CASE ID #296714805
The Fraud Ring That Looked Like Two Hundred Strangers
Investigator on the case

Kyle Truax
Fraud Consultant
Kyle Truax works with SEON customers across fintech, travel, iGaming and e-commerce on bonus abuse, account takeovers, chargebacks, bot attacks and multi-accounting. He sits at the seam between fraud and AML, where transaction monitoring, suspicious activity investigations and payment risk overlap, helping teams tighten detection without pushing good customers into review queues. Prior to SEON, he held fraud, AML and risk positions at theScore and BetMGM.
What you will learn
- An operation that regenerates a fresh device ID for every account defeats conventional device-linking outright, and the absence of any shared identifier is itself the anomaly worth investigating.
- An audio fingerprint is close to unique on real hardware, so nearly 200 accounts collapsing to two values indicates two device templates rather than two coincidences.
- A single operating system build ID appearing across different phone models is not rare — it is impossible on genuine hardware, which makes it one of the few signals a spoofing tool cannot argue with.
- Detection built on fingerprint uniformity rather than specific values survives the operator’s next template, because the clones re-link themselves no matter what numbers they report.
I. No pause, no typo
Nearly two hundred accounts on a rewards platform were moving through onboarding and cashing in on the same incentive program, over and over. Looked at one at a time, a few of them might have passed for enthusiastic customers. Looked at together, almost everything about them was suspicious from the first pass, not because of one glaring tell, but because of how many small ones showed up all at once.
Some of it was behavioral. A real person filling out a signup form pauses. They mistype something and correct it. They read a screen for a second before tapping next, and that second is never exactly the same length twice. They scroll past a paragraph they don’t care about at a different speed than they scroll through one they do. None of that is a conscious choice. It’s what a human attention span produces. These accounts didn’t produce any of it. Every session moved through the same steps at the same pace, no hesitation, no correction, no variation from one account to the next. That’s one script running the same instructions two hundred times.
Behavioral signals confirm the script, but sometimes they’re the first thing a fraudster adjusts. The hardware underneath is harder to fake: a random pause here, a fake typo there.
“So instead of stopping at behavior, we looked at what these accounts were actually running on.”
That’s where the collection of small tells turned into something harder to explain away.
II. Two devices, not two hundred
A fingerprint built from how a device processes audio is supposed to come back close to unique. Real hardware has enough natural variation that two devices rarely land on the same value by chance. Across this cluster, nearly every account collapsed to just two values, not similar values but identical ones, split into two groups.
At the same time, every account was reporting the same font count, a small fraction of what an ordinary device carries. Real phones and laptops accumulate fonts through updates, installed apps and language packs over months and years of normal use.
“A browser reporting an identical, stripped-down count across every account in the cluster isn’t two hundred people’s individual devices. It’s one browser build, cloned repeatedly.”
And a piece of the software profile leaked something that shouldn’t have been possible on genuine hardware at all: the exact same build identifier, showing up across phone models that don’t share hardware. A build identifier is essentially a version stamp the operating system reports for itself, a label that says “this is exactly this software, assembled at this point, for this specific device configuration.”
Different phone models, even from the same manufacturer, get their own distinct stamp because the software is compiled slightly differently for each one. Seeing the identical stamp on phone models that shouldn’t share one is a bit like finding the same factory production code on two cars from different manufacturers. It doesn’t happen from two separate assembly lines. It happens when only one template is copied and relabeled.
None of these three signals lived in the same part of a device. Audio processing, installed fonts, and a system build identifier are unrelated on a real phone. The only way they’d all point to the same two-way split, on the same nearly two hundred accounts, is if they weren’t describing two hundred devices at all. They were describing two.
III. Disposable IDs, permanent tells
The network layer told the same story from a different angle. These sessions were routed through mobile proxy infrastructure, and that infrastructure was leaking into the exact field that’s supposed to describe a phone carrier. And the accounts weren’t trickling in one at a time. They arrived in coordinated batches over a few days, the rhythm of a script running on a schedule, not individual people signing up whenever they happened to feel like it.
There was no shared device ID across any of the accounts. Everyone had their own, freshly generated. Most conventional detection links account for a single, surface-level identifier, so this cluster would normally read as two hundred unrelated strangers. That’s the point of a script like this: it’s built to spin every device detail and make each account look unique.
“The identifiers were disposable by design. The deeper device signals underneath them weren’t.”
That deeper uniformity is exactly what the fix is built on. The next time this fraudster spins up a new template, with new device IDs and new fingerprint values, the clones will still all report the same hardware profile as each other. That sameness is what re-links them automatically, no matter what the specific numbers are next time.
No one signal here would have been enough to call this a ring. A behavioral flag alone gets adjusted around. An identical audio fingerprint alone might be an odd coincidence. But behavior, three independent hardware layers and network infrastructure all agreeing on the same two-way split, on nearly two hundred accounts that shared no device ID at all, isn’t a coincidence. It’s what shared infrastructure looks like when you have enough independent signals to see it.

