How Fraud Teams Link Related Accounts
An individual fraudulent account is usually unremarkable. What exposes an operation is that its accounts share things they should not, and finding those overlaps is a distinct discipline from scoring a session.
Linkage works on overlaps, not identifiers
Rather than asking who an account belongs to, linkage asks which other accounts share an attribute with it, and how unlikely that sharing is.
Any attribute can serve: a contact address, a payment instrument, a delivery location, a device characteristic, a session address. None of them identifies anyone alone.
The strength of a link depends on how rare the shared value is. Two accounts on the same large carrier address share almost nothing, while two accounts sharing an unusual payment instrument share a great deal.
Normalisation is where the work is
Attributes are deliberately varied to avoid exact matches, so linkage depends on recognising values that differ superficially while referring to the same thing.
Address formats, punctuation variants in contact details and equivalent spellings all need canonicalising before comparison, and each normalisation rule risks merging things that are genuinely distinct.
Getting this wrong in either direction is costly: too little normalisation misses the operation, too much links unrelated customers into a single false cluster.
Timing and sequence are strong links
Accounts created within a short window following an identical registration path are linked by behaviour even when they share no attribute values at all.
Coordinated activity later shows the same property. Actions performed in near-lockstep across accounts indicate a single operator regardless of how carefully attributes were varied.
These behavioural links are harder to avoid than attribute links, because varying timing convincingly costs throughput and throughput is usually the point.
Clusters need thresholds and review
Because links are probabilistic, a cluster grows until some threshold stops it, and setting that threshold badly can absorb enormous numbers of legitimate accounts through a single common attribute.
Shared household infrastructure and shared corporate networks are the usual culprits, since families and colleagues legitimately share almost everything a naive rule would link on.
Serious implementations therefore weight link types explicitly, cap the influence of common values, and route large clusters to human review before any action is taken.
Action at cluster level raises the stakes
Acting on a cluster affects many accounts at once, so an error affects many innocent people at once rather than one.
This is why cluster actions are usually graduated, beginning with additional verification rather than closure, and why appeal paths matter more here than for individual decisions. A wrongly linked customer has no way to know what they were linked by, and cannot explain themselves without being told.