Blog B2Proxy Image

Why does an IP change not prevent cross-border account linkage?

Why does an IP change not prevent cross-border account linkage?

B2Proxy Image August 26.2026
B2Proxy Image

<p style="line-height: 2;"><span style="font-size: 16px;">Those involved in </span><a href="https://www.b2proxy.com/use-case/e-commerce" target="_blank"><span style="color: rgb(9, 109, 217); font-size: 16px;">multi-store e-commerce </span></a><span style="font-size: 16px;">operations have likely encountered this situation: after several stores have been running smoothly, you suddenly receive a notification from the platform stating that "there is a suspicion that one account is linked to another account." In mild cases, this may result in partial access restrictions; in severe cases, all stores may be restricted from using the service.</span></p><p style="line-height: 2;"><span style="font-size: 16px;">Many people's first reaction upon receiving an email is "What terrible luck!" —but upon closer reflection, if nine out of ten stores are linked, is this really just a matter of luck?</span></p><p style="line-height: 2;"><span style="font-size: 16px;">By 2026, the risk control systems used by major e-commerce platforms would no longer rely solely on IP addresses to determine merchant associations. Instead, these platforms would conduct comprehensive analyses of data from multiple dimensions—such as IP range ownership, device fingerprints, browser environment, payment methods, and operational behavior patterns—and then perform cross-verification to identify any "hidden connections" between stores. Simply assigning a different IP address to each store is no longer sufficient to resolve association detection challenges.</span></p><p style="line-height: 2;"><span style="font-size: 16px;">Starting from the underlying logic of platform risk control, this article systematically breaks down the detection dimensions associated with account associations and provides actionable environmental management solutions.</span></p><p style="line-height: 2;"><br></p><p style="line-height: 2;"><span style="font-size: 24px;"><strong>What exactly is the platform detecting?</strong></span></p><p style="line-height: 2;"><span style="font-size: 16px;">Imagine the risk control system as an evidence collector. It doesn't care whether "you are the same person"; what it cares about is whether "the similarity between these accounts exceeds a random baseline." The collected signals can be broadly categorized into four layers.</span></p><p style="line-height: 2;"><span style="font-size: 19px;"><strong>network layer </strong></span></p><p style="line-height: 2;"><span style="font-size: 16px;">The network layer includes the exit IP address, ASN (Autonomous System Number), DNS resolution path, consistency between the IP geographic location and the account registration location, and the local IP address exposed by WebRTC, among other factors.</span></p><p style="line-height: 2;"><span style="font-size: 16px;">Many people still perceive the network layer as simply "just change the IP address" —a notion that dates back several years. In reality, the determination of the network layer now encompasses at least four dimensions.</span></p><p style="line-height: 2;"><span style="font-size: 16px;">·IP type identification: Data center IP, residential IP, and mobile cellular IP addresses can be queried in the ASN database. An account claiming to provide internet access to a household in Texas, USA, but whose export ASN belongs to a cloud service provider's data center range, is itself a negative indicator.</span></p><p style="line-height: 2;"><span style="font-size: 16px;">·IP stability: When the same account is located in Los Angeles today, in Frankfurt tomorrow, and then returns to Los Angeles the day after – such a migration pattern is extremely unlikely among real-world users.</span></p><p style="line-height: 2;"><span style="font-size: 16px;">·IP range association: When multiple accounts are active simultaneously within the same IP range, the algorithm will interpret this as an "indirect association." Therefore, simply purchasing several different IPs does not guarantee compliance.</span></p><p style="line-height: 2;"><span style="font-size: 16px;">·Network protocol fingerprinting: The platform can also infer whether a user is operating within an emulated environment by analyzing the WebRTC protocol, the system's time zone, or even the number of network hops (TTL).</span></p><p style="line-height: 2;"><span style="font-size: 19px;"><strong>Equipment Layer</strong></span></p><p style="line-height: 2;"><span style="font-size: 16px;">The Device Layer includes browser fingerprinting data (e.g., Canvas fingerprint, WebGL fingerprint, font list, screen resolution, operating system version, etc.), hardware specifications, audio fingerprinting data, media device list, and more.</span></p><p style="line-height: 2;"><span style="font-size: 16px;">The browser fingerprint is a set of nearly unique device characteristics; the platform performs a horizontal comparison of dozens of data points. The core criteria for determination include:</span></p><p style="line-height: 2;"><span style="font-size: 16px;">·Graphics Layer: Canvas Fingerprint (calculates a pixel hash after rendering graphics), WebGL Fingerprint (reads information about the GPU manufacturer and renderer).</span></p><p style="line-height: 2;"><span style="font-size: 16px;">·Font Layer: List of system-available fonts and font rendering variations; Environment Layer: Screen resolution, color depth, number of hardware concurrent threads, device memory; Basic Identifiers: User-Agent, language settings, time zone</span></p><p style="line-height: 2;"><span style="font-size: 16px;">·Device fingerprinting is the most difficult to mask. Even if the IP address is changed or cookies are cleared, as long as the browser fingerprint remains the same, the platform still has a high probability of determining that the account is associated. For platforms, the consistency of device fingerprints is far more challenging than that of IP addresses—IP addresses can be changed, but devices do not change every single day.</span></p><p style="line-height: 2;"><span style="font-size: 19px;"><strong>Behavioral Layer</strong></span></p><p style="line-height: 2;"><span style="font-size: 16px;">The behavioral layer encompasses mouse movement trajectories, click rhythm, input habits, page scrolling patterns, interaction paths, abnormal login times, and more.</span></p><p style="line-height: 2;"><span style="font-size: 16px;">This represents the key upgrade focus for various platforms in 2026. Even when dealing with different IPs or devices, if your multiple stores exhibit highly consistent behaviors—such as product listing timelines, pricing strategies, product description styles, or customer service response templates—the platform's AI model will be able to identify the behavioral patterns characteristic of "the same operator." This dimension is the most challenging to defend against, as it does not rely on hardware-based data but instead analyzes your "operational habits."</span></p><p style="line-height: 2;"><span style="font-size: 19px;"><strong>Relationship Layer</strong></span></p><p style="line-height: 2;"><span style="font-size: 16px;">The relationship layer includes Cookies, local storage, payment cards, shipping addresses, phone numbers, email addresses, social graphs, etc.</span></p><p style="line-height: 2;"><span style="font-size: 16px;">When multiple stores use the same payment account, the same credit card, or the same PayPal account, this constitutes direct evidence of association at the payment level. Some platforms even perform cross-referencing of the payment account's registration details and IP addresses. The use of the same credit card, the same business address, the same brand, or the same company all serve as readily available pieces of evidence of association.</span></p><p style="line-height: 2;"><span style="font-size: 16px;">Risk control is not based on a single metric but involves constructing a comprehensive risk score. For example, two accounts with the same IP address but different fingerprints may be classified as having a moderate risk level; however, if both accounts share the same IP address, identical fingerprint profiles, similar behavior patterns, and the same shipping address, their risk score will surge.</span></p><p style="line-height: 2;"><br></p><p style="line-height: 2;"><span style="font-size: 24px;"><strong>Why do these approaches fail to resolve the correlation issue?</strong></span></p><p style="line-height: 2;"><span style="font-size: 19px;"><strong>Change IP address only; Keep fingerprint unchanged.</strong></span></p><p style="line-height: 2;"><span style="font-size: 16px;">Many people assume that simply changing the IP address of a store guarantees security. However, the factors used by the platform to detect activity extend far beyond just the IP address. If multiple accounts are logged into the same device using the same browser, the browser fingerprints will be highly similar; even if the IP addresses differ, the platform can still identify the accounts as belonging to the "same device." Changing only the IP address without altering the browser fingerprint is a classic example of inconsistent environmental conditions—and such behavior is likely to be flagged as suspicious by the risk control system.</span></p><p style="line-height: 2;"><span style="font-size: 19px;"><strong>Only replace the fingerprint; Keep the IP address unchanged.</strong></span></p><p style="line-height: 2;"><span style="font-size: 16px;">Conversely, if each account uses a different browser fingerprint but all accounts share the same IP exit—meaning multiple accounts share the same network identity—this also constitutes a clear indicator of correlation.</span></p><p style="line-height: 2;"><span style="font-size: 19px;"><strong>Multiple virtual machines or browser instances</strong></span></p><p style="line-height: 2;"><span style="font-size: 16px;">When there are few accounts, running multiple virtual machines or multiple browser instances can indeed hold things together for a while. However, as the number of accounts grows, the limitations of these two approaches become quite apparent. While virtual machines allow each store to have its own independent system, this comes at a significant resource cost; moreover, since these virtual machines default to using the host machine's network, running multiple virtual machines effectively uses the same network exit point. More critically, the graphics card, network card, and memory specifications of virtual machines differ significantly from those of physical machines – and the platform can identify these differences by comparing the hardware characteristics.</span></p><p style="line-height: 2;"><span style="font-size: 16px;">Running multiple browser instances may seem like a simple task, but managing account credentials, cookies, and plugins all requires manual intervention; switching between dozens of windows frequently makes sequential numbering almost unavoidable.</span></p><p style="line-height: 2;"><span style="font-size: 19px;"><strong>Stealth Mode or Invisible Browsing</strong></span></p><p style="line-height: 2;"><span style="font-size: 16px;">The stealth mode simply does not save browsing history locally; however, browser fingerprints, IP addresses, and other information are still collected. The platform captures every single parameter it needs to.</span></p><p style="line-height: 2;"><br></p><p style="line-height: 2;"><span style="font-size: 24px;"><strong>How to achieve true environmental isolation?</strong></span></p><p style="line-height: 2;"><span style="font-size: 16px;">Core Principle: One Account – One IP – One Fingerprint</span></p><p style="line-height: 2;"><span style="font-size: 16px;">Each account must have an independent network access point, an independent device fingerprint, and an independent browser environment – all three are required.</span></p><p style="line-height: 2;"><span style="font-size: 19px;"><strong>Static residential IP +Independent IP segment</strong></span></p><p style="line-height: 2;"><span style="font-size: 16px;">For account management services, it is recommended to prioritize static residential IP addresses. These addresses remain fixed over the long term and do not switch automatically, making them ideal for scenarios such as cross-border account management or store backend administration where maintaining a persistent login state is required.</span></p><p style="line-height: 2;"><span style="font-size: 19px;"><strong>Be careful when selecting an IP address.</strong></span></p><p style="line-height: 2;"><span style="font-size: 16px;">·IP type: Prefer residential IP addresses over data center IP addresses. Data center IP addresses are assigned an ASN by the cloud service provider and are easily identifiable as data center traffic.</span></p><p style="line-height: 2;"><span style="font-size: 16px;">·IP independence: It is advisable for each account's IP address to be assigned by a different carrier or from a different IP range to avoid "indirect associations."</span></p><p style="line-height: 2;"><span style="font-size: 16px;">·IP geolocation matching: The IP location must match the account registration location and time zone settings.</span></p><p style="line-height: 2;"><span style="font-size: 19px;"><strong>Fingerprint Browser</strong></span></p><p style="line-height: 2;"><span style="font-size: 16px;">Fingerprint Browser modifies the browser parameters returned to websites at the kernel level to generate a unique, consistent browser fingerprint for each account. It is more lightweight than virtual machines and offers a more thorough alternative to running multiple instances of a standard browser.</span></p><p style="line-height: 2;"><span style="font-size: 16px;">Please note when configuring the Fingerprint Browser.</span></p><p style="line-height: 2;"><span style="font-size: 16px;">Fingerprint parameters must be consistent: What determines the stability of an account environment is never whether "how many fingerprint modifications were made," but rather whether "the fingerprint modifications look authentic." The more parameters are adjusted and the more aggressive the randomization approach is, the easier it becomes for the system to be compromised. Solutions with truly low anomaly rates ensure that every set of parameter configurations across all environments falls within the statistical distribution observed on real devices—and remains unchanged over time.</span></p><p style="line-height: 2;"><span style="font-size: 16px;">Fingerprint and IP address must match: If the IP address is from New York, USA, set the time zone to US Eastern Time, the language to en-US, and select a common set of American-style fonts.</span></p><p style="line-height: 2;"><span style="font-size: 19px;"><strong>Operational Practice Differentiation</strong></span></p><p style="line-height: 2;"><span style="font-size: 16px;">Account and IP environment considerations are merely the foundation; behavioral-level isolation should not be overlooked either. Even when multiple stores maintain identical product listing schedules, completely consistent pricing strategies, or highly similar product description templates – and even when their networks and devices are fully isolated – the platform's AI model may still detect correlations based on their behavioral patterns. In practice, risks can be mitigated through the following measures: maintain a certain time gap between the product listing schedules of each store to avoid synchronized operations; tailor pricing strategies according to the distinct positioning of each store; avoid directly replicating the same product description templates or customer service scripts for different stores – instead, draft them independently; and stagger the login times of each account to prevent them from being accessed during the same time slot. These adjustments may seem minor, but they can effectively reduce the risk of behavioral correlation over the long term.</span></p><p style="line-height: 2;"><br></p><p style="line-height: 2;"><span style="font-size: 24px;"><strong>Conclusion</strong></span></p><p style="line-height: 2;"><span style="font-size: 16px;">Account association detection has been upgraded from simple IP address comparison to a cross-validation approach spanning four dimensions: network, device, behavior, and relationships.</span></p><p style="line-height: 2;"><span style="font-size: 16px;">The core principle of defense is not simply "evading a specific detection point," but rather ensuring that each account becomes an independent, self-consistent digital identity across three dimensions—network, device, and behavior. The IP address must be unique and possess residential attributes; the device fingerprint must be independent and have consistent parameters; and the behavior patterns must be distinctive and align with the actual characteristics of real-world users.</span></p><p style="line-height: 2;"><span style="font-size: 16px;">When selecting solutions, it is recommended to prioritize three key metrics: IP authenticity (whether the IP is a residential IP), fingerprint uniqueness (whether each environment has distinct fingerprint parameters), and environment consistency (whether the fingerprint parameters match the IP's geographic location). Combining these three factors enables the establishment of a truly effective and long-term stable multi-account management system.</span></p>

You might also enjoy

Access B2Proxy's Proxy Network

Just 5 minutes to get started with your online activity

View pricing
B2Proxy Image B2Proxy Image
B2Proxy Image B2Proxy Image