
Rupt research · 2026
Product misuse
Why people use your product for purposes it is not meant for, and how to stop them
Products are built to enable people to do things. Humans being humans, some of them find ways to use these products for different and often harmful purposes. This paper is our take on the problem, why now is an important time to solve it, and how we do it at Rupt.
It draws on published research and on anonymized cases from the platforms Rupt protects. Figures marked Rupt data come from our own investigations.
Rupt research
Product misuse
Why people use your product for purposes it is not meant for, and how to stop them
September 2026
Key findings
Fraud and abuse aren't a collection of unrelated problems. They are one problem, product misuse: anyone using your product for a purpose it was not built for. One kind of misuse is often a prelude to the next.
People misuse products for one of two motives. Some are maximizing their own gains. Others knowingly set out to hurt or steal from someone.
There are two ways to respond: take away the reward, or take away the method. What the misuse costs you decides which one.
AI changed the game. One person with an AI assistant can now do what used to take a trained team, and today's agents look human to traditional checks.
Defense is a balance between keeping bad actors out and leaving good users alone. It takes people, time and technology, and it never ends.
Point-in-time checks are easy to bypass, and a patchwork of vendors is costly and never adds up to a unified view.
Misuse left unchecked can kill a company, but a defense that costs more than the problem won't last either.
The answer is a holistic system: one view of the user and their behavior, friction applied only where it's needed, and a price that makes sense. Measure it by the before and after, the risk you mitigated, and how good users were affected.
Part I
What is fraud and abuse, really?
01
The problem is product misuse
Fraud and abuse are catch-all terms. The real problem, as we see it, is using a product for a purpose it was not meant for.
1212
accounts made by hand to test the defenses, 12 days before 120,000 fake signups1
Rupt looks at fraud and abuse not as a collection of unrelated problems in the product, such as fake signups, bots and account sharing. What we've seen from working with dozens of companies and millions of users is that the core problem is a single one: product misuse.
We've rarely seen a product with only one type of abuse. Fake signups are often followed by bad behavior like spam, scraping or card testing1. Even when the misuse is a single type, it is often a prelude to other types of misuse2, or just the bad actors testing what they can get away with in the product.
In one case we tracked, the bad actors started testing the waters with a few fake signups and a few card tests, then really unleashed the attack with over 120,000 fake signups in three months. When the product plugged a hole, they moved on to another one1.
So we define the problem as product misuse: anyone using your product for a purpose it was not built for. Nailing the definition is important because it allows us to build a solution that addresses the root causes of the problem, rather than playing whack-a-mole with the symptoms.
02
Why do people misuse products?
Two broad categories: some people are maximizing their own gain. Others set out to hurt or steal from someone. The distinction helps shape the response.
36%36%
of reported fraud in 2024 was first-party, committed by the account holder8
We distinguish between the motive and the reason behind product misuse. The motive is the short-term goal, and the reason is the underlying philosophical reasoning. We have our own thoughts and research on the philosophical part, but will save them for another report. For most products, understanding the motive is enough to formulate a good response.
We split motives into two main categories. The first motive is maximizing gains: ordinary people squeezing more out of a product than they paid for. Examples include opening multiple accounts to take advantage of free trials and sharing an account to avoid paying for one3. It doesn't hurt when it happens in small numbers, but when it eventually spreads, the leaked revenue3 and the bad data4 can massively hurt a product's economics.
The second motive is malicious: someone who knowingly seeks to hurt or steal from others. We caught a scammer who built a fresh identity every day for five months to phish the brokers on a marketplace5. Others use face-swapping software to pass job interviews and then hand the work to someone else6,7.
Why people knowingly put so much energy and intelligence into hurting others is a fascinating question, and not one this paper tries to answer. We care about the motive for a practical reason: it tells you how to respond. If you want to read more, reach out to us and we can share a recommended reading list.
03
How to respond to product misuse
In its simplest form, the response to misuse is to either take away the reward or take away the method.
There are two ways to deal with someone using your product for the wrong purpose. The first is to take away the reward they seek. If what they want doesn't really hurt you, you don't have to fight them. Take, for example, someone trying to use a demo form as a relay to send spam. If you stop sending confirmations, they have nothing to gain and will eventually give up.
Social platforms have done this for years with shadowbans, where a spammer keeps posting but nobody sees it. Game studios do it too. Riot Games explains why it doesn't ban cheaters the moment it spots them: "this will present an opportunity for the cheat developers to A/B test our detections"9. Cloudflare makes the same point about bots: blocking them "can alert the attacker that you are on to them"10.
The second response is to take away the method. This is as close as you can get to stopping the actor, and it is the right call when their actions carry a real cost: a shared seat that takes revenue, duplicate accounts that ruin data quality, scams against your other users, and so on. The safest way to act here is to put in guards that are designed to stop the misuse, and to keep watching after the gate, because the actor will try again.
Knowing which case you're in dictates what to measure, how hard to push, and how much friction is worth adding.
…we don't immediately ban them, because this will present an opportunity for the cheat developers to A/B test our detections.
04
AI changes the game
What used to take a computer science degree and a trained team can now be done by one person with an AI assistant.
12.5×12.5×
growth in AI-driven bot attacks in 202515
Scams and abuse used to be rare, expensive and easy to spot. They took real technical skill to set up. Even then, the tells were obvious: broken English, clumsy fake profiles, forms filled in at inhuman speed, and so on. Now one person with an AI coding assistant can build what used to take a team. AI makes ideas come easier, execution faster and iteration inevitable.
The FBI warns that generative AI "reduces the time and effort criminals must expend to deceive their targets" and can correct the errors that used to give fraud away12. Microsoft reports that AI "has started to lower the technical bar", so that a fake storefront now takes minutes instead of days or weeks13. In one study, fully AI-written phishing emails were clicked 54% of the time, as often as emails written by human experts14. AI-driven bot attacks grew 12.5 times in 202515.
Bots also stopped looking like bots. AI agents now drive real browsers, move the cursor like a person and pass the checks built to stop scripts. Cloudflare says there is "no meaningful difference" between an AI assistant booking concert tickets and the human who would have done it16. LexisNexis reports that bots now mimic human cursor movement well enough to fool behavioral detection17. Agents still fail most of the hardest interactive CAPTCHAs18, but the gap is closing19, and this is only the beginning of browser automation.
There is no meaningful difference between the AI assistant booking concert tickets and the human who would have done so manually.
The data
Who is on the web
Share of all web traffic, 2025. Good bots are the remainder after bad bots. Each dot is a third of a percent of all traffic.
47%47%
People
13%13%
Good bots
- People
- 47%
- Good bots
- 13%
- Bad bots
- 40%
Source: Thales / Imperva15
05
The defender's dilemma
Keep the bad actors out without hurting the good users, while keeping the economics in your favor, in a game that never ends.
The ultimate balance of defense is this: don't hurt the good users, and keep the bad ones out. In technical terms, precision and recall. Remember, this is a human problem, not a technical one, so you will never solve 100% of it (no one can solve humans). If you push too hard, real customers will see friction. If you push too little, misuse occurs. Getting both right takes people, time and technology. Most companies can't hire, train or adapt fast enough.
The shortage is not new. In 2003 the US government's National Strategy to Secure Cyberspace already warned of "an inability to find sufficient numbers of adequately trained and/or appropriately certified personnel"20. More than twenty years later, the Government Accountability Office still reports that "a shortage of skilled workers" makes the job hard21, and US employers posted 514,359 cybersecurity job listings in a single year22.
Teams also don't want to be doing this. People join a company to build the product and help its users do something useful, not to spend their weeks building protections around it. And once you start, it never ends. Attackers iterate, so defenses have to keep changing too. It is a continuous journey, not a once-and-done project.
Even beyond the shortage of talent, for companies lucky enough to find well-trained people, getting a plethora of commodity vendors just to get the basic protections is a huge endeavor, and it ends up having less impact and more cost23.
Organizations have people. But those people are overwhelmed, under-resourced, and unable to develop the capabilities they need because they're too busy running today's operations.
06
Point-in-time checks and fragmented approaches are not enough
Single unconnected checks in auth and onboarding are now easy to bypass, and building a patchwork of vendors is costly and doesn't provide a unified and complete view.
- United States
- $0.26
- United Kingdom
- $0.10
- Russia
- $0.08
Source: University of Cambridge29
A check in the authentication flow is just one layer, and it used to be enough. But now disposable emails, synthetic identities and more get past the auth gate and then wreak havoc25,26. Deepfakes can be streamed straight into a camera check27, and deepfakes make up one in five biometric fraud attempts28. Fraudsters see those as single-time checks they can easily bypass. A US phone verification can be bought for $0.26, just to name one trick29.
Point-in-time checks can also be passed by a real person on purpose. Account farms pay people to sign up and verify, then sell the accounts. Researchers bought a verified US business bank account for about $350, for a company that did not exist30. Once the account is theirs, the real activity begins.
Behind the point-in-time checks, most companies build a patchwork. Two or three vendors and some in-house code used to be enough. Now security teams run an average of 83 tools from 29 vendors, and more than half say the fragmentation limits their ability to respond31. Among fraud leaders, 80% say getting a unified view of their data is a challenge, and 85% plan to add yet another vendor32.
Adding another vendor means another integration, another translation layer, another separate call, another contract to manage. What you end up with is less a full view of the user, account, action and behavior, and more a Frankenstein's monster of data that nobody evaluates as a whole.
07
The true cost of misuse
Let it run and it can end the company. Fight it the expensive way and it eats the margin.
1 in 41 in 4
job candidate profiles could be fake by 202833
Letting misuse run unchecked can kill a company. If all your data is bad data, if all your leads are fake, if all your job applicants are AI agents, people leave, and that's it. Gartner projects that by 2028, one in four job candidate profiles worldwide could be fake33. And 41% of IT, security, risk and fraud leaders say their company has already hired and onboarded a fraudulent candidate34.
This cost will show up. It's hard to track, but it does. It shows up in support tickets, in data quality, in churn, in the people you hire to review cases, and in the engineering and product time spent building defenses instead of the product. Every $1 of fraud costs US financial institutions $5.7535.
But you can't spend all your revenue on it either. The defenses themselves are expensive. Building fraud prevention in-house costs roughly $743,000 in year one at a million evaluations a month, and assembling point vendors about $332,00023. At that price, many companies decide to live with the abuse.
Any real answer has to make the math work on both sides: less abuse, and a defense that costs less than the problem it solves.
08
A holistic approach
We see the solution as one system forming a unified view of the user and the behavior, protecting continuously, at a price that makes sense.
2M+2M+
malicious accounts found in one month at Facebook and Instagram by grouping accounts that act alike39
The answer is not another gate. It is a system that watches behavior continuously, from signup through every action that matters, and makes the math work in favor of the product and its good users again. Identities are cheap to make and easy to throw away29. But behavior is always the definitive indicator.
Research backs continuity. Browser fingerprints change often, yet can still be linked over time37, and 91% of their attributes stay identical over nearly six months38. Grouping accounts that act alike surfaced more than two million malicious accounts in one month at Facebook and Instagram39. Even forged devices give themselves away as a group: in one ring, a key browser field was empty on every attack device and on 0.3% of real users1.
Building a unified trust system is the first step. The second step is building an appropriate, progressive response. If you add friction to every single user, you are certain to lose good customers40. So Rupt seeks to apply friction for a very specific purpose, at a very specific moment, in a very specific way41. The goal is to stop the misuse while leaving the good users alone, and to do it in a way that is invisible to the good users.
And it has to be priced so it doesn't break the customer's own economics. Protection that costs more than the abuse is not protection anyone will keep.
Forging a fingerprint is easy. Forging a distribution of fingerprints that looks like a real user base is much harder.
09
How Rupt does it
We make AI work for you: your eyes and ears in the market and on the fraud streets.
85%85%
less in year one with Rupt than building in-house23
Rupt is our answer. We make AI work for you instead of against you. We are your eyes and ears in the market and on the fraud streets: watching, observing and building up knowledge across many customers and many behaviors, then turning it into a framework that keeps updating and protects your product without getting in your good users' way. The least friction possible, and the most abuse prevention possible.
What we sell is peace of mind: some of the best people in the market working as hard as they can to give you the highest level of protection and coverage. Getting the same coverage yourself would take years and far more money. Our own comparison puts year one with Rupt at 85% less than building in-house and 66% less than assembling point vendors, with integration in about four weeks23.
We also treat user experience as a first-class concern for our customers and their end users. Good UX is surprisingly hard to find in fraud tools. A fraud leader told us recently that they were switching vendors because their current one added too much friction and a poor experience for their end users42.
It shows in the results. One marketplace started enforcing on 1 to 2% of traffic and tightened as each step proved safe, and its users came to see verification as a feature43. Shared accounts that were challenged stayed longer than unshared ones44. Friction with good UX feels different to the end user. It feels much more like a service than a barrier.
We were worried people would hate it. Instead, they said ‘Why haven't you done this sooner?’ They don't see verification as friction, they see it as a feature.
10
What to measure
Abuse caught and good users left alone, measured together, plus the risk you took off the table.
22%22%
of the revenue from shared accounts recovered on average, across 30 software companies3
Measurement can be a slippery slope. In the interest of keeping the report short, we won't go into excessive detail here. But the measurement should at least cover three things: a before-and-after snapshot, how much risk you mitigated, and how good users were affected.
Rupt will specifically track the entire risk journey for a given user, give specific metrics for each step and tie the results together automatically for known misuses. For example, if account sharing is the misuse being handled, we will directly track how many sharers converted and created their own accounts. One customer uncovered $1M+ in ARR lost to account sharing, then saw more than $250,000 in new ARR in 2024 alone, directly attributable to the reduction in account sharing36.
Friction is also measured. But remember, not all friction is bad. A challenge with good UX is often seen as a feature, and can even increase conversion43. However, with progressive challenges, there are more difficult challenges to clear, and those should be measured. For most companies Rupt protects, the strongest challenges often only affect less than 5% of the traffic. This not only keeps good users happy but also keeps the cost of the solution down.
Trust Booster #001
One device, 400 fake accounts
One actor made about 400 fake accounts in 30 days. Every account shared a device, an IP, an email pattern and a bot score. Six signup signals gave the ring away.
Read the caseTrust Booster #002
120,000 fake accounts without opening the signup page
A card testing operation called the APIs directly. Domain blocking, IP blocking and email codes were already running. Here is what stopped it.
Read the caseTrust Booster #003
Thousands of fake leads, made by hand
One person built a fresh identity every day for five months. Every bot check came back negative. Reuse is what caught him.
Read the caseTrust Booster #004
One seat, 41 people
A single subscription ended up shared across 227 IP addresses, then scraped by a headless browser. Account sharing was the signal that uncovered the rest.
Read the caseCustomer story
How a marketplace shut down a realtor scam ring
A fresh identity every day, for five months, used to scam the brokers on a property marketplace. Scam reports fell by about 90%.
Read the caseThe questions we hear most from product and engineering teams.
What do you mean by product misuse?
Anyone using your product for a purpose that doesn't match what you built it for. That includes classic fraud, but also account sharing, multi-accounting, promo abuse, fake leads, fake postings and scams against other users.
Should we always block abusers?
No. If an actor is a nuisance that doesn't really cost you, denying them the objective and letting them continue is often better, because blocking tells them to change tactics. Stop them outright when their actions carry a real cost.
Isn't a CAPTCHA or a KYC check enough?
Not anymore. Bots solve CAPTCHAs, AI agents drive real browsers, deepfakes are streamed into camera checks, and verified accounts are for sale. A check at the door says nothing about who uses the account next month.
Won't more checks hurt conversion?
Checks applied to everyone do. The point of a risk score is to apply friction only where the risk is, so most real users never see a challenge. Start on a small share of traffic and tighten as each step proves safe.
Is device fingerprinting reliable?
On its own, not reliable enough to act on. Fingerprints can be shared by identical devices and change over time. Combined with network, identity and behavioral signals, and required to match on independent networks before accounts are linked, they are one of the strongest signals available.
Where should we start?
With the single action where product misuse costs you the most. Log every signal at that step, including from rejected attempts, score it, and challenge the riskiest slice. Measure abuse caught, good users challenged, and conversion at that step.
The terms we use, defined the way we use them.
- Product misuse
- Using a product for a purpose it was not built for.
- Self-serving abuse
- Abuse by ordinary users maximizing their own gain, such as extra accounts or shared seats.
- Malicious fraud
- Abuse by someone who knowingly sets out to hurt or steal from others.
- First-party fraud
- Fraud committed by the account holder, rather than by someone who stole their identity.
- Shadowban
- Letting an abuser keep acting while hiding the effect, so they don't learn they were caught.
- Account sharing
- One paid account used by several people who did not each pay.
- Account takeover
- An attacker gaining control of a real user's account, usually with stolen or reused passwords.
- Account farm
- An operation that pays people to open and verify accounts, then sells them.
- Device fingerprint
- An identifier built from a device's browser and hardware traits, used to recognize it again without cookies.
- Injection attack
- Feeding synthetic or recorded video straight into an identity check instead of a live camera.
- Precision and recall
- How many of the people you stopped deserved it, and how much of the abuse you caught.
Sources
- 1Rupt Rupt data . Trust Booster #002: How a card testing ring made 120,000 fake accounts. 2026. rupt.dev/blog/card-testing-ring-120000-fake-accounts
- 2Rupt Rupt data . Trust Booster #004: One seat, 41 people. 2026. rupt.dev/blog/one-seat-41-people
- 3Rupt Rupt data . Monetizing account sharing: results from 30 software companies. 2024. rupt.dev/blog/monetizing-account-sharing-results
- 4Kantar. How to combat survey fraud. Undated, data from Q4 2022.www.kantar.com/north-america/inspiration/research-services/how-to-combat-survey-fraud-pf
- 5Rupt Rupt data . Trust Booster #003: Thousands of fake leads, made by hand. 2026. rupt.dev/blog/thousands-of-fake-leads-made-by-hand
- 6FBI Internet Crime Complaint Center. North Korean IT workers conducting data extortion (PSA250123). January 2025.www.ic3.gov/PSA/2025/PSA250123
- 7FBI Internet Crime Complaint Center. Public service announcement on North Korean IT workers (PSA250723-4). July 2025.www.ic3.gov/PSA/2025/PSA250723-4
- 8LexisNexis Risk Solutions. Cybercrime Report. May 2025.risk.lexisnexis.com/about-us/press-room/press-release/20250513-cybercrime-report
- 9Riot Games. Vanguard x VALORANT. September 2024.playvalorant.com/en-us/news/game-updates/vanguard-x-valorant/
- 10Cloudflare. Trapping misbehaving bots in an AI Labyrinth. March 2025.blog.cloudflare.com/ai-labyrinth/
- 11Rupt Rupt data . Abuse of Rupt's own demo request form. 2026.First-hand incident on rupt.dev.
- 12FBI Internet Crime Complaint Center. Criminals use generative artificial intelligence to facilitate financial fraud. December 2024.www.ic3.gov/PSA/2024/PSA241203
- 13Microsoft. Cyber Signals issue 9: AI-powered deception. April 2025.www.microsoft.com/en-us/security/blog/2025/04/16/cyber-signals-issue-9-ai-powered-deception-emerging-fraud-threats-and-countermeasures/
- 14arXiv. Evaluating large language models' capability to launch fully automated spear phishing campaigns (Heiding, Schneier et al.). November 2024.Preprint.arxiv.org/abs/2412.00586
- 15Thales / Imperva. 2026 Bad Bot Report. April 2026.cpl.thalesgroup.com/about-us/newsroom/ai-driven-bot-attacks-surged-according-to-bad-bot-report
- 16Cloudflare. Past bots and humans. April 2026.blog.cloudflare.com/past-bots-and-humans/
- 17LexisNexis Risk Solutions. Cybercrime Report: global fraud. March 2026.risk.lexisnexis.com/global/en/about-us/press-room/press-release/20260326-ccr-global-fraud
- 18arXiv. Open CaptchaWorld: a web-based benchmark for testing multimodal agents. May 2025.Preprint.arxiv.org/abs/2505.24878
- 19arXiv. Robot visions: breaking reCAPTCHA at zero cost and zero shot. September 2026.Preprint.arxiv.org/abs/2609.18518
- 20The White House. The National Strategy to Secure Cyberspace. February 2003.www.cisa.gov/sites/default/files/publications/cyberspace_strategy.pdf
- 21US Government Accountability Office. Cybersecurity workforce, GAO-25-106795. January 2025.www.gao.gov/products/gao-25-106795
- 22NIST. New CyberSeek updates reveal 57,000 increase in cybersecurity job openings. June 2025.www.nist.gov/news-events/news/2025/06/new-cyberseek-updates-reveal-57000-increase-cybersecurity-job-openings
- 23Rupt Rupt data . Build vs buy: what fraud prevention costs in year one. September 2026.Defaults of 1 million evaluations a month, at vendors' published list prices. rupt.dev/compare/build-vs-buy
- 24SANS Institute. SANS | GIAC Cybersecurity Workforce Research Report. March 2026.Survey of 947 organizations across six regions.www.sans.org/press/announcements/sans-research-cybersecurity-talent-shortage-narrative-wrong-real-crisis-what-your-team-doesnt-know-starting-ai
- 25Rupt Rupt data . Signup test of 11 marketplaces in the US, UK and Australia. 2026.Unpublished field test. Each signup used a disposable email and an invalid phone number.
- 26Sumsub. Identity Fraud Report 2025–2026. November 2025.sumsub.com/newsroom/sumsubs-annual-report-fraud-shifts-to-complex-multi-step-schemes-in-2025-agentic-ai-scams-poised-to-surge-in-2026/
- 27iProov. Threat Intelligence Report 2025. February 2025.www.iproov.com/press/annual-identity-verification-threat-intelligence-report
- 28Entrust. 2026 Identity Fraud Report, as reported by Biometric Update. November 2025.www.biometricupdate.com/202511/protect-every-layer-of-identity-to-thwart-deepfake-injection-attacks-entrust
- 29University of Cambridge. Price of a bot army revealed across hundreds of online platforms. December 2025.www.cam.ac.uk/stories/price-bot-army-global-index
- 30Resistant AI. Verified account buying. October 2025.resistant.ai/blog/verified-account-buying
- 31IBM and Palo Alto Networks. Platformization is key to reduce cybersecurity complexity. January 2025.newsroom.ibm.com/2025-01-28-ibm-and-palo-alto-networks-find-platformization-is-key-to-reduce-cybersecurity-complexity
- 32SEON. 2026 Fraud and AML report. February 2026.seon.io/resources/news/seons-2026-fraud-aml-report-while-ai-is-everywhere-fraud-teams-are-still-growing/
- 33Gartner, as reported by HR Dive. Fake job candidates are on the rise. 2025.www.hrdive.com/news/fake-job-candidates-ai/757126/
- 34GetReal Security. 41% of enterprises surveyed report having hired and onboarded fraudulent candidates. 2025.Survey of 668 IT, cybersecurity, risk and fraud leaders at companies with 1,000 or more employees, September 2025.www.getrealsecurity.com/resources/new-getreal-security-research-41-of-enterprises-surveyed-report-having-hired-and-onboarded-fraudulent-candidates
- 35LexisNexis Risk Solutions. True Cost of Fraud Study: Financial Services and Lending. September 2025.risk.lexisnexis.com/about-us/press-room/press-release/20250910-fraud-multiplier
- 36Rupt Rupt data . How Agorapulse prevented seat sharing and grew revenue. 2024. rupt.dev/blog/how-agorapulse-prevented-seat-sharing-and-grew-revenue-by-hundreds-of-thousands-of-dollars
- 37IEEE S&P. FP-STALKER: Tracking Browser Fingerprint Evolutions (Vastel et al.). 2018.doi.org/10.1109/SP.2018.00008
- 38ACM Transactions on the Web. A Large-scale Empirical Analysis of Browser Fingerprints Properties for Web Authentication (Andriamilanto et al.). 2021.arxiv.org/abs/2006.09511
- 39ACM CCS. Uncovering Large Groups of Active Malicious Accounts in Online Social Networks (Cao et al.). 2014.doi.org/10.1145/2660267.2660269
- 40Signicat. The battle to onboard 2022. March 2022.Survey of 7,600 adults in 14 European countries.www.signicat.com/press-releases/the-battle-to-onboard-2022
- 41Google, with NYU and UC San Diego. New research: How effective is basic account hygiene at preventing hijacking. May 2019.security.googleblog.com/2019/05/new-research-how-effective-is-basic.html
- 42Rupt Rupt data . Conversations with fraud and trust and safety leaders. 2026.Anonymized at the speakers' request.
- 43Rupt Rupt data . How Crexi stopped product abuse and improved lead quality. 2026. rupt.dev/blog/how-crexi-stopped-product-abuse-increased-customer-trust-and-improved-lead-quality-with-rupt
- 44Rupt Rupt data . Does account sharing prevention cause churn?. 2024. rupt.dev/blog/does-account-sharing-prevention-cause-churn
Know which users and agents you can trust. Prevent fraud and abuse.