The Green Sheet Online Edition
August 24, 2026 • 26:08:02
From signup to signal: How tumbling, sequencing and gibberish reveal modern fraud
Fraud has become an identity engineering problem. Automated tools now generate email addresses, usernames and full account profiles at a scale that outpaces traditional controls. These identities are not crude fakes; they are constructed to pass validation, blend into legitimate traffic and exploit systems from the inside.
The shift requires a different lens to flag and protect against fraud. While we previously anchored identity fraud to whether an identity is valid, today identity reflects genuine human behavior. Answering that comes down to how three identity signals—structure, velocity and context—are interpreted in real time including some of the clearest indicators of automated fraud today: email tumbling, sequencing and gibberish generation.
Structure as a signal of intent
Structure reveals how an identity was created. Fraudulent identities generated at scale tend to follow repeatable construction patterns. Email tumbling is a clear example. By inserting dots, numbers, or slight variations into a base email address, fraudsters can create thousands of unique-looking accounts that all route back to a single inbox. Each address passes validation, yet the underlying structure exposes its origin.
Sequencing operates similarly. Email addresses or usernames are generated in predictable increments: names followed by ascending numbers, slight character shifts or formulaic combinations. Individually, they appear benign. In aggregate, they form a pattern that is highly unlikely to occur organically.
Gibberish is another structural indicator. At first glance, these identities look random—strings of characters with no obvious meaning. They are often produced by algorithms designed to mimic randomness while adhering to specific rules. That consistency, when analyzed at scale, becomes detectable.
Velocity as a signal of coordination
Velocity adds a time dimension to identity creation, exposing how structured patterns are deployed. Synthetic and automated fraud is built for throughput. Tumbling, sequencing and gibberish generation are not used in isolation; they are executed rapidly and repeatedly. Large volumes of similarly constructed identities appear within compressed timeframes, often targeting specific entry points such as signup flows or promotional campaigns.
This speed is difficult to replicate through genuine user behavior, so when identities sharing structural similarities are created in quick succession, it points to orchestration and a coordinated system. Velocity turns these patterns into proof connecting individual identities into campaigns, revealing the scale and intent behind them.
Context as a signal of risk
Structure and velocity indicate how and when identities are created. Context explains what they mean. Email intelligence provides a critical layer of this context. Attributes such as domain reputation, address age, historical usage and associations with other identities all contribute to a more complete risk profile.
A tumbled email tied to a newly created domain carries a different level of risk than a similar structure associated with a long-established inbox. Sequenced identities linked to low-activity or disposable domains reinforce the likelihood of automation. Gibberish strings tied to broader clusters of synthetic behavior further strengthen the signal.
Context connects these indicators, transforming them from isolated observations into actionable intelligence. This allows organizations to go beyond individual identities and assess the networks and behaviors they belong to.
From signals to real-time intelligence
Structure, velocity and context are most powerful when applied together. They shift fraud detection from static validation to dynamic interpretation—where identity is understood as behavior, not just data. This shift is increasingly reflected in how organizations are investing in fraud prevention. Demand for real-time, identity-first intelligence across sectors such as fintech and AdTech, where trust at the point of entry is critical, is rising.
Transforming the email address into a living, contextual source of truth enables organizations to detect synthetic and automated identities at inception; surface nuanced patterns like tumbling, sequencing and gibberish generation; and make high-confidence risk decisions in milliseconds.
Effective fraud prevention now depends on the ability to interpret the behavior embedded within identity signals and act on it immediately. That capability is what allows organizations to get ahead of automated threats rather than reacting to them after the fact.
Acting at the point of creation
The compression of time between identity creation and exploitation leaves little margin for delay. While fraudulent accounts can be generated, validated and operational within moments, applying intelligence at the point of entry changes the dynamic.
By identifying structural patterns like tumbling and sequencing, detecting the velocity of coordinated creation, and grounding those signals in rich contextual data, organizations can stop fraudulent identities before they take hold. This approach reduces downstream losses, limits operational burden and preserves a smoother experience for legitimate customers.
Fraud today is manufactured, often through identities created at scale, rather than perpetrated through stolen identities. Distinguishing between the two depends on recognizing the signals embedded in identity itself—and acting on them with speed and precision. 
Diarmuid Thoma is head of Fraud & Data for AtData, an Experian company. As organizations confront increasingly sophisticated fraud tactics driven by automation and AI, Thoma noted, assessing identity risk at critical decision points—including account opening, login, transaction and account change events—helps prevent fraud losses before they occur. Through strategic analysis and innovation, Thoma's team refines methods to combat online fraud, underscoring a commitment to integrity and security in digital finance. Their efforts contribute to a resilient infrastructure, pivotal in maintaining trust and operational excellence within the dynamic fraud prevention sector. Contact him via LinkedIn at linkedin.com/in/diarmuid-thoma.
Notice to readers: These are archived articles. Contact information, links and other details may be out of date. We regret any inconvenience.



