A user can pass an identity verification check, build a credible history, and still become part of a fraud event down the line. That’s because fraudsters are no longer hiding behind fake identities. They’re hiding behind mule accounts: real people, with valid IDs, and established account histories.
I recently sat down with Jeff Giuffrida, Manager of Behavioral Engineering at Etsy for a webinar on how marketplaces can proactively detect fraudulent activity beyond just onboarding.
The core theme was clear: identity can no longer be treated as a one-time decision made at signup. Trust needs to be evaluated continuously, with passive signals providing the foundation for recognizing when a once-trusted account begins to present new risk.
Contact Signals: Email, Phone and Address
One of the clearest opportunities for marketplaces is to turn basic contact information into a source of ongoing intelligence. Email, phone, and address signals can reveal an attribute’s history, usage, and connections, especially when evaluated together, rather than simply checked for validity at signup.
These signals together can surface patterns that a one-time validation would miss, such as a disposable email linked to multiple accounts, a recently activated phone number that does not align with the user’s identity, or an address connected to fraudulent listings. Together, they can help you identify account farming, identity misuse, or coordinated fraud.
The opportunity: Use existing contact signals to establish context around an account at signup.
Device Signals: Integrity, History, and Velocity Signals
Another opportunity is to understand the device behind an account, not just the user presenting it. For example, a new seller may sign up from a device already associated with 19 other seller accounts. That connection may reveal shared infrastructure, account farming, or other relationships that would not be visible from the signup alone.
To uncover these connections, marketplaces can evaluate three dimensions of device signals:
- Integrity: Whether the device shows signs of tampering, emulation, rooting, or other manipulation.
- History: How many buyer and seller accounts the device is connected to, and whether those accounts have prior fraud issues.
- Velocity: Whether the device is being used to create accounts, post listings, or make purchases at an unusually high rate
The opportunity: Connect device activity across accounts to uncover hidden relationships, identify changes in account control, and detect coordinated abuse earlier.
Contextual Signals: Network and Location
Basic IP and location checks can miss critical context. For example, a seller may sign in from a familiar device but suddenly access the account through an anonymous network, change the account’s payout details, and begin transferring funds. Or, a buyer account that typically makes purchases from one region may suddenly log in from another location, update its payment method, and place several high-value orders. Individually, each event may have a reasonable explanation. Together, they may indicate account takeover, account sharing, or coordinated abuse.
Network and location signals provide a broader view of where activity originates and whether it aligns with the account’s known identity, device, and behavior.
The opportunity: Continuously monitor where and how users access an account. Detect network or location changes that fall outside the user’s established profile, and use those signals to trigger step-up verification, investigation, or intervention.
Behavioral Signals: Typing Patterns, Automation, and Behavioral Changes
A trusted account can become risky without any obvious change to its contact, device, or login credentials. For example, a seller may suddenly create dozens of listings, copy and paste identical descriptions, have identical typing or navigation patterns across multiple accounts, or message buyers at an unusually high rate.
Behavioral signals can distinguish normal activity from automation or coordinated abuse. Rather than treating trust as a one-time decision based only on who created the account or which device they use, combine behavioral signals with device, network, connection, and historical signals to evaluate whether current activity aligns with the account’s established digital profile.
The opportunity: Treat behavior as an ongoing indicator of trust. Continuously compare how a user interacts with an account against its established patterns, so you can detect meaningful shifts in activity.
Bring these signals together
The value of these signals comes from connecting them. Socure’s identity graph serves as that connective layer, linking contact attributes, devices, locations, behaviors, listings, and payment / payout methods.
When these signals come together, you can make more informed decisions throughout the entire customer journey, enabling your teams to identify coordinated abuse, detect changes in account control, and determine when to trigger step-up verification.
The goal is not to add friction to every interaction. It is to understand the full context behind an account and focus intervention where the signals point to an increase in risk, while allowing trustworthy buyers and sellers to continue with minimal disruption.
Want to learn how marketplaces can detect fraud beyond onboarding? Check out my recent webinar with Jeff: Defending the Platform: High-Security Onboarding with Zero Added Friction
Source link
