Stop New-Account and Signup-Bonus Abuse: How to Shut Down Multi-Accounting
When your welcome offer funds multi-accounting instead of real first-time buyers, promo spend is wasted. Here is how multi-accounting works and how to shut it down.
Your welcome offer is meant to win a real first-time customer, but a meaningful share of it is quietly funding the same people signing up again and again. New-account and signup-bonus abuse is multi-accounting: one person, or an organized ring, creates many accounts to claim your new-customer discount, referral bonus, or free trial repeatedly, so promo spend you budgeted for acquisition is spent on customers you already had, or never had at all. This is not a fringe risk, because account creation is now the single most-attacked point in the customer lifecycle: TransUnion found that 8.3% of digital account-creation attempts were suspected fraud in 2025, the highest-risk stage of any across the consumer journey (TransUnion1). I build fraud tooling at RankShield, and the reason new-account fraud prevention is so often missed is that each individual signup looks perfectly fine; the abuse is only visible in the relationships between accounts. What this guide gives you is how multi-accounting actually works, and the three controls that shut it down, single-use tokenized offers, graph-based multi-account detection, and per-identity redemption caps, framed for a retail or DTC store rather than an iGaming site. One honest note first: real customers sometimes share a device or address, a household, an office, a library, so the goal is to catch multi-accounting patterns and verify, not to blanket-block anyone who looks slightly linked.
How common is new-account and signup-bonus abuse?
Common enough that account creation is now the most-attacked stage of the entire customer lifecycle. TransUnion’s 2025 fraud analysis found that 8.3% of digital account-creation attempts were suspected of fraud, higher than any other stage, from login to transaction, meaning roughly one in twelve new signups carries a fraud signal (TransUnion1). Not all of that is bonus farming, but signup-time abuse is a large part of why account creation is where the risk concentrates.
Automation is what makes it scale. A single person gaming your offer a few times is annoying; bots creating hundreds of accounts is a budget problem, and automated traffic now makes up 53% of all web traffic, much of it hitting exactly the signup and account-creation flows where offers live (Imperva2). When your welcome discount is worth real money, it becomes a target worth automating against, the same way any payout does.
It is worth being honest about the spectrum, because not all of this is organized crime. At one end is a casual customer making a second account to get the new-customer discount again; at the other is a coordinated ring or a bot farm harvesting bonuses at scale, sometimes as a step toward larger fraud. The casual end wastes margin; the organized end wastes real money and pollutes your data. Both are multi-accounting, and both are invisible if you only ever look at one signup at a time, which is the core of the problem.
How does multi-accounting actually work?
Multi-accounting works by making one person or ring look like many first-time customers, using cheap, disposable identifiers to open account after account. The tools are mundane: throwaway or aliased email addresses, small variations on a name or address, virtual and prepaid cards that generate a fresh number per account, and device or browser spoofing to avoid looking like the same machine twice. Each account is built to pass your signup check on its own, because your signup check only ever sees one account at a time.
At the organized end, this is automated end to end. A script or a bot farm spins up accounts in bulk, solving or bypassing basic friction, rotating IPs and devices, and claiming the offer on each, then either using the discounted goods, reselling them, or cashing out referral and store credit. The economics are simple: if your welcome offer is worth more than the cost of creating an account, automation makes farming it profitable, so the more generous the offer, the harder it is attacked.
The reason it evades most defenses is that the fraud is not in any single account; it is in the relationships between them. One signup from a new email on a new-looking device is indistinguishable from a real new customer. It is only when you can see that fifty of those signups share a device fingerprint, a payment instrument, or a subtle behavioral pattern that the ring becomes obvious. This is why the effective controls are all about linking accounts and limiting redemptions across the links, not about scrutinizing any one signup harder.
How do single-use, tokenized offers help?
Single-use, tokenized offers help by making each promotion redeemable exactly once and binding it to something harder to fake than an email address. Instead of a shareable code that anyone can reuse, or an offer tied to an email that costs nothing to create, you issue a token that is valid for a single redemption and attached to a verified identity or payment instrument. Once redeemed, it is dead, so the same offer cannot be farmed across a hundred throwaway accounts.
The key is what you bind the offer to, because binding to a weak identifier just moves the problem. An offer tied to an email address is trivially farmed, since emails are free and infinite; an offer tied to a verified phone number, a real payment instrument, or a device-plus-identity signal is far more expensive to multiply. You are raising the cost of each additional redemption from near-zero to something that actually deters bulk abuse, which is the whole game with promo protection.
Tokenization also gives you clean enforcement and clean data. Because each offer is a single-use token rather than a reusable code floating around, you can see exactly what was issued, what was redeemed, and by whom, which both stops the double-dip and stops your acquisition metrics from being polluted by farmed signups. It will not catch a determined ring on its own, but it removes the easiest and most common abuse, the shared or reused code, and forces the rest of the abuse into the patterns that graph detection is built to catch.
How does graph-based multi-account detection work?
Graph-based detection works by treating accounts as nodes and their shared attributes as links, so that accounts connected by the same device, payment instrument, address, or behavioral fingerprint form a visible cluster instead of appearing as unrelated strangers. When one device fingerprint links to forty accounts, or a dozen accounts share a single payment instrument or a normalized address, that cluster is the multi-accounting ring, and it is only visible at the graph level. This is the core control, because it targets exactly the relationship information that single-signup checks throw away.
The signals you link on matter, and the strong ones are hard to vary at scale: device and browser fingerprint, payment instrument, normalized shipping and billing address, and behavioral patterns like signup timing and navigation. Weak identifiers like email are easy to multiply and should carry little weight; strong, costly-to-rotate signals are what hold a cluster together. The same relationship view also connects to other fraud, since the identities in a farming ring often overlap with the ones behind synthetic-identity and account-takeover activity, which we covered in synthetic identity fraud at checkout.
The honest constraint is that links are not guilt, and treating them as guilt is how you punish real customers. A household with three family members, an office network, a university dorm, or a shared library computer will legitimately show multiple accounts on one device or address, and those are real customers, not a ring. So a good graph system scores the strength and shape of the cluster, dozens of accounts churning offers on one device is a ring; three accounts on a family device over two years is a household, and routes the suspicious clusters to verification rather than auto-blocking everything that shares a node.
How do per-identity redemption caps work?
Per-identity redemption caps work by limiting how many times your offer can be claimed per real person, defined by strong signals, rather than per email or per account, which cost nothing to multiply. Instead of "one welcome discount per account," the rule becomes "one welcome discount per verified identity," where identity is the cluster of device, payment instrument, and address that graph detection resolves. That way, opening a second, third, or fortieth account does not unlock a second, third, or fortieth offer, because they all resolve to the same identity.
Pair the cap with velocity limits on the signup flow itself, so bulk creation is throttled before it even reaches redemption. If dozens of accounts are being created from one device, network, or narrow time window, that burst is a signal to slow down, challenge, or hold, independent of whether each account eventually claims the offer. Velocity control at signup is the cheapest place to blunt automated farming, because it stops the ring from scaling in the first place.
Keep the guardrail visible while you enforce, because the failure mode is capping out a real customer. Set the caps and velocity thresholds where genuine behavior comfortably fits, allow for shared households and offices, and route edge cases to a verification step rather than a hard rejection, so a real second family member can still redeem. Done this way, per-identity caps and velocity limits quietly remove the profit from multi-accounting without punishing the legitimate customers who happen to share a roof or a network. Combining tokenized offers, graph detection, and per-identity caps into one screen is what RankShield’s fraud protection for Shopify is built to do.
How do you make sure your offers reach real customers?
You make sure your offers reach real customers by defending the account-creation stage, because that is where the abuse concentrates and where your promo budget leaks. New-account and signup-bonus abuse is multi-accounting: one person, ring, or bot making themselves look like many first-time customers to claim your welcome offer over and over, using throwaway emails, virtual cards, and spoofed devices. It is the highest-risk stage in the customer lifecycle, with TransUnion finding 8.3% of account-creation attempts suspected of fraud, and it is invisible if you only ever look at one signup at a time, because the abuse lives in the relationships between accounts, not in any single one.
Three controls shut it down together: single-use tokenized offers that can be claimed only once and bound to a verified identity, graph-based detection that links accounts by the device, payment, and address signals a ring cannot cheaply vary, and per-identity redemption caps with signup velocity limits that stop the same person from unlocking the offer again through a new account. Keep the honest guardrail throughout, real customers share households, offices, and networks, so score the pattern and verify the edge cases rather than blanket-blocking anyone who looks linked. Done right, your welcome offer goes back to doing its job, winning real first-time customers. To put these controls on your own store, see how RankShield protects your signups and offers.
Questions, answered.
What is new-account or signup-bonus abuse?
New-account or signup-bonus abuse, also called multi-accounting, is when one person or an organized ring creates many accounts to claim a promotion repeatedly, most often a new-customer welcome discount, a referral bonus, a free trial, or store credit. Instead of the offer winning a genuine first-time customer, it is farmed by the same actor over and over using disposable identifiers: throwaway or aliased emails, small variations on a name or address, virtual and prepaid cards that produce a fresh number each time, and device or browser spoofing to avoid looking like the same machine. At the casual end it is a customer making a second account for the discount again; at the organized end it is a bot farm or ring harvesting bonuses at scale, sometimes as a step toward larger fraud. The reason it is so effective is that each account looks perfectly legitimate on its own, so a signup check that examines one account at a time cannot see the abuse. It only becomes visible in the relationships between accounts, which is why the effective defenses focus on linking accounts and capping redemptions across the links.
How common is new-account fraud?
It is common enough that account creation is now the single most-attacked stage of the customer lifecycle. TransUnion’s 2025 fraud analysis found that 8.3% of digital account-creation attempts were suspected of fraud, higher than any other stage from login through transaction, which works out to roughly one in twelve new signups carrying a fraud signal. Not all of that is bonus farming specifically, but signup-time abuse is a major reason the risk concentrates at account creation. Automation is what pushes it to scale: automated traffic now makes up the majority of web traffic, and much of it targets exactly the signup and account-creation flows where offers live, because a welcome discount worth real money is a payout worth automating against. It is worth being honest that the activity spans a spectrum, from a casual customer opening a second account for the discount to a coordinated ring or bot farm harvesting bonuses in bulk. The casual end wastes margin and the organized end wastes real money and pollutes acquisition data, but both are multi-accounting and both are invisible unless you look across accounts rather than at one signup at a time.
How do I stop people creating multiple accounts to abuse offers?
You stop it with three controls that work together, because no single one is enough. First, make offers single-use and tokenized, redeemable exactly once and bound to a strong identifier like a verified phone or payment instrument rather than an email address, which costs nothing to multiply. Second, use graph-based detection to link accounts by the signals a ring cannot cheaply vary, device and browser fingerprint, payment instrument, normalized address, and behavioral patterns, so that fifty accounts sharing one device show up as a cluster instead of fifty strangers. Third, set redemption caps per identity, defined by that cluster of strong signals, rather than per account or email, and add velocity limits that throttle bulk signups from one device or network before they even reach redemption. Together these raise the cost of each additional fake account from near-zero to something that deters farming. The crucial guardrail is to remember that real customers sometimes share devices and addresses, so score the strength of a cluster and route suspicious ones to verification rather than blanket-blocking everyone who appears linked.
Will blocking multi-accounts hurt real customers?
It can, if you block on links alone, which is exactly the mistake to avoid. Real customers legitimately share devices and addresses all the time: a household with several family members, an office or shared workplace network, a university dorm, or a public library computer will all show multiple accounts on one device or address, and those are genuine customers, not a ring. If you treat any shared signal as proof of abuse and auto-block, you will turn away real buyers and damage the acquisition the offer was meant to drive. The right approach is to score the shape and strength of a cluster rather than the mere existence of a link. Dozens of accounts rapidly churning offers on a single device, with rotating throwaway emails and virtual cards, is a ring; three accounts on a family device accumulated over two years is a household. A good system distinguishes these by the volume, velocity, and pattern of the cluster, and routes the genuinely suspicious ones to a verification step, a confirmation, a challenge, or a hold, instead of a hard rejection. That way you remove the profit from multi-accounting while letting a real second family member still redeem.
What is graph-based fraud detection?
Graph-based fraud detection is a technique that models accounts as nodes and their shared attributes as connections, so that accounts linked by the same device, payment instrument, address, or behavioral fingerprint form a visible cluster instead of appearing as unrelated individuals. It matters for multi-accounting because the abuse is not visible in any single account, which looks like a normal new customer, but only in the relationships between accounts, which is precisely what a graph captures. When one device fingerprint connects to forty accounts, or a dozen accounts share a single payment card or a normalized address, that cluster is the multi-accounting ring. The strength of the technique depends on linking on hard-to-vary signals: device and browser fingerprint, payment instrument, and normalized address carry weight, while weak identifiers like email should carry little because they are trivially multiplied. The same relationship view is valuable beyond promo abuse, because the identities in a farming ring often overlap with those behind synthetic-identity and account-takeover activity. Used responsibly, graph detection scores the size and shape of a cluster and sends the suspicious ones to verification, rather than treating every shared link as proof of fraud.
Should I just make my welcome offer less generous to stop abuse?
Reducing the offer is a blunt lever that trades away real acquisition to deny fraud, so it is usually the wrong first move. A smaller welcome offer does make farming less profitable, but it also makes the offer less effective at winning the genuine first-time customers it exists for, so you pay for reduced abuse with reduced acquisition, which is often a worse deal than the abuse itself. The better approach is to keep the offer competitive and protect it with controls that raise the cost of abuse without touching the value to real customers: single-use tokenized offers bound to a verified identity, graph-based detection that catches multi-account clusters, and per-identity redemption caps with signup velocity limits. Those controls target the farming specifically, so a real first-time customer gets the full offer while a ring cannot claim it fifty times. There is a place for tuning offer generosity as part of overall economics, but it should not be your primary fraud control, because shrinking the offer punishes your best prospects to inconvenience the abusers, whereas targeted controls remove the abuse and leave the offer intact for the people it is meant to win.
References
- TransUnion. 2025 State of Omnichannel Fraud Report (8.3% of digital account-creation attempts suspected of fraud in 2025, the highest-risk stage across the consumer lifecycle).
- Imperva (Thales). 2026 Bad Bot Report (automated traffic 53% of all web traffic; bots target signup and account-creation flows).
- FBI Internet Crime Complaint Center (IC3). 2024 Internet Crime Report ($16.6B in reported losses; macro fraud context).
Jamie Kloncz
Founder & CEO, RankShield
Jamie Kloncz is the founder and CEO of RankShield, the verifiable AI and quantum security platform. He started the company after two attacks landed in a single week: his phone was cloned, and his business was hit by a click-fraud campaign. One targeted him as a person, the other his livelihood, and no single tool defended both. That experience, together with surviving an AI voice-clone scam, shaped RankShield’s core belief: the threats of the AI age are personal first, and trust should be something you can check, not just extend.
Make every AI action provable.
RankShield is the verifiable, quantum-safe AI security platform — protection you can check, not just trust.