How to Investigate a Suspected Fraud Farm Featured Image

How to Investigate a Suspected Fraud Farm

Fraud farms can be hard to identify because the accounts, devices, and transactions involved often look unrelated when reviewed one at a time.

When you suspect coordinated activity, the key is to look for connections across accounts, devices, locations, timing, risk history, and money movement.

Here are steps fraud teams should take when investigating a suspected fraud farm.

 

Key Takeaways

  • Fraud farms are easiest to miss when activity is reviewed one account at a time. The useful signal often comes from relationships across accounts, devices, and locations.

  • Look for relationships, not isolated signals. Fraud farms can make individual accounts, devices, and transactions look unrelated. The stronger evidence often comes from how those signals connect.

  • Coordination matters more than any one suspicious event. High velocity can expose automation, while dormant accounts activated together can reveal a more patient, staged operation.

     

1. Start with suspicious activity

Begin with the account, device, transaction, or activity that raised a flag.

Capture the basic facts first:

  • Which account or accounts are involved?
  • Which devices accessed them?
  • When did the activity happen?
  • Where did it originate?
  • What transactions or actions were suspicious?

Then use that starting point to look for related activity.

2. Connect accounts and devices

Map the relationships between accounts and devices.

Look for things like:

  • one device tied to many accounts
  • the same accounts appearing across several devices
  • unusually high concentrations of accounts around a small set of devices

The goal is to find connections that would be easy to miss if each account were reviewed separately.

3. Check for device manipulation

Next, determine how much confidence you can put in the device identities you’re seeing.

Look for signs of:

  • app cloning
  • emulation
  • spoofing
  • application tampering
  • uninstall and reinstall behavior
  • factory resets

These techniques can make the same underlying device or operation look new to the fraud stack.

4. Check velocity and timing patterns

Look at when accounts and devices act, not just what they do.

Coordinated operations can show up in different timing patterns.

One is high velocity: many accounts or devices taking similar actions within a short window. That can point to automation or a single operation controlling activity at scale.

The opposite pattern can also be suspicious. Fraudsters may create large numbers of accounts and leave them inactive so they can build account age before they are used. Those accounts may then become active together when the fraud operation begins.

Look for:

  • many accounts being created or accessed within short windows
  • multiple devices taking similar actions at the same time
  • large batches of new accounts with little or no initial activity
  • dormant accounts becoming active around the same time
  • groups of accounts following similar transaction or login patterns

The signal is coordinated timing across accounts or devices that are supposed to be independent.

5. Look for shared locations

Check whether seemingly unrelated accounts or devices are operating from the same precise physical location.

Location is much more useful when it is precise enough to separate legitimate density from shared fraud infrastructure.

Knowing that dozens of devices are in the same apartment building may not tell you much. Being able to pinpoint activity to the same apartment can make the relationship much clearer.

Look for:

  • multiple suspicious accounts or devices operating from the same precise location
  • new device identities repeatedly appearing at that location
  • accounts tied to the location that also show signs of cloning, resets, spoofing, or tampering
  • devices or locations already associated with known fraud or mule activity
  • unusual concentrations of accounts that would be difficult to explain as normal household behavior

6. Check the risk history

Review whether the infrastructure has appeared in previous fraud.

Check:

  • Has this device been associated with confirmed fraud before?
  • Have other accounts linked to either one been identified as mules?
  • Does the same infrastructure keep appearing in separate investigations?

This is especially useful when fraudsters rotate the signals that are easiest to change.

A newly created account may have no history. A new device identity may also look clean. A location or another connected device may already be tied to known fraud.

Historical risk gives you more context for deciding whether you are seeing a new user or another part of an operation you have already encountered.

7. Confirm the activity looks coordinated

Review the evidence together before deciding that you are looking at a fraud farm.

No single signal proves coordinated fraud on its own.

A stronger case may include:

  • many accounts connected to the same devices
  • rapid or sequential device turnover
  • cloning, emulation, spoofing, resets, or tampering
  • seemingly unrelated accounts tied to the same precise location
  • synchronized activity across accounts
  • previous fraud or mule activity linked to the same infrastructure

The question at this stage is whether those relationships are better explained by normal user behavior or by one coordinated operation.

That is where the investigation moves from individual account risk to understanding the infrastructure behind the activity.

8. Follow the money

Once the activity appears coordinated, trace the movement of funds.

Determine:

  • where the funds originated
  • which accounts received them
  • whether multiple mule accounts were involved
  • where the funds moved next
  • which financial institutions, payment providers, or exchanges were involved

This can expose relationships that device or location analysis alone may not show.

It also connects the technical investigation to the financial activity the operation was supporting.

9. Build a useful case for law enforcement

Once you've connected the activity and followed the money, document what you've found in a way that makes the broader operation clear.

This becomes especially important when the activity spans multiple accounts, transactions, or financial institutions. Law enforcement needs more than a list of suspicious transactions. They need enough context to understand what happened, how the activity is connected, and where to investigate next.

Document:

  • what triggered the investigation
  • which accounts and devices are involved
  • how they are connected
  • which locations are relevant
  • any signs of device manipulation
  • the sequence of activity
  • what fraud occurred
  • where the funds went
  • which other institutions or exchanges are involved
  • where investigators should look next

The goal is to give investigators the context they need to understand the operation, not just the individual transactions.

 

Get the infographic → How to Investigate a Suspected Fraud Farm

No single signal is enough

Fraud farms are built to adapt as individual controls get stronger.

A weak device ID may be bypassed through reinstalls. More persistent device identification can push fraudsters toward app cloners and emulators. Detecting those tools can push them toward factory resets, additional physical devices, or other ways of changing the apparent device identity.

That is why investigating a suspected fraud farm cannot rely on one or two signals in isolation.

The strongest evidence comes from the relationships between them.

For more on how fraud farms are changing, how AI and automation are affecting their operating model, and what fraud teams and law enforcement are seeing in practice, watch the full discussion on AI-Powered Fraud Farms: How Organized Fraud Scales and Stays Hidden.

Frequently Asked Questions

What is a fraud farm?

A fraud farm is a coordinated operation that uses multiple accounts, devices, identities, or payment methods to commit fraud at scale. The activity can be difficult to identify because individual accounts or transactions may appear unrelated.

How can fraud teams detect a fraud farm?

Fraud teams can detect suspected fraud farms by looking for connections across accounts, devices, locations, timing patterns, risk history, and money movement. The strongest evidence usually comes from coordinated behavior across multiple signals.

What are the common signs of a fraud farm?

Common signs include multiple accounts tied to the same devices or precise locations, synchronized activity, unusual account or device velocity, device manipulation, dormant accounts becoming active together, and infrastructure previously associated with fraud.

Why is it important to look at multiple signals when investigating fraud farms?

No single signal is enough to confirm a fraud farm. Fraudsters can rotate accounts, manipulate device identities, or change other signals, so investigators need to evaluate how devices, locations, accounts, timing, and risk history connect across the broader operation.

 

By clicking "Accept" or continuing to use this Website after this notice, you agree to our Terms of Use - including your rights, responsibilities, and how we handle disputes.