Stopping Multi-Accounting & Sockpuppets
One person, many accounts. Multi-accounting and sockpuppets drain welcome offers, stack referrals, and dodge bans. Learn how to link accounts by device, IP, and email, and the controls that stop abuse at checkout.

A single motivated abuser rarely uses one account. They use ten, or fifty. Multi-accounting is the practice of one person operating many accounts to multiply a benefit that was meant to be granted once: a welcome discount, a first-order coupon, a free-shipping threshold trick, a referral payout, or simply a way to keep buying after a ban. The fake accounts are often called sockpuppets, and left unchecked they quietly bleed margin from every promotion you run.
The problem is not that fake accounts exist. It is that they look, individually, exactly like real new customers. The abuse only becomes visible when you stop looking at accounts one at a time and start looking at what connects them.
What multi-accounting costs you
The damage is rarely one dramatic event. It is a slow leak.
- Welcome-offer farming. A 15% first-order discount claimed 40 times by one person is a 40x loss on a benefit you budgeted for once.
- Referral and reward stacking. One person referring their own sockpuppets collects payouts on fake signups. (More on the referral angle in its own right.)
- Ban evasion. A customer you blocked for chargebacks or abuse simply creates a fresh account and continues.
- Review and social manipulation. Sockpuppets inflate ratings or vote-brigade, distorting your storefront's trust signals.
- Inventory hoarding. On limited items, multiple accounts let one buyer exceed per-customer purchase limits.
The linking problem
To stop multi-accounting you have to answer one question reliably: *are these two accounts the same person?* No single identifier is enough on its own, because each can be changed.
- Email is trivially cheap. Plus-addressing (
name+1@,name+2@), disposable domains, and dot tricks in Gmail all produce "unique" emails that route to one inbox. - IP address links accounts sharing a network, but it is noisy. Families, offices, and shared Wi-Fi all produce shared IPs, and abusers rotate through VPNs and proxies to look different each time.
- Device fingerprint is far stickier. The combination of browser, OS, screen, fonts, timezone, and hardware traits tends to persist even when email and IP change.
The reliable approach is correlation across all three plus behavior, not reliance on any one.
Signals that reveal sockpuppets
Signals.
- Shared device across "different" accounts. The strongest single tell. Ten accounts, ten emails, one device fingerprint is not ten customers.
- Email pattern families. A cluster of addresses with the same root and incrementing suffixes, or many signups from the same disposable domain in a short window.
- IP and subnet clustering. Many new accounts from one IP or a tight subnet range, especially paired with anonymizing infrastructure.
- Behavioral sameness. Identical browsing paths, same time-of-day activity, same product picks, same shipping address reused under different names.
- Velocity. A spike of new-account creations right before or during a promotion is classic offer-farming preparation.
- Anonymization. VPN, proxy, or Tor traffic behind account creation is a strong amplifier for every other signal, because legitimate first-time shoppers rarely need to hide their network.
Controls that stop the abuse
1. Cut off anonymized traffic at the door.
The cheapest way to create endless sockpuppets is to look like a different person each time through a VPN or proxy. Removing that ability collapses the economics of the whole scheme. Shieldy Fraud Filter applies checkout-level blocking for VPN, proxy, Tor, and bot traffic, so the fastest identity-rotation trick stops working. You can also restrict by country and IP to shut down clusters originating from a known-bad source.
2. Correlate identity, do not trust one field.
Treat email, IP, and device together. If two accounts share a device fingerprint, the fact that their emails differ is meaningless. AI fraud scoring that blends these signals is what turns "ten separate new customers" into "one abuser with ten masks." Shieldy's scoring is designed to weigh device, network, and identity signals as a single risk picture rather than firing on any one field.
3. Enforce per-person, not per-account, limits.
Welcome offers, first-order discounts, and per-customer purchase caps should be tied to the *linked identity*, not the account row. Once you can link sockpuppets, a "one per customer" rule finally means one per person.
4. Add friction to suspicious signups.
For new accounts on anonymized networks or sharing a device with a flagged account, require verification, hold the first order for review, or block the discount rather than the whole order. Real customers pass easily; farms stall.
5. Make ban evasion stick.
When you block an abuser, block the *cluster*, not just the account. If you only cancel one email, they are back in minutes. Blocking the underlying device and network signals is what makes a ban actually hold.
A practical rollout
- Enable VPN, proxy, Tor, and bot blocking at checkout to kill cheap identity rotation.
- Turn on device and network correlation so accounts can be linked.
- Bind promotions and purchase limits to the linked identity, not the account.
- Alert on new-account creation velocity spikes around promotions.
- When banning an abuser, block the full signal cluster, not a single email.
- Let AI scoring combine device, IP, and email-pattern signals into one decision.
Multi-accounting only works when every fake account gets judged in isolation. The moment you can see the thread connecting them, one abuser's fifty masks collapse back into one blockable person.
Want that linking and blocking running automatically? Shieldy Fraud Filter correlates device, IP, and network signals at checkout and starts on a Free plan, with room to scale on the pricing page.
Protect your Shopify store today
Install Shieldy free — block fraud, bots, and VPNs in under 5 minutes.
Install on Shopify — Free


