[{"data":1,"prerenderedAt":314},["ShallowReactive",2],{"\u002Fblog\u002Fthousands-of-fake-leads-made-by-hand":3},{"id":4,"title":5,"accomplishment1":6,"accomplishment2":6,"accomplishment3":6,"author":7,"body":8,"category":298,"createdAt":299,"description":300,"executiveSummary":6,"extension":301,"founded":6,"headquarters":6,"img":302,"meta":303,"navigation":305,"og-img":302,"path":306,"rawbody":307,"seo":308,"sitemap":309,"size":6,"status":310,"stem":311,"tags":312,"updatedAt":6,"website":6,"__hash__":313},"blog\u002F4.blog\u002F56.Thousands of fake leads made by hand.md","Thousands of fake leads, made by hand, with no bot signals at all",null,"Ahmed Saleh",{"type":9,"value":10,"toc":280},"minimark",[11,15,19,22,29,34,39,42,45,49,52,56,59,62,66,69,73,76,79,83,86,89,92,95,99,102,109,115,121,125,128,203,206,209,213,241,245,248,251,254,258],[12,13,5],"h1",{"id":14},"thousands-of-fake-leads-made-by-hand-with-no-bot-signals-at-all",[16,17,18],"p",{},"Every week I take one real fraud or abuse case, walk through what the actor actually did, and list the rules you can add to your own trust engine because of it. This is edition #003.",[16,20,21],{},"This week: thousands of fake leads on a marketplace, spamming the providers there and trying to pull them off platform. Every one of those leads was made by hand.",[16,23,24],{},[25,26],"img",{"alt":27,"src":28},"Trust Booster #003: marketplace fake leads, one new account almost every day for five months","\u002Fimg\u002Fblog\u002Ftrust-booster-fake-leads.png",[30,31,33],"h2",{"id":32},"how-they-did-it","How they did it",[35,36,38],"h3",{"id":37},"_1-signing-up","1. Signing up",[16,40,41],{},"The actor signs up with a real, valid email and a junk phone number carrying area code 245. That area code doesn't exist in the North American numbering plan, but it passes a simple regex check, so the form takes it. Email 2FA is no obstacle, because it is a real inbox that he opened himself.",[16,43,44],{},"Thirty accounts on this platform sat on area code 245, which is unassigned.",[35,46,48],{"id":47},"_2-hitting-the-wall","2. Hitting the wall",[16,50,51],{},"Once spam got bad enough, the marketplace started requiring a verified phone number before you could message a provider, with a limit of one account per number. At that point the junk number stopped being good enough.",[35,53,55],{"id":54},"_3-buying-a-burner","3. Buying a burner",[16,57,58],{},"So he bought an SMS-only line. Real carrier, real mobile number, voice service switched off. Call it and you get a carrier intercept.",[16,60,61],{},"Every phone intelligence lookup we ran came back valid, active, mobile, low risk. None of them test whether a human can actually be reached on the number, which is the only question that matters here.",[35,63,65],{"id":64},"_4-rotating-ips","4. Rotating IPs",[16,67,68],{},"A new IP every few days, then commercial VPN exits once he got more careful.",[35,70,72],{"id":71},"_5-spamming-providers","5. Spamming providers",[16,74,75],{},"Fifty or more fake leads and spam messages a day, going after the providers' card and bank details, until enough of them complained and the account got banned. Then he would start tomorrow's identity.",[16,77,78],{},"One new account almost every single day, for five months.",[30,80,82],{"id":81},"this-was-a-human","This was a human",[16,84,85],{},"Every bot check we run came back negative. No webdriver, no automation globals, no synthetic events, nothing headless.",[16,87,88],{},"He typed the codes himself, at ordinary human speed. Our SMS verifications complete at a median of 15 seconds and his came in around 10, which puts him in the same range as a quarter of the real users on that platform.",[16,90,91],{},"A real person, doing it by hand, every day, for months.",[16,93,94],{},"Every velocity rule stayed quiet, because one account a day isn't a spike. Every bot rule stayed quiet, because there was no bot. He was slower than the alerting and more patient than the review queue.",[30,96,98],{"id":97},"what-did-not-work","What did not work",[16,100,101],{},"All three of these were already running.",[16,103,104,108],{},[105,106,107],"strong",{},"Email verification."," The inboxes were real, at gmail, mail.com and tutamail, and he opened them himself. There was nothing to break.",[16,110,111,114],{},[105,112,113],{},"Phone verification."," A real mobile line on a real carrier, provisioned for SMS with voice disabled. Every lookup returns valid, active, low risk.",[16,116,117,120],{},[105,118,119],{},"Bot detection."," There was no bot.",[30,122,124],{"id":123},"what-did-work","What did work",[16,126,127],{},"Reuse. That's the whole answer, and it fell out in this order:",[129,130,131,147],"table",{},[132,133,134],"thead",{},[135,136,137,141,144],"tr",{},[138,139,140],"th",{},"Signal",[138,142,143],{},"This actor",[138,145,146],{},"Normal",[148,149,150,162,172,182,193],"tbody",{},[135,151,152,156,159],{},[153,154,155],"td",{},"identities per browser",[153,157,158],{},"19",[153,160,161],{},"1",[135,163,164,167,170],{},[153,165,166],{},"identities per origin IP",[153,168,169],{},"18",[153,171,161],{},[135,173,174,177,180],{},[153,175,176],{},"identities per throwaway number",[153,178,179],{},"6",[153,181,161],{},[135,183,184,187,190],{},[153,185,186],{},"accounts on area code 245",[153,188,189],{},"30",[153,191,192],{},"unassigned",[135,194,195,198,201],{},[153,196,197],{},"fingerprint reuse at challenge",[153,199,200],{},"35",[153,202,161],{},[16,204,205],{},"He never changed browsers. One fingerprint carried 19 separate identities. That fingerprint pointed at an IP, and that IP carried 18 distinct signups, where every other address from the same country in our database carried exactly one.",[16,207,208],{},"From there the naming pattern fell out, and the naming pattern gave up the rest of the ring: nearly 70 accounts built from the same baby-name database. The throwaway numbers he abandoned were reused too, so one discarded number tied six identities together on its own.",[30,210,212],{"id":211},"rules-worth-adding-to-your-engine","Rules worth adding to your engine",[214,215,216,220,223,226,229,232,235,238],"ol",{},[217,218,219],"li",{},"Reject impossible area codes at the form.",[217,221,222],{},"Count identities per fingerprint, not accounts per fingerprint.",[217,224,225],{},"Link accounts that share a discarded phone or email.",[217,227,228],{},"Alert when one IP carries many distinct signups.",[217,230,231],{},"Score numbers that take texts but not calls.",[217,233,234],{},"Check for patterns in how accounts get created.",[217,236,237],{},"Keep the IP, device, phone and email from rejected signups. This is valuable data. A rejected signup still tells you that someone is trying repeatedly.",[217,239,240],{},"Never read \"no bot signals\" as \"no fraud\". This is the critical one.",[30,242,244],{"id":243},"the-takeaway","The takeaway",[16,246,247],{},"This actor was patient and determined and was almost certainly a human assisted by AI.",[16,249,250],{},"The best way to catch and deter those is with a human assisted by AI, or better yet an AI assisted by a human. Run an agent to do the initial flagging and potentially apply pressure to suspicious accounts, and keep a person in the loop to adjust as he adapts.",[252,253],"trust-booster-callout",{},[30,255,257],{"id":256},"more-trust-booster-cases","More Trust Booster cases",[259,260,261,268,274],"ul",{},[217,262,263],{},[264,265,267],"a",{"href":266},"\u002Fblog\u002Fone-device-400-fake-accounts","One device, 400 fake accounts: the six signals that gave the ring away",[217,269,270],{},[264,271,273],{"href":272},"\u002Fblog\u002Fcard-testing-ring-120000-fake-accounts","How a card testing ring made 120,000 fake accounts without opening the signup page",[217,275,276],{},[264,277,279],{"href":278},"\u002Fblog\u002Fone-seat-41-people","One seat, 41 people: how account sharing hid a scraping and resale ring",{"title":281,"searchDepth":282,"depth":282,"links":283},"",2,[284,292,293,294,295,296,297],{"id":32,"depth":282,"text":33,"children":285},[286,288,289,290,291],{"id":37,"depth":287,"text":38},3,{"id":47,"depth":287,"text":48},{"id":54,"depth":287,"text":55},{"id":64,"depth":287,"text":65},{"id":71,"depth":287,"text":72},{"id":81,"depth":282,"text":82},{"id":97,"depth":282,"text":98},{"id":123,"depth":282,"text":124},{"id":211,"depth":282,"text":212},{"id":243,"depth":282,"text":244},{"id":256,"depth":282,"text":257},"Research","2026-08-13","Trust Booster #003. One person spent five months creating a fresh identity almost every day on a marketplace and spamming its providers. Every bot check came back negative. Reuse is what caught him.","md","\u002Fimg\u002Fblog\u002Ftrust-booster-fake-leads-cover.png",{"head":304},{"title":5},true,"\u002Fblog\u002Fthousands-of-fake-leads-made-by-hand","---\ntitle: Thousands of fake leads, made by hand, with no bot signals at all\nhead:\n  title: Thousands of fake leads, made by hand, with no bot signals at all\ndescription: \"Trust Booster #003. One person spent five months creating a fresh identity almost every day on a marketplace and spamming its providers. Every bot check came back negative. Reuse is what caught him.\"\nauthor: Ahmed Saleh\ncreatedAt: 2026-08-13\nimg: \u002Fimg\u002Fblog\u002Ftrust-booster-fake-leads-cover.png\nog-img: \u002Fimg\u002Fblog\u002Ftrust-booster-fake-leads-cover.png\ncategory: Research\ntags: trust booster, fake leads, marketplace fraud, phone verification, SMS burner, device fingerprinting, fake account prevention\nstatus: published\n---\n\n# Thousands of fake leads, made by hand, with no bot signals at all\n\nEvery week I take one real fraud or abuse case, walk through what the actor actually did, and list the rules you can add to your own trust engine because of it. This is edition #003.\n\nThis week: thousands of fake leads on a marketplace, spamming the providers there and trying to pull them off platform. Every one of those leads was made by hand.\n\n![Trust Booster #003: marketplace fake leads, one new account almost every day for five months](\u002Fimg\u002Fblog\u002Ftrust-booster-fake-leads.png)\n\n## How they did it\n\n### 1. Signing up\n\nThe actor signs up with a real, valid email and a junk phone number carrying area code 245. That area code doesn't exist in the North American numbering plan, but it passes a simple regex check, so the form takes it. Email 2FA is no obstacle, because it is a real inbox that he opened himself.\n\nThirty accounts on this platform sat on area code 245, which is unassigned.\n\n### 2. Hitting the wall\n\nOnce spam got bad enough, the marketplace started requiring a verified phone number before you could message a provider, with a limit of one account per number. At that point the junk number stopped being good enough.\n\n### 3. Buying a burner\n\nSo he bought an SMS-only line. Real carrier, real mobile number, voice service switched off. Call it and you get a carrier intercept.\n\nEvery phone intelligence lookup we ran came back valid, active, mobile, low risk. None of them test whether a human can actually be reached on the number, which is the only question that matters here.\n\n### 4. Rotating IPs\n\nA new IP every few days, then commercial VPN exits once he got more careful.\n\n### 5. Spamming providers\n\nFifty or more fake leads and spam messages a day, going after the providers' card and bank details, until enough of them complained and the account got banned. Then he would start tomorrow's identity.\n\nOne new account almost every single day, for five months.\n\n## This was a human\n\nEvery bot check we run came back negative. No webdriver, no automation globals, no synthetic events, nothing headless.\n\nHe typed the codes himself, at ordinary human speed. Our SMS verifications complete at a median of 15 seconds and his came in around 10, which puts him in the same range as a quarter of the real users on that platform.\n\nA real person, doing it by hand, every day, for months.\n\nEvery velocity rule stayed quiet, because one account a day isn't a spike. Every bot rule stayed quiet, because there was no bot. He was slower than the alerting and more patient than the review queue.\n\n## What did not work\n\nAll three of these were already running.\n\n**Email verification.** The inboxes were real, at gmail, mail.com and tutamail, and he opened them himself. There was nothing to break.\n\n**Phone verification.** A real mobile line on a real carrier, provisioned for SMS with voice disabled. Every lookup returns valid, active, low risk.\n\n**Bot detection.** There was no bot.\n\n## What did work\n\nReuse. That's the whole answer, and it fell out in this order:\n\n| Signal                          | This actor | Normal     |\n| ------------------------------- | ---------- | ---------- |\n| identities per browser          | 19         | 1          |\n| identities per origin IP        | 18         | 1          |\n| identities per throwaway number | 6          | 1          |\n| accounts on area code 245       | 30         | unassigned |\n| fingerprint reuse at challenge  | 35         | 1          |\n\nHe never changed browsers. One fingerprint carried 19 separate identities. That fingerprint pointed at an IP, and that IP carried 18 distinct signups, where every other address from the same country in our database carried exactly one.\n\nFrom there the naming pattern fell out, and the naming pattern gave up the rest of the ring: nearly 70 accounts built from the same baby-name database. The throwaway numbers he abandoned were reused too, so one discarded number tied six identities together on its own.\n\n## Rules worth adding to your engine\n\n1. Reject impossible area codes at the form.\n2. Count identities per fingerprint, not accounts per fingerprint.\n3. Link accounts that share a discarded phone or email.\n4. Alert when one IP carries many distinct signups.\n5. Score numbers that take texts but not calls.\n6. Check for patterns in how accounts get created.\n7. Keep the IP, device, phone and email from rejected signups. This is valuable data. A rejected signup still tells you that someone is trying repeatedly.\n8. Never read \"no bot signals\" as \"no fraud\". This is the critical one.\n\n## The takeaway\n\nThis actor was patient and determined and was almost certainly a human assisted by AI.\n\nThe best way to catch and deter those is with a human assisted by AI, or better yet an AI assisted by a human. Run an agent to do the initial flagging and potentially apply pressure to suspicious accounts, and keep a person in the loop to adjust as he adapts.\n\n::TrustBoosterCallout\n::\n\n## More Trust Booster cases\n\n- [One device, 400 fake accounts: the six signals that gave the ring away](\u002Fblog\u002Fone-device-400-fake-accounts)\n- [How a card testing ring made 120,000 fake accounts without opening the signup page](\u002Fblog\u002Fcard-testing-ring-120000-fake-accounts)\n- [One seat, 41 people: how account sharing hid a scraping and resale ring](\u002Fblog\u002Fone-seat-41-people)\n",{"title":5,"description":300},{"loc":306},"published","4.blog\u002F56.Thousands of fake leads made by hand","trust booster, fake leads, marketplace fraud, phone verification, SMS burner, device fingerprinting, fake account prevention","tOJweHfh7AD9CXXjYVS24Qfskga4dESqmBzPR-SxF4w",1787249130672]