Fraud and abuse glossary

Plain-language definitions of the terms that come up when you protect a product from fraud and abuse, with the signals that reveal each one.

Account sharing

Account sharing is when multiple people use one set of login credentials. Learn how it drains subscription revenue and the signals that reveal it.

Account takeover

Account takeover (ATO) is when an attacker gains control of a legitimate user's account through stolen credentials, phishing, or session hijacking.

Ban evasion

Ban evasion is when a banned user returns to a platform under a new account, device, or IP address. Learn how to detect and stop repeat offenders.

Bonus abuse

Bonus abuse is the exploitation of signup, deposit, and referral promotions through multiple accounts. Learn how it works and how to detect it.

Bot detection

Bot detection separates automated traffic, scrapers, credential stuffers, and AI agents from human users using device, network, and behavioral signals.

Browser fingerprinting

Browser fingerprinting combines canvas, WebGL, fonts, and other browser attributes into an identifier that recognizes a returning browser without cookies.

Credential stuffing

Credential stuffing is the automated replay of leaked username and password pairs against login forms. Learn how it works and the signals that expose it.

Device fingerprinting

Device fingerprinting identifies a device by combining signals like canvas rendering, WebGL, fonts, and hardware traits into a stable identifier.

Fake account detection

Fake account detection identifies accounts created by bots or fraud rings at signup, using email, IP, device, and automation signals to block abuse early.

Impossible travel

Impossible travel is when two logins on one account come from locations too far apart to reach in the time between them, a classic account takeover signal.

Multiaccounting

Multiaccounting is one person running multiple accounts on one platform to abuse free trials, farm referral rewards, evade bans, or manipulate marketplaces.

SMS pumping

SMS pumping is toll fraud where attackers trigger OTP texts to number ranges they profit from. You pay the messaging bill and they take a cut.