Blog
How to catch a farmed account: 3 ...

How to catch a farmed account: 3 detection typologies, and why true professionals leave few signals behind

We’ve talked plenty about verified account buying and account farmers. Now, it’s time to look at how to catch them.
Published 31 Aug 2026Updated 31 Aug 2026
Resistant AI Logo
Table of contents
Subscribe to our newsletter

The most dangerous account farmers are the ones you'll never notice.

A year of buying accounts and tracking these sellers has taught us how an account be farmed, and more importantly, how it can be detected.

And the level of sophistication of the account farmer very much matters. Both for understanding how much of an overall threat a specific vendor is, but just as much for knowing where exactly the dividing line between amateurs and pros really rests.

When it comes to scale, this dividing line is not straightforward. Account farmers of various sophistication levels can create numerous fraudulent yet verified accounts and cover multiple platforms. Sizable volume and activity are not reserved only for organized farming groups.

Knowing what type of an account farmer you’re dealing with tells you what to look for on the detection side of things. While document authenticity analysis is the obvious start, you also need to know which data points or behaviors can hint at the account being a product of a farming operation.

Let’s dig into the different account farmer archetypes and how to prevent them from allowing criminals to access your platform.

General considerations

When assessing our experience with account farmers, there are three main areas we focus on:

  • Account package assets. Documents, liveness, credentials.

     

  • Operational security. Infrastructure, handover, behavior.

  • Sales motion. Advertising, deal processing, coverage, division of labor.

These areas are the three points in the account farming lifecycle where a farmer can and usually does leave a trace: assembling the goods, hiding the work, and running the sale.

Each archetype differs. An account farmer can be advanced from one perspective and amateur from another, and that mismatch is itself a detection signal.

And while we obviously haven't seen every account farmer variation, we've bought and dissected enough accounts to know which parts of the KYC and selling process might give a farmed account away.

The Hustler: Scale without opsec

We start at the most detectable level of an account farmer, one that we have labelled as the Hustler. We were able to see inside one account farm of this type without directly buying from them, which partially symbolizes the low level of sophistication.

Our initial touchpoint was UI screenshots of logged-in accounts that the farmer would post into Telegram channels to advertise their services. These screenshots were not anonymized and showed the account holder name, giving us a clear starting point, as they were onboarded on a platform we were already working with.

With help from the platform, we were then able to look at these accounts' behavior and details from the inside, quickly revealing that this account farmer was never too worried about getting caught. 

Because looking at just one account and its onboarding, device and behavioral characteristics, we were quickly able to identify a cluster of tens of accounts sharing the same data points and being created with the same MO.

TI_ARTICLE_Account_Farming_Typologies_Hustler_Detection_Cluster

All of the clustered accounts were business accounts, started using a legally registered shell company with a company director or a PSC (person with significant control aka the company owner) from a high-risk jurisdiction.

The identities behind the shell companies seemed real, both at the document level and the context one, as conducting some OSINT research on the identities involved pointed to social profiles behind some of these persons and indicating real-life activity.

Non-ID documents used during onboarding hinted at the use of online templates from template farmers or harvesting these from publicly available template hubs.

As these were business accounts, an important part of the business legend was also these accounts providing links to marketplace/merchant seller profiles that were, however, dysfunctional or non-existing.

And, to top it all off, numerous accounts from the cluster shared a very similar transactional pattern. Short timeframe, equal amounts of money in and money out, often receiving a sum and redistributing it among several other accounts. Classic money laundering potential.

Now, why do we view this kind of operation as one with a low amount of sophistication?

After all, this farmer might have created hundreds of both personal and business accounts, and clearly has created a process to get accounts verified repeatedly.

But the fact that you can commit a crime numerous times does not make you a pro. On the contrary, if you do something repeatedly but do not cover your tracks properly, sooner or later you will be detected, provided the platform has the right defenses in place.

This is what we mean by using The Hustler name here. Pure focus on getting accounts created and sold, but no palpable consideration for proper operational security or secure advertising.

We never had to buy a thing. His own advertising, and his own repeated patterns, handed us the entire cluster.

The Soloist: Sloppy at handover

The term “Soloist” as an amalgam of the words "solo" and "specialist" implies this type of account farmer knows what they’re doing. But it also specifies this is a one-man operation that has its limitations.

If the Hustler never has to meet you, and gives his product away through his own careless advertising, the Soloist is the opposite: the entire transaction runs through one person, in real time, and that is exactly where he leaks signals for detection as well.

The Soloist is also the archetype we have interacted with most during our initial account purchases when we needed to test the market and purchase a business account for a payment platform.

At the very beginning, the conversation moved quickly. The account farmer quickly informed us he has the account we were looking for available, and that we can process the purchase through direct distribution and the 50/50 approach (half the money now, half after).

Once the conditions were agreed and the first part of the funds transferred, the deal started moving. But this is where the Soloist’s workflow revealed data points useful for detection.

For starters, the farmer instructed us to have our own phone number ready so that he could switch within the account setup to direct the new one-time login passwords to us.

The phone number change is a tracked action for the account, and something that can be flagged as unusual or suspicious, especially if the change includes phone numbers from vastly different jurisdictions.

The same goes for email addresses, which we were also instructed to update after the farmer sent us the logins. Different infrastructure, same partial sloppiness that can trigger detection because regular users don’t change credentials often, especially without any significant history of using the accounts.

Regarding the device to access the account itself, the Soloist gave us no instructions on IPs, proxies or a dedicated device, all information included in packages we have purchased elsewhere (more on that later). Though we could not confirm, lack of further instruction suggests mistakes will be made and shared infra characteristics will be detected with proper analysis.

The emblematic aspect of this operation is the one-man setup, and we experienced it first hand when waiting for the account handover. Inquiring us to trust him (and even sending us an alleged picture of himself on a moped somewhere in Pakistan), we were forced to wait for the farmer to get home to process the deal. Such activity can’t be scaled and suggests an independent operator making a decent living on account fraud, albeit in a moderate volume.

TI_ARTICLE_Account_Farming_Typologies_The_Soloist_Telegram_Conversation_Redacted

Moped-aside, we ultimately logged into the account, implying a successful deal. The final remaining component to hand over were the documents themselves.

And this is where things got tricky. The account farmer provided us with several assets, specifically:

  • ID document (front and back)
  • Certificate of good standing for a U.S. entity
  • IRS-issued EIN letter

Each of these assets had serious flaws. The ID was a very low quality image that shouldn’t pass anywhere. The certificate of good standing and the EIN letter were clearly tampered with, likely leveraging online templates.

Checking the account from the inside showed that the ID documents the account farmer gave us might have shown the same personal details, but an entirely different person from the account’s holder selfie uploaded during onboarding. The farmer might have done this on purpose to keep his quality identity assets for himself, thinking that we would not discover the mismatch. 

On top of that, the company documents pointed to an LLC company incorporated in Wyoming, but when we checked the official business registries of the state, the LLC wasn’t there. This was truly a hardly usable document package of low quality and false information which was not the one used for the onboarding of the account itself in the first place.

While the account farmer’s intention is unknown, his negligence and subpar evidence package become a very discoverable fake account and, even if he passed onboarding initially, the legend won’t hold for long. In other words, the Soloist probably has a lot of dissatisfied customers. 

And where the Hustler is undone by lazy advertising and the repeated patterns and shared account characteristics that make his operation clusterable, the Soloist is undone by the deal itself. His lack of opsec and those tracked credential changes mean we could eventually cluster him too, by focusing on those handover actions across an account's lifecycle. The difference is cost: with the Hustler, the cluster is there for the taking. With the Soloist, we'd have to buy from him again and again to assemble it.

Lastly, the Soloist excels at reaching out. After our first purchase with such an account farmer, we were being consistently cold-texted about further purchases.

And whenever we asked about another account for a specific platform or jurisdiction, the farmer always promised to deliver, just to keep us on the hook. More often than not, the deal went nowhere. He couldn't actually source the account, though he'd still tell us to reach out if we needed anything else.

From what we’ve experienced, successful and professional account farmers don’t need to cold call as much. They wait for the demand to come to them, which changes the perspective both for account creation turnaround time and the amount of signals left behind for detection. Because the pros have this figured out in bulk.

The Franchise Farmer: Thousands of accounts, on-demand

This one is the real deal.

We’ve seen franchise farmers numerous times within several of the marketplace channels we’re monitoring. And we decided to reach out, once again, to purchase a business account on a financial platform.

From the get-go, this kind of a seller showed off a structured approach. Right after our initial query, the account farmer sent us a link to a sole proprietorship record in the french business register, commenting that:

  • Documents will be similar, but yours, not these (i.e. our own account will be tied to a similar sole proprietorship entity with similar documents)
  • Phone number and email provided
  • All data for the accounts + documents on both sides and a selfie with the (ID) document will be provided
  • France-based account tied to sole proprietorship registered with a Spanish identity

This is clearly a pre-written, structured description of what the account package will contain. The first traces of an existing selling/distribution motion and system.

Next up, the deal processing. The farmer suggested to process the deal through a third-party escrow service widely known in the criminal ecosystem simply as “Gross.” This escrow platform doesn’t allow for negotiations or direct transfers, keeping to a much higher standard of control (and trust), and ensuring that you can get your money back in case the deal was not satisfactory. Even fraudsters prefer to avoid being scammed.

Once the deal was created and confirmed within the escrow service, we moved right into one of the most representative signs of a professional operation: technical support and clearly defined roles. The “customer care” account we agreed to the deal with referred us to a different account for handling the setup and the handover.

Instantly, we got a message from the tech support account with the entire package info:

  • Account-tied, fresh email credentials
  • Reserve email credentials (created with dedicated mail service such as firstmail.ltd)
  • SIM bot service to receive passwords
  • Account login credentials
  • Proxy & IP details
  • Device emulator credentials & provider details
  • Link to documents storage
  • Link to register of the company/proprietorship the account was registered for
  • Instructions on behavior, including stuff like ”don’t keep money on accounts for longer periods of time” and ”cash-in-cash-out, preferably at night“

TI_ARTICLE_Account_Farming_Typologies_Franchise_Farmer_Package_Redacted

One more thing that caught our attention in the package description: the order numbering.

While this could obviously be made up, having purchased numerous accounts with this vendor, we have seen order IDs ranging from the 4000s to the 9000s in the span of several months.

If true, this is a vendor that has created and sold thousands of accounts across platforms in maybe less than a year of operation. Considering the price of an account could be around 300$ on average, such an account farmer could have already made millions of dollars. More than enough to keep the operation running, developing and growing.

And it didn’t end with the package details. Having not done this before, we were walked through the technical setup by the support persona. From suggesting an anti-detect browser to setting up the proxy and logging into both the dedicated virtual device and the bought account.

The cherry on top? The farmer confirmed that we would retain absolute control of the account, explaining that the real persona does not have access, but is still available for a premium payment in case of a liveness check. In short, a ready-to-be-activated liveness mule.

With this kind of a farmer, possible detection signals are scarce. The documents used were real, the opsec kept device and network datapoints were local and without change. And, as these accounts were created fresh and on-demand, there’s no activity to analyze in the early stage of the account lifecycle.

This is a level of professionalism account farmers can get to, and based on the order numbering indication, these are the ones who might do the most business (and fast).

Technically speaking, we were a satisfied customer as well. Considering that this farmer is offering accounts for at least 50 different platforms in 6 different jurisdictions, chances are more than high that fraudsters running fraudulent accounts across different platforms keep coming back to this vendor.

After all, the farmer told us himself that “we make many accounts, glad to cooperate,” he didn’t press us on making a future deal leaving the door open for us to come back to him without implying a dire need to extract money or worrying sense of urgency.

Detection typologies

Having gone through the archetypes in detail, several things can be done to detect each of these.

Facing a Hustler? Look at creation-time clustering: shared device/IP across many accounts, public non-anonymized advertising, template documents, structuring patterns. This one can be detected throughout the account lifecycle, and that applies to all accounts sharing some of the same characteristics in a cluster.

Facing a Soloist? Look at the handover: tracked phone/email swaps across jurisdictions, document flaws and registry mismatches. This farmer cares about selling anything right away, doesn’t worry too much about building proper opsec or reputation, and likely doesn’t worry about getting caught.

Facing a Franchise Farmer? The per-account signals are scarce by design, so the leverage moves elsewhere: the marketplace-level intelligence (order numbering, catalog breadth, the escrow-and-support pattern), and detection that watches the account over its life rather than at onboarding. The burden of opsec shifts to the buyer, and that's where the lifecycle signal eventually appears.

For a complete breakdown of the typologies and how to spot them, check out the signal matrix below.

Account Farmer Archetype How they advertise & sell Documents & identity Network & device intelligence Handover & setup

Behavior over time Detected where?
The Hustler Non-anonymized screenshots in Telegram channels Real IDs behind shell companies, non-ID docs forged using online templates Same devices, same IPs across tens of accounts No direct sale needed (you can find his accounts via the screenshots) Cluster-wide structuring, similar transaction patterns All throughout the lifecycle

The Soloist Direct messaging & negotiation, over-promises, cold-calling, flaky delivery Low-quality IDs, forged non-ID docs, phantom LLC used absent from registry No IP/proxy/device guidance Phone + email swap after login (tracked actions that can trigger flagging) Legend short-lived, patterns can emerge across account package setup Mainly at handover
The Franchise Farmer Multi-channel presence, wide offering, pre-written package specification Real documents, real person and real business entity without access, selfie with ID supplied, mule for liveness for a premium Anti-detect browser, purchased proxy, device emulator, consistent per account Roles split (customer care, tech support), full infra bundle + behavioral instructions Fresh, on-demand accounts → little history at first; the instructed pattern only shows across the lifecycle Tough to stop at handover, detectable via behavioral patterns later in the lifecycle

Regardless of the archetype, advanced defenses should pay ample attention during the entire lifecycle. This entails proactive threat research, document authenticity and liveness controls, transaction monitoring, and network, device, and behavioral analysis.

The next signal frontier

We realize these account farmer archetypes are uneven. Overlaps happen, and there’s a lot of variety, but these are the scenarios we experienced most frequently.

While document authenticity and device and network intelligence is where you start, it is not where you finish. If the account farmers operate with few signals for detection, we need to move beyond obvious signals and derive new ones from specific modus operandi markers.

Resistant Documents helps you on this front by understanding not only where a document was altered, but also highlights what software or online document generator or editing tool has been used to do so.

With respect to the account lifecycle itself, Resistant Transactions detects suspicious account behaviour, specialising in muling and perpetrator detection. The analysis includes both transactional and non-transactional behaviors, with bespoke data schemata, allowing you to map even the tiniest signals during advanced account handovers.

Because if we can find out what tools for the so-called passing KYC the farmers are using, we’re one step closer to derive new signals and catch them.

But more on that next time.

Enjoyed this content? Sign up for our "Threat Radar" newsletter using the form on your left!

Blog post author
Jan Indra Threat Intelligence Investigator Jan Indra is a former investigative journalist and financial crime analyst who leads the Threat Intelligence unit. He specializes in discovering fraud rings and analyzing their activities, and is responsible for all of Resistant AI’s investigations.