How to prevent marketplace fraud: types, signals, and the actor behind them

Last updated on July 21, 2026 · 10 min read
A marketplace carries a kind of fraud a single-vendor store never has to think about. It runs two sides, buyers and sellers, and trusts them to transact with each other, so an actor can enter as a buyer, a seller, or both, and can spin up as many of each as the sign-up flow allows. That is what makes marketplace fraud its own category: the same person wearing a shopper account, a seller account, and a reviewer account, all made to look like unrelated strangers. I ran operations for online businesses where the accounts that caused the most damage were not the loudest ones, they were the quiet cluster of "separate" users that turned out to be one hand, and in 2026 the pattern that kept surfacing was a ring hiding behind a swapped email and a rotated IP while the device behind the session stayed the same. This guide maps the main types of marketplace fraud, folds triangulation fraud in as the marketplace-specific one, and shows how reading the device behind each account links the ring without forcing a check on every honest user.
Key takeaways
- Marketplace fraud is fraud that exploits the two-sided model: one actor operating many buyer, seller, or reviewer accounts that are built to look unrelated.
- The recognizable types are buyer scams, seller scams, triangulation fraud, account takeover, collusion and fake-review rings, and organized refund or return rings.
- Triangulation fraud is the marketplace-specific one: a hidden middleman inserts a stolen-card order between a real buyer and a real retailer, and it needs its own section.
- The common thread under every type is one actor behind many accounts. The email, the card, and the listing change per account while the device and connection stay the same.
- You read it at the device and network level and score each account, so your own marketplace rules decide the action and an honest buyer or seller transacts untouched.
What is marketplace fraud?
Marketplace fraud is any scheme that abuses the two-sided structure of an online marketplace, where independent buyers and sellers transact and the platform sits in the middle. Because a marketplace onboards both sides, a single actor can register as a buyer, as a seller, or as both, and can operate many accounts at once, each presented as an unrelated person. The forms range from buyer-side scams and seller-side scams to triangulation fraud, account takeover, collusion and fake-review rings, and organized refund rings. What unites them is that the fabricated part is the identity behind the account, so the marketplace's real problem is telling one actor's many accounts apart from a crowd of genuine strangers.
What marketplace fraud does an online marketplace face?
The fraud hitting a two-sided platform is not one thing, but the list is short and it repeats across every category of marketplace, from resale and rideshare to short-stay rentals, food delivery, and freelance work. Naming the types in one place helps, because most of them share a root and a fix even though they wear different roles. Each has its own deeper guide where one exists; this is the map.
| Fraud type | What it is | Covered in depth |
|---|---|---|
| Buyer scams | a buyer claiming an item never arrived, disputing a legitimate charge, or opening throwaway accounts to abuse offers | refund and return abuse |
| Seller scams | a seller listing goods they never ship, posting fake listings, or cycling stores to escape a bad reputation | this guide |
| Triangulation fraud | a hidden middleman inserts a stolen-card order between a real buyer and a real retailer | this guide, below |
| Account takeover | an attacker signs into a real buyer's or seller's account and transacts as the trusted owner | account takeover |
| Collusion and fake-review rings | clusters of accounts that trade with themselves or post reviews to inflate a listing or bury a rival | fake reviews |
| Organized refund and return rings | a return or refund scheme run across many accounts, funneled back to one device, card, or address | refund and return abuse |
The roles differ, but read down the middle column and the same sentence keeps surfacing: one actor, many accounts. That is why these can be handled together instead of one campaign at a time. Two of the types carry a behavioral half as well, a single account that returns too much or posts one fake review, which lives in your order and review data; the device layer's job is the multi-account half, linking the accounts behind a refund ring or a review cluster so the pattern stops hiding as unrelated users.
The scale is not trivial. The U.S. Federal Trade Commission reported that consumers lost more than $10 billion to fraud in 2023, with online shopping among the most commonly reported categories.
That marketplace slice sits inside a still larger total: Juniper Research projects global ecommerce fraud losses rising from $56 billion in 2025 to 131 billion dollars by 2030. The platform absorbs the chargeback and the reputational cost even when the money changes hands between two of its users.
Triangulation fraud: the marketplace-specific one
Triangulation fraud is the type most tied to the marketplace model, and it earns its own section because it hides inside transactions that all look legitimate. It is a form of card-not-present fraud with three players: a genuine buyer, a fraudster acting as a secret middleman, and a real retailer that unknowingly fulfills the order.
Here is the shape it takes:
- A real buyer orders a popular item, often trending electronics or luxury goods, from a listing on a marketplace at an attractive price.
- The fraudster, posing as the marketplace seller, buys that same item from a legitimate retailer using a stolen card, then keeps the buyer's genuine payment.
- The retailer ships the item to the buyer's real address and is left holding the chargeback when the stolen card is reported.
- The buyer receives the item and never realizes they were part of the scheme.
What makes triangulation fraud so effective is that every leg looks ordinary in isolation. The buyer's payment is real, the retailer's order is a normal purchase, and the only paper trail points back to the buyer who received the goods. The fraud becomes visible only when you connect the seller account placing these orders to the device driving them, because that middleman account is the piece the scheme cannot cheaply reissue. The same fraudster typically runs many such listings from the same machine, which is what ties a spray of "unrelated" orders back to one source. This overlaps with account takeover when the stolen card is pulled from a hijacked account rather than a breached list, and with organized refund and return abuse when the resold goods cycle back as returns.
Fraud runs on both sides of the marketplace
A single-vendor store worries about the buyer. A marketplace has to watch both sides of its own aisle, because the actor can pick whichever role fits the scheme.
Buyer-side fraud
On the buyer side, an actor opens accounts to claim goods and dispute the charge, to abuse first-order or referral offers across throwaway identities, or to run the return end of a refund ring. The buyer's payment is often their own or a stolen card that clears, so nothing about the transaction looks wrong at the moment it is submitted, and the abuse only shows when the accounts behind it are linked.
Seller-side fraud
On the seller side, the same freedom to onboard becomes a listing that never ships, a fake storefront built to collect payments and vanish, a seller cycling new stores to shed a bad reputation, or the middleman account behind triangulation fraud. A seller who is banned simply signs up again with a new email and a new store name, so the marketplace needs a way to recognize the returning operator rather than the new display name.
Both sides converge on the same question the platform has to answer at onboarding and at transaction time: is this a genuine new participant, or the same actor from a role you already know. That is an identity question, read at the device and network behind the account, and it is the shared control across every type in the table above.
The one thread: one actor, many accounts
Strip the role away and every type on the list is the same move: a single actor produces a stream of accounts that each look like an unrelated buyer, seller, or reviewer. It is the one-actor-many-accounts pattern behind multi-accounting, where a fresh email and a rotated IP still fail to keep a determined operator apart from the crowd.
What ties the accounts back together is what the actor cannot cheaply reissue per account. The email is a disposable address, the IP is rentable, the listing name is free, but the device behind the session and the network it rides stay the same from one "separate" account to the next. So a marketplace does not have to solve six problems; it has to answer one question the moment an account acts, whether it signs up, lists, checks out, or requests a refund: how new is this participant, really. The broader account-abuse mechanic runs in depth through the ecommerce account and offer abuse playbook, with the full set of signup-time and redemption-time signals.
How a marketplace reads it without adding friction
The reflex when fraud climbs is to add friction to everyone: force identity checks on every seller, gate every first purchase behind verification, slow the whole two-sided flow to catch a few rings. That tax lands on every honest buyer and seller, and on a marketplace friction is measured directly in listings not posted and carts not completed. Reading the device first inverts the order.
Read the device, not just the account
A JavaScript snippet identifies the participant on the page, and your marketplace reads a risk score for that session when an account signs up, lists an item, checks out, or asks for a refund. A device already seen behind a cluster of seller stores or a run of refund claims scores high; a genuine first-time buyer or seller on a normal connection scores clean and transacts with nothing added.
We measured how well that holds. Sending the same device back through a new inbox, a clean cookie jar, and a different connection, the derived identifier still matched it to the account cluster we had already seen, up to 99 percent of the time, which is what turns a spray of supposedly unrelated buyer and seller accounts into one linked ring. It stays probabilistic rather than a guaranteed identity, so it feeds your marketplace rules as a supporting signal rather than an automatic block.
Because the score is separate from the action, your own marketplace rules decide what a risky account gets, hold a payout for review, step up to a verification check on that account, or let it through, while the real participant transacts freely. That separation, read quietly and decide explicitly, is what lets a platform link rings without turning onboarding into an obstacle course. It reads the browser and device rather than hooking into the payment flow, so it runs the same across a custom marketplace and a hosted one, and it works alongside your existing payment screening and trust-and-safety review.
How ShieldLabs helps marketplaces
ShieldLabs runs on your signup, listing, checkout, or refund page through one JavaScript snippet, and it risk-scores every participant on the first visit, so you have a read on the actor behind an account before a payout goes out or a listing goes live. At the center is persistent identification that ties a "fresh" buyer or seller account back to a device already seen, even after the actor switches email, clears cookies, and rotates IP. It reads the anonymity signals behind the session too, so a seller account arriving through a VPN, an anonymous proxy, a datacenter, or an anti-detect browser is flagged for what those tools are built to hide.
Each visit returns a risk score from 0 to 100 with the named signals behind it, and across accounts the pre-built patterns surface which ones trace back to one device, so a collusion ring or a triangulation seller reads as a linked cluster rather than a pile of separate orders. You take the risk score and named signals through the API and webhooks and decide, by your own rules, what a risky account gets; the read is explainable, so you set the threshold and can always say why a payout was held. The verdict stays in your application where it belongs, weighed as a supporting signal into your own decision, and the same identity layer complements the payment screening and trust-and-safety review already running on the other side of the platform.
Sources
- Wikipedia: Disposable email address
- OWASP: Automated Threats to Web Applications (account creation and abuse of functionality)
- U.S. Federal Trade Commission: As nationwide fraud losses top $10 billion in 2023, FTC steps up efforts to protect the public (2024)
- Wikipedia: Card not present transaction
- Juniper Research: Fraudulent eCommerce Transactions to Surpass 131 Billion Dollars by 2030 (2025)
Frequently asked questions
- What is marketplace fraud?
- Marketplace fraud is any scheme that abuses the two-sided structure of an online marketplace, where independent buyers and sellers transact and the platform sits in the middle. Because a marketplace onboards both sides, one actor can register as a buyer, a seller, or both, and operate many accounts at once, each presented as an unrelated person. It covers buyer scams, seller scams, triangulation fraud, account takeover, collusion and fake-review rings, and organized refund rings. The fabricated part is the identity behind the account, so the platform's real problem is telling one actor's many accounts apart from a crowd of genuine strangers.
- What is triangulation fraud?
- Triangulation fraud is a form of card-not-present fraud with three players: a genuine buyer, a fraudster acting as a secret middleman, and a real retailer that unknowingly fulfills the order. The buyer orders an item from a marketplace listing at an attractive price, the fraudster posing as the seller buys that item from a legitimate retailer with a stolen card and keeps the buyer's payment, and the retailer ships to the buyer and is left holding the chargeback. Every leg looks ordinary in isolation, so it becomes visible mainly when the seller account is linked to the device driving many such orders.
- How is marketplace fraud different from regular ecommerce fraud?
- Regular ecommerce fraud runs against a single vendor, so the store mostly watches the buyer and the payment. A marketplace runs two sides and trusts its own users to transact with each other, which opens seller-side schemes like fake listings and store cycling, plus marketplace-specific ones like triangulation fraud where the fraudster hides inside a legitimate-looking transaction. The shared trait is one actor operating many accounts across roles, which is an identity pattern read at the device and network behind each account rather than at the card alone.
- Can you stop marketplace fraud without adding friction for real buyers and sellers?
- Yes, by reading the device and network behind each account instead of gating everyone with checks, then scoring how new the participant really is and acting only on the high-risk accounts. A genuine first-time buyer or seller on a normal connection scores clean and transacts with no extra step, while a device already behind a cluster of stores or refund claims stands out. Because the score is separate from the action, your marketplace rules hold or step up only the accounts that look linked, so the friction lands on the ring and not the honest participant.
- How does ShieldLabs help marketplaces?
- ShieldLabs adds one JavaScript snippet to your signup, listing, checkout, or refund page and, on the first visit, returns a risk score from 0 to 100 with the named anonymity signals and persistent identification behind it. That identifier ties a fresh buyer or seller account back to a device already seen even after a new email and a rotated IP, and the pre-built patterns surface which accounts trace to one device, so a collusion or triangulation ring reads as a linked cluster. You take the score and named signals through the API and webhooks and decide by your own rules; it surfaces the evidence and complements your payment screening and trust-and-safety review. The free tier covers your first 5,000 identifications.
Related articles

The 8 best free-trial abuse prevention tools in 2026
The 8 best free-trial abuse prevention tools in 2026, how prevention works by linking many trial signups back to one device, and how to choose.

How to prevent refund and return abuse
How to prevent refund and return abuse: the multi-account refund-ring slice you can detect, how it differs from wardrobing and chargebacks, and how to read it.

How to prevent online travel fraud: the types and the actor behind them
What online travel fraud is, the main types from stolen-card bookings to miles theft and fake listings, and how the device behind a booking ties them together.