Harm:

Account Resale

Definition: Selling stolen account credentials to enable users to assume new identities.
Motivation:
Financial
Legal Status:
Rarely criminalized
Platform ToS:
Violates Policy
Victim Visibility:
Unaware
Classification:
Contextually Sensitive
TSPA Abuse Type:
None

The problem of account describes the unauthorized buying and selling of user accounts. It encompasses users who intentionally decide to sell their account, as wall as users whose accounts have been hijacked. Account resale only occurs on platforms where the progress or status tied to the identity of the user is valuable:

  • In games, progress, achievements, or valuable virtual items can be obtained through account purchasing via real world currency
  • In email providers, older accounts are often more highly trusted by spam-filters, and are often purchased by spammers to facilitate spam.
  • In social media, accounts with lots of followers are often bought and sold.
  • In e-commerce, seller accounts with large number of good ratings are valuable to new entrants.
  • In online finance, selling an account (even with no assets tied to it) can be a powerful tool to aid the perpetration of money laundering.

As a form of identity fraud, unauthorized sale of accounts undermines the integrity of trust, poses security risks, and cuts against the ethos of fairness in online spaces.

What features facilitate Account Resale?

Identity
Individuals' ability to represent themselves in a digital space.

How can platform design prevent Account Resale?

Limit account volume
Reducing the volume of accounts a person can create restricts their capacity to cause harm at scale.
Two-Factor Authentication
Authenticating users through two types of credentials (something you have, something you know, something you are).
Is something missing, or could it be better?
Loading...