New Sign-Ups Are Up, but Are They Real Customers? Fake Accounts Created by Bots
Summary
An increase in new sign-ups does not necessarily mean an increase in real customers. Automated tools can create multiple accounts to repeatedly claim new-user coupons, referral rewards, free trials, points, and other promotional benefits.
Fake account creation is no longer limited to repeatedly signing up from the same IP address. By combining disposable email addresses, multiple IPs and sessions, and real browsers, each sign-up request can appear to come from a different legitimate user.
Email verification and CAPTCHA can validate certain steps in the sign-up process, but they cannot determine why multiple accounts were created or what those accounts do after registration.
Businesses therefore need to look beyond individual sign-up requests and analyze login IDs, sessions, access environments, request frequency, and how benefits are used after registration.
An increase in new sign-ups during an event or marketing campaign is generally considered a positive signal for most services. If registrations rise after a marketing campaign, that increase may be treated as an important campaign outcome. Similarly, for free trials or coupon promotions, the number of users acquired can serve as a key performance metric.
However, just because users complete the registration process through an event or marketing campaign does not necessarily mean that every new account represents a real customer.
Automated bots can do more than simply crawl websites. They can also use a service's legitimate registration functionality to create multiple accounts. Why does this matter? The impact goes beyond simply inflating membership numbers. Fake accounts can drain promotional budgets and reduce the benefits available to legitimate customers. This activity can also distort customer data and marketing campaign performance. Because it uses legitimate service functionality as intended, it often looks different from conventional web attacks.
OWASP, a nonprofit foundation focused on improving software security, classifies this type of automated threat as OAT-019 Account Creation. It refers to the creation of multiple accounts through a service's legitimate registration functionality, which are then used for other forms of abuse.
So how can businesses distinguish legitimate new customers from automated activity designed to appear as multiple individual users?
Why Do Bots Go Beyond Crawling and Create Accounts?
If the goal is simply to collect publicly available information from a website, creating an account is often unnecessary. Bots that go as far as registering accounts may therefore have different objectives, including:
Repeatedly claiming new-user coupons and first-purchase discounts
Collecting referral and invite rewards
Repeatedly using free trial periods
Collecting points, mileage, or in-game items
Entering events multiple times
Manipulating engagement metrics such as reviews, comments, or votes
Creating accounts for later use in spam, resale, or account attacks
Not all fake accounts are created through fully automated processes. Account creation and repetitive data entry can be automated while humans handle only the steps that are more difficult to automate, such as CAPTCHA or mobile phone verification.
When Cloudflare announced Account Abuse Protection in 2026, it noted that automation alone is no longer sufficient to explain modern account abuse. When attackers use real browsers and residential proxies, it becomes more difficult to distinguish automated bot requests from those made by actual users based solely on individual requests.
As hybrid approaches combining bots and human involvement become more common, businesses need to evaluate not only ‘Is this an automated request?’ but also ‘Does this behavior resemble that of a real user?’
How Are Fake Accounts Created?
The core of fake account creation is the automation of registration functionality that a service already provides.
Attackers can repeatedly execute the registration process to create multiple accounts. In particular, disposable email services or multiple email addresses can be used to continuously create accounts that appear to belong to different users.
The important point is that, from the service's perspective, each registration request may appear to follow the normal sign-up process.
Looking only at the request format—such as accessing the registration page and entering the required information—the activity may not look significantly different from that of a legitimate user.
In other words, fake account creation is less about exploiting a technical vulnerability and more about business logic abuse, where legitimate service functionality is automated and repeatedly used in unintended ways.
This can also lead to promotion abuse, where accounts are created solely to claim benefits offered by the service. These accounts are recorded as new users in company data but do not develop into long-term customer relationships, potentially distorting data and undermining campaign performance.
What Damage Can Fake Accounts Cause?
Fake accounts created by bots can affect businesses and services in several ways.
Impact | Problem |
|---|---|
Promotion costs | New-user coupons, free credits, referral rewards, and other benefits may be distributed to accounts that do not represent genuine prospective customers. |
Customer data | Membership and active-user numbers can become inflated, making it harder to understand the characteristics and behavior of actual customers. |
Campaign performance | Sign-up conversion rates may appear high while purchase and retention rates remain low, distorting channel-level performance analysis. |
Operational costs | Additional work may be required for fraudulent account reviews, order cancellations, refunds, customer support, and policy changes. |
Customer experience | Limited benefits and inventory intended for legitimate customers may be depleted, while promotion requirements may become excessively complicated as businesses attempt to distinguish real customers from fake accounts. |
Brand trust | Repeated monopolization of promotional benefits by a small number of users can increase concerns about the fairness of promotions. |
In one case involving a sporting goods brand, automated traffic abused discount codes and manipulated promotional and ordering systems, resulting in distorted analytics data and financial losses.
Are Email Verification and CAPTCHA Enough?
Email verification and CAPTCHA remain useful security measures, but each has limitations when it comes to verifying whether an account belongs to a real customer.
Email verification confirms that a user can access a particular email address. However, it cannot determine whether that address belongs to a genuine long-term customer, whether it is disposable, or whether a single person has created multiple email addresses.
CAPTCHA is used to provide additional verification that a current request is being performed by a human. However, CAPTCHA can still be passed when humans participate in certain stages of the process or when browser-based automation is used.
The same limitation applies to IP blocking. By using multiple IP addresses and proxies, attackers can make each account appear to originate from a different location. Conversely, in environments such as businesses, schools, or public networks, multiple legitimate users may share a single IP address. Aggressive IP-based blocking can therefore affect legitimate customers.
In other words, an individual signal can help narrow down suspicious activity, but it is difficult to treat any single signal as definitive proof of abuse.
What Should You Look at to Identify Fake Accounts?
The key is to look beyond individual registration requests and analyze the connected journey from account creation to benefit redemption.
Accounts and sessions
Were multiple accounts created sequentially within a short period?
Were multiple login IDs used from the same session or a similar access environment?
Did the account stop showing activity immediately after claiming a benefit?
Access environment
Do multiple accounts share identical or similar browser or device characteristics?
Do different IP addresses repeatedly share the same ASN, proxy, or network characteristics?
Are there signs of browser automation tools or unusually modified environments?
Behavioral patterns
Are the intervals between registration inputs and clicks unusually consistent across multiple accounts?
Does activity concentrate on registration, coupon issuance, and redemption URLs without the browsing journey typically seen among legitimate users?
Is the time between registration and benefit redemption unusually short or repeated in a consistent pattern?
Final business outcomes
Is there a significant gap between the number of new sign-ups and actual purchases or activations?
Are shipping addresses, payment methods, referrers, or benefit redemption destinations connected across multiple accounts?
Does account creation and coupon usage increase abnormally during specific campaigns?
Some of this information needs to be analyzed through bot management systems, while other data resides in membership, ordering, and payment systems. For this reason, it is important not to analyze security-team access logs separately from promotion data owned by marketing and service operations teams.
How Should Businesses Respond to Promotion Abuse?
1. Identify Which Areas Need Protection First
There is no need to apply the same level of verification to every page. Start by identifying areas where automation can directly lead to financial costs or loss of promotional benefits.
Registration form submission
Email and mobile phone verification requests
Login and account recovery
Coupon and free-credit issuance
Referral code entry and reward distribution
Point redemption and first-purchase checkout
2. Connect Account Creation with Benefit Usage
When looking only at the registration stage, each account may appear legitimate. However, repeated abuse becomes easier to identify when you connect what happens afterward—for example, when multiple accounts immediately follow the same path, claim the same benefit, and then stop showing any further activity.
3. Apply Different Responses Based on Risk Level
Immediately blocking users based on a single suspicious signal can affect legitimate customers. Responses should therefore vary according to the level of risk.
Risk Level | Example Response |
|---|---|
Low | Allow access normally and observe behavioral data. |
Medium | Apply CAPTCHA, email reverification, or additional authentication. |
High | Consider account- or session-level restrictions, withholding benefits, or blocking requests. |
Repeated abuse | Review related accounts and benefit usage history and take action according to business policies. |
4. Measure Actual Outcomes, Not Just the Number of Blocks
The goal of preventing fake accounts is not to block as many requests as possible. The objective is to ensure that legitimate customers can register and use benefits smoothly while reducing repeated benefit claims by the same actors.
Businesses should therefore monitor metrics such as:
Activation and purchase conversion rates among new sign-ups
Percentage of accounts that leave immediately after registration or only claim promotional benefits
Number of duplicate or suspicious benefit redemptions by campaign
Time spent on account reviews and customer support
Completion rates for additional verification and drop-off rates among legitimate customers
False-positive cases before and after policy changes
Before Counting Accounts, Make Sure They Represent Real Customers
Promotion abuse can be carried out by automated bots using legitimate registration functionality. As a result, promotional budgets can be lost and customer data can become contaminated even when there are no service outages or obvious signs of hacking or credential stuffing.
Looking only at the number of new sign-ups is not enough to understand actual campaign performance. A particular email address does not necessarily indicate a bot, and multiple users registering from the same IP address should not automatically be classified as abnormal.
Businesses need to connect not only who registered, but also the environment and behavioral flow through which they registered and what benefits they used afterward.
For future promotions, the more important question is not simply "How many accounts were created?" but "How many real customers signed up and went on to use the service normally?" To answer that question, businesses need to analyze multiple behavioral and access signals together.
FAQ
Q. Are fake account creation and account takeover the same type of attack?
No. Fake account creation involves an attacker creating large numbers of new accounts, while account takeover involves unauthorized access to existing customer accounts. However, both attacks can involve automated registration or login requests and the use of multiple IP addresses and sessions, making it important to analyze both behavior and access environments.
Q. Can mobile phone or email verification prevent fake accounts?
They can increase the cost of creating accounts and reduce certain types of abuse. However, attackers may use multiple email addresses, virtual phone numbers, or verification processes involving human participation. Completing verification alone therefore does not guarantee that an account belongs to a genuine customer. Post-registration behavior and benefit usage should also be analyzed.
Q. Should all accounts created from the same IP address be blocked?
Generally, no. Multiple legitimate users may share a single IP address in corporate, educational, or public networks. Conversely, attackers can distribute activity across multiple IP addresses. IP address is an important signal, but it should be evaluated together with sessions, accounts, browser characteristics, and behavioral patterns.
Q. Can BotManager prevent all forms of promotion abuse on its own?
BotManager detects and controls automation tools and abnormal access and behavioral patterns. However, coupon eligibility, relationships between orders, payment methods, shipping addresses, and similar information belong to a company's business data.
Effective prevention therefore requires bot management policies to work together with account, promotion, and order policies.