SardineCon SF/2026

Learn More
Account & access fraud4 分で読めます

Sleeper accountとは?

SUBSCRIBE

A sleeper account is an account opened on purpose and kept deliberately quiet, sometimes running small real transactions to look normal, then switched on later for fraud or laundering once it looks seasoned and low-risk. The waiting is the point: it lets the account age past new-account scrutiny and build a trusted-looking track record before the first big move.

What is a sleeper account, in plain English?

A sleeper account is a real account that a fraudster opens and then lets sit. It might pass onboarding cleanly, sit idle for months, or run a trickle of small everyday transactions like a subscription or a low-value transfer. Nothing about it looks alarming, because nothing is meant to. The account is being seasoned, so that by the time it is used for the real purpose it no longer looks new.

The strategy works because most risk controls treat account age and history as a proxy for trust. A brand-new account draws velocity limits, step-up checks, and manual review; an account that has been open a year with a clean record often gets waved through. A sleeper account weaponizes that logic. It buys the patience needed to defeat new-account scrutiny and inherit the softer treatment that goes to established customers.

In fraud and AML work, sleeper accounts sit at the overlap of account origination fraud and money laundering. They can be individual accounts held by a mule, synthetic identities kept warm before a bust-out, or dormant business accounts reactivated to move illicit funds. The common thread is a long quiet stretch followed by sudden, out-of-character activity.

How a sleeper account gets activated

The lifecycle is deliberately slow at the front and fast at the back:

  1. Open — Clean onboarding. The account is opened with credentials good enough to pass KYC, then left largely untouched.
  2. Season — Build a boring history. Small, normal-looking transactions run for months so the account ages and earns a low-risk score.
  3. Trigger — Switch on. A device change, new login, or new funding source precedes the first real move.
    • Fraud path — Bust-out. Credit lines are maxed or the balance is drained fast, then the account is abandoned.
    • Laundering path — Pass-through. Large deposits arrive and move straight out to other accounts within hours.
  4. Exit — Cash out and vanish. Funds leave through cards, transfers, or crypto off-ramps and the account goes silent again or is closed.

Who is involved?

Who

Their role

The organizer

Opens or buys accounts in bulk and decides when to activate each one.

The account holder or mule

The name on the account. Sometimes a recruited mule, sometimes a synthetic or stolen identity.

The bank or platform

Holds the account and, through age-based scoring, gives it the trusted treatment the scheme relies on.

The fraud or AML team

Has to distinguish a real dormant customer waking up from a seasoned account being switched on.

What it looks like in practice

In practice

A checking account opens with valid documents and then does almost nothing for fourteen months: one small recurring payment and an occasional low-value transfer. Its risk score is low and it is well past every new-account rule.

One evening the account logs in from a new device in a different region, adds a new external payee, and receives three inbound transfers totaling a large sum. Within two hours the money is pushed out to accounts the customer has never touched before. The clean history said trusted; the sudden shape of the activity says otherwise.

Why it is dangerous for operators

Sleeper accounts are dangerous precisely because they beat the controls built to catch fresh fraud. By the time the account acts, it has aged out of velocity caps and step-up rules, and its clean record actively lowers the score at the exact moment scrutiny is most needed. Teams that lean heavily on tenure and prior good behavior can end up giving the account a free pass on its worst transaction.

The other problem is scale. Organizers open sleeper accounts in bulk and activate them in waves, so a single detection is rarely a single account. Treat a confirmed sleeper as a lead into a wider network, and resist the instinct to let a long clean history clear sudden, out-of-character activity on its own.

What to watch in the data

  • Long idle then sudden spike. Months of near-zero activity followed by high-value or high-speed transactions is the core signature.
  • Changed device or location. A new device, browser, or region right before the first real move suggests control changed hands.
  • New beneficiaries and funding. Fresh payees and a new funding source appearing together with the spike, not gradually.
  • Thin, patterned seasoning. A history that looks manufactured: identical small amounts, single subscriptions, or transfers only large enough to keep the account alive.
  • Clustered activation. Many aged, dormant accounts waking up in the same window is a network signal, not a coincidence.

Quick questions

How is a sleeper account different from a normal dormant account?

A dormant account is simply one a real customer stopped using. A sleeper account was kept quiet on purpose to age past scrutiny before fraud or laundering. The behavior looks identical until activation, which is why the shape of the wake-up matters so much.

Why does the early good behavior matter?

It is bait. The small, normal transactions exist to lower the risk score and build tenure, so the account inherits the softer controls given to trusted customers. Do not let a clean history alone clear a sudden high-value move.

Are sleeper accounts always opened with fake identities?

No. They can use synthetic identities, stolen identities, or real recruited mules. Some are legitimate accounts later sold or taken over. The seasoning strategy is the constant, not the identity type.

What is the single strongest signal?

A long dormancy followed by an abrupt jump in value or speed, especially paired with a device change, new payees, or a new funding source. Any one of those with a fresh activation deserves a hard look.

How do sleeper accounts relate to bust-outs?

Seasoning is often the setup phase for a bust-out. The account builds trust and credit quietly, then the bust-out is the activation where limits are maxed and the balance is drained before abandonment.

Should tenure still count toward trust?

Yes, but not blindly. Tenure is useful context, not proof. Weight it alongside the current transaction shape, device signals, and network links rather than letting age override an obvious anomaly.

Go deeper

Sleeper accountと併せて知っておきたい用語