Sportsbook Bonus Abuse, Account Theft, Suspected Money Laundering Amount to ‘World Cup of Fraud’, per SEON Report

The 2026 World Cup was ripe for fraudsters looking to take advantage of dormant sports betting accounts and retention bonuses offered by sportsbooks, the report finds.

Sportsbook Bonus Abuse, Account Theft, Suspected Money Laundering Amount to ‘World Cup of Fraud’, per SEON Report
image by Philipp Salveter (Shutterstock)

The 104-match, 48-team, five-week, three-host country tournament that concluded with Spain as global soccer champions in July was, George Pace declares, the World Cup of fraud.

According to a report released this week by global fraud prevention platform SEON, where Pace serves as the lead product marketing manager for betting and gaming, untoward activity including potential money laundering, the theft of accounts and manipulation of bonuses and promotions – not an illegal activity, but one sportsbooks monitor in hopes of quashing – mushroomed in the environment of a massive tournament that rapt billions of soccer fans around the world. The results bear potential lessons domestically as the core driver of legal (and otherwise) sports betting in the United States – the National Football League – commences regular season games on Sept. 9

“The World Cup, obviously it’s every four years, and this is the World Cup of soccer and football, but it’s also the World Cup for fraud,” Pace told Gambling Insider. “You’re going to see the biggest promotions. You’re going to see the biggest incentives, and there’s so many different games, and the fraudsters are looking at this, and they’re getting hungry because they know this is going to be a big opportunity for them.”

The full report, which studied the world’s gambling economies as regions and lumped the U.S. with the rest of North America, found that operators appear to have taken a Trojan Horse approach before the World Cup, welcoming back oddly dormant accounts in the hopes of rooting out potential malfeasance. The tradeoff: not alienating customers who tune in only for major events and might otherwise bolt for competitors.

More Incidents Come Football Season?

Cyber security expert Matthew Wein, who publishes the Secure Stakes newsletter, said that while the report may signal progress, “the cat and mouse game continues between fraudsters and defenders.”

“AI will speed up the tempo of attacks and will let attackers scale their attacks across more and more potential victims without much additional cost or effort,” Wein told Gambling Insider. 

“As the report points out, operators relaxed their checks at certain points to reduce friction and increase app adoption. If this happens again for, say, the start of college or pro football season to accommodate business objectives, it may lead to more incidents down the line.  

“There is a cyber hygiene component that I think should be connected to responsible gaming efforts. Users should be aware of risks connected to dormant accounts that may still have their credit card or banking information attached. They should be aware of the risks of re-used passwords.  They should understand what information they are sharing with operators when they sign up and how to best protect that data.”

Inside SEON’s World Cup Fraud Analysis

The company’s key findings, using its AI-powered, proprietary platform, whose results are offered through subscriptions to gambling vendors:

  • Dormant accounts, “acquired, stolen or curated,” were a preferred entry point, with 83% more activity reported from accounts that had passed verification checks well before the World Cup.
  • While blocked fraudulent withdrawals averaged $202 before the event, they rose to an average of $436 of during it, as, SEON claims, “attackers concentrated on fewer high-value attempts.” Fraudsters made these attempts soon after their ill-gotten login-ins went active on new devices.
  • Concentrating on match-day traffic spikes, a 115% increase in stolen-credential logins was detected in Europe.

Inside SEON and the Global Fraud-Prevention Industry

Founded in 2017, SEON sells anti-fraud and anti-money-laundering solutions to more than 5,000 customers in fintech, payments, retail, crypto, and betting and gaming, using ID verification, AI, device intelligence, and digital footprint data. SEON lists dozens of gaming companies as clients, including Flutter.

Gambling Insider spoke at length with Pace about the state of gambling industry fraud.

GI: What do you define as fraud?
Pace
: Largely, we’re talking about bonus abuse, whether or not that’s welcome bonus abuse, which is taking those claims, ‘Hey, sign up, you put in $5 and we’ll give you $150.’ Those are those acquisition bonuses.

There’s also retention bonuses that really encourage people to come back or reactivate their accounts or reward average players. There could be fraud through synthetic IDs. There’s first-party and third-party fraud, which could be by the player, the actual owner of the credit card, or it could be issued after an account was stolen.

There’s multi-accounting, another big tactic that fraudsters would use to harvest these bonuses. 

Money laundering is obviously a big one. Stolen cards.

So, you name it, we’re looking at all of these different accounts, largely around transactions, account integrity, and bonus protection. 

GI: So the victims can be a person or a sportsbook?
Pace: It’s actually both. We work with the operators and platform providers, and they will have these bonuses they think they’re giving genuine players.

This is their growth strategy. However, the more generous you tend to be with your bonuses, you create a bigger surface area for frauds. And it really tends to amplify the problems.

Now, you talk about the customer side. If I’m just an average player, I’m just trying to bet on a game here and there. If my account gets stolen, I’ve now lost this money. 

Then the operator not only has to deal with the charge back, but they also have to make the player or customer whole. So, they end up losing. They get hit on both ends. 

So the operators are in jeopardy. It hurts their overall profitability and their ability to be more generous with these bonuses. 

Then your average day folks that are just betting, these are just average people trying to make the game more interesting or trying to bet and play and have some fun. They end up losing a lot of money, potentially getting their card stolen, their identity infringed on, and I think it’s a big violation for them as well.

GI: What does SEON gather to make these assertions?
Pace:
What’s great about SEON is we have the most proprietary data points.

From onboarding through pretty much every stage of the journey, what makes it really unique is that we look at all of these digital and social signals together. I believe we’re around 1,100 different proprietary signals that can really assess if this is a real email and if it’s coming from a real device.

Does the person who owns this device are where they say they are? Has this device changed? Have we seen withdrawal patterns or login patterns that look anomalous?

Have we seen this device before? Have we seen this IP [address] before?

There’s a lot of these different factors that the operators can use to kind of triage and triangulate if you are who you say you are.

GI: How does it do this?
Pace: I think there’s a few different factors for privacy. When we consider this entire report, obviously this is proprietary data for these operators.

We can look into when you register or whenever you interact with one of our sites, we can use our device intelligence to kind of get a sense. It’s basically a very deep digital footprint that allows us to understand the specifics of a device. Obviously, I think there’s a lot of data that we can get.

It’s actually very surprising. We can see your battery level. We can see if your phone is sitting upright. What’s your screen size? There’s so many different factors that go into it.

Then you layer in the biometric angle, figure out typing speed, mouse movement, and other patterns if they’re within a range of human mobility. 

Then we look at your email, your phone, your IP, and assess your digital history, which I think is one of the most unique elements, because that’s something that really can’t be faked.

Generally, when I think about it being data breaches, I check myself on our site, and I’ve been involved in, I think, 30 different data breaches. And generally, that’s really bad. But from a broad perspective, it’s actually good. It shows this is a real person’s address, and it’s actually been used. 

From a data side, going back to your question, we follow all the top processes to make sure that this data stays within the company that it works with. We follow all of the best-in-class certifications to make sure that we ensure privacy for all [personally identifiable information] or whatever data that we collect.

GI: How can you act on detecting when someone has been a victim of fraud?
Pace: If you were going to go back, you’d be able to show a full log of what was contained within that system. So, for example, if I could see a whole audit trail, it’s almost like a permanent report card. It’s like you see the account that was created from login.

You could see the IP, the device, and it could say, ‘All right, this is George’s phone. He’s got his home address, and he logged in, and this is where he logs in to play.’ But then there would be a … think of it as almost like a call log.

Like, if you’re looking at your phone, there would be a new login coming from a new device that would get flagged. It would be flagged from a new IP. Maybe it would be flagged that there were a few password attempts where they guessed wrong on a few password attempts.

Then it triggered a [two-factor authentication]. Then after that, they maybe stole my email. We’re able to get in.

Then that would be logged and say, ‘Hey, this is a login from a different device from a different location.’

We can check for impossible travel. I’m in Austin, Texas. Maybe somebody tries to log in in California a few hours later. They would obviously flag [that]. 

Our rules, they’re fully bespoke. We have 200 preset rules for each of the verticals that we sell to, and from there, we work with our customers and our audit funding process to really personalize them in full no-code editors, so you can build whatever rules you want.

GI: What’s the value in a big event like the World Cup as a hunting ground of fraud?
Pace: We did a survey at the beginning of the year where we went out to, I think it was about 340 different betting and gaming operators across the globe, and we said, ‘Hey, what do you guys think is going to happen in ‘26?’ We knew the World Cup was going to be here, and we got their perspective.

This report, this benchmarking report, really takes what they said and kind of matches it up to what actually happened. So when they talk about their defenses, where are they thinking? Where are they building their defenses?

Well, were those actually vulnerabilities? Were they fortified? From this data, we’re able to look at top operators across the globe and see where they got hit.

I think what’s really great, too, it’s good to call out [that this report] isn’t how much [sportsbooks] lost. This is actually fraud that was blocked.

It’s kind of like that bank robber analogy, where the bank robbers put on the clothes of the hostages and walk out the front door. That’s kind of what they want to do. They use these big events to disguise and camouflage their activity.

So when you have a tool that’s not connected to the other ones – it takes [business intelligence] a week to stitch everything together – you’re going to be completely reactive. But with SEON, we stitch together every stage of the customer journey in one view. We talked about that account change logged in from a new device in California.

That immediately gets flagged. That means the person that’s managing your AML [anti money laundering] has all of the data that your KYC [know your customer] person has. That has all of the same data that your fraud team has.

GI: How well did the sportsbooks do in protecting themselves and customers?
Pace: From early feedback that we’ve been hearing, they are all saying that this has been an incredible event for them, massive, massive wins on their side. I mean, as everyone knows, the betting has been up, so much activity.

I think what they’re doing now is trying to do that post-mortem to understand, ‘OK, I won a lot, but, how much of this did we get to keep at the end of the day? How bad did we get hit?’

So they know it’s good, but they’re doing this analysis post-mortem to really try to contextualize the full ROI. How did the fraudsters do? I think they did also very well at the end of the day.

One of the main tactics that we saw a huge rise in was what we call dormant account abuse. It’s really tied to retention abuse, where we’ve seen a lot of operators have this almost inherent trust where if a player already has an account that’s been dormant maybe 90 days or a half a year, if it comes back, it’s like, ‘Well, we’ve already seen you before, so we don’t need to re-verify.’ 

A lot of times those accounts are sold on the dark web, they’re stolen, they’re inherited, and they get passed that trust, and then that allows them to claim those retention bonus offers, which a lot of times are actually way more lucrative than that one-time welcome bonus. 

The welcome bonus is ‘Hey, there’s $200, thanks for creating the account.’ They take the $200. But a lot of times those retention ones get you for daily logins, and they give these big incentives, and from the operator’s side, their dashboards are all saying, ‘Hey, great, our marketing campaign’s doing great with how many players we got back.’ But then at the end, the P&L says a completely different story.

So from one side, you have a whole team that’s basically thinking, ‘Wow, we’re going to do great, let’s keep doing more of these.’ And the fraudsters are like, ‘Yeah, please keep doing these, because I’m going to keep farming these bonuses.’ 

GI: Is what some of these accounts are doing actually fraud, assuming they weren’t stolen?
Pace: It’s technically not a crime. We call it fraud just because it’s technically a breach of the terms and conditions. If you think of it in a traditional casino sense, it’s like counting cards.

It does become a crime, though, when they start to money-launder and they start to use those accounts to often move the funds to try and obfuscate the path. We find that that also seems to be the case as well. They don’t just use the account.

Unfortunately, these guys are very smart, so they don’t just use one account for one thing. They tend to have multipurpose, and they really extract the maximum value that they can from every tool that they have.

GI: What’s your headline from this report?
Pace: I’ve been very focused on the retention side because I think it’s personally an area that a lot of operators can do a lot more to defend. I think everyone’s always watching the front door. 

Our operators have done a really good job of preventing that welcome bonus abuse. However, when you start to think about the entire scheme in general, this account aging, or taking accounts and playing a long-term game, buying these previously trusted accounts, for me, that was my main theory that I was hoping to validate and be able to see an 83% increase across the global network.

In [Latin America], we saw 118% increase in dormant account activity related to fraudulent transactions. I think one of the other things, too, to call out is massive, massive registration volumes, which obviously weren’t to be expected. However, we saw a 16% decline in block rates.

You might think that’s more fraudsters just getting through. No, not necessarily. I would say that the drop in block rates was largely because, if I’m an operator, I don’t want to block you and then send you to my competitor.

In a way, they’re saying, ‘Hey, I’m willing to maybe let a few fraudsters through, but I’m going to be watching you throughout the entire way.’ So, it’s basically, you’ll have a higher fraud risk rating next to your name. The more you do after that initial incident, they’re basically watching you like a hawk, and then they’ll try to block you right before you take the money out.

It’s that progressive. We call it dynamic friction. The more risky that you get, the more risky your actions are.

You’re basically waiting until you’re 100% sure. Then you block the fraudster at the very end.

Stay updated with GI
Follow Gambling Insider for independent news, analysis and industry expertise.
Brant James
Writer

Brant James has covered the gambling industry for nearly a decade, arriving as a tenured sportswriter just as legal sports betting began to transform the way leagues do business, and the way fans consider the games they love.

Gambling is a business of numbers, but ultimately every story is about people. That’s why he’s looking for the personalities and ambitions behind emerging trends, social issues, or technologies.

An alum of the Tampa Bay Times, ESPN.com, espnW, SI.com, and USA Today, he’s covered motorsports and the NHL beats. He ruined a couple decent pairs of shoes covering the Kentucky Derby and once made a tail-hook landing on an aircraft carrier with Dale Earnhardt Jr.  He rode to the top of Mt. Washington with Travis Pastrana, and John Tortorella yelled at him numerous times. A couple were justified.

Visit Profile

Gambling Insider delivers the latest industry news, in-depth features, and operator reviews that you can trust. Our team combines rigorous editorial standards with decades of specialized expertise to ensure accuracy and fairness. We are committed to delivering clear, impartial, and dependable coverage across the global gambling sector.

More News