Glossary of Online Fraud

The dregs of internet society are a resourceful lot. Scammers, spammers, freeloaders, bad bots, and assorted other pests employ a whole arsenal of dirty tricks to exploit your free trials, wreck your metrics, harm your legitimate users, ratchet up your costs, and generally cause trouble on your site.

Here are the tricks you're most likely to find behind the fake signups and duplicate accounts in your user table, plus the defenses that hold up. Each entry explains the term, why it matters when you run an online product or community, and how to detect and stop it.

Account Takeover

An attacker gains control of a legitimate user's account. How Dregs spots the change in device, location, credentials, and behavior.

Anti-Detect Browser

A browser that gives every profile a different, convincing device fingerprint, and the clues it still leaves behind.

Ban Evasion

The user you removed, back under a new account. Why email and IP bans don't hold, and how to recognize the same person on the next signup.

Behavioral Analytics

Reading patterns across an account's activity rather than judging one event in isolation. How Dregs finds suspicious changes and repeated behavior.

Bot Detection

Separating useful automation from bots that create accounts, scrape content, test credentials, or abuse your product.

Bot Farm

A pool of automated accounts run as one resource. How it differs from a botnet, and what gives the coordination away.

CAPTCHA Alternatives

Identifying automation without forcing every legitimate user to solve a puzzle. Why CAPTCHAs fail accessibility, and what to use instead of a challenge wall.

CAPTCHA Solver Farm

A service that answers CAPTCHAs by the thousand for a few dollars, and why that makes CAPTCHA a toll rather than a barrier.

Credential Stuffing

Attackers test stolen username and password pairs against your login page at scale. How Dregs catches the campaign and the accounts it compromises.

Device Fingerprinting

Recognizing a browser and device from the characteristics they reveal. How Dregs uses fingerprints alongside network, identity, and behavior.

Disposable Email Address

A temporary inbox that lasts just long enough to receive a confirmation link, and what it means for your signup form.

Duplicate Accounts

One person operating several accounts to multiply a benefit or evade a restriction. How Dregs connects accounts that are trying to look unrelated.

Fake Signups

Fabricated profiles and junk registrations that pollute your user table and distort growth metrics. How Dregs scores each signup.

Fraud Detection

Finding suspicious accounts and activity before abuse becomes expensive. How Dregs combines identity, device, network, and behavioral evidence.

Fraud Scoring

Scoring the account rather than one visit or IP. How Dregs keeps Humanity, Authenticity, Uniqueness, and Behavior as separate fraud scores.

Free Trial Abuse

The same person repeatedly claiming a trial under fresh accounts. How Dregs links the new signup to the trials that came before it.

Headless Browser

A browser controlled through code rather than by a person clicking through a visible interface. How Dregs detects the automation it leaves behind.

Identity Graph

A map of accounts and the evidence connecting them. How Dregs exposes duplicate accounts, fraud rings, and other coordinated activity.

Identity Stitching

Connecting fragments that belong to one operator, even when the accounts are trying to look unrelated. How Dregs finds the evidence between them.

Impossible Travel

One account, two places, and not enough time to get between them. What the signal catches and why VPNs make it noisy.

Multi-Accounting

Operating several accounts at once to stack rewards, trials, votes, or other benefits. How Dregs detects the shared operator behind them.

New Account Fraud

A new account that isn't a genuine customer. Banks mean a stolen or synthetic identity, while on a SaaS product it usually means fake signups.

Phone Farm

A rack of real handsets operated together, so one party's activity looks like the activity of a great many people.

Plus Addressing

One inbox, unlimited addresses. Why blocking the feature backfires, and how to handle the duplicates instead.

Referral Fraud

Fraudsters refer their own fake accounts to collect rewards from both sides. How Dregs connects the referrer to the fictional friends being referred.

Promo Abuse

Launch credits and signup coupons collected more than once. How Dregs links the reused device to the redemptions that never become a paid plan.

Signup Abuse

Fake signups, trial freeloaders, bots, and junk in the user table, and how that differs from a stolen login or leaked passwords hammering the login page.

SMS Pumping

Verification texts requested and never completed. How scores on the account differ from an SMS firewall, and how to stop the next send.

Sock Puppet Account

A second or third identity posing as a different person, so one voice can sound like a consensus or give itself false credibility.

Trialmaxxing

Never letting a free trial end. How the same freeloader keeps signing up again, and how SaaS teams can stop it.

UEBA and UBA

Using behavior to find activity that doesn't fit an account's history or its peers. How Dregs applies the approach to your external users.

User Risk Scoring

Measuring the risk attached to each user rather than one transaction or IP address. How Dregs produces four scores with the evidence behind them.

Velocity Checks

Counting how often something happens, and why a threshold on its own isn't enough to keep repeat abuse in check.

Start a free trial and score signup abuse on your SaaS.

Dregs helps you catch fake signups, trial abuse, ban evasion, and bots. Each account gets Humanity, Authenticity, Uniqueness, and Behavior scores that open into their observations, so you can see exactly why.

Start Free Trial