TL;DR
- Bonus abuse is an account-farming problem, not a promotions-budget problem.
- A verified player account holds resale value long after the bonus clears.
- UK rules expect operators to catch false, stolen and mule IDs at registration.
- Detection should escalate by risk tier rather than add checks for everyone.
- Over-verification pushes genuine players toward unlicensed offshore operators.
In April 2025 the UK Gambling Commission told licensees to check whether their ID document checks are good enough to catch false, stolen and mule documents. Most businesses cannot answer this because they have two separate teams solving the problem. Marketing often owns bonus abuse, and compliance owns the money laundering part. This approach isn’t ideal because fraud rings don’t work that way.
The account that gets opened to claim a welcome offer is, in most cases, the same account that gets used later to move someone else’s money, which is the reason iGaming fraud prevention that only counts wasted bonuses doesn’t work.
What is iGaming fraud?
iGaming fraud is any attempt to take value from a gambling platform by misrepresenting who is playing, and it clusters at two moments rather than spreading across the player journey. Registration is where a fraudster enters the platform. Withdrawal is where value leaves.
Online casino fraud takes a handful of recognisable shapes. Multi-accounting puts one person behind many accounts. Bonus abuse converts promotional credit into withdrawable balance. Chip dumping and gnoming use colluding accounts at the same table to move value deliberately from one player to another. Account takeover borrows a genuine player’s credentials, and chargeback fraud reverses a deposit after the money has already been played through.
Each of those works only while the operator cannot tell whether the person behind a new account has been seen before, which is the single question carrying most of the load across iGaming risk.
What is bonus abuse in online casinos?
Bonus abuse in online casinos happens when someone opens accounts specifically to claim welcome offers, free bets or promotional credit, clears the wagering requirement with minimal genuine play, and withdraws. One person, ten email addresses, and ten welcome bonuses.
The economics of that attack changed once the account itself became the asset.
Shufti’s own multi-accounting analysis names the same behaviour as account farming, where synthetic identities build a portfolio of KYC-verified accounts for onwards resale.
Why the marketing-cost view fails
An operator that treats bonus abuse as promotional leakage ends up with a budget conversation and a tighter offer-level rule, and both of those leave the accounts exactly where they are. The ring forfeits one promotion and keeps ten verified identities it can rent, sell, or use to layer third-party funds through play. Once those accounts start receiving money the account holder never earned, the exposure stops being an acquisition line item and becomes a reporting obligation with a regulator attached. The bonus was never the prize. The bonus was the acquisition cost of the account.
How do online casinos detect fraudulent players?
Online casinos detect fraudulent players by looking across accounts rather than at each account in isolation, because every technique described above looks entirely legitimate when a single registration is examined on its own. Practical iGaming fraud detection rests on five signals, and fraud and risk management for gaming and gambling operators works best when each signal is read against the others rather than alone.
- Biometric deduplication: A new selfie is compared against the population of already-verified players, so the same face cannot hold two accounts whatever document or name is presented. Deduplication is the only one of the five that answers the uniqueness question directly.
- Device and network intelligence: Device fingerprinting surfaces the emulators, anti-detect browsers and residential proxies that make two hundred accounts look like two hundred people. Rings rotate infrastructure constantly, so treat this as corroboration rather than proof.
- Behavioural signals during play: Scripted wagering, correlated bet timing across accounts and mechanical completion of a wagering requirement all diverge from the way a real player behaves over a session.
- Payment instrument clustering: Cards issued in the same bank range, repeated bank accounts and matching payout destinations link accounts that appear to share nothing else.
- Ongoing screening and transaction monitoring: Funds arriving from many accounts and leaving quickly, high transaction velocity with low retention, and money pooling into a single account are the classic mule signatures, and they appear after onboarding rather than during it.
How to sequence the checks
The sequence in which verifications are done matters more than the size of the stack.
That restraint has a commercial rationale as well as a technical one.
Effective online gambling fraud prevention is therefore tiered by risk, not uniformly heavy.

iGaming affiliate fraud
iGaming affiliate fraud is the manipulation of affiliate partnerships to earn commission on traffic or players that are not genuine, and it draws on the same account supply as bonus abuse. An affiliate paid per registration has an incentive to deliver registrations, whereas a ring holding farmed accounts has registrations to sell.
Regulators have already joined those dots. Malta’s Financial Intelligence Analysis Unit and the Malta Gaming Authority revised their Implementing Procedures for the remote gaming sector partly to elaborate on risk factors, including the involvement of affiliates. The Gambling Commission’s April 2025 update makes a parallel point about third-party business relationships and names white-label partnerships and incoming investment as areas where licensees have applied insufficient due diligence.
The practical consequence is that affiliate quality and player uniqueness turn out to be the same measurement. An affiliate whose cohort fails deduplication at several times that of the average is a due diligence question.
Why do gambling operators need age verification?
Gambling operators need age verification because licence conditions in regulated markets prohibit a customer from gambling at all until identity and date of birth are confirmed, which makes the check a precondition to trading. Age also sits inside the same registration step as everything above, which helps an operator verify identity properly from the same evidence.
In Great Britain, LCCP Licence Condition 17.1.1 requires licensees to obtain and verify a customer’s name, address and date of birth before that customer is permitted to gamble, and it stops operators from demanding information at withdrawal that they could reasonably have requested earlier. The current LCCP version took effect on 19 January 2026.
| Market | What must be established | When |
| Great Britain (UKGC) | Name, address and date of birth, verified | Before the customer is permitted to gamble |
| Malta (MGA and FIAU) | Customer due diligence and a customer risk assessment | By first withdrawal, or at EUR 2,000 cumulative deposits over a rolling 180 days, whichever comes first |
Malta has shown what happens when the underlying architecture cannot support that timing. On 23 March 2026, the Financial Intelligence Analysis Unit imposed an administrative penalty on Stanleybet Malta Limited for failures in customer due diligence, customer risk assessment and monitoring, including an inability to link a customer’s cumulative transactions across a network of outlets, per the FIAU publication notice.
The company has appealed, and the decision remains subject to that process. The transferable finding is architectural rather than procedural. A threshold a customer can walk around by using a different outlet or a different account was never really a threshold.
Where Shufti fits in iGaming fraud prevention
Most operators can say how many accounts they verified last month. Far fewer can say how many belonged to people already verified, and that second number is where bonus abuse and mule exposure both sit.
Shufti’s Face Verification Solution runs cross-account biometric deduplication, comparing the face presented at registration against faces already verified on the platform and flagging a match regardless of the document, name, or device used. A ring can buy fresh documents and rotate devices, but the same biometric vector cannot hold two verified accounts, so the duplicate surfaces at the moment the bonus would otherwise be credited.
The same check catches a self-excluded customer returning under a new identity, which is a licensing problem rather than a fraud loss. Shufti’s liveness holds iBeta Level 3 conformance under ISO/IEC 30107-3, so the face being compared belongs to a live person.
Frequently Asked Questions
What is iGaming fraud?
Any attempt to take value from a gambling platform by misrepresenting who is playing. The main forms are multi-accounting, bonus abuse, chip dumping, account takeover and chargeback fraud, and they concentrate at registration and at withdrawal.
What tools are used for iGaming risk management?
Fraud risk management in iGaming typically combines document and biometric identity verification at onboarding, device fingerprinting and behavioural monitoring during play, and AML screening against sanctions, PEP, and adverse media databases throughout the player lifecycle.















