For software-as-a-service companies that rely on low-friction online signup, making it easy for a new user to register, start a trial, or access a product is often central to how these companies grow. But the same systems that help companies capture demand can also carry fraudulent registrations into CRM, sales, and reporting workflows before they are identified as fraudulent. The costs may show up in different places wasted sales time, distorted growth data or direct financial losses and they are not always visible immediately.
In 2021, as reports of registration fraud climbed sharply across industries, companies of very different sizes and resources responded in very different ways.
For a SaaS company, making signup easier is often part of a growth strategy: self-service registration, free trials, API access, and instant account activation all lower barriers for new users. Those same features can also allow fraudulent accounts to get through signup.
Without screening at signup, fraudulent accounts can be counted as new users, added to a CRM, and passed to sales. The effects extend beyond security: sales teams may spend time on fake leads, while growth and marketing data can include those accounts alongside legitimate signups. The challenge is to identify those accounts early without adding unnecessary friction for legitimate users and, in some cases, without building a separate fraud operation from scratch.
Online registration abuse was rising sharply in 2021. In November, fraud-prevention company Arkose Labs reported 560 million malicious attempts on registration flows in the third quarter, roughly four times the level it had seen at the start of the year. The data covered several digital industries, not SaaS alone.
Also Read: The 3 Stages of the Data Privacy Maturity Curve
Businesses were becoming more worried about fraud, while customers were also expecting a smoother online experience. Experian’s 2021 Global Identity and Fraud Report surveyed more than 9,000 consumers and 2,700 businesses across 10 countries. Two-thirds of the businesses said they had become more concerned about fraud since the pandemic began. Among consumers, 60 percent said they expected a better online experience than before the pandemic, while 55 percent still ranked security as a top priority.
In May 2020, incident-management startup Spike.sh discovered that scammers were exploiting its signup flow, which verified new accounts with an automated phone call. Using disposable email addresses, they created dozens of fake accounts within an hour, triggering a wave of verification calls to international numbers a form of toll fraud that runs up telecom charges on someone else’s account.
By the time Spike.sh’s credit-card provider flagged the activity; the calls had already cost $870. Its founder described fixing it the same day: switching from voice to SMS verification, restricting which countries it would call and eventually requiring Google sign-in instead of email and password.
In August 2021, AWS published guidance on preventing free-trial abuse, citing fake email addresses, disposable phone numbers, and stolen or fake credit-card information among common tactics. The architecture it described was designed to work without in-house machine-learning expertise.
At Plivo, a cloud communications company with no dedicated fraud team, the problem surfaced through growth reporting.
“I started as a growth analyst doing reporting for the growth team. I noticed fraudulent signups were a problem, figured out a way to detect and block them,” said Eswar Singavarapu, a senior business analyst working on reporting and analytics for the company’s growth team. “The sales team was wasting time on fake leads, and the company was losing money on fraudulent accounts,” he said.
Between 2019 and 2020, Singavarapu developed a screening workflow that combined behavioral and firmographic signals with data from Clearbit, a business-data provider, and FullContact, an identity-data provider. The workflow considered those signals together rather than relying on any one of them alone. He used Zapier, a workflow automation platform, to automate the next step, allowing registrations to proceed, be rejected or be sent for manual review.
The workflow was built largely from tools already used across the company’s sales, marketing and data operations. Singavarapu developed the detection logic, enrichment process, and automation without a specialist fraud vendor or a dedicated data science team. The screening combined multiple automated checks, including repeated signups from the same IP address, with manual review. Patterns identified during review could then be used to update the rules as new types of fraudulent activity appeared.
According to Singavarapu, fraudulent signups fell by about 90 percent after the workflow was introduced. Before the workflow, he said, the company was seeing hundreds of fraudulent signups a day. Those signups were distorting lead-to-opportunity conversion rates, so he had to remove them manually from growth reporting.
Addressing registration abuse does not always require a dedicated fraud team or an in-house machine-learning group. For growth and revenue teams, screening fraudulent registrations early can also serve as a form of data quality control keeping fake accounts out of the CRM, sales pipeline and reporting systems used to measure acquisition. As registration abuse continues to challenge companies built around self-service signup, practical responses may increasingly come from adapting the tools and processes already used to support growth.






























