion, running a mule network, or seeding a synthetic cluster.

The trick is that it cannot rely on name alone, because fraudsters change the obvious fields freely. Instead it leans on the things that are harder to vary at scale: device fingerprints, IP addresses, payment cards, addresses, and behavioral patterns like the same typing rhythm or the same daily timing. When enough of these line up across accounts, they are probably one party.

In fraud and AML, this sits alongside entity resolution and network analysis. It is how you turn a pile of look-alike accounts into a picture of who actually controls them, which is the difference between blocking one account and unwinding a whole cluster.

Signal

Why it links accounts

Device fingerprint

The same device or emulator behind many accounts is hard to fake away and strongly links them.

Payment instrument

A shared card, bank account, or wallet often ties supposedly separate users to one funder.

Network and location

Repeated IPs, address reuse, or the same geolocation across accounts suggest a single operator.

Behavior

Matching typing cadence, session timing, and navigation patterns reveal the same person at the keyboard.

Who is involved?

Who

Their role

The abuser

Opens many accounts to farm bonuses, dodge a ban, or run mules under one hidden hand.

The fraud team

Builds the links, sizes the cluster, and decides what enforcement is fair and defensible.

The growth team

Cares because duplicate abuse burns promo budget and distorts activation metrics.

The legitimate look-alike

A shared household or a personal-plus-business user who must not be swept up by mistake.

What it looks like in practice

In practice

A signup promo pays a bonus for each new funded account. Overnight, forty accounts claim it, each with a different name and email. On their own they look like organic growth, so the growth dashboard celebrates.

Linking the accounts by device and payment shows all forty ran on three device fingerprints and cashed out to two bank accounts. The typing cadence and session times match across the batch. It is one operator farming the promo. Because the team separated this from genuine shared-household cases first, it clawed back the bonuses and closed the cluster without hitting real customers.

Why it matters to operators

Duplicate accounts quietly drain money and distort your view of the business. Bonus farms burn acquisition budget, ban evaders reappear after you thought they were gone, and mule clusters give a fraud operation the many landing spots it needs. Catching the link turns a whack-a-mole problem into a single takedown.

The real skill is enforcement, not just detection. A shared device or address can mean a fraud ring, but it can also mean a family, a shared office, or one person with a personal and a business account. Separate genuine abuse from legitimate overlap before you shut anything down, because a wrong block is a lost good customer and a complaint you will have to answer.

What to watch in the data

  • Shared device at scale. Many accounts on one device fingerprint or emulator is a strong duplicate signal, not a coincidence.
  • Common cash-out. Different accounts funneling to the same bank account or card usually share one controller.
  • Synchronized behavior. Batches that sign up, act, and cash out on the same schedule point to automation by one operator.
  • Recycled details. Slight variations of one email or address across accounts often mean the same person dodging exact-match checks.
  • Legitimate overlap. Shared households and personal-plus-business users look similar, so confirm intent before enforcing.

Quick questions

Why not just match on name and email?

Because those are the easiest fields to change. Fraudsters vary names and emails freely, so detection leans on device, payment, network, and behavior signals that are harder to alter across many accounts.

How is this different from entity resolution?

Entity resolution links records to a single real person or business across systems. Duplicate account detection is a focused application of that idea, aimed specifically at finding multiple accounts run by one party.

What abuse does it catch most?

Common cases are promo and bonus farming, ban evasion after a closure, mule networks needing many accounts, and synthetic clusters. Each relies on one controller operating many look-alike accounts.

How do I avoid punishing shared households?

Treat shared device or address as a lead, not a verdict. Look for intent signals like coordinated cash-out or automation, and build a review path so legitimate overlap can be cleared before enforcement.

Can fraudsters defeat device links?

They try, using emulators, virtual machines, and fingerprint spoofing. That is why detection combines device with payment, behavior, and network signals, since defeating all of them at once across a cluster is much harder.

Go deeper

  • NIST Digital Identity Guidelines (SP 800-63) ↗ — The US standard for identity proofing and authentication assurance levels.
  • FATF ↗ — The global standard-setter for AML, counter-terrorist-financing, and counter-proliferation. Recommendations, guidance, and jurisdiction lists.

Duplicate account detectionと併せて知っておきたい用語