SecuritySnack - Account Farmers and Sellers

Published on: 
August 3, 2026

In December 2024 we reported on account trafficking websites, and since then we’ve observed a continued expansion of these openly fraudulent account reseller markets.

Almost every digital service, from cloud infrastructure to payment processors and AI platforms, requires an email address to sign up. Unfortunately, major email providers have notoriously lax fraud prevention. This creates a massive loophole, resulting in an absurdly high volume of fraudulent emails that subsequently serve as the gateway for spam, malicious infrastructure, bot networks and fraudulent accounts across all manner of other services. 

So why don’t tech companies and email providers crack down harder on fraud? 

Maybe the answer lies in the aggressive push for user base growth and reducing friction to new sign ups. Internal product teams frequently soften security friction such as multi-factor authentication (MFA) and know your customer (KYC) checks to inflate user adoption numbers. But how many of those new users are legitimate vs fraudulent? 

To legally protect themselves while marketing this inflated growth, companies bury boilerplate disclaimers in their SEC filings. These warnings essentially state: "We estimate that a certain percentage of our active accounts are duplicate, fraudulent, or bot-driven." If these legal warnings spike year-over-year, it is a clear sign that a company's internal security is losing the war against fake accounts, even as their marketing team may tout rapid expansions in user adoption. This internal pressure is especially true of service providers that create a multi-service ecosystem to hook users in. Multi-service providers offer many or all of the following services: email, office software, cloud hosting and storage, browsers, payment apps and more. Some also offer hardware in their ecosystem of connected services. The service teams and product teams within these ecosystems fight hard to prevent anti-fraud and abuse teams from implementing the much needed mitigations because those mitigations are perceived as high friction points that reduce user adoption. Those service teams tend to win that fight and a flood of fraudulent accounts and activity paint the image of rapid user adoption and success.

There is a real cost to that fake growth. Ignoring the problem carries heavy operational and legal risks. Recent history has shown as much with Twitter famously exposed during its acquisition for massively underreporting spam accounts while promoting an exaggerated monetizable daily active users number. Meta explicitly admitted in one of its 10-K filings that up to 14% of its user base is duplicate or fraudulent. Alphabet & Microsoft both rely heavily on boilerplate SEC warnings to shield their monetization metrics from investor lawsuits. That said, there has been a regulatory crackdown in which the SEC intensified enforcement against “tech washing” by penalizing platforms that use synthetic bot behavior to inflate their market value. The SEC's Cyber and Emerging Technologies Unit (CETU) should pursue enforcement actions against platforms utilizing fake metrics or synthetic behavior to inflate platform utility. If a tech provider aggressively markets user or enterprise growth driven by automated, non-vetted registrations, it falls squarely under SEC anti-fraud enforcement regarding misleading capabilities and metrics.

Similar to the cybersecurity landscape, the fraud and abuse ecosystem  ebbs and flows. When defenders apply new countermeasures and mitigations, the fraudsters quickly adapt and their underground economy continues to thrive. Malicious actors make a living dedicating their efforts to farming the creation and resale of accounts, compromising legitimate ones, and selling “aged” or already KYC-verified accounts. For the right price, fraudsters can simply buy their way past a platform’s defenses. 

This report surveyed some of the most recent sites alleging to sell such accounts. It is the hope of this report to renew efforts to mitigate fraudulent account creations across the IT industry from email to VPS, social media to payment services and more. It is also the hope of this report to better collaborate with fraud and abuse teams. They’re on your side. Help them help you. 

Merchants purporting to sell verified Stripe and Shopify Accounts

thepaygate[.]store

 

Fraud Services that Purport to Protect Stripe Accounts from Being Banned

ghostaudit[.]io

Audit Stripe Accounts

churnbot[.]co

Credit Card Store

track2ccdumps[.]ru | dumps-cc-best[.]ru

Survey

Domain Screenshot Description
gmailpva[.]comScreenshot of gmailpva[.]com“Official PVA Accounts Marketplace | Buy Verified Social & Email Accounts.”

Price: $2.10–$40 per account (11 platforms)

Contact: WhatsApp: +923000848427 | Telegram

Accounts advertised: Gmail, Instagram, TikTok, Twitter, Facebook, Reddit, Discord, YouTube, LinkedIn, PayPal, Yahoo
socialaccountshop[.]comScreenshot of socialaccountshop[.]com“Buy Aged Accounts and Reputation Services — Get access to high-quality aged accounts and trusted reputation services designed to support your online growth.”

Accounts advertised: Gmail, Instagram, TikTok, Twitter, Facebook, Reddit, YouTube, LinkedIn, PayPal, Google
buyaccounts[.]storeScreenshot of buyaccounts[.]store“A TO Z SHOP — Global Payment, Banking & Crypto Solutions.”

Active multi-platform financial fraud shop displaying real-time “Active/Online” status indicators for each product type. 247+ customer reviews visible. Claims 4+ years in operation. Explicitly markets “Verified Accounts” globally.

Accounts advertised: Stripe, Bank of America, Visa Gift Card, PayPal Business, Mercury Bank, Crypto
gmailshop[.]comScreenshot of gmailshop[.]com谷歌邮箱商城 (Google Mailbox Mall). Chinese-language WooCommerce Gmail account shop using Google branding.

Product specializations include: 2FA-enabled accounts, US-region accounts, 3-month aged accounts (¥6.6), and Edu (.edu Google Workspace) accounts.

Price: From ¥9.9 (~$1.37 USD)

Accounts advertised: Gmail
buyawsaccounts[.]comScreenshot of buyawsaccounts[.]com“Buy AWS Accounts, grow your Business — buy AWS accounts with the cheapest rate on the market.”

Claims 2,567+ accounts sold, 4.9 rating. Three price tiers suggest account types (credit levels / vCPU quotas). Selling cloud computing at scale.

Price: $30 / $45 / $70

Contact: Telegram + WhatsApp

Accounts advertised: AWS
accountstore[.]netScreenshot of accountstore[.]net“Agency accounts for Google Ads campaigns — Enjoy high trust and gain an advantage over your competitors! Easily pay for advertising on Google from any country.”

Explicitly sells elevated-trust Google Ads agency accounts to bypass Google’s country restrictions and fraud detection. Used to run large-scale scam ad campaigns under trusted umbrellas.

Price: £5 – €300

Accounts advertised: Google Ads
buyaccounts[.]netScreenshot of buyaccounts[.]netChinese-language TikTok account wholesale (title: “TK账号购买|TK千粉/白号批发平台-24H自动发货”).

Product types: 白号 (fresh accounts), 已实名 (real-name/identity-verified per China’s registration requirement), 1k-follower accounts, and TikTok Shop e-commerce accounts. 24H auto-delivery = high-volume automated operation. The “已实名” category implies selling accounts that have cleared China’s national ID verification system.

Price: 23.30 CNY/account (~$3.20 USD)

Contact: Telegram: @jingkerr

Accounts advertised: TikTok / TK Shop
buyaccounts[.]coScreenshot of buyaccounts[.]co“BuyAccounts[.]co | Social Media Accounts Marketplace.”

Marketplace with wallet/balance/recharge system, Purchase History tab, API documentation, and currency/language selectors.

Accounts advertised: Twitter/X, Facebook, Instagram, TikTok, Gmail, Hotmail
bulkaccounts[.]shopScreenshot of bulkaccounts[.]shopVietnamese-language account shop.

Sells accounts for dozens of providers. Offers API and bulk purchase options as well as YouTube tutorial and multiple customer service contacts with 24/7 operations. Includes sale of AI accounts including Grok and Cursor.

Price: USDT Trc20/Bep20/ERC20 (minimum 1 USDT via Binance)

Contact: Telegram: @Bulksms0000 | dipongkorcdasdd[@]gmail[.]com

Accounts advertised: Gmail, Google Workspace, Google Voice, Hotmail, Outlook, TextNow, Talkatone, TextFree, TextPuls, WhatsApp, Telegram, Facebook, Instagram, Twitter (X), TikTok, LinkedIn, Discord, Reddit, ChatGPT, Gemini Pro, Grok, Super Grok, ElevenLabs, Kling AI, Veo3 Ultra, CapCut Pro, Cursor, GPM, YouTube, ExpressVPN, CyberGhost, VyprVPN, ZoogVPN, NordVPN, Surfshark, Apple ID, iCloud, T-Mobile
buytwitteraccounts[.]comScreenshot of buytwitteraccounts[.]comActive Twitter/X shop with explicit pricing grid for old vs. new accounts.

Nav also includes Bank Accounts, Ads Accounts, Crypto Exchange for a broader cross-platform fraud marketplace. Old accounts command premium because they evade new-account detection and have established trust signals.

Price: New: $9 | Old: $20 | 5× New: $40 | 5× Old: $95

Accounts advertised: Twitter/X, Bank Accounts, Crypto, Ads
redditaccounts[.]comScreenshot of redditaccounts[.]com“Buy Reddit Accounts — Aged, High-Karma & Instant Delivery.”

Claims: “Real hand-crafted, high karma, and aged accounts available.” Reddit karma requires years of genuine community participation, which is more difficult to manufacture at scale. Selling aged high-karma accounts is near-certain evidence of account theft or hijacking. Claims 50k+ orders, 5/5 rating. “Safety first — we prioritise safety so your accounts last perfectly for all projects.”

Accounts advertised: Reddit


Actionable Advice for Defenders

Fraud and abuse teams are on the front lines of this fight. While fraudsters constantly adapt, their automated tools and bulk operations leave distinct footprints. Here are practical steps to identify and block accounts originating from these underground marketplaces.

Scrutinize the Signup Funnel
Account farmers rely on volume. Even when using residential proxies, they often reveal themselves through impossible form-fill speeds or identical hardware telemetry. Monitor for blocks of accounts created sequentially, accounts originating from the same autonomous system numbers (ASNs), or signups using highly predictable email naming conventions.

Watch for Sleeper Accounts
Our survey shows a clear price markup for "aged" accounts. Farmers create these accounts and let them sit dormant for months to bypass new-account filters and build a false sense of trust. Flag accounts that show zero activity for a long period and suddenly initiate high-volume actions like bulk API requests, ad creation, or mass messaging.

Detect Account Takeover Signals
High-karma and established accounts are commonly the result of a hijacked legitimate user and almost always against user terms of service by providers. Defenders need to watch for sudden identity shifts. A user logging in from a new geographic region using a completely different device footprint and immediately changing their recovery email is a massive red flag. Force step-up authentication when these high-risk account changes occur.

Target Fraud-Friendly Infrastructure
Feed threat intelligence directly into your registration pipeline. Block or heavily throttle signups coming from known proxy networks and bulletproof hosting providers. Maintain and frequently update a blocklist of temporary or disposable email domains, as these are heavily abused by automated account creators.

Conclusion

The tech industry has to stop treating account abuse and mass fraud as an acceptable cost of doing business. Ignoring this underground economy creates a domino effect that degrades the broader internet. When major providers allow fraudulent accounts to flourish, they directly fuel spam, enable malicious infrastructure, and burden security teams everywhere.

Stopping this requires a hard reset on internal corporate incentives. Product and marketing departments cannot continue to be rewarded for raw user growth if those numbers are artificially inflated by synthetic registrations. Anti-fraud and abuse teams must be given the authority to introduce necessary friction. Implementing mandatory MFA, rigorous identity checks, and behavioral analysis is essential, and these security controls should never be overridden by executives chasing adoption metrics.

Additionally, the industry must address the massive role of account takeover (ATO) in these marketplaces. The high premium placed on "aged", high-karma, and verified accounts is a direct result of hijacked legitimate users. Service providers have a fundamental responsibility to protect their customers from these compromises. Defending the platform means deploying stricter backend detections while actively giving users the security settings, login telemetry, and alerts they need to monitor and lock down their own accounts. The tools to stop account farming already exist. Companies need to empower their security teams to use them.


IOCs

Fraudulent Account Marketplaces and Services

Domain Domain
thepaygate[.]storegmailshop[.]com
ghostaudit[.]iobuyawsaccounts[.]com
churnbot[.]coaccountstore[.]net
track2ccdumps[.]rubuyaccounts[.]net
dumps-cc-best[.]rubuyaccounts[.]co
gmailpva[.]combulkaccounts[.]shop
socialaccountshop[.]combuytwitteraccounts[.]com
buyaccounts[.]storeredditaccounts[.]com


Threat Actor Contact Handles & Emails

Channel Identifier
WhatsApp+923000848427
Telegram@jingkerr
Telegram@Bulksms0000
Emaildipongkorcdasdd[@]gmail[.]com

Related Content

SecuritySnacks
Scarcity Scams
Discover how scarcity scams exploit government service bottlenecks to commit wire fraud and identity theft. Learn the tactics behind fake fast-track portals.
Learn More
SecuritySnacks
Cybersecurity Reading List - Week of 2026-06-01
Commentary followed by links to cybersecurity articles and resources that caught our interest internally.
Learn More
SecuritySnacks
SecuritySnack - Hijacking Corporate Sessions
A sophisticated AiTM phishing kit bypassing traditional MFA to steal Microsoft 365 session cookies. Get the full breakdown and IOCs.
Learn More