Player collusion is coordinated play between two or more accounts designed to extract value from other players or the operator. The risk concentrates where it’s hardest to see: players who pass KYC individually, show no link at registration and only reveal their coordination at the gameplay and transaction level.
For poker and multiplayer game operators, that gap between clean signups and dirty play is where the money leaks.
Key Takeaways about detecting player collusion
What Is Player Collusion?
Player collusion is an agreement between two or more players to coordinate their actions at the table, giving themselves an unfair advantage over other players or the operator. It differs from multi-accounting in a specific way: a multi-accounter is one person running several identities, while colluders are different people who each pass KYC on their own merits and only become visible as a group through their behavior and shared signals.
Collusion appears wherever the game structure rewards coordination. In poker, two players sharing hole-card information or refusing to bet against each other can systematically drain a third player at the table.
- In sports betting, coordinated accounts can exploit arbitrage across bet types or manipulate market lines.
- In casino games with multiplayer mechanics, collusion rings can cycle bonuses and promotional value between accounts that appear unrelated.
The common thread is that the connection between colluding accounts is invisible at the point of registration. The players are not connected just on the registration level or affiliate level, but on a game style level, and the operator has to find that connection before the colluders act on it.
Types of Player Collusion
Not every collusion scheme looks the same at the table, and each type leaves different traces in the data. Knowing the typology matters because it determines which detection layer actually catches it.
Soft play
Soft play is when one player deliberately avoids betting or raising against a partner, protecting their stack while playing aggressively against everyone else. The result is a lopsided pattern: two players at the same table who never meaningfully contest each other’s hands, even when the cards warrant it. Fraud analysts build soft play reports between specific player pairs to surface the pattern, comparing their head-to-head aggression against their baseline behavior with the rest of the table.
Chip dumping
Chip dumping is the deliberate transfer of chips from one account to another through intentional losing. A player makes oversized bets with weak hands or calls obvious bluffs, funneling value to the receiving account. It’s a money-movement mechanism disguised as bad play, and it intersects directly with bonus abuse: a player can sign up with a deposit bonus, dump those chips to a partner and cash out through the clean account.
Chip dumping is particularly hard to address with fraud tooling alone. Account-linkage systems alone won’t catch chip dumping — the evidence lives in the game engine’s hand history. What they do catch is the connection between the dumper and the receiver: shared devices, overlapping payment methods, coordinated session timing. That’s the thread an operator pulls to know which hands to investigate.
Whipsawing and signalling
Whipsawing is a two-player squeeze play. Partners sitting on either side of a target alternate raising and re-raising, inflating the pot and trapping the middle player into calling increasingly expensive bets with no room to maneuver. The colluders don’t need to win every hand — they just need to force enough bad calls to grind down the target’s stack over a session.
Signalling is communication disguised as gameplay. A colluder uses a specific bet size, an unusual raise amount or a deliberate timing pattern to tell their partner what they’re holding — without ever leaving the table. Combined with whipsawing, it turns the squeeze play from opportunistic into precise: the partner knows exactly when to raise and when to fold because the bet itself carries the message.
Collusion rings and multi-accounting
Collusion rings scale the problem: instead of two players, three or more accounts pass value in a loop. Player A loses to player B, player B loses to player C, player C loses to player A again, making the transfer harder to trace than a straight two-way dump.
Multi-accounting is the solo version: a single person runs multiple accounts at one table, giving themselves a statistical advantage by seeing more hole cards and controlling more of the action. The identities look distinct at registration, but the accounts share device fingerprints, login patterns or payment methods underneath.
Why Player Collusion Is Hard to Detect
The core problem is that organized colluders deliberately avoid the signals most fraud systems rely on. They register with real identities on their own devices, funded by their own payment methods and they pass KYC without a hitch. There’s no shared IP at signup, no reused email domain, nothing that ties one account to another. At the account level, every player looks legitimate.
The coordination happens off-platform, in Telegram groups, Discord servers and phone calls, while the evidence sits in gameplay data that fraud platforms rarely touch. To find the connection between accounts you need device, network and identity signals; to confirm what the players are doing with that connection you need gameplay analysis. Most operators have one layer or the other, and the fraud lives in the gap between them.
“We thought we had everything covered because we understood the nuances of our business, platform and users. But we discovered layers of fraud, from friendly to extreme. We realized how exposed we were.”
Claudia Farrugia, Head of Operations at MrQ
How to Detect Player Collusion
Collusion detection works best as a layered approach, combining account-linkage signals that surface the connection between players with gameplay-pattern monitoring that confirms the coordination. No single signal is definitive on its own — a shared IP could mean a shared household, while a soft-play pattern could be coincidence over a small sample.
Link accounts with device intelligence
Device intelligence is the strongest account-linkage signal for collusion because colluders who use separate identities, emails and payment methods often slip up at the device level. A device ID (built from hardware attributes, browser configuration and other identifiers) can link accounts that look completely independent on every other dimension.
The workflow is straightforward: start from a known-bad account, pull its device ID, then check which other accounts share that same identifier. At scale, that means running a batch of 50,000 accounts and surfacing the 10 that share a device ID, then blocking the device. Shared password hashes and browser hashes serve as secondary linkage signals, less persistent than a device ID but still effective when colluders reuse credentials or browser profiles across accounts.
Screen connection and location signals
IP sharing, residential proxy detection and geolocation anomalies add a second linkage layer. Two accounts that consistently log in from the same IP range, particularly during gameplay sessions, are worth flagging even when their registration data is clean. VPN and proxy detection matters here because organized colluders route traffic through residential proxies to mask the fact that they’re in the same location.
IP alone is not definitive. Addresses rotate, households share connections and mobile networks reuse IPs across users, but a shared IP becomes meaningful when the accounts also share a device fingerprint, play at the same tables or show complementary betting patterns.
Cluster accounts with network analysis
Network analysis is where individual linkage signals compound into a visible structure. Rather than evaluating each account in isolation, clustering maps the relationships between accounts that share multiple data points (device, IP, payment method / BIN, geolocation, behavioral patterns ) and groups them into networks.
The workflow starts from a single confirmed bad actor and expands outward: link other accounts by device ID, build the network, then batch-check a larger pool for shared device IDs and block. The output is a cluster with measurable properties that a fraud analyst can act on before the colluding accounts reach payout. Manual review catches one pair at a time; network clustering surfaces the whole ring from a single starting point, along with new accounts that join the pattern later.
Enrich with digital footprint and cross-operator signals
Data enrichment adds context that neither device signals nor gameplay data provide on their own. Running an account’s email address, phone number and IP against external sources builds a picture of the identity behind the account. Is this a real person with a real digital history, or a thin profile created for a single purpose?
Cross-operator signals are particularly valuable for collusion detection. If an email address or phone number appears on multiple iGaming platforms and carries a high fraud ratio across them, the risk profile shifts before the player places a single bet. Membership at a competitor is a data point, not a disqualifier, but combined with a thin digital footprint and linkage to other flagged accounts, it sharpens the signal.
Layer in gameplay and behavioral monitoring
Account-linkage signals find the connection between players while gameplay monitoring confirms what they’re doing with it. The two serve different functions: a fraud platform detects device-linked accounts and behavioral anomalies at registration and transaction level, while the operator’s game engine or PAM analyzes hand histories, bet sizing, win rates between player pairs and session overlap to spot patterns like consistent soft play or abnormal chip-transfer flows.
Operators who layer both close the gap that either system leaves open on its own: flagging linked accounts through device and network intelligence, then monitoring those flagged accounts for gameplay anomalies on the platform side.
How to Prevent Player Collusion
The same signals that catch collusion after the fact can stop it before it pays out — the difference is where in the player lifecycle you apply them.
- Flag linked accounts before deposit: Score every new account against device, network and identity signals at registration. When two or more accounts share a device ID, a password hash or a payment method, flag the cluster and deny registration bonuses automatically. Rings that can’t collect bonus value on their first session move on to easier targets.
- Hold payouts on flagged accounts: Even if colluders get through registration, hold withdrawals on any account that carries a linkage flag until a fraud analyst reviews the cluster. The cost of a delayed payout on a legitimate player is a support ticket while the cost of paying out a collusion ring is unrecoverable.
- Restrict table seating for linked accounts: If two or more accounts share device or network signals, prevent them from sitting at the same table or entering the same tournament. This doesn’t stop collusion entirely — players on separate devices can still coordinate — but it removes the easiest path and forces the ring to invest more effort per attempt.
- Feed confirmed cases back into your models: Every confirmed collusion case is training data. Label it, feed it into your scoring rules and machine learning models, and the next ring that fits the same pattern gets caught faster. A scoring model without confirmed outcomes is guessing the same way every time, while the rings will learn the patterns and find new workarounds.
- Make enforcement visible: State plainly in your terms of service, help center and ban notifications that linked accounts are monitored and collusion results in forfeiture and permanent bans. When other players and potential bad actors can see that enforcement is real, rings are more likely to move on to platforms that don’t advertise what they catch.
How SEON Detects Player Collusion
SEON finds the connection between colluding accounts before they reach payout. Network and cluster detection groups accounts that share device signatures, IP addresses, payment data and behavioral patterns into scored clusters with measurable connection strength. Starting from one confirmed case, the system will expand the network automatically, uncovering new connections that traditional tools and methods woul miss.
Device intelligence links accounts even when users clear cookies or reset browsers. Digital footprint analysis adds external context through email, phone and social media lookups to separate real players from disposable identities.
Together, these layers give operators a scored, evidence-backed view of which accounts are connected and how strong that connection is. Before those players can make their first play.
See which players are linked before they sit at the same table.
Speak with an Expert
FAQ
How do poker sites detect collusion?
Poker operators combine two detection layers. The first is account linkage: using device fingerprinting, IP analysis, network clustering and identity enrichment to find connections between accounts that appear independent at registration. The second is gameplay monitoring: analyzing hand histories, win rates between specific player pairs and betting patterns for signs of coordinated play like soft play or chip dumping. Neither layer is sufficient alone.
What is soft play in online poker?
Soft play is when a player deliberately avoids betting or raising against a specific opponent to protect their stack, while playing aggressively against everyone else. It’s one of the most common forms of collusion in online poker because it’s subtle — the colluder doesn’t need to make obviously bad plays, just selectively passive ones.
What is chip dumping?
Chip dumping is the intentional transfer of chips from one account to another through deliberately losing hands. The dumping player makes oversized bets with weak hands or calls into obvious strength, funneling value to a partner. It’s often used to cash out bonus money or move illicit funds through the poker platform.
Is player collusion illegal?
Player collusion is prohibited in virtually every regulated iGaming market, though whether it rises to a crime depends on the jurisdiction and the conduct. In most markets it violates the operator’s terms of service and leads to account closure, forfeiture of funds and bans. Where collusion involves stolen identities or laundering money through chip dumping, it can cross into criminal territory. Operators are typically required by their license conditions to detect and prevent it as part of their responsible gaming and anti-fraud obligations.
