iGaming Fraud Trends
Understanding the identity networks behind bonus abuse, multi-player accounting and jurisdiction circumvention
Shufti’s Identity Network Intelligence Report shows a 13.77% bonus abuse rate in iGaming. The report also found that 38.07% of fraud was linked multi-account activity, while 22.73% of VPN and proxy cases involved attempts to access restricted markets.
Schedule a DemoShufti Prevents potential bonus abuse of $30 Million
Shufti’s H1 2026 iGaming fraud data shows 13.77% of cases were associated with potential Bonus Abuse, out of the full population of cases assessed in the period.
of cases were associated with potential Bonus Abuse, out of the full population of cases assessed in the period.
More than $30 million in potential Bonus Abuse exposure was prevented through fraud detection. The exposure is associated with accounts carrying shared identity, shared device or previous-fraud signals, and calculated from a detected population equal to 13.77% of cases.
Every account in the flagged population not only represents KYC Compliance risk but also the bonus abuse losses. It also wastes acquisition spend on marketing as promotional bonus goes to a duplicate or coordinated sign-up rather than a genuinely new player. The same pattern increases manual review volume as flagged accounts accumulate if left uncontrolled and eventually increases the operational constraints for the iGaming businesses.
Identity fraud for the sake of committing Bonus Abuse is typically identified through the repeated or coordinated use of multiple sign-ups or player accounts to access promotional incentives intended for eligible players. Multi-accounting, duplicate identities, shared devices and related network patterns are common indicators of this activity. This differs from advantage play, in which a single genuine customer makes optimal use of legitimate promotional terms without deception or duplication.
Shared identity documents, shared devices, previous fraud associations, account history, network relationships and behavioural patterns provide the relevant detection signals.
Multiple Registration
Repeated onboarding attempts
Linked Accounts
Shared identity, device or fraud history
Repeated Promotional Claims
The same incentive claimed more than once
Promotional Exposure
Value paid out beyond entitlement
Fraud in iGaming Operates Through Connected Networks
Corroborated signals, not isolated anomalies, are what surface the scale of the risk sitting at the point of registration, at bonus release and at the jurisdiction border.
VPN and Proxy Cases Linked to Jurisdiction Circumvention
22.73% of VPN and proxy-originated cases across Shufti’s H1 2026 iGaming fraud data were associated with Jurisdiction Circumvention. The same VPNs, proxies and location-spoofing tools are used to reach jurisdiction-specific promotional offers and to evade age-related access controls. That makes bonus abuse, jurisdiction eligibility and age assurance one connected problem.
Cases Linked to Known Fraud Indicators
Shufti’s H1 2026 iGaming data shows that 16.05% of cases were linked to known fraud indicators through multiple corroborated fraud signals, out of the complete population assessed during the period. This is the clearest single measure of the fraud risk iGaming operators carry at the point of registration.
Fraud Associated With Shared-Device Connectivity
According to Shufti H1 2026 iGaming identity fraud report 38.07% of fraud is associated with shared devices connectivity, out of the population of cases eligible for device fingerprinting and showing additional indicators of fraud. Players, or coordinated groups, often use multiple accounts to repeatedly access promotional incentives, circumvent player-level restrictions, evade account limits, or obscure the relationships between accounts.
Identities in the Largest Shared Fraud Network
The largest shared fraud network in the dataset was linked to 181 identities through shared devices, documents and other identity signals. This case of ring fraud also shows how iGaming sector s vulnerable to fraud networks.
Significance of Identity Network Intelligence to Prevent iGaming Fraud
In iGaming, identity verification is not only required to meet regulatory obligations but also to prevent significant financial losses caused by bonus abuse, multi-accounting and jurisdiction hopping. Traditional KYC checks answer whether a single player’s document, selfie or device appears genuine at the point of registration. They do not reveal whether the same identity has been used across multiple accounts, whether several players are connected through shared devices or documents, or whether a new registration is linked to previous fraudulent activity.
Identity Network Intelligence addresses this gap by identifying relationships between identities, biometric evidence, documents, devices, network signals, geographic information, verification history and previous fraud associations. This enables iGaming operators to detect coordinated fraud patterns behind activities such as bonus abuse, multi-player accounts and attempts to bypass jurisdiction controls. Decisions stay based on multiple contextual signals rather than isolated similarities. iGaming operators can prevent fraud losses, without creating unnecessary friction for legitimate players, by assessing each registration against the wider network of activity.
Detecting Fraud While Preventing Loss of Legitimate Users
Shufti does not treat an individual anomaly as conclusive evidence of fraud. The fraud detection methodology evaluates potentially concerning signals alongside contextual evidence: identity and document consistency, device and session behaviour, geographic and network intelligence, verification history, relationships between accounts, and patterns observed across repeated attempts. A single signal considered in isolation is rarely sufficient to distinguish a legitimate customer from an elevated-risk one.
Figure 2. Signal-to-decision framework: distinguishing isolated anomalies from elevated riskSignal
An anomaly appears: a foreign document, a retry, a shared device, a VPN origin.
Context
Identity and document consistency, device and session behaviour, geography, history.
Corroboration
Do further signals reinforce the concern, or support the customer’s legitimacy?
Decision
Proceed where evidence supports legitimacy; escalate, restrict or decline where signals reinforce.
Behavioural biometrics is one the signals which can help distinguish a genuine user from fraudulent one. For example, a genuine user may pause, correct a mistake or vary their typing speed, while automated submissions often follow a faster and more consistent pattern.
The methodology therefore distinguishes isolated anomalies that can occur during legitimate customer journeys from combinations of signals that, taken together, indicate elevated risk. Positioned correctly, this is both a fraud-prevention benefit and a conversion benefit. iGaming operators that only ever act on corroborated risk protect revenue from coordinated abuse. They also avoid unnecessary friction, and unnecessary lost conversions, for the genuine players the business depends on.
Where additional evidence supports the legitimacy of the customer, the case can proceed. Where multiple signals reinforce the original concern, the case can be escalated, restricted or declined. This sequence underpins every section that follows.
How to Detect Identity Fraud to Prevent Bonus Abuse in iGaming
Identity fraud, an identity that is stolen, synthetic, or manipulated, sits upstream of most connected fraud in iGaming. It creates the accounts that Bonus Abuse, multi-accounting and jurisdiction circumvention later depend on. It takes two connected forms, a synthetic identity built from a mixture of genuine and fabricated information, and a genuine identity presented through a fake, altered, or manipulated document. Both share the same underlying question: does the presented identity correspond to a real individual, and has that identity, or elements of it, appeared previously in the network.
of cases in Shufti’s H1 2026 iGaming fraud data were linked to identities with a prior history of fraud.
This is not a duplicate-player metric. It measures how much activity touched an identity that had already been associated with fraud elsewhere in the network. That is a different question from whether that identity was operating multiple accounts, and a different risk dimension from the duplicate-identity and shared-device figures covered later in this report.
Where Identity Network Intelligence Protects the Player Journey
Identity Network Intelligence applies across four points in the player journey, rather than at registration alone.
Account creation
Identity deduplication, 1:N biometric matching, document authenticity verification and digital footprint analysis check the new registration against the full existing player population rather than a single stored reference. Duplicate, synthetic and fraudulent registrations are caught before an account is created.
Bonus release
Shared identity, shared device, previous-fraud and digital footprint connections together identify coordinated attempts to access promotional value. Bonus value is stopped before it reaches a connected fraudulent account.
Player activity
Verification history, previous fraud associations and behavioural consistency across sessions are assessed alongside other contextual signals rather than acted on in isolation. That identifies previously connected identities while avoiding false positives.
Jurisdiction access
VPN and proxy detection identifies attempts to mask location, supported by geographic and digital footprint signals. Market access stays aligned with what iGaming operators are actually licensed to serve.
A Second Account Can Multiply the Risk Attached to One Identity
According to Shufti H1 2026 iGaming identity fraud report 38.07% of fraud is associated with shared devices connectivity, out of the population of cases eligible for device fingerprinting. Players, or coordinated groups, often use multiple accounts to repeatedly access promotional incentives, circumvent player-level restrictions, evade account limits, or obscure the relationships between accounts.
A connected cluster of accounts multiplies every cost attached to the identity behind it: promotional exposure across each linked account, and additional manual review once the cluster is flagged. Where a self-excluded individual is part of the cluster, it also carries a self-exclusion failure with direct licence exposure attached.
Duplicate Identity Rate in iGaming
Figure 3. Duplicate-identity rate across Shufti’s H1 2026 iGaming fraud data.Shufti’s H1 2026 iGaming fraud data shows 2.85% of cases reflected a duplicate-identity rate, out of the population of cases eligible for biometric proof-of-life matching. Where device intelligence identifies connections between accounts, identity deduplication identifies repeated use of the same identity. The two signals provide complementary views of connected-account activity, strongest when read together.
Identity deduplication and 1:N biometric matching provide the relevant detection signals, checking each new registration against the full existing player population rather than a single stored reference.
Identity Fraud Rate for Jurisdiction Circumvention in iGaming
22.73% of VPN and proxy-originated cases across Shufti’s H1 2026 iGaming fraud data were associated with Jurisdiction Circumvention. VPN and proxy infrastructure allows a player to obscure their true location and circumvent jurisdictional restrictions, distinct from geographic mismatch, which functions only as a supporting detection signal. Location eligibility is assessed separately from identity verification. Eligibility to play a regulated iGaming product depends on identity, age, physical location, jurisdiction and product all aligning at once. A player can be genuinely who they say they are, pass every identity check, and still be ineligible if their true location falls outside the licensed market.
Jurisdiction circumvention exposes iGaming operators to the same regulatory consequence regardless of a player’s intent: a licence condition breach or a market-eligibility review. It also dilutes promotional and acquisition spend directed at players they were never permitted to serve in the first place.
Jurisdiction Hopping Used for Bonus Abuse
A player may use a VPN to reach a jurisdiction-specific promotional offer or a bonus unavailable in their home market. Each of the seven US states with a live, regulated online casino market requires operators to confirm that a player is physically within state lines for every session, not only at registration. That reflects the view that jurisdiction eligibility can change within a single player’s activity.
Jurisdiction Hopping Used for Circumvention of Age Verification
The same VPNs, proxies and location-spoofing tools used to bypass geofenced iGaming products can also be used alongside other techniques to evade age-related access controls. Age verification and jurisdiction circumvention are closely related compliance challenges rather than separate risks. This is particularly significant in the United States, where regulated online casinos must verify both a player’s age and their physical location before wagering is permitted.
In the UK, gambling-trade reporting has linked the rollout of Online Safety Act age-assurance duties to a rise in VPN use aimed at bypassing age checks. The same technical methods can be repurposed across different regulatory regimes.
How Shufti is Helping iGaming Prevent Fraud Through Identity Network Intelligence
Population-level identity deduplication.
New registrations are checked against the existing player population rather than a single stored reference, helping identify duplicate identities even when submitted details vary.
1:N biometric matching.
Biometric evidence is compared against the wider population to surface repeat identities across multiple accounts.
Identity-to-device linkage.
Identity and device signals are assessed together, enabling iGaming operators to identify connected activity such as multiple identities sharing a device. That is what allows a finding like the 181-identity network to be surfaced at all.
Contextual risk assessment.
Fraud is not identified through one or two similarities alone; Shufti evaluates contextual signals, compares suspicious activity against known fraud patterns, and applies customised workflows based on the operator’s own risk requirements.
Explainable decisioning.
Each decision is supported by the specific signals that produced it and resolves to a defined outcome, allow, request more evidence, review, restrict, reverify or decline.
Identity Verification in iGaming Is No Longer Only a Compliance Check
In iGaming, identity verification is not only required to meet regulatory obligations but also to prevent significant financial losses caused by bonus abuse, multi-accounting and jurisdiction hopping.
Regulatory obligation
Customer due diligence and AML compliance remain the baseline requirement at onboarding.
Financial exposure
Bonus abuse, multi-accounting and jurisdiction hopping turn verification into direct financial exposure.
Genuine players
Acting on a single flagged signal costs conversions, so risk has to be corroborated before it is acted on.
A single signal considered in isolation is rarely sufficient to distinguish a legitimate customer from an elevated-risk one. Whether a document is fraudulent or an identity is fake is established by corroborating several signals: identity and document consistency, device and session behaviour, geographic and network intelligence, verification history and relationships between accounts. iGaming operators that only ever act on corroborated risk protect revenue from coordinated abuse. They also avoid unnecessary friction, and unnecessary lost conversions, for the genuine players the business depends on.
Recommendations for iGaming Operators
Review whether current controls assess identity, device and network signals together, or only in isolation. The findings in this report are only visible when they are read together.
Confirm whether duplicate-identity and shared-device checks run before promotional value is released, not only at account creation.
Establish whether a single anomaly, a VPN, a shared device, a foreign-issued document, results in an automatic decline or triggers a contextual review.
Assess whether jurisdiction and age-verification controls are treated as one connected problem or two separate ones. The overlap is set out under Jurisdiction Circumvention above.
Identify where manual review volume is currently driven by low-context, single-signal alerts that a connected risk view could resolve automatically.
Confirm that fraud detection does not come at the expense of genuine users. The value of this approach depends on both outcomes holding at once.
Frequently asked questions (FAQs)
Shufti’s H1 2026 iGaming fraud data shows 13.77% of cases were associated with potential Bonus Abuse, out of the full population of cases assessed in the period.
Shufti’s fraud detection prevented more than $30 million in potential bonus abuse exposure by identifying accounts linked through shared identities, shared devices, or previous fraud signals. These cases represented 13.77% of the detected population.
Identity Network Intelligence identifies relationships between identities, biometric evidence, documents, devices, network signals, geographic information, verification history and previous fraud associations. This enables iGaming operators to detect coordinated fraud patterns behind activities such as bonus abuse, multi-player accounts and attempts to bypass jurisdiction controls, while ensuring that decisions are based on multiple contextual signals rather than isolated similarities.
According to Shufti H1 2026 iGaming identity fraud report 38.07% of fraud is associated with shared devices connectivity, out of the population of cases eligible for device fingerprinting.
Shufti’s H1 2026 iGaming fraud data shows 2.85% of cases reflected a duplicate-identity rate, out of the population of cases eligible for biometric proof-of-life matching.
22.73% of VPN and proxy-originated cases across Shufti’s H1 2026 iGaming fraud data were associated with Jurisdiction Circumvention. VPN and proxy infrastructure allows a player to obscure their true location and circumvent jurisdictional restrictions, distinct from geographic mismatch, which functions only as a supporting detection signal.
A single unusual signal should not be treated as proof of fraud. Fraud detection should instead corroborate multiple signals, such as identity and document consistency, device and session behaviour, location and network data, verification history, account relationships, and repeated activity. This gives operators a clearer basis for separating genuine users from higher-risk activity.
Shufti’s H1 2026 iGaming data shows that 16.05% of cases were linked to known fraud indicators through multiple corroborated fraud signals, out of the complete population assessed during the period. This is the clearest single measure of the fraud risk an iGaming operator carries at the point of registration. Within the same dataset, 28.79% of cases were linked to identities with a prior history of fraud.
Fraud rings are detected by assessing identity and device signals together rather than in isolation, which allows an operator to see multiple identities sharing a device, a document or a previous fraud association. The largest shared fraud network in the dataset was linked to 181 identities through shared devices, documents and other identity signals, a finding that is only visible when identity, device, network and behavioural evidence are corroborated as one connected risk view.
Bonus abuse is prevented by running duplicate-identity and shared-device checks before promotional value is released, not only at account creation. At bonus release, shared identity, shared device, previous-fraud and digital footprint connections together identify coordinated attempts to access promotional value. Bonus value is stopped before it reaches a connected fraudulent account. Shared identity documents, shared devices, previous fraud associations, account history, network relationships and behavioural patterns provide the relevant detection signals.
Device fingerprinting, behavioural signals, network and IP intelligence, and verification history provide the relevant detection signals for multi-accounting, combined with identity-level evidence to build a fuller picture of potential connected-account activity. Identity deduplication and 1:N biometric matching add the identity view, checking each new registration against the full existing player population rather than a single stored reference. In Shufti’s H1 2026 iGaming data, 38.07% of fraud is associated with shared devices connectivity and 2.85% of cases reflected a duplicate-identity rate.
VPN and proxy detection identifies attempts to mask location, supported by geographic and digital footprint signals. Market access stays aligned with what iGaming operators are actually licensed to serve. Location eligibility is assessed separately from identity verification, because eligibility to play a regulated iGaming product depends on identity, age, physical location, jurisdiction and product all aligning at once. 22.73% of VPN and proxy-originated cases across Shufti’s H1 2026 iGaming fraud data were associated with Jurisdiction Circumvention.
Identity fraud for the sake of committing Bonus Abuse is typically identified through the repeated or coordinated use of multiple sign-ups or player accounts to access promotional incentives intended for eligible players, with multi-accounting, duplicate identities, shared devices and related network patterns providing common indicators of this activity. This differs from advantage play, in which a single genuine customer makes optimal use of legitimate promotional terms without deception or duplication.
Traditional KYC checks answer whether a single player’s document, selfie or device appears genuine at the point of registration, but they do not reveal whether the same identity has been used across multiple accounts, whether several players are connected through shared devices or documents, or whether a new registration is linked to previous fraudulent activity. Identity Network Intelligence addresses this gap by identifying relationships between identities, biometric evidence, documents, devices, network signals, geographic information, verification history and previous fraud associations.
Form submitted successfully!
Thank you for your interest — your report is loading now.
See What Identity Fraud Looks Like Across iGaming
Detecting identity fraud is only part of the challenge. Operators also need enough evidence to act without wrongly rejecting legitimate players. The report explores multi-account activity, bonus abuse and other identity fraud patterns, along with the signals that can help teams distinguish genuine risk from normal player behaviour.
























