Down on the device farm: Dozens of phones, over a thousand "players," not one real customer Skip to content

Down on the device farm: Dozens of phones, over a thousand “players,” not one real customer

Read time:
3 minutes

A crop of fake customers, harvested and replanted in a day.

GeoComply Fraud Files — true fraud stories from the industry's front lines, featuring expert analysis from the Fraud and Risk Management team.

Summary The TL;DR
  • Read the device, not just the account. Dozens of rooted, reset, automated devices hid behind over a thousand “unique” accounts. Account-level checks alone would never have connected them.
  • Stack signals, don’t chase single flags. No SIM, no PIN, heavy automation, high latency, a one-day lifespan: forgettable in isolation, conclusive in combination.
  • Act before the payout, not after. Catching the pattern before the redemption window turned a monthly loss into a stopped one.
  • Precision beats a blunt block. Targeting the farm instead of the field protects genuine new users from friction on the day you most want them to stay.

Over a thousand new players signed up to a rewards app. On dozens of phones. And not one of those phones had a SIM card. 

Most fraud checks hunt for what’s there. The tell here was what wasn’t: no SIM present. That’s the kind of pattern most signals miss because an empty tray won’t trip a velocity rule or a device blocklist.

On paper it looked like a promotion doing its job. Underneath, it was a device farm exploiting peak growing conditions.

Welcome to GeoComply’s Fraud Files: true fraud stories from the fraud front lines. Today, we’re looking at a rewards app that found a device farm living underneath its user-acquisition program.

The platform knew they were being targeted. But they couldn’t risk spraying pesticide on the legitimate new customers they’d worked to win.

We’re joined by Ana Einolghozati, Data Scientist at GeoComply, who helped build and ship the device manipulation detection model that surfaced the pattern and weeded out the abuse with precision.

A bumper crop of new players

The app paid users for engagement, with a simple path from sign-up to redemption. The low payout threshold was deliberate: it made the reward feel accessible from day one. It also made the program attractive to fraudsters. And they came in droves. Fresh names, fresh handles, fresh devices, all arriving to claim the reward.

To a basic view, this was a promotion working exactly as intended. New user, new device ID, clean-looking account, small payout. Job done.

But the team could see the signs of a problem. They knew the program was being exploited. What they couldn’t do was tell a real new player apart from a fraudster before the money left the system.

And the cost of not knowing was adding up: six-figure annualized losses, with fraud accounting for almost a fifth of the program’s reward spend, plus the broader risk of reputational damage and downstream data-quality risks across the partner ecosystem.

When the device looks nice, you don’t think twice

Device-centric multi-accounting is built to defeat exactly the checks most systems lean on. Each account looks unique, because it is: a new handle, a new device ID, no obvious link to the last one. Each device looks new, because it was just wiped clean. Ask “is this a new user on a new device” and the answer is yes.

The tell was never going to be in any single account, or any single device. It was in what the devices had in common, and in how they behaved.

As Ana put it:

Most fraud stacks chase the tactic: the new synthetic ID, the freshly reset device, the next emulator. The tactics change faster than any rule can. KYC checks who someone claims to be, and AI slips synthetic identities past it every day.
A fraudster can reset their device. What they can’t reset is the ring: dozens of accounts still transacting off the same device hardware lineage, in the same places, running the same play. A farm that looked like a thousand strangers resolves into a handful of rings.

There SIMs to be a problem here

Once the team looked past the accounts and at the machines running them, the same portrait kept reappearing. These weren’t set up or run the way real people set up and run their phones:

  • No SIM, weird security settings, abnormal patterns
  • The tell-tale lag of latency
  • Devices that blinked in and out of existence in a short timeframe
  • A handful of smaller tells all pointing the same way

Individually, any one of these could pass for a slightly odd, security-averse user. Stacked together, on device after device, they spelled one thing: a device farm of rooted phones, or a single host machine running a stack of emulators, all driven by scripts.

Then the scale came into focus. The 1,000+ “players” weren’t actually 1,000+ people. 

Spotting a manipulated device is one thing. Seeing that over a thousand of them are really the same dozens of devices is another. The signals flagged the devices as fake. Connecting their shared traits and behaviour is what collapsed 1,000+ “players” down to 60+ machines, spread across more than 1,500 transactions.

Ana says:

No one of these flags convicts a device on its own. Plenty of real phones run hot, or sit behind a slow connection. What you can’t explain away is all of them at once, on device after device, in the same shape. One signal is noise but the whole stack is a fraud syndicate.

Why a factory reset isn’t a clean slate

Here’s the part fraudsters are counting on you not to know. Wiping a device resets the obvious identifiers, the ones a quick check reads first: the device ID, the user agent. Randomize those and one phone can pass for a hundred.

A device reset wipes the surface layer: advertising IDs, app data, cookies. Those are the identifiers basic fingerprinting relies on, which is why a wiped phone looks brand new to a simple check.
But a reset can’t change the hardware itself. Traits built into the physical device at the factory survive every wipe. And it can’t erase the pattern: the same accounts, the same locations, the same play, showing up again on a “new” device. Our models look for what survives the wipe, and connect the accounts behind it.

Instead of chasing a thousand accounts one at a time, you can see the dozens of machines behind them.

The difference between playing whack-a-mole and pulling up the whole root system.

“99% of these crops are poison.”

Armed with the device signals, the team could finally see the full cycle for what it was: accounts spun up on rooted devices and emulators, scripts run to hit the minimum bonus, rewards harvested after the redemption window, then the devices wiped and the next crop planted.

At scale, on repeat.

The detection running underneath this was our device manipulation model, scoring devices on a daily basis and routing suspect activity into the team’s case review. When they validated their own investigation against those signals, the numbers agreed: 99% detection accuracy.

Ana says:

That level of confidence changed what they could do. Instead of catching fraud at the redemption event, after the payout had already gone, they could act before the redemption stage, closing the loss rather than reporting it. Automated actioning takes that from a manual review queue toward a hands-off response.

The early win was already clear: fraud-driven reward costs dropped by more than 80%, reducing losses to as low as 3% of gift card spend.

The difference between good apples and rotten ones

The harder trick was doing all of that without punishing real people.

Organic new users behave a lot like a farm on day one. They sign up, they play a little, they cash out fast, often just to check the reward is real. Block too aggressively and you turn away the exact customers the promotion was built to win.

Ana says:

Device manipulation signals let us draw the line at the machine, not the person, so a genuine new player never has to prove themselves but fraudsters get weeded out. That precision isn’t luck.
It comes from years and years of data and billions of checks every month feeding these models. At that scale the patterns aren’t subtle, and that’s how we reach 99% detection accuracy and act on it with confidence. 

To see how fraud teams are catching device farms before the payout instead of after, talk to our fraud experts.

Ana Einolghozati | Data Scientist, GeoComply

Ana Einolghozati is a Data Scientist at GeoComply, where she builds the machine learning models that catch device manipulation, from rooted phones and emulators to device farms running at scale. Her work is teaching systems to tell a real device from a disguised one, fast enough to matter.

 

Madeleine Ritzker | Fraud Journalist, GeoComply

Madeleine Ritzker covers fraud intelligence for GeoComply, translating the hard work of the industry’s risk and fraud teams into stories that reveal what’s actually happening on the digital front lines. Fraud Files is your way to keep up with the latest tricks and trends sweeping through the darkest corners of the web.

Images in this article have been modified to protect personally identifiable information, but remain representative of the real case details.

 

Related Posts

Spatial Safeguards: Combatting AI Platform Abuse With Location Intelligence

Compliance readiness playbook: Why your geolocation signal is the foundation under every compliance control

FanDuel and GeoComply Renew Strategic Partnership with New Multi-Year Deal