Identity fraud is not always committed by one person targeting one account. Organized fraud rings coordinate people, stolen identities, manipulated documents, devices, payment methods, and digital infrastructure to create or control networks of accounts.

Each account may appear legitimate when reviewed independently. The broader pattern becomes visible only when platforms connect identity, biometric, device, behavioral, and transaction evidence across accounts.

INTERPOL notes that organized criminal groups use fraudulent accounts to transfer and launder proceeds from cybercrime and other illicit activity. INTERPOL I-Checkit

1. What Is a Fraud Ring?

A fraud ring is a coordinated group of actors, accounts, or identities working together to commit or support fraud.

Different participants may perform specialized roles:

  • Obtaining stolen identity data
  • Creating or modifying identity documents
  • Opening accounts
  • Completing face verification
  • Controlling devices and communication channels
  • Receiving or transferring funds
  • Withdrawing proceeds
  • Reusing successful attack methods

The person completing identity verification may not be the person controlling the account afterward. Some participants knowingly support the scheme, while others may be recruited as money mules without understanding the full operation.

Europol identifies document and identity fraud as infrastructure that can support online fraud, money laundering, trafficking, and other organized criminal activity. Europol report on criminal networks

2. How Fraud Rings Build Multiple Accounts

Fraud rings attempt to make related accounts appear independent. They may vary the visible information used for each registration, including:

  • Names and identity documents
  • Email addresses and phone numbers
  • Devices and network connections
  • Residential or delivery addresses
  • Payment instruments
  • Facial images
  • Application timing and transaction behavior

Some accounts use entirely stolen identities. Others combine real and fabricated information to create synthetic profiles. A legitimate participant may also pass onboarding for several accounts and later transfer control to the fraud ring.

The objective is separation: if one account is detected, the remaining accounts should appear unrelated and continue operating.

3. Common Fraud-Ring Operating Models

Coordinated identity fraud can support several business attacks.

Account Farming

Large numbers of accounts are created and prepared for later abuse. The accounts may remain inactive until they are sold, used for transactions, or activated during a coordinated campaign.

Promotion and Credit Abuse

Related accounts repeatedly claim welcome bonuses, referral incentives, coupons, credit limits, or subsidized services.

Money-Mule Networks

Accounts receive and transfer fraudulent proceeds through several intermediate steps, making the original source and final beneficiary harder to identify.

Marketplace Manipulation

Fake buyers and sellers coordinate reviews, purchases, refunds, chargebacks, or artificial transaction volume.

Re-entry After Enforcement

A previously blocked participant returns using a new identity profile, document, device, or account owner.

4. Why Individual Account Checks Miss the Network

A conventional onboarding process evaluates whether one application meets predefined requirements. It may verify the document, compare the applicant’s face with the document portrait, perform liveness detection, and screen basic risk signals.

A fraud ring can exploit this account-by-account view. Each application may use a different identity and device while retaining less obvious links to the same operation.

Platforms should therefore ask two questions:

  • Is this application trustworthy on its own?
  • How is it connected to previously observed identities, devices, accounts, and transactions?

Passing individual identity verification does not prove that an account is unrelated to coordinated abuse.

5. Signals That Can Reveal Connected Accounts

Fraud-ring detection becomes stronger when different evidence types are linked.

Identity and Document Signals

Related accounts may reuse document numbers, addresses, portraits, document templates, contact details, or slightly modified identity information.

Biometric Signals

One person may appear across multiple accounts registered under different names. Face++ Face Search uses 1:N comparison to search a captured face against an enrolled collection and return similar candidates.

This can support duplicate-account detection, but a biometric candidate should trigger contextual investigation rather than automatic rejection. Face++ recommends combining face-search results with document, device, behavioral, and account evidence. How Face Search Detects Multi-Account Fraud

Device and Network Signals

Connections may include shared devices, device fingerprints, IP ranges, proxies, emulators, operating environments, or repeated changes between identities on the same device.

Behavioral and Transaction Signals

Related accounts may follow similar onboarding sequences, operate at synchronized times, share beneficiaries, transfer funds through the same paths, or repeat the same withdrawal behavior.

No single shared attribute necessarily proves coordination. Households, shared workplaces, and public networks can create legitimate overlap.

6. From Shared Signals to a Fraud Network

A useful investigation model represents entities and relationships as a network:

  • Nodes: Customers, accounts, faces, documents, devices, phone numbers, addresses, payment methods, and beneficiaries
  • Edges: Shared, matched, accessed, transferred to, registered with, or referred by

This structure can reveal clusters that are difficult to detect in separate account records.

For example, ten accounts may use different names and documents but connect to two devices, one facial identity, and a common withdrawal destination. The combination is more informative than any single match.

Relevant indicators include:

  • Number of linked accounts
  • Strength and type of each connection
  • Frequency of shared attributes
  • Time proximity between registrations
  • Transaction flow between accounts
  • Previous confirmed fraud within the cluster

7. Building a Risk-Based Detection Workflow

A layered fraud-ring detection process can include:

  1. Verify each identity document and extracted field.
  2. Perform face comparison and liveness detection.
  3. Search for potential biometric duplication where appropriate.
  4. Link devices, networks, contact details, and payment instruments.
  5. Evaluate behavioral and transaction similarities.
  6. Calculate account-level and network-level risk.
  7. Route uncertain clusters for investigation.
  8. Apply restrictions proportionate to the evidence.

Face++ face comparison can establish whether a user matches a claimed identity, while Face Search can support 1:N investigation across enrolled facial records. Liveness detection helps assess whether the current session involves genuine presence rather than a presentation or synthetic-media attack.

These biometric signals should become part of the wider risk model rather than operate as standalone blocking rules.

8. Reducing False Positives

Connections do not always indicate a fraud ring. Legitimate users may share:

  • A household address
  • A family device
  • A corporate network
  • A payment instrument
  • Similar names
  • Public Wi-Fi
  • Authorized representatives

Platforms should distinguish weak links from high-confidence patterns. A shared IP address alone may have limited value. A repeated face match combined with different identities, reused devices, synchronized activity, and a common beneficiary creates substantially stronger evidence.

Manual reviewers should receive the relevant cluster, connection types, timelines, confidence scores, and original verification evidence rather than an unexplained risk label.

9. Frequently Asked Questions

Q1. What is coordinated identity fraud?

It is fraud involving multiple related identities, accounts, people, or technical resources operating toward a shared objective.

Q2. Can Face++ identify accounts belonging to the same person?

Face++ Face Search can return facial candidates from an enrolled collection. Platforms must determine whether those candidates represent prohibited duplication using appropriate thresholds and supporting evidence.

Q3. Does a shared device prove that accounts belong to a fraud ring?

No. Shared devices can have legitimate explanations. Device evidence should be evaluated with identity, biometric, behavioral, and transaction signals.

Q4. Why is liveness detection still necessary?

Fraud rings may use photographs, replays, deepfakes, or injected media to impersonate identity holders. Liveness detection addresses genuine presence, while network analysis addresses relationships across accounts.

10. Detect the Network, Not Only the Account

Fraud rings are designed to survive the loss of individual accounts. Detecting them requires platforms to move beyond isolated verification results and evaluate how identities, faces, devices, behaviors, and transactions connect.

By combining Face++ face comparison, Face Search, and liveness detection with document, device, and account-linkage analysis, digital platforms can identify coordinated identity fraud earlier and make more proportionate risk decisions.