How do fake buyer accounts fuel refund fraud on marketplaces?
Why refund fraud needs fake accounts
Refund fraud is one of the few bot-driven attacks where the account itself is the weapon. A refund request from a ten-year-old account with hundreds of clean orders gets approved fast, because marketplaces optimize for buyer trust. Fraud rings know this, so they build accounts that look exactly like that: aged, active, and trustworthy, except none of the history is real.
The farming phase is patient. Bots create accounts in bulk, run them through small legitimate-looking purchases, leave reviews, and let them sit. Some accounts are bought outright from data breaches or sold by their original owners. By the time the fraud phase starts, the accounts pass every superficial check: verified email, real device fingerprints, normal-looking order patterns.
Scale is what makes the economics work. A single fraudulent refund nets a few hundred dollars at most. A ring running ten thousand farmed accounts, each filing one or two claims before burning, turns policy abuse into a revenue line. The accounts are disposable; the playbook is not.
The claims that fake accounts file
Item-not-received is the workhorse. The account places an order, the parcel is delivered (often to a reshipping address or a vacant property the ring controls), and the account reports non-delivery. Marketplaces refund first and investigate later, because holding a buyer's money during a dispute is worse for retention than eating the occasional fraud loss. The ring counts on that ordering of priorities.
Empty-box and wrong-item returns are the second wave. The account returns the item, but the box contains something worthless or nothing at all. Warehouse inspection catches the obvious cases, but at marketplace return volumes, spot checks miss plenty. A ring that learns which categories get inspected least concentrates there.
Double-dipping closes the loop. After the marketplace refunds, the account files a chargeback with the card issuer, collecting twice. The marketplace eats the chargeback fee on top of the refund. Card networks eventually flag the pattern, but by then the accounts are burned and the ring has moved to fresh ones.
The signals that expose farmed accounts
Farmed accounts reveal themselves in the boring metadata. Creation bursts: hundreds of accounts created from the same IP range in the same week, then left dormant for months. Purchase patterns that look rehearsed: identical small orders across accounts, reviews posted in the same order, refunds filed within days of the first large purchase.
Device and payment identity are harder to fake at scale. Real buyers accumulate a mess of devices, addresses, and payment methods over the years. Farmed accounts stay suspiciously clean: one device, one card, one address, then a refund claim. Device fingerprint sharing across supposedly unrelated accounts is the strongest single signal of a ring.
Behavioral timing tells the rest. Fake accounts file claims fast, often within days of account reactivation. Real buyers with genuine problems usually contact support first, try the seller, wait. The fraud account goes straight for the refund button, because the account was built for exactly that moment.
Refunding without feeding the rings
The fix is risk-scoring the refund decision, not just the checkout. Before a refund is approved, score the account: age weighted by activity, claim frequency across the account's history, device and payment overlap with known fraud networks, and whether the shipping address has a history of non-delivery claims. High-risk refunds get routed to manual review; low-risk ones stay instant.
Address intelligence matters more than most teams expect. Reshipping addresses, vacant properties, and parcel lockers used by rings accumulate claim histories. A delivery address with forty non-delivery claims from forty different accounts is not an unlucky neighborhood; it is infrastructure. Block the address, not just the accounts.
Finally, close the double-dip window. Coordinate refund data with chargeback representment so a refunded order cannot also win a chargeback dispute. And track claim velocity per account lifetime, not just per month: a farmed account files its one or two claims and dies, so lifetime claim rate catches what monthly windows miss.
Do tighter refund checks hurt legitimate buyers?
Barely, if the checks are account-based rather than policy-based. Real buyers have messy, long histories that score clean. The accounts that get flagged are the ones that look too clean: new-ish, single-device, first big purchase followed by a claim. Keep instant refunds for established accounts and you preserve the buyer experience where it counts.
Can you stop refund fraud at the account-creation step?
You can slow it down, which is often enough. Rate-limiting account creation per device and IP, requiring phone verification for selling-adjacent activity, and aging requirements before high-value refunds all raise the ring's costs. The goal is not perfect prevention; it is making farming unprofitable relative to easier targets.
Should marketplaces share fraud-ring intelligence?
The device and address fingerprints of a ring are rarely marketplace-specific. Rings hit multiple platforms with the same infrastructure. Industry fraud-sharing feeds let one marketplace's confirmed ring become every marketplace's blocklist. The platforms that share see fewer repeat attacks; the rings move to whoever does not.