Signup abuse · entity linkage

15,008 unlabeled signups. 251 likely multi-account actors.

A merchant handed over a snapshot with no labels — nobody said who was abusive, or whether abuse existed at all. We linked accounts only when a strong identity signal, or two weaker ones, said they were the same person. Legitimate customers stay out of the graph.

  1. 15,008signups in the snapshot
  2. keysevery field collapsed to an identity
  3. 470pairs that cleared the gate
  4. 251clusters / 587 linked accounts
CERTAIN
204
would take to a merchant
HIGH
44
strong, needs a second look
MEDIUM
3
corroborated, not proven
Left out
14,421
singletons we refused to link

Three cases worth opening

Start here instead of the full graph. Each card is a real cluster from this run.

What actually linked them

Most CERTAIN clusters are Gmail alias rings. Device hash and card (BIN + last 4) are the interesting minority — rarer, and usually the cases that are not just the same inbox.

204clusters
📱 device41clusters
👤 name4clusters
💳 card2clusters

Sorted by size among CERTAIN, then HIGH. That is not the same as link weight — a two-account Gmail alias can score higher than a nine-account ring.

Cluster IDSizeConfidenceSignal
C000529CERTAINExplore →
C000518CERTAINExplore →
C000016CERTAINExplore →
C000535CERTAINExplore →
C000735CERTAINExplore →
C000544CERTAINExplore →
C000624CERTAINExplore →
C000714CERTAINExplore →