Account farmers vary widely in sophistication, requiring firms to look beyond KYC and use behavioural, device and lifecycle signals to detect fraud.
The most dangerous account farmers are the ones you’ll never notice.
A year of buying accounts and tracking these sellers has taught us how an account can be farmed and, more importantly, how to detect it.
And the level of sophistication of the account farmer matters a lot. This matters not only for understanding how much of an overall threat a specific vendor is, but also for knowing where the dividing line between amateurs and pros really lies.
When it comes to scale, this dividing line is not straightforward. Account farmers of varying sophistication can create numerous fraudulent yet verified accounts across multiple platforms. Sizable volume and activity are not reserved only for organised farming groups.
Knowing what type of account farmer you’re dealing with tells you what to look for on the detection side. While document authenticity analysis is the obvious starting point, you also need to know which data points or behaviours can hint that an account is a product of a farming operation.
Let’s dig into different account-farmer archetypes and how to prevent them from letting criminals access your platform.
General considerations
When assessing our experience with account farmers, there are three main areas we focus on:
- Account package assets. Documents, liveness, credentials.
- Operational security. Infrastructure, handover, behaviour.
- Sales motion. Advertising, deal processing, coverage, division of labour.
These areas are the three points in the account farming lifecycle where a farmer can and usually does leave a trace: assembling the goods, hiding the work, and running the sale.
Each archetype differs. An account farmer can be advanced from one perspective and amateur from another, and that mismatch is itself a detection signal.
And while we obviously haven’t seen every account farmer variation, we’ve bought and dissected enough accounts to know which parts of the KYC and selling process might give a farmed account away.
The Hustler: Scale without opsec
We start at the most detectable level of an account farmer, which we have labelled the Hustler. We were able to see inside one account farm of this type without directly buying from them, which partially symbolises the low level of sophistication.
Our initial touchpoint was UI screenshots of logged-in accounts that the farmer posted in Telegram channels to advertise their services. These screenshots were not anonymised and showed the account holder’s name, giving us a clear starting point, as they were onboarded on a platform we were already working with.
With help from the platform, we were then able to look at these accounts’ behaviour and details from the inside, quickly revealing that this account farmer was never too worried about getting caught.
By reviewing one account and its onboarding, device, and behavioural characteristics, we quickly identified a cluster of tens of accounts sharing the same data points and created with the same MO.

All clustered accounts were business accounts, started using a legally registered shell company, and controlled by a company director or a PSC (person with significant control, aka the company owner) from a high-risk jurisdiction.
The identities behind the shell companies seemed real, both at the document level and the context level, as conducting some OSINT research on the identities involved pointed to social profiles behind some of these persons and indicated real-life activity.
Non-ID documents used during onboarding hinted at the use of online templates from template farmers or harvesting these from publicly available template hubs.
As these were business accounts, an important part of the business legend was also these accounts providing links to marketplace/merchant seller profiles that were, however, dysfunctional or non-existent.
To top it all off, numerous accounts in the cluster shared a very similar transactional pattern. Short timeframe, equal amounts of money in and money out, often receiving a sum and redistributing it among several other accounts. Classic money laundering potential.
So why do we view this kind of operation as low-sophistication?
After all, this farmer might have created hundreds of personal and business accounts and clearly has a process for getting accounts verified repeatedly.
But committing a crime repeatedly does not make you a pro. On the contrary, if you do something repeatedly but do not cover your tracks properly, sooner or later you will be detected, provided the platform has the right defences in place.
This is what we mean by using The Hustler name here. Pure focus on getting accounts created and sold, with no real consideration for operational security or secure advertising.
We never had to buy a thing. His own advertising and repeated patterns handed us the entire cluster.
The Soloist: Sloppy at handover
The term “Soloist” as an amalgam of the words “solo” and “specialist” implies this type of account farmer knows what they’re doing. But it also specifies that this is a one-man operation with its limitations.
If the Hustler never has to meet you and gives his product away through careless advertising, the Soloist is the opposite: the entire transaction runs through one person in real time, and that is exactly where he leaks signals for detection as well.
The Soloist is also the archetype we interacted with most during our initial account purchases, when we needed to test the market and buy a business account for a payment platform.
At the very beginning, the conversation moved quickly. The account farmer quickly told us he had the account we wanted available and that we could process the purchase through direct distribution and the 50/50 approach (half the money now, half after).
Once the conditions were agreed and the first part of the funds transferred, the deal started moving. But this is where the Soloist’s workflow revealed data points useful for detection.
For starters, the farmer instructed us to have our own phone number ready so that he could switch within the account setup to direct the new one-time login passwords to us.
The phone number change is a tracked account action and can be flagged as unusual or suspicious, especially if it includes phone numbers from vastly different jurisdictions.
The same goes for email addresses, which we were also instructed to update after the farmer sent us the logins. Different infrastructure, same partial sloppiness that can trigger detection because regular users don’t change credentials often, especially without any significant history of using the accounts.
Regarding the device to access the account itself, the Soloist gave us no instructions on IPs, proxies or a dedicated device, all information included in packages we have purchased elsewhere (more on that later). Though we could not confirm, the lack of further instruction suggests mistakes will be made and shared infra characteristics will be detected with proper analysis.
The emblematic aspect of this operation is the one-man setup, and we experienced it first-hand when waiting for the account handover. He asked us to trust him (and even sent us an alleged picture of himself on a moped somewhere in Pakistan), and we were forced to wait for the farmer to get home to process the deal. Such activity can’t be scaled and suggests an independent operator making a decent living on account fraud, albeit in a moderate volume.

Moped-aside, we ultimately logged into the account, implying a successful deal. The final remaining component to hand over was the documents themselves.
That’s where things got tricky. The account farmer provided us with several assets, specifically:
- ID document (front and back)
- Certificate of good standing for a U.S. entity
- IRS-issued EIN letter
Each asset had serious flaws. The ID was a very low-quality image that shouldn’t pass anywhere. The certificate of good standing and the EIN letter were clearly tampered with, likely leveraging online templates.
Checking the account from the inside showed that the ID documents the account farmer gave us might have shown the same personal details, but an entirely different person from the account holder’s selfie uploaded during onboarding. The farmer may have done this on purpose to keep his quality identity assets for himself, thinking we wouldn’t discover the mismatch.
On top of that, the company documents pointed to an LLC incorporated in Wyoming, but when we checked the state’s official business registries, the LLC wasn’t there. This was a barely usable, low-quality document package with false information, and it wasn’t the one used to onboard the account in the first place.
While the account farmer’s intention is unknown, his negligence and subpar evidence package make it a very discoverable fake account, and even if he passed onboarding initially, the legend won’t hold for long. In other words, the Soloist probably has many dissatisfied customers.
And where the Hustler is undone by lazy advertising and the repeated patterns and shared account characteristics that make his operation clusterable, the Soloist is undone by the deal itself. His lack of opsec and those tracked credential changes mean we could eventually cluster him too, by focusing on those handover actions across an account’s lifecycle. The difference is cost: with the Hustler, the cluster is there to take. With the Soloist, we’d have to buy from him again and again to assemble it.
Lastly, the Soloist excels at reaching out. After our first purchase with such an account farmer, we were consistently cold-texted about further purchases.
And whenever we asked about another account for a specific platform or jurisdiction, the farmer always promised to deliver, just to keep us on the hook. More often than not, the deal went nowhere. He couldn’t actually source the account, though he’d still tell us to reach out if we needed anything else.
From what we’ve experienced, successful and professional account farmers don’t need to cold call as much. They wait for demand to come to them, which changes the perspective on both account-creation turnaround time and the number of signals left behind for detection. Because the pros have this figured out in bulk.
The Franchise Farmer: Thousands of accounts, on-demand
This one is the real deal.
We’ve seen franchise farmers numerous times within several of the marketplace channels we’re monitoring. And we decided to reach out again to purchase a business account on a financial platform.
From the get-go, this kind of seller showed off a structured approach. Right after our initial query, the account farmer sent us a link to a sole proprietorship record in the French business register, commenting that:
- Documents will be similar, but yours, not these (i.e. our own account will be tied to a similar sole proprietorship entity with similar documents)
- Phone number and email provided
- All data for the accounts + documents on both sides and a selfie with the (ID) document will be provided
- France-based account tied to sole proprietorship registered with a Spanish identity
This is clearly a pre-written, structured description of what the account package will contain. The first traces of an existing selling/distribution motion and system.
Next up, the deal processing. The farmer suggested processing the deal through a third-party escrow service widely known in the criminal ecosystem simply as “Gross.” This escrow platform doesn’t allow negotiations or direct transfers, maintaining a much higher standard of control (and trust) and ensuring you can get your money back if the deal isn’t satisfactory. Even fraudsters prefer not to get scammed.
Once the deal was created and confirmed within the escrow service, we moved right into one of the most representative signs of a professional operation: technical support and clearly defined roles. The “customer care” account we agreed to the deal with referred us to a different account to handle the setup and handover.
Instantly, we got a message from the tech support account with the entire package info:
- Account-tied, fresh email credentials
- Reserve email credentials (created with a dedicated mail service such as firstmail.ltd)
- SIM bot service to receive passwords
- Account login credentials
- Proxy & IP details
- Device emulator credentials & provider details
- Link to documents storage
- Link to register of the company/proprietorship the account was registered for
- Instructions on behaviour, including stuff like ”don’t keep money on accounts for longer periods of time” and ”cash-in-cash-out, preferably at night“

One more thing that caught our attention in the package description: the order numbering.
While this could obviously be made up, we’ve purchased numerous accounts from this vendor and seen order IDs ranging from the 4000s to the 9000s over several months.
If true, this vendor has created and sold thousands of accounts across platforms in maybe less than a year of operation. Considering the price of an account could be around 300$ on average, such an account farmer could have already made millions of dollars. More than enough to keep the operation running, developing and growing.
And it didn’t end with the package details. Since we hadn’t done this before, the support persona walked us through the technical setup. From suggesting an anti-detect browser to setting up the proxy and logging into both the dedicated virtual device and the bought account.
The cherry on top? The farmer confirmed that we would retain absolute control of the account, explaining that the real persona does not have access, but is still available for a premium payment in case of a liveness check. In short, a ready-to-be-activated liveness mule.
With this kind of farmer, possible detection signals are scarce. The documents used were real; the opsec kept device and network datapoints local and unchanged. And because these accounts were created fresh and on demand, there’s no activity to analyse in the early stage of the account lifecycle.
This is the level of professionalism account farmers can reach, and based on the order numbering, these are the ones who might do the most business (and fast).
Technically speaking, we were a satisfied customer as well. Given that this farmer offers accounts for at least 50 different platforms in 6 different jurisdictions, it’s highly likely that fraudsters running fraudulent accounts across platforms keep coming back to this vendor.
After all, the farmer told us himself that “we make many accounts, glad to cooperate.” He didn’t press us on a future deal, leaving the door open for us to come back without implying a dire need to extract money or a sense of urgency.
Detection typologies
After reviewing the archetypes in detail, you can detect each one in several ways.
Facing a Hustler? Look at creation-time clustering: shared device/IP across many accounts, public non-anonymised advertising, template documents, structuring patterns. This can be detected throughout the account lifecycle, and it applies to all accounts sharing the same characteristics in a cluster.
Facing a Soloist? Look at the handover: tracked phone/email swaps across jurisdictions, document flaws and registry mismatches. This farmer cares about selling anything right away, doesn’t worry too much about building proper opsec or reputation, and likely doesn’t worry about getting caught.
Facing a Franchise Farmer? Per-account signals are scarce by design, so the leverage shifts elsewhere: marketplace-level intelligence (order numbering, catalogue breadth, the escrow-and-support pattern), and detection that watches the account over its life rather than at onboarding. The burden of opsec shifts to the buyer, and that’s where the lifecycle signal eventually appears.
For a complete breakdown of the typologies and how to spot them, check out the signal matrix below.
| Account Farmer Archetype | How they advertise & sell | Documents & identity | Network & device intelligence | Handover & setup | Behavior over time | Detected where? |
| The Hustler | Non-anonymized screenshots in Telegram channels | Real IDs behind shell companies, non-ID docs forged using online templates | Same devices, same IPs across tens of accounts | No direct sale needed (you can find his accounts via the screenshots) | Cluster-wide structuring, similar transaction patterns | All throughout the lifecycle |
| The Soloist | Direct messaging & negotiation, over-promises, cold-calling, flaky delivery | Low-quality IDs, forged non-ID docs, phantom LLC used absent from registry | No IP/proxy/device guidance | Phone + email swap after login (tracked actions that can trigger flagging) | Legend short-lived, patterns can emerge across account package setup | Mainly at handover |
| The Franchise Farmer | Multi-channel presence, wide offering, pre-written package specification | Real documents, real person and real business entity without access, selfie with ID supplied, mule for liveness for a premium | Anti-detect browser, purchased proxy, device emulator, consistent per account | Roles split (customer care, tech support), full infra bundle + behavioral instructions | Fresh, on-demand accounts → little history at first; the instructed pattern only shows across the lifecycle | Tough to stop at handover, detectable via behavioral patterns later in the lifecycle |
Regardless of the archetype, advanced defences should pay ample attention during the entire lifecycle. This entails proactive threat research, document authenticity and liveness controls, transaction monitoring, and network, device, and behavioural analysis.
The next signal frontier
We realise these account farmer archetypes are uneven. Overlaps happen, and there’s a lot of variety, but these are the scenarios we’ve seen most often.
While document authenticity and device and network intelligence are where you start, it is not where you finish. If account farmers operate with few detection signals, we need to move beyond obvious signals and derive new ones from specific modus operandi markers.
Resistant Documents helps on this front by identifying not only where a document was altered, but also which software, online document generator, or editing tool was used.
For account lifecycle itself, Resistant Transactions detects suspicious account behaviour, specialising in muling and perpetrator detection. The analysis includes both transactional and non-transactional behaviours, with bespoke data schemata, allowing you to map even the tiniest signals during advanced account handovers.
Because if we can identify the tools farmers use for so-called passing KYC, we’re one step closer to deriving new signals and catching them.
But more on that next time.
Enjoyed this content? Sign up for our “Threat Radar” newsletter using the form on your left!



















