Table of content

Casino Bonus Hunters: Multi-Million Schemes and a Growing Threat to the Industry

Date Last Modified: 25 May, 2026

For years, casino bonus hunters were treated as a predictable side effect of growth. Operators knew some players would register, clear a welcome offer, withdraw, and disappear. It was built into the math part of the customer acquisition cost.

That assumption no longer holds. What the industry is facing today is not aggressive bonus play, but something far more structured. Across multiple jurisdictions, bonus abuse has evolved into a system: scalable, repeatable, and in many cases indistinguishable from organised financial crime. The shift did not happen overnight, and for a long time, it went largely unnoticed. But recent cases make one thing clear — this is no longer a marginal issue.

From Individual Play to Scalable Systems

The idea that bonus abuse is still about players pushing the limits of casino terms breaks down the moment you look at what is happening in the United States right now.

In Connecticut, two 29-year-olds — Amitoj Kapur and Siddharth Lillaney — were arrested by federal agents after authorities uncovered what they describe as a long-running fraud operation built on online gaming promotions. Both men are residents of Glastonbury, and both are now facing a long list of criminal charges that go far beyond anything typically associated with bonus abuse.

The case formally escalated on February 3, 2026, when a grand jury in New Haven approved charges against them. Those charges include electronic fraud, misuse of personal information, and money laundering — not internal policy violations, but federal offences. After their arrest, the defendants were brought before a judge and later released while the case proceeds, meaning the legal process is still ongoing and unresolved.

What investigators describe is not aggressive bonus play. It is a system. According to court filings, Kapur and Lillaney spent years building a method that allowed them to repeatedly access “new player” promotions by pretending to be different people every time. Online casinos and sportsbooks routinely offer free bets, bonus credits, and sign-up incentives to attract users. The entire scheme was built around extracting those offers over and over again.

To do that, they allegedly purchased stolen identity data from illegal online sellers. These were not partial profiles. The data included enough personal information to open accounts in other people’s names — people who, in most cases, had no idea their identities were being used.

Authorities estimate that around 3,000 individuals were affected. Whenever a gaming site required additional verification, the two men did not stop. Instead, they reportedly searched public record databases to gather extra details about those same individuals. That allowed them to answer security questions correctly and keep the accounts from being flagged or blocked.

Once accounts were active, the process was repeated at scale. Each new identity meant access to another welcome bonus.

The money flow followed a clear structure as well. When bonus bets generated winnings, those funds were not withdrawn directly. They were first moved into prepaid virtual cards, then transferred into bank and investment accounts controlled by Kapur and Lillaney. By the time the money reached its final destination, it was already layered — a pattern that prosecutors associate with laundering rather than simple account misuse.

Investigators believe the operation began around 2021 and, over time, generated close to $3 million. U.S. Attorney David X. Sullivan made the position of authorities explicit. This was not seen as casual misuse of promotions or players “gaming the system.” It was described as a scheme built on identity theft and large-scale deception.

That distinction matters more than anything else in this case. Multi-accounting has existed for years. In most situations, it leads to confiscated winnings or account closures. Here, the same basic idea — creating multiple accounts to claim bonuses — crossed a line because of how it was executed: stolen identities, thousands of victims, and a structured financial flow designed to extract and move money at scale.

This is the point where the conversation around bonus hunters changes. What used to be treated as a terms-and-conditions issue is now being prosecuted as a criminal business model.

Different Strategies, Same Outcome

There is no single blueprint for bonus abuse. That is exactly why it keeps working. The industry often tries to define it through isolated behaviours — multi-accounting, arbitrage, bonus cycling — but real-world cases show something much more fragmented. The methods vary depending on resources, geography, and risk tolerance. The outcome does not.

At one end of the spectrum are slow, long-term operations that avoid attention by design. In the Netherlands, this became evident in 2023, when authorities arrested a couple in Limburg — a 42-year-old man and his 37-year-old partner — following an investigation that had been ongoing for approximately fifteen years. The case was handled by the Dutch Fiscal Information and Investigation Service (FIOD), and by the time arrests were made, prosecutors concluded that the pair had extracted more than €2 million from online casinos.

What makes this case stand out is not complexity, but persistence. According to investigators, the couple relied on forged documents and multi-accounting to repeatedly claim welcome bonuses intended strictly for new customers. There was no need for automation at scale or coordinated networks. The system worked because it was controlled and repeatable — opening accounts under different identities, triggering bonuses, clearing conditions, and extracting value in cycles that ran for years without interruption.

The financial side of the operation followed the same logic. Authorities believe the proceeds were laundered through real estate investments, turning bonus-derived winnings into tangible assets and making the origin of funds significantly harder to trace.

There was no large infrastructure, no visible spike, no sudden wave of withdrawals. The scheme stayed below detection thresholds because nothing about it appeared urgent or abnormal in isolation. That is precisely why it lasted as long as it did. By the time it surfaced in 2023, the damage had already accumulated over more than a decade.

At the other end are cases that operate on a completely different level. In Greece, authorities uncovered a coordinated criminal network built specifically to exploit bonus systems at scale. The case, first reported by Proto Thema, involves 43 suspects accused of systematically defrauding licensed online bookmakers through a combination of arbitrage betting and repeated bonus claims.

This was not opportunistic abuse. It was organised. According to police findings, the group relied on arbitrage strategies to remove risk from betting. By placing calculated wagers across different outcomes, participants were able to lock in returns regardless of how sporting events concluded. Bonuses were not an extra — they were the mechanism that made the model profitable.

To scale the operation, members registered hundreds of user accounts using the personal data of third parties. Each new identity unlocked access to another welcome offer, allowing the same cycle to be repeated across accounts without exposure at the individual level.

Authorities estimate that illegal proceeds exceeded €1.5 million, while direct financial damage to operators surpassed €120,000. Those numbers only reflect what could be measured. What initially appeared to be scattered accounts quickly turned out to be part of a single system.

Investigators identified clear links between profiles — shared digital fingerprints, synchronised login behaviour, and matching activity patterns. These were not isolated users. They were coordinated nodes inside one structure.

The operation traces back to at least early 2020 and continued for years, expanding gradually rather than appearing as a single large-scale incident. That slow build made it harder to detect, even as the number of accounts increased.

It was only in February 2026 that Greek law enforcement moved to dismantle the network, meaning the scheme had been running in the background for several years before it was formally uncovered.

When authorities carried out searches across multiple properties, the scale became physical, not just digital. Officers seized more than €19,000 in cash, along with access credentials connected to over 700 accounts. They recovered more than 500 SIM cards and upwards of 200 mobile devices — infrastructure built specifically to maintain account separation and bypass detection systems.

Five luxury vehicles were confiscated, with prosecutors linking them to proceeds from the operation. At two locations, police also found a handgun and ammunition. That detail matters because it shifts the perception of the case. This was not a loose group exploiting loopholes. It was an organised setup operating with the structure and resources of a criminal enterprise.

The charges reflect that reality. The suspects now face accusations including fraud, document forgery, violations of gaming regulations, money laundering, and participation in a criminal organisation.

What makes this case important is not just its size, but its structure. Unlike the Dutch operation, which relied on staying invisible over time, the Greek network relied on coordination, volume, and controlled expansion. It did not avoid scale — it engineered it.

Three different approaches. Three different speeds. Three different risk models. The result is the same in every case. Bonus systems, designed as a marketing expense, were turned into a controlled and repeatable source of profit.

Why Casinos Keep Missing the Signals

If the schemes are so different, why do they keep working? The answer lies less in player behaviour and more in how operators are structured internally.

Most fraud detection systems are still built around fixed rules: flag unusual IP activity, detect duplicate devices, and monitor withdrawal patterns. These tools were effective against earlier forms of abuse, but they struggle with modern strategies that are designed specifically to avoid triggering them.

The Connecticut case demonstrates this clearly. The suspects did not simply create fake accounts — they used real personal data, supplemented it with publicly available information, and answered verification questions correctly. From the system’s perspective, these accounts did not look suspicious. They looked legitimate.

The “Stalker” interview reinforces the same point from the opposite side. According to him, any parameter a fraud system relies on — device fingerprints, IP addresses, even identity verification — can be manipulated with enough effort. That does not mean these tools are useless, but it does mean they are no longer sufficient.

There is also a deeper issue: fragmentation. In many operators, KYC, payments, CRM, and gameplay data are handled separately. A user may look normal in each system individually while still being part of a coordinated abuse pattern when viewed as a whole. Without cross-system analysis, those patterns remain invisible.

The Dutch case again highlights the consequences. Fifteen years of continuous activity suggest not just a clever scheme, but a lack of longitudinal tracking. The system was not built to connect behaviour over that timeframe.

The Economics Behind Bonus Abuse

To understand why bonus abuse continues to grow, it is necessary to look at the incentives. From the operator’s perspective, bonuses are a marketing expense. They are priced based on expected player behaviour — how much of the bonus will be converted into real money, how much will be lost back to the house, and how many players will remain active.

From the abuser’s perspective, bonuses are a financial instrument. The difference is critical. While operators think in averages, bonus hunters think in expected value (EV). They identify scenarios where the structure of a promotion creates a positive return, then scale that scenario as much as possible.

The numbers from real cases make this clear. A system generating $100,000+ per month, as described by Stalker, is not exploiting randomness. It is exploiting mispricing. A network extracting €1.5 million through arbitrage is not gaming. It is executing a strategy.

Even the Connecticut case, which involved identity theft, ultimately depended on the same principle. The stolen identities were simply a way to multiply access to promotions. The underlying profitability still came from the bonuses themselves.

This is why the problem persists. As long as the expected value of exploiting a bonus exceeds the cost of doing so — whether that cost is time, data, or infrastructure — the model remains viable.

Technology Is Not Keeping Up

There is a growing tendency to frame bonus abuse as a technological arms race. In reality, it is an uneven one. On the fraud side, tools are becoming more accessible:

  • synthetic identities generated with AI

  • automated account creation scripts

  • coordinated device and network setups

On the operator side, many systems are still reactive. They identify known patterns rather than emerging ones.

The criticism of device fingerprinting as a “losing game,” voiced in the Stalker interview, reflects a broader issue. These systems assume stability — that a device or user profile remains consistent. Modern abuse strategies are built around variability. The result is a gap. Fraud evolves continuously, while detection updates in cycles.

Why New Markets Are Especially Vulnerable

This gap becomes even more pronounced in emerging markets. In regions where online gaming is expanding rapidly, operators are focused on growth. Marketing budgets increase, onboarding processes are streamlined, and friction is reduced to attract new users. Fraud detection often lags behind that expansion.

This is exactly the environment where bonus abuse thrives. Unlike mature markets, where large anomalies may trigger alerts, emerging markets tend to see a high volume of smaller transactions. Instead of one large fraud event, operators face thousands of minor exploitations — each individually insignificant, but collectively substantial.

The patterns seen in the US and Europe are not isolated. They are transferable. The same methods that generated millions in established markets can be applied, often more effectively, in markets where controls are still developing.

The Industry’s Core Miscalculation

At the centre of all of this is a simple misalignment. Bonus abuse is still widely treated as a marketing inefficiency rather than a financial risk.

That distinction matters. Marketing inefficiencies are tolerated. Financial losses are measured and minimised. As long as bonus abuse is absorbed into acquisition costs, it does not receive the same level of scrutiny as other forms of fraud. The result is predictable: it grows.

The cases discussed earlier are not outliers. They are indicators. Each one reveals a different aspect of the same problem — scale, persistence, coordination, profitability.

What Needs to Change

Solving the issue does not require eliminating bonuses or restricting players. It requires a shift in how the problem is approached.

First, operators need to move beyond rule-based detection toward behavioural analysis. The question is no longer whether an account looks legitimate at registration, but whether its activity over time aligns with genuine play.

Second, systems need to be integrated. Patterns that are invisible within individual datasets often become obvious when viewed across payments, gameplay, and account behaviour.

Finally, incentives need to change. As long as exploiting a system is more profitable than reporting its weaknesses, the most capable actors will continue to operate outside it.

Conclusion

The evolution of casino bonus hunters is not a story about players getting smarter. It is a story about systems being outpaced.

From a $3 million identity fraud scheme in Connecticut to a €2 million long-term operation in the Netherlands, from a 43-person network in Greece to a single operator generating a six-figure monthly income, the pattern is consistent. Bonus abuse scales. It adapts. And it persists.

What was once dismissed as opportunistic behaviour has become something far more structured — a parallel economy built on the gaps within the industry itself.

The question is no longer whether bonus abuse is a problem. The question is how long the current model can sustain it.