Account Sharing Prevention
Account sharing undermines revenue, security, and regulatory standing across every industry that extends services, access, or benefits to a verified individual. The business impact varies by context, but the underlying failure is consistent: credentials authenticate a device or a password, not a person.
The sharing patterns organizations encounter include:
- Subscription sharing: streaming, gaming, and SaaS platform credentials shared across households or networks, reducing paid subscriber counts and undermining per-seat licensing models
- Credential reselling: account credentials sold or rented to third parties, often at scale, as an informal secondary market
- Workplace license abuse: enterprise software licenses shared across more users than contracted, inflating effective usage beyond purchased entitlements
- Healthcare proxy access: patient portal credentials shared with family members or caregivers, creating privacy, consent, and regulatory exposure under HIPAA and equivalent frameworks
- Financial account access: banking and investment account credentials shared with family members or advisors, bypassing the identity assurance controls the account was opened under
- Gaming and competition integrity: account credentials shared to allow higher-skilled players to perform on behalf of the account holder, distorting rankings and competitive outcomes
- Credential exposure: every additional person using shared credentials is an additional vector for phishing, credential theft, and social engineering, expanding the account’s attack surface beyond the verified account holder’s control
- Gig economy credential sharing: unknown and potentially unqualified workers substituting for known, credentialed workers, creating potential liability
In regulated industries, shared account access creates liability that extends beyond revenue loss. A transaction or interaction conducted by someone other than the verified account holder may not meet the identity assurance requirements of the applicable regulatory framework, regardless of whether the account holder consented to sharing.
Daon provides organizations with the tools to control account sharing by binding account access to a verified identity established at enrollment through a government-issued document matched to a live selfie.
Server-side face biometric authentication confirms the same person at every subsequent interaction, tying access to the individual rather than device or credential possession. Presentation Attack Detection tested by iBeta to ISO 30107-3 Level 2 and injection attack detection aligned with CEN/TS 18099 apply at both enrollment and authentication, ensuring the face captured is always live and present.
For activities with inherent risk, continuous authentication uses risk signals and business-defined workflows to trigger reauthentication, confirming the same person who logged in remains present.
Daon secures over 2 billion identities across six continents, supporting account holders across 200+ countries. For global organizations, that coverage means the same enrollment and authentication controls apply regardless of where the account holder is located.
Our cloud-native, SaaS-based Identity Continuity platform for orchestrating the full customer identity journey from identity verification to cross-channel authentication with a single user record.
Product Details
Daon’s 5th generation identity fraud prevention platform capable of supporting the entier identity journey hosted in the cloud or on-premises.
Product Details
Our digital identity verification application that provides global identity document validation and biometric face matching to ensure every user is who they claim to be
Product Details
Our face biometric authentication application for access and step-up authentication against a server-hosted, encrypted face template.
Product Details
Our suite of multi-factor authentication factors includes biometric, possession, and knowledge-based factors, empowering organizations to customize authentication workflows to individual use cases.
Product DetailsOther Use Cases
Agentic AI Attacks in the Contact Center
Defend against agentic AI attacks in the contact center by implementing real-time synthetic audio detection from the first seconds of a call.
Read MoreContact Center Fraud Detection
Minimize contact center fraud with voice authentication, synthetic voice detection, and step-up authentication in IVR and live agent applications.
Read MoreHealthcare Insurance Fraud Prevention
Bind verified identity and channel-based authentication factors to a single patient record for a central proven identity across all points of interaction.
Read More