JustBrowser
Use Cases13 min read

Why Loyalty and Rewards Programs Detect Multi-Accounting (and the Browser Layer Behind It)

JustBrowser Platform Team·

The email from United MileagePlus arrived on a Tuesday afternoon. "Account Review Required." Nothing else in the subject. The body was three paragraphs of corporate legal language that boiled down to: we've frozen your accounts, plural, because we believe they're connected.

Accounts. Plural.

This wasn't speculation. They'd linked four MileagePlus numbers that were supposed to be completely separate — different emails, different mailing addresses, different credit cards. The confirmation came when all four accounts received the same "Account Review Required" email within the same hour.

Four years of accumulated miles across those accounts. Sign-up bonuses. Shopping portal earnings. Transfer partner points. All frozen because — and here's the part that stings — the device fingerprint was identical. They'd been accessed from the same browser on the same machine. To United, these four "strangers" were obviously the same person.

I'm not going to pretend I don't know why people run multiple loyalty accounts. The sign-up bonuses alone make it tempting. 60,000 miles for a new United card. 80,000 points for Hilton Honors. Stack a few of those across "separate" identities and you're looking at free international flights. The math makes sense. The execution is where it falls apart.

Loyalty program clawbacks are brutal because they're often delayed.

You've successfully created accounts, earned bonuses, maybe even redeemed some points. Everything seems fine for months. Then — often triggered by a redemption that crosses some internal threshold — the fraud review kicks in. And when they find linking evidence, they don't just freeze one account. They freeze everything connected to that device fingerprint.

I've heard from users who lost six-figure point balances across multiple hotel programs. (Not at VDL — this is industry chatter from forums and communities where operators compare notes.) The clawback wasn't immediate. The accounts ran for over a year before a high-value redemption — a week at a Maldives resort on points — triggered manual review. Review found device linking. All accounts frozen within 72 hours.

The detection tech loyalty programs use is nastier than you'd expect. It's not the same as retail e-commerce fraud detection (that's a different problem with different vendors). If you're tracking your own site's analytics during testing, tools like JustAnalytics can help you understand visitor patterns without the fingerprinting overhead. Loyalty programs lean heavily on specialized fraud intelligence services built for account-level abuse detection.

The big name is iovation, now owned by TransUnion. iovation's device reputation network covers hundreds of millions of devices. When you log into a loyalty program using iovation's technology, your device fingerprint gets checked against their global database. If that same fingerprint has accessed other accounts on other loyalty programs — even different programs in different industries — that history follows you. It's cross-program intelligence. The canvas hash that accessed your United account also accessed a Marriott account and a Hilton account? Linked. All three programs now know.

This is different from single-site fingerprinting. It's an industry consortium where fraud signals are shared.

Why The Obvious Fixes Fall Short

The first thing people try when they suspect device linking is browser separation. Chrome for Account A. Firefox for Account B. Safari for Account C. Maybe throw in Edge because why not.

This helps more than incognito mode — different browser engines do produce different fingerprints. But. It's not enough.

Canvas rendering differs between browsers, sure. But screen resolution stays the same. Timezone stays the same. Installed fonts are largely the same (some browser-specific fonts aside). Hardware characteristics — GPU model, CPU core count, memory — all identical across browsers on the same machine. And iovation-style services specifically look for multi-browser patterns on the same device. They've seen this trick before. Many, many times.

VPNs? Please. Loyalty programs flag datacenter and commercial VPN IP ranges automatically. United, Delta, the major hotel programs — they all elevate fraud scores for accounts accessed from known VPN exit nodes. You're not hiding. You're signaling "I'm trying to hide." That's worse.

Incognito mode clears cookies. It does nothing else. Your canvas fingerprint is identical in incognito. WebGL renderer string? Same. AudioContext? Same. The fingerprint that links your accounts doesn't live in cookies. It lives in how your hardware renders specific browser API outputs.

Virtual machines help more than browsers because you can configure different virtual hardware. But VMs have their own detection vectors. VMware and VirtualBox expose identifiable artifacts that fingerprinting scripts check for. Running a loyalty account from a detected VM often elevates fraud scores — it looks like you're hiding something, which you are.

Here's the core problem: loyalty programs use composite device reputation, not single-signal detection. They're cross-referencing device fingerprint + IP history + payment method patterns + redemption address clustering + behavioral velocity. Defeating one vector while leaving others exposed just means they catch you through a different signal.

The Detection Stack: What Loyalty Programs Actually Use

Let me walk through what modern loyalty program fraud detection looks like. This isn't speculation — it's based on public documentation from the vendors these programs use.

iovation (TransUnion) maintains a device reputation network covering 6+ billion device profiles as of their 2025 public disclosures. When you access a loyalty program running iovation, your device gets scored against historical behavior — not just on that program, but across their entire network. A device that's accessed 10 different loyalty programs in 90 days looks very different from a device that's accessed one. That pattern gets flagged.

iovation's "device print" combines browser fingerprinting (canvas, WebGL, fonts, plugins, screen) with deeper signals: installed applications on desktop, TCP/IP stack characteristics, and behavioral biometrics. They publish case studies about catching multi-accounters where individual fingerprint vectors were spoofed but behavioral patterns weren't. The combination of signals is what makes their detection hard to defeat. Annoying? Yes. But it works.

Sift is another major player in loyalty program fraud. Their "Digital Trust & Safety" platform processes over 70 billion events annually (their 2024 stats). Sift builds device graphs — if Device A transfers points to Email X, and Device B also transfers points to Email X, those devices get linked even if their fingerprints are completely different. It's graph analysis, not just fingerprinting.

FingerprintJS Pro (the commercial version, not the open-source demo) is used by some loyalty programs for browser-level identification. Their public accuracy claims are 99.5% visitor identification. Even when cookies are cleared. Even in private browsing. Even with VPNs. The commercial version includes signals the open-source version doesn't: TLS fingerprint analysis, HTTP/2 settings, and more. We've covered TLS fingerprinting as its own detection vector.

Behavioral biometrics are showing up more often now. How you type. How you move your mouse. The rhythm of your scrolling. Nudata (owned by Mastercard) and BioCatch build behavioral profiles that persist across sessions. Two accounts might have different device fingerprints, but if the human operating them types at the same cadence with the same typo patterns, that's a linking signal. I find this one creepy, honestly.

Payment method intelligence. When you add a credit card to a loyalty account, that card's hash gets stored. Add the same card to a different account — even a different program if they share payment intelligence — and you've created a link. Some programs go further: they check card BINs, issuing banks, billing address patterns. Three accounts all using Amex cards from the same small credit union in suburban Ohio? Suspicious.

Redemption graph analysis. Points get redeemed to something: flights, hotels, gift cards, merchandise. Multiple accounts all redeeming to the same physical address, same email domain, or same household create linking evidence. Programs delay enforcement specifically to build redemption pattern data before acting.

The cascade is brutal when it happens. You might operate for a year without issues. Then one redemption — maybe a business class flight on transferred points — triggers manual review. Manual review pulls device intelligence. Device intelligence shows fingerprint overlap with three other accounts. All four accounts freeze within hours.

That's the part that gets me: you think you're winning right up until you're not.

What Actually Works: Isolation Architecture

Real separation from iovation-style detection requires multiple isolation layers working together. I'm going to be direct about what this takes.

Layer 1: Real fingerprint isolation. Each account needs a browser profile with completely different device characteristics. Different canvas rendering. Different WebGL output. Different font list. Different AudioContext values. And — this is critical — these values need to be internally consistent. Your spoofed GPU string should match your spoofed WebGL renderer should match your canvas rendering characteristics. Random values from different device populations get flagged as tampering.

This is what antidetect browsers do at the engine level. JustBrowser uses a modified Chromium build with native C++ patches. The fingerprint values aren't spoofed by an extension (which detection scripts check for). They're generated by the browser engine itself, producing outputs that match real-world device populations. The detection testing workflow shows how to verify this works before you trust it with real accounts.

Layer 2: Network isolation. Each account needs its own IP address. Residential, not datacenter. Geo-consistent with the account's claimed location. If your Marriott account claims a billing address in Phoenix, accessing it from a German datacenter IP is an obvious red flag.

Residential proxies run $3-8 per IP per month for quality providers. One IP per account, sticky sessions (not rotating). The IP should never be shared across loyalty accounts. Even residential IPs get clustered by iovation when multiple accounts hit them within a short window.

Layer 3: Payment isolation. Each account needs its own payment method that can't be linked to the others. This is harder than it sounds. Virtual cards from services like VeloCards help because each card has a distinct number and isn't tied to your personal card on file — managing multiple card identities is covered in their virtual card management guide. But some loyalty programs check the underlying funding source for virtual cards — and if your VeloCards are all funded from the same bank account, that's a linking vector at the funding layer.

Physical prepaid cards work but are operationally painful. Cash-loaded at different retailers, used for different accounts. Exhausting. The operational overhead is why most multi-accounters eventually get lazy and reuse payment methods. That's when they get caught.

Layer 4: Behavioral separation. This is the hardest layer because it requires ongoing discipline. Each account should have different login times, different redemption patterns, different browsing behavior. Accounts that all log in at 9 AM Pacific, all browse the same flight routes, all redeem points within the same week — those patterns cluster even when fingerprints are isolated.

The operators who survive long-term (again, from industry forum chatter, not our customers) treat each account as a separate persona with distinct habits. It's exhausting. But it's what iovation's behavioral analysis looks for.

The Cost-Benefit Reality

Here's where I'm supposed to tell you JustBrowser solves everything and you should sign up today.

But I'd rather be honest: multi-accounting on loyalty programs is a cat-and-mouse game where the programs hold most of the cards. They have cross-industry intelligence sharing. They have years of historical device data. They have the ability to delay enforcement until redemption, maximizing your sunk cost before they clawback.

Look, I've watched people way smarter than me get burned on this.

The isolation stack I described above — proper antidetect browser, residential proxies per account, separate payment methods, behavioral discipline — costs money to maintain and time to operate. You're looking at $50-100/month in infrastructure for a handful of accounts, plus the hours spent maintaining operational security.

For casual points collectors thinking about running two or three extra accounts for sign-up bonuses? The juice probably isn't worth the squeeze. You'll spend more on infrastructure than you'll earn in points, and you'll still get caught eventually because operational discipline slips.

For operators running this at scale as an actual business — which is who I assume is still reading at this point — the calculation is different. Scale economics change the math. But you already know that.

The actual use cases for this detection knowledge? Understanding how your own loyalty program detects abuse (if you're building one). Security research into device fingerprinting. QA testing for loyalty platform developers. For teams building fraud detection systems, ClickzProtect covers the ad-side of click fraud detection. Those are real. We built JustBrowser for operators and engineers who need browser-level identity control for real purposes. Multi-accounting on loyalty programs... falls into a greyer zone.

I'm not here to moralize. I'm explaining how detection works. What you do with that knowledge is your business.

Frequently Asked Questions

How do loyalty programs detect that multiple accounts belong to the same person?

Loyalty programs use device fingerprinting services like iovation (TransUnion), FingerprintJS, and Sift that generate unique device IDs from 40+ browser parameters. When two accounts share the same canvas hash, WebGL signature, font list, and AudioContext output, they get flagged as linked. Programs also cross-reference payment methods, redemption addresses, and IP patterns to build confidence scores before taking action.

Can I use VPNs or incognito mode to avoid loyalty program detection?

No. VPNs only change your IP address, and incognito mode only clears cookies — neither affects device fingerprinting. Loyalty programs specifically flag VPN and datacenter IPs as higher-risk signals. The fingerprint comes from hardware and rendering characteristics that persist across sessions, browsers, and privacy modes. You need a browser that generates genuinely different fingerprint values per profile.

Programs can freeze accounts pending review, claw back points already credited, void pending redemptions, ban all linked accounts simultaneously, and in severe cases report to shared fraud databases that other loyalty programs access. Some programs like airlines have redeposited miles, then banned the accounts months later when they detected the linking pattern. The consequences are often delayed and cumulative.

Is running multiple loyalty program accounts illegal?

Not criminally in most jurisdictions — it's a Terms of Service violation, not fraud in the legal sense. But programs treat it as abuse and can void points, ban accounts, and refuse redemptions without refund. The economic consequences can be significant if you've accumulated substantial points across linked accounts. Some programs also share abuse data with industry consortiums.


Try JustBrowser

Native Chromium antidetect browser — not extension-based. Real C++ engine patches at the canvas / WebGL / font / TLS layer, so 40+ identity parameters are real, not faked. REST API for Playwright, Puppeteer, Selenium. Free tier: 5 profiles. Pro $9.99/mo: unlimited.

Get started → · How it differs from Multilogin / GoLogin / AdsPower

Ready to manage multiple accounts?

Seven days free, then $9.99/month — one plan, everything included.

We'd like to use Google Analytics, a Google service, to understand how our website is used. It sets two cookies in your browser and runs only if you click Accept. You can change your choice at any time with Cookie settings. Cookie Policy

Sign-in cookies and the cookie that remembers this choice are always on; the website needs them to work.

Google Analytics, a Google service, helps us understand how our website is used. It sets two cookies, _ga and _ga_TVZHQ99TZW. It is now onoff in this browser. If your browser sends a Global Privacy Control or Do Not Track signal, it stays off. Cookie Policy