In December 2024 we reported on account trafficking websites, and since then we’ve observed a continued expansion of these openly fraudulent account reseller markets.
Almost every digital service, from cloud infrastructure to payment processors and AI platforms, requires an email address to sign up. Unfortunately, major email providers have notoriously lax fraud prevention. This creates a massive loophole, resulting in an absurdly high volume of fraudulent emails that subsequently serve as the gateway for spam, malicious infrastructure, bot networks and fraudulent accounts across all manner of other services.
So why don’t tech companies and email providers crack down harder on fraud?
Maybe the answer lies in the aggressive push for user base growth and reducing friction to new sign ups. Internal product teams frequently soften security friction such as multi-factor authentication (MFA) and know your customer (KYC) checks to inflate user adoption numbers. But how many of those new users are legitimate vs fraudulent?
To legally protect themselves while marketing this inflated growth, companies bury boilerplate disclaimers in their SEC filings. These warnings essentially state: "We estimate that a certain percentage of our active accounts are duplicate, fraudulent, or bot-driven." If these legal warnings spike year-over-year, it is a clear sign that a company's internal security is losing the war against fake accounts, even as their marketing team may tout rapid expansions in user adoption. This internal pressure is especially true of service providers that create a multi-service ecosystem to hook users in. Multi-service providers offer many or all of the following services: email, office software, cloud hosting and storage, browsers, payment apps and more. Some also offer hardware in their ecosystem of connected services. The service teams and product teams within these ecosystems fight hard to prevent anti-fraud and abuse teams from implementing the much needed mitigations because those mitigations are perceived as high friction points that reduce user adoption. Those service teams tend to win that fight and a flood of fraudulent accounts and activity paint the image of rapid user adoption and success.
There is a real cost to that fake growth. Ignoring the problem carries heavy operational and legal risks. Recent history has shown as much with Twitter famously exposed during its acquisition for massively underreporting spam accounts while promoting an exaggerated monetizable daily active users number. Meta explicitly admitted in one of its 10-K filings that up to 14% of its user base is duplicate or fraudulent. Alphabet & Microsoft both rely heavily on boilerplate SEC warnings to shield their monetization metrics from investor lawsuits. That said, there has been a regulatory crackdown in which the SEC intensified enforcement against “tech washing” by penalizing platforms that use synthetic bot behavior to inflate their market value. The SEC's Cyber and Emerging Technologies Unit (CETU) should pursue enforcement actions against platforms utilizing fake metrics or synthetic behavior to inflate platform utility. If a tech provider aggressively markets user or enterprise growth driven by automated, non-vetted registrations, it falls squarely under SEC anti-fraud enforcement regarding misleading capabilities and metrics.
Similar to the cybersecurity landscape, the fraud and abuse ecosystem ebbs and flows. When defenders apply new countermeasures and mitigations, the fraudsters quickly adapt and their underground economy continues to thrive. Malicious actors make a living dedicating their efforts to farming the creation and resale of accounts, compromising legitimate ones, and selling “aged” or already KYC-verified accounts. For the right price, fraudsters can simply buy their way past a platform’s defenses.
This report surveyed some of the most recent sites alleging to sell such accounts. It is the hope of this report to renew efforts to mitigate fraudulent account creations across the IT industry from email to VPS, social media to payment services and more. It is also the hope of this report to better collaborate with fraud and abuse teams. They’re on your side. Help them help you.
Merchants purporting to sell verified Stripe and Shopify Accounts



Fraud Services that Purport to Protect Stripe Accounts from Being Banned


Audit Stripe Accounts

Credit Card Store

Survey
Actionable Advice for Defenders
Fraud and abuse teams are on the front lines of this fight. While fraudsters constantly adapt, their automated tools and bulk operations leave distinct footprints. Here are practical steps to identify and block accounts originating from these underground marketplaces.
Scrutinize the Signup Funnel
Account farmers rely on volume. Even when using residential proxies, they often reveal themselves through impossible form-fill speeds or identical hardware telemetry. Monitor for blocks of accounts created sequentially, accounts originating from the same autonomous system numbers (ASNs), or signups using highly predictable email naming conventions.
Watch for Sleeper Accounts
Our survey shows a clear price markup for "aged" accounts. Farmers create these accounts and let them sit dormant for months to bypass new-account filters and build a false sense of trust. Flag accounts that show zero activity for a long period and suddenly initiate high-volume actions like bulk API requests, ad creation, or mass messaging.
Detect Account Takeover Signals
High-karma and established accounts are commonly the result of a hijacked legitimate user and almost always against user terms of service by providers. Defenders need to watch for sudden identity shifts. A user logging in from a new geographic region using a completely different device footprint and immediately changing their recovery email is a massive red flag. Force step-up authentication when these high-risk account changes occur.
Target Fraud-Friendly Infrastructure
Feed threat intelligence directly into your registration pipeline. Block or heavily throttle signups coming from known proxy networks and bulletproof hosting providers. Maintain and frequently update a blocklist of temporary or disposable email domains, as these are heavily abused by automated account creators.
Conclusion
The tech industry has to stop treating account abuse and mass fraud as an acceptable cost of doing business. Ignoring this underground economy creates a domino effect that degrades the broader internet. When major providers allow fraudulent accounts to flourish, they directly fuel spam, enable malicious infrastructure, and burden security teams everywhere.
Stopping this requires a hard reset on internal corporate incentives. Product and marketing departments cannot continue to be rewarded for raw user growth if those numbers are artificially inflated by synthetic registrations. Anti-fraud and abuse teams must be given the authority to introduce necessary friction. Implementing mandatory MFA, rigorous identity checks, and behavioral analysis is essential, and these security controls should never be overridden by executives chasing adoption metrics.
Additionally, the industry must address the massive role of account takeover (ATO) in these marketplaces. The high premium placed on "aged", high-karma, and verified accounts is a direct result of hijacked legitimate users. Service providers have a fundamental responsibility to protect their customers from these compromises. Defending the platform means deploying stricter backend detections while actively giving users the security settings, login telemetry, and alerts they need to monitor and lock down their own accounts. The tools to stop account farming already exist. Companies need to empower their security teams to use them.
IOCs
Fraudulent Account Marketplaces and Services
Threat Actor Contact Handles & Emails
![Screenshot of gmailpva[.]com](https://cdn.prod.website-files.com/6941445776ba1afe6af8317e/6a712066d2408b72a64af666_account-farmers-gmailpva-com.webp)
![Screenshot of socialaccountshop[.]com](https://cdn.prod.website-files.com/6941445776ba1afe6af8317e/6a7120666bf7eaa437ea87b6_account-farmers-socialaccountshop-com.webp)
![Screenshot of buyaccounts[.]store](https://cdn.prod.website-files.com/6941445776ba1afe6af8317e/6a712067472040edb10e6221_account-farmers-buyaccounts-store.webp)
![Screenshot of gmailshop[.]com](https://cdn.prod.website-files.com/6941445776ba1afe6af8317e/6a7120677a5f7fdcf1ea41f1_account-farmers-gmailshop-com.webp)
![Screenshot of buyawsaccounts[.]com](https://cdn.prod.website-files.com/6941445776ba1afe6af8317e/6a7120680ebb9d782a948544_account-farmers-buyawsaccounts-com.webp)
![Screenshot of accountstore[.]net](https://cdn.prod.website-files.com/6941445776ba1afe6af8317e/6a7120680ebb9d782a948592_account-farmers-accountstore-net.webp)
![Screenshot of buyaccounts[.]net](https://cdn.prod.website-files.com/6941445776ba1afe6af8317e/6a71206851ed184a1ab32dc3_account-farmers-buyaccounts-net.webp)
![Screenshot of buyaccounts[.]co](https://cdn.prod.website-files.com/6941445776ba1afe6af8317e/6a712069e35c477bee22433e_account-farmers-buyaccounts-co.webp)
![Screenshot of bulkaccounts[.]shop](https://cdn.prod.website-files.com/6941445776ba1afe6af8317e/6a71206951ed184a1ab32e0e_account-farmers-bulkaccounts-shop.webp)
![Screenshot of buytwitteraccounts[.]com](https://cdn.prod.website-files.com/6941445776ba1afe6af8317e/6a71206951ed184a1ab32e67_account-farmers-buytwitteraccounts-com.webp)
![Screenshot of redditaccounts[.]com](https://cdn.prod.website-files.com/6941445776ba1afe6af8317e/6a71206a17c9456cac6ade5f_account-farmers-redditaccounts-com.webp)
.png)


