Platform
Solutions
Resources
Company
Resources
Solutions

Bonus abuse and multi-accounting: seeing the connection

Bonus abuse does not look like a rule violation when examining individual accounts. TruvaLI uncovers account clusters linked through device, IP, payment method, and email patterns.

Bonus abuse is the repeated exploitation of promotions and welcome campaigns by the same individual using multiple accounts. When looking at a single account, there is no violation: the user registered, claimed the bonus, and met the requirements. The violation lies in the relationship between the accounts.

How are accounts linked?

LinkWhat it shows
Device IDAccounts opened and used from the same device
IP and networkThe same address, same provider, or same VPN exit node
Payment methodThe same card, same IBAN, or same wallet address
Email patternHighly similar addresses or sequentially numbered accounts
Identity detailsCombinations of the same address, same phone number, or same date of birth
Behavioral synchronicityAccount groups operating at the same times and in the same sequence

Fuzzy matching is decisive for emails: clusters like first.last1@, first.last2@, and first.last3@ only become visible through checks that compare addresses against each other. The email provider also matters; account clusters registered via disposable email providers flag a distinct risk.

On the IP side, the characteristics of the address are analyzed: geolocation, ownership records, and rDNS determine whether the address is a proxy, a VPN, or a residential internet service provider. The number of accounts sharing the same address serves as a separate risk signal.

Who connects the dots?

What brings individual signals together is the relationship network. When an account becomes suspicious, it opens up all other accounts linked to it via device, payment method, or address for investigation. As the cluster grows, the pattern becomes clear: ten accounts operating from the same device, on the same day, with the same bonus flow cannot be explained by coincidence. Details are on the fraud detection page.

How is a rule written?

In bonus abuse, a rule is usually not a threshold but a relationship question: such as "if logins have been made to three different customer accounts from the same device ID". Being able to write this type of check without technical knowledge is the practical side of the system; you describe what the check should be in your own words, and the corresponding draft rule is generated. The rule writing with prompts page explains this.

It is important to consider how much a rule will affect legitimate users: two people playing from the same household or a shared corporate network might be incorrectly flagged as a cluster. How many accounts the new threshold would have caught in historical traffic is measured beforehand using rule simulation.

How are results processed?

A cluster triggers a case, which contains all associated accounts, the links between them, the triggered rule and its version, and the investigator's justification. Revoking the bonus, restricting the account, or clearing the cluster are decisions that are recorded. The workflow is detailed on the alert and case management page.

The industry framework and regulatory expectations are discussed on the gaming and betting page.

Common questions

Why is bonus abuse invisible on a single account?
Because a single account behaves in compliance with the rules: the user registers, claims the bonus, and meets the requirements. The violation lies in the relationship between the accounts.
What information is used to link accounts together?
Device ID, IP and network, payment method, email patterns, identity detail combinations, and behavioral synchronicity.
How are similar email addresses detected?
Addresses are scanned against each other using fuzzy matching; this reveals highly similar or sequentially numbered email clusters. The use of disposable email providers serves as an additional signal.
Is VPN usage considered a violation on its own?
No, it is not. The characteristics of the IP address are just one of many signals; the final decision depends on the combination of signals and the rules defined by the institution.
Can two people playing from the same household be mistakenly flagged as a cluster?
This risk is real, which is why the number of accounts a new threshold would catch in historical traffic is measured before the rule goes live.
Is technical knowledge required to write this type of rule?
No, it is not. You can describe what the check should be in your own words, and the corresponding draft rule is generated; the draft does not go live without approval.
What happens when a cluster is detected?
The cluster triggers a case where the accounts, the links between them, the triggered rule, and the investigator's justification are kept together. Revoking the bonus or clearing the cluster is recorded as a decision.
Can decisions be audited later?
Yes. Which rule and version was triggered, and who made the decision with what justification, is recorded in an immutable audit trail.

Related