Referral Fraud Prevention

Prevent referral fraud before payouts hit fake accounts

Keep referral payouts, invite credits, and rewards on real advocates, and stop one person from claiming both sides of every referral

Referral Fraud Prevention illustration

How ShieldLabs helps

Stop self-referral loops

Catch one person opening both referrer and referee accounts to collect both payouts

Block referral farms

Spot coordinated rings creating dozens of accounts to milk referral programs at scale

Protect referral budget

Keep ambassador commissions, invite credits, and refer-a-friend rewards on real customers

Keep real advocates friction-free

Legitimate referrers earn rewards without delays, holds, or extra verification

How ShieldLabs prevents referral fraud

ShieldLabs recognizes the real visitor behind every anonymous session, so your team can stop fraudulent referrals before payouts clear

Accurate Identification

Identify returning visitors and users across sessions, cleared cookies, incognito mode, and rotated IP

Accurate Identification

Risk Signals

Detection of VPN, proxy, Tor, anti-detect browser, IP reputation and other risk signals on every visit, with 99.9% risk signal detection accuracy

Risk Signals

Risk Score

A ready-to-use score reflecting the risk of each visit, with the weight of every signal behind it

Risk Score

High-Risk Events

High-Risk Events detected out of the box: multi-accounting, account sharing, impossible travel and account takeover, each with Medium or High confidence

High-Risk Events

Real-Time Analytics

See how much of your traffic is masked, with an overall quality score and a breakdown of the sources sending your visits

Real-Time Analytics

Start preventing referral fraud in 5 minutes

Easily integrate into any signup, referral redemption, or payout flow

  1. 1

    Create your account

    Get 5,000 free identifications

  2. 2

    Add the snippet

    It identifies every visitor and returns their risk signals and a risk score

  3. 3

    Check your traffic quality

    See how much of your traffic is masked, with an overall traffic score

  4. 4

    Use the API and Webhooks

    Get the risk score, risk signals and High-Risk Events in your backend to stop fraud and abuse

api.shieldlabs.ai/v1/visits/latest
{
  "request_id": "0c284695-cf0b-4755-8beb-0a2e9536595e",
  "visitor_id": "aa8c616a-8a25-4a5e-bee2-a9a08e5128a4",
  "device_id": "6a45967d-1371-9652-ba99-b01ea3992208",
  "user_hid": "u_9f2a41c7",
  "public_ip": { "ip": "62.197.149.124", "country": "United States" },
  "local_ip": { "ip": "45.83.91.7", "country": "United States" },
  "connection_type": "vpn",
  "os": "Windows",
  "browser": "Chrome",
  "device_type": "desktop",
  "risk_score": 85,
  "signals": [
    { "name": "antidetect_browser", "weight": 60 },
    { "name": "vpn", "weight": 15 },
    { "name": "timezone_mismatch", "weight": 10 }
  ]
}

Start preventing referral fraud today

Free 5,000 one-time identifications, with transparent pricing that scales with your needs

Frequently asked questions

Referral fraud is the exploitation of a customer-referral program by one person claiming rewards under multiple identities to collect payouts they are not entitled to. Some platforms call the same behavior referral abuse or referral program fraud, but the underlying tactic is identical: one person, many accounts.

  • Self-referral: opening both a referrer and a referee account to collect both sides of one payout.
  • Account farming: spinning up dozens of accounts to claim referral credits at scale.
  • The shared signal: one persistent visitor and user behind many accounts at signup.

ShieldLabs surfaces this with persistent identification across sessions, so the same person is recognized regardless of email, IP, or cleared cookies.

Fraud teams typically classify referral fraud into four shapes, but all four reduce to the same multi-account signal at signup: one person, many identities.

  • Self-referral: one person creating both the referrer and the referee account to collect both sides of the payout.
  • Exploitation: a legitimate user gaming the program rules by stacking offers or bending eligibility.
  • Account cycling: closing and reopening accounts to re-qualify as new.
  • Broadcasting: publicly leaking a personal referral code so anyone can claim it.

ShieldLabs surfaces the underlying tactic with persistent identification on every visit, linking the accounts behind all four shapes.

Referral fraud usually breaches a platform's terms of service rather than criminal law, so most enforcement is handled by the operator rather than the courts.

  • What operators can do: void rewards, reverse credits, close accounts, and refund disputed payouts.
  • When it becomes criminal: rare, and usually tied to stolen identities, stolen payment methods, or organized rings.
  • Stricter contexts: fintech and crypto programs face more scrutiny because referral payouts overlap with KYC and AML obligations.

ShieldLabs gives operators the evidence to enforce their terms: persistent visitor and user identification, risk signals, and High-Risk Events such as multi-accounting.

Referral fraud is customers exploiting a customer-referral program by opening fake accounts to collect their own rewards, while affiliate fraud is paid partners gaming the program to inflate commissions. Different actors, overlapping detection layer.

  • Referral fraud: a customer self-deals, opening multiple accounts to refer themselves.
  • Affiliate fraud: a partner uses cookie stuffing, fake lead generation, or bot traffic to claim commissions they did not earn.
  • What they share: both leak when device fingerprinting and IP intelligence link the supposed new customer back to the referrer or affiliate.

ShieldLabs surfaces the multi-account signal behind both, linking related accounts regardless of email, IP, or cleared cookies.

A self-referral is the most common referral fraud shape: one person opens two accounts, one as the referrer and one as the referee, and collects both sides of the payout. It is detected by linking the supposed new customer back to the existing referrer through signals that email or IP rules miss:

  • Device fingerprinting recognizes the same device behind both accounts, even after cleared cookies or incognito.
  • Anti-detect browser detection and OS mismatch flag attempts to look like a different machine.
  • Persistent identification holds across cleared cookies and rotated IPs, so the link survives evasion.

Matched before the payout is issued, the referrer-referee pair can be held for review instead of credited automatically.

Effective referral program fraud prevention combines three layers so risky payouts are caught before credits clear, not after.

  • Identity signals at signup: device fingerprinting, IP intelligence, anti-detect browser detection, and disposable-email checks to link related accounts.
  • High-Risk Events: multi-accounting detected out of the box when one person runs many accounts.
  • Payout delay: hold referral credits for review when the risk score is high.

ShieldLabs returns a 0-100 risk score with a full signal breakdown from a single JS snippet on signup, so fraud teams can choose verification, hold, or automatic credit for each case before payouts clear.

Operators detect referral fraud at signup by combining several signals into one risk picture, so abuse is caught upstream before a credit is issued or a payout clears.

  • Device fingerprinting: links accounts across sessions, even after cleared cookies.
  • IP reputation and anonymizer detection: surfaces VPN, proxy, Tor, and anti-detect browser use.
  • Disposable-email and multi-accounting checks: flag throwaway addresses and many accounts run by one person.

ShieldLabs runs all of this from a single JS snippet, returning persistent visitor and user identification with a 0-100 risk score on every visit, even when cookies are cleared and IPs rotate.

ShieldLabs stops referral fraud by flagging risky payouts and helping block fraudulent and abusive traffic. It returns a risk score, a full signal breakdown and High-Risk Events, and you choose the action for each case.

  • Trusted scores (0-29): credit the referral as normal.
  • Suspicious scores (30-59): require email or phone verification first.
  • Dangerous scores (60-100): hold the payout for manual review before it clears.

ShieldLabs includes 5,000 free identifications, so you can see the results on your own traffic first.

ShieldLabs sits between referral attribution platforms and heavyweight fraud suites: it adds the device-and-network signal layer that referral tools lack, as enterprise-level functionality without enterprise pricing. Referral attribution platforms track who referred whom, but do not fingerprint devices or detect anti-detect browsers. ShieldLabs gives you the full signal set on a transparent plan, with High-Risk Events and a 0-100 risk score on every signup. It drops next to a referral platform via API, ready in 5 minutes.