- Blog
- How to Investigate a Suspected Fraud Farm
How to Investigate a Suspected Fraud Farm
Subscribe to Incognia’s content
Fraud farms can be hard to identify because the accounts, devices, and transactions involved often look unrelated when reviewed one at a time.
When you suspect coordinated activity, the key is to look for connections across accounts, devices, locations, timing, risk history, and money movement.
Here are steps fraud teams should take when investigating a suspected fraud farm.
Key Takeaways
-
Fraud farms are easiest to miss when activity is reviewed one account at a time. The useful signal often comes from relationships across accounts, devices, and locations.
-
Look for relationships, not isolated signals. Fraud farms can make individual accounts, devices, and transactions look unrelated. The stronger evidence often comes from how those signals connect.
-
Coordination matters more than any one suspicious event. High velocity can expose automation, while dormant accounts activated together can reveal a more patient, staged operation.
1. Start with suspicious activity
Begin with the account, device, transaction, or activity that raised a flag.
Capture the basic facts first:
- Which account or accounts are involved?
- Which devices accessed them?
- When did the activity happen?
- Where did it originate?
- What transactions or actions were suspicious?
Then use that starting point to look for related activity.
2. Connect accounts and devices
Map the relationships between accounts and devices.
Look for things like:
- one device tied to many accounts
- the same accounts appearing across several devices
- unusually high concentrations of accounts around a small set of devices
The goal is to find connections that would be easy to miss if each account were reviewed separately.
3. Check for device manipulation
Next, determine how much confidence you can put in the device identities you’re seeing.
Look for signs of:
- app cloning
- emulation
- spoofing
- application tampering
- uninstall and reinstall behavior
- factory resets
These techniques can make the same underlying device or operation look new to the fraud stack.
4. Check velocity and timing patterns
Look at when accounts and devices act, not just what they do.
Coordinated operations can show up in different timing patterns.
One is high velocity: many accounts or devices taking similar actions within a short window. That can point to automation or a single operation controlling activity at scale.
The opposite pattern can also be suspicious. Fraudsters may create large numbers of accounts and leave them inactive so they can build account age before they are used. Those accounts may then become active together when the fraud operation begins.
Look for:
- many accounts being created or accessed within short windows
- multiple devices taking similar actions at the same time
- large batches of new accounts with little or no initial activity
- dormant accounts becoming active around the same time
- groups of accounts following similar transaction or login patterns
The signal is coordinated timing across accounts or devices that are supposed to be independent.
5. Look for shared locations
Check whether seemingly unrelated accounts or devices are operating from the same precise physical location.
Location is much more useful when it is precise enough to separate legitimate density from shared fraud infrastructure.
Knowing that dozens of devices are in the same apartment building may not tell you much. Being able to pinpoint activity to the same apartment can make the relationship much clearer.
Look for:
- multiple suspicious accounts or devices operating from the same precise location
- new device identities repeatedly appearing at that location
- accounts tied to the location that also show signs of cloning, resets, spoofing, or tampering
- devices or locations already associated with known fraud or mule activity
- unusual concentrations of accounts that would be difficult to explain as normal household behavior
6. Check the risk history
Review whether the infrastructure has appeared in previous fraud.
Check:
- Has this device been associated with confirmed fraud before?
- Have other accounts linked to either one been identified as mules?
- Does the same infrastructure keep appearing in separate investigations?
This is especially useful when fraudsters rotate the signals that are easiest to change.
A newly created account may have no history. A new device identity may also look clean. A location or another connected device may already be tied to known fraud.
Historical risk gives you more context for deciding whether you are seeing a new user or another part of an operation you have already encountered.
7. Confirm the activity looks coordinated
Review the evidence together before deciding that you are looking at a fraud farm.
No single signal proves coordinated fraud on its own.
A stronger case may include:
- many accounts connected to the same devices
- rapid or sequential device turnover
- cloning, emulation, spoofing, resets, or tampering
- seemingly unrelated accounts tied to the same precise location
- synchronized activity across accounts
- previous fraud or mule activity linked to the same infrastructure
The question at this stage is whether those relationships are better explained by normal user behavior or by one coordinated operation.
That is where the investigation moves from individual account risk to understanding the infrastructure behind the activity.
8. Follow the money
Once the activity appears coordinated, trace the movement of funds.
Determine:
- where the funds originated
- which accounts received them
- whether multiple mule accounts were involved
- where the funds moved next
- which financial institutions, payment providers, or exchanges were involved
This can expose relationships that device or location analysis alone may not show.
It also connects the technical investigation to the financial activity the operation was supporting.
9. Build a useful case for law enforcement
Once you've connected the activity and followed the money, document what you've found in a way that makes the broader operation clear.
This becomes especially important when the activity spans multiple accounts, transactions, or financial institutions. Law enforcement needs more than a list of suspicious transactions. They need enough context to understand what happened, how the activity is connected, and where to investigate next.
Document:
- what triggered the investigation
- which accounts and devices are involved
- how they are connected
- which locations are relevant
- any signs of device manipulation
- the sequence of activity
- what fraud occurred
- where the funds went
- which other institutions or exchanges are involved
- where investigators should look next
The goal is to give investigators the context they need to understand the operation, not just the individual transactions.
Get the infographic → How to Investigate a Suspected Fraud Farm
No single signal is enough
Fraud farms are built to adapt as individual controls get stronger.
A weak device ID may be bypassed through reinstalls. More persistent device identification can push fraudsters toward app cloners and emulators. Detecting those tools can push them toward factory resets, additional physical devices, or other ways of changing the apparent device identity.
That is why investigating a suspected fraud farm cannot rely on one or two signals in isolation.
The strongest evidence comes from the relationships between them.
For more on how fraud farms are changing, how AI and automation are affecting their operating model, and what fraud teams and law enforcement are seeing in practice, watch the full discussion on AI-Powered Fraud Farms: How Organized Fraud Scales and Stays Hidden.
Frequently Asked Questions
What is a fraud farm?
How can fraud teams detect a fraud farm?
Fraud teams can detect suspected fraud farms by looking for connections across accounts, devices, locations, timing patterns, risk history, and money movement. The strongest evidence usually comes from coordinated behavior across multiple signals.
What are the common signs of a fraud farm?
Why is it important to look at multiple signals when investigating fraud farms?