Industry Explained

August 5, 2026

Inside the Business of iGaming Fraud

Online gambling fraud rarely begins with anything dramatic. There’s no breach, no alarm, nothing that would look out of place in a monthly report. More often, it starts with a promotional offer, a reused password, a stolen identity, or a payment dispute that looks completely ordinary in isolation. The damage only becomes visible after someone connects the same devices, cards, accounts, and withdrawal destinations, and by that point, the operator may have already paid an acquisition commission, issued a bonus, and allowed the proceeds to leave.

The problem is unusually broad because a gambling account combines several things criminals can monetise at once: promotional credit, stored balances, payment access, and rapid cash-out. At the same time, operators need customers to register and deposit quickly, which leaves fraud teams under constant pressure not to obstruct legitimate players. Every additional check may prevent a loss, but it can also reduce conversion, and this tension defines basically everything that follows.

Bonuses as inventory 

Sign-up offers are designed to absorb the cost of acquiring a customer. Fraudsters treat that subsidy as inventory. They create multiple accounts, use purchased identities, rotate devices, and route traffic through VPNs or residential proxies to appear unrelated. The bonus value is then converted into withdrawable funds through low-risk bets, opposing wagers, or coordinated play. None of this is in any way new or sophisticated, and that’s largely why it keeps working.

Sumsub’s 2025 iGaming report, based on more than three million examined fraud attempts and a survey of over 100 businesses, attributed 63.8% of detected sector fraud to bonus abuse. It should be said that the figure comes from a company selling fraud products rather than from any industry-wide audit. But it does match an obvious incentive: bonuses provide a known reward, clear eligibility rules, and a repeatable process.

At the industrial scale, bonus abuse looks less like a customer exploiting loose terms and more like a logistics operation. Organisers obtain identities, prepare accounts, assign devices and payment methods, then centralise the withdrawals. Generative AI has reduced the cost of fake documents and face images, while account marketplaces provide verified profiles to buyers who never completed the checks themselves.

Accounts as entry points 

An established account can be more valuable than a new identity, because it has already passed verification and may contain funds, loyalty status, or saved payment methods. Criminals obtain credentials through phishing, malware, data breaches, or simple password reuse, then change the account details and attempt a withdrawal before the owner notices.

Account takeover is not unique to gambling. Cifas data cited by UK Finance showed a 76% increase in reported account-takeover cases during 2024, while SIM-swap fraud rose by more than 1,000%. Gambling accounts are useful targets because deposits, withdrawals, and verification prompts are all routine there, which gives criminals room to disguise abnormal activity as ordinary betting behaviour.

The issue is, a correct password and a one-time code may still be controlled by an attacker. Operators therefore compare the device, location, session history, and withdrawal destination against the customer’s previous activity. A login from a new phone followed immediately by a password reset and a maximum withdrawal carries a very different risk from the same login followed by normal play.

Paying with other people’s money 

Stolen cards offer the most direct route into the system. A criminal deposits another person’s money, places enough bets to make the balance appear legitimate, and tries to withdraw through another instrument. The operator can lose the withdrawn funds, the original deposit after a chargeback, the processor fees, and any bonus attached to the transaction.

Though not every disputed payment follows a stolen card. “Friendly fraud” occurs when the cardholder made the deposit themselves but later claims it was unauthorised, sometimes after losing. Cifas research published in 2025 found that 15% of surveyed UK consumers incorrectly believed that using chargebacks to recover gambling losses was legal. To be clear, the figure measures attitudes rather than the actual frequency of the behaviour, but it’s not a particularly reassuring number either way.

Closed-loop withdrawal rules reduce the exposure by returning money through the same method used to deposit. Britain’s Gambling Commission treats open-loop arrangements as a money-laundering risk, because they allow funds to enter through one instrument and leave through another. Fraud and money laundering are technically separate problems, but they overlap when gambling converts stolen or criminal funds into apparently legitimate withdrawals.

Manufacturing the first-time depositor 

Operators commonly pay affiliates when a referred customer registers, deposits, or meets an activity threshold. That creates another product to counterfeit: the first-time depositor. An affiliate or connected fraud ring can submit bot traffic, synthetic identities, or self-referrals, collect a cost-per-acquisition payment, and leave the operator with accounts that never become profitable customers. The operator may end up paying for the same fabricated customer several times over, through affiliate commission, bonus credit, and processing costs.

Fraudulent traffic also contaminates the marketing data itself. Acquisition costs appear higher, retention appears worse, and genuine affiliates end up being judged against competitors whose conversion numbers were manufactured.

Detection requires connecting affiliate and player data rather than reviewing them separately. Repeated devices, matching withdrawal accounts, similar deposit amounts, and clusters of registrations from one partner can expose a scheme. Operators also remain responsible for affiliate conduct in regulated markets, so weak oversight can create advertising and licensing problems beyond the direct loss.

Verification doesn’t end at onboarding 

Traditional KYC checks establish whether a submitted identity appears genuine at registration. What they don’t establish is that the same person will control the account indefinitely, or that every later transaction is legitimate. Verified accounts can be sold, taken over, or used by organised groups long after passing a perfectly clean onboarding process.

Continuous monitoring therefore examines the relationships among devices, accounts, payment instruments, locations, and behaviour. Device fingerprinting can reveal many “new” customers using the same hardware. Geolocation can connect accounts to one property, while graph analysis can identify groups sharing withdrawal destinations or coordinating wagers, without relying on any one decisive signal.

The Gambling Commission acknowledges that operators may request selfies or additional documents when identity theft is suspected. It also warns them not to postpone checks until withdrawal when the information could reasonably have been requested earlier. This distinction matters quite a lot, because fraud controls are easily turned into a pretext for delaying legitimate payouts.

Blocking the wrong people 

An aggressive rules engine can improve fraud numbers by blocking nearly everyone who appears unusual. The commercial damage then simply moves elsewhere: failed registrations, frozen withdrawals, support workload, and complaints from legitimate players. A traveller using a VPN, a household sharing one connection, or a customer replacing their phone can all resemble parts of a fraud pattern.

Manual review remains necessary for the ambiguous cases, but it’s slow and expensive, especially when major events cause registrations and deposits to surge. Automated systems must decide which users can proceed, which need another check, and which should be stopped. The useful measure here is not the highest rejection rate, but the smallest combined loss from fraud and unnecessary friction.

Unfortunately, AI makes that balance harder rather than solving it. Fraudsters use synthetic documents, deepfakes, bots, and automated account creation, while vendors respond with behavioural models and network analysis. Systems trained on historical fraud can miss new methods, and an opaque risk score offers very little help when a regulator or a customer asks why exactly an account was blocked.

An economic decision, in the end 

Operators cannot eliminate fraud without making the product nearly unusable, so what they really decide is how much risk to accept at each stage of the customer lifecycle. A routine deposit may justify lighter checks, while a large withdrawal, a sudden device change, or a linked-account pattern warrants more scrutiny.

Effective controls combine identity, payment, device, location, and behavioural data, rather than buying one tool and calling the problem solved. Organised groups still adapt, because the rewards are immediate and the rules are visible. Criminals search for methods whose expected payout exceeds the cost of identities, devices, and failed attempts, while operators try to make each attack too expensive to scale.

The business behind iGaming fraud is built on legitimate features used in unintended combinations. Bonuses become cashable assets, affiliate commissions become fabricated acquisitions, verified accounts become resale inventory, and fast withdrawals become an exit route. Operators lose when they examine each event separately, because the fraud ring saw the full transaction from the very beginning.