-
26 February 2026, 3:29 am
#1
Mobile traffic, CGNAT & “duplicate IP” a recurring issue with some casino programs.
I would like to share an observation and see whether others are noticing a similar pattern.
Over the past few months we have experienced comparable situations with more than one casino program where traffic was flagged by fraud teams due to so called anomalies, with duplicate IPs mentioned as the primary reason. In both cases the traffic source was community based, mainly Facebook and Telegram, with a strong mobile component.
A large percentage of users were playing via mobile networks using LTE or 5G. As most people in this industry are aware, mobile carriers operate behind CGNAT, which naturally results in multiple unrelated users sharing the same public IP address.
In our cases the user behavior was clearly diversified. We saw low depositors, medium depositors and some higher value players. There were no chargebacks, no reused payment methods and no obvious behavioral or device level correlation. The only repeated signal referenced by the programs was IP overlap.
From a technical standpoint, relying solely on IP duplication as a primary fraud indicator for mobile traffic seems outdated. CGNAT related IP overlap is standard in many mobile first and T2 or T3 markets.
What is more concerning is that no concrete case examples or logs were shared, and no additional correlation beyond IP was provided. The wording and timing of the explanations were also strikingly similar across different brands.
This raises a broader question for affiliates working with community driven or mobile heavy traffic. Are some programs still treating IP duplication as a core fraud signal despite the realities of modern mobile networks?
We have tested several hybrid deals where weekly revenue share performance was clearly positive, typically in the range of 650 to 800 USD per week. At the same time CPA conversions were systematically flagged and reversed as fraud, effectively removing the CPA component of the hybrid structure.
This creates the impression that revenue share is allowed to continue as long as it generates value, while CPA payouts are retroactively removed under broad fraud labels without transparent case level evidence.
The intention of this post is not to attack any specific brand. I am genuinely interested in understanding whether this is becoming a wider industry issue and how affiliates are adapting to protect themselves before scaling traffic further.
Input from the operator side would also be very welcome.
-
-
13 March 2026, 10:01 am
#2
Our experience is that some GEOs are more prone to such flags than others. Some traffic sources too.
A primary example is India where a lot of times, customers may register in bulk or be motivated by the same promotion.
The operator's bonus offer may also be a factor here, if the bonus creates the misconception to users that it can be abused, the operator may then think that it's the affilaite's fault.
I think in these cases, clear open communication and sharing of all relevant data is very important between operators and affiliates.
Just adding our 2 cents in this discussion and would also love to hear from operators on this.
-
Tags for this Thread
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules