Delivery Rider Account Sharing: Why Onboarding Verification Is No Longer Enough
Delivery Rider Account Sharing: Why Onboarding Verification Is No Longer Enough
Even if a delivery platform verifies a rider's identity document, mobile number, and payout account during onboarding, it cannot automatically assume that the registered rider is the person actually completing deliveries.
A legitimate rider may successfully complete identity verification using their own credentials. But once the account has been created, login information can be shared, rented, or even sold to someone else.
As delivery platforms continue to grow, account sharing has become an operational challenge rather than an isolated security incident.
In the UK, major delivery platforms including Deliveroo, Uber Eats, and Just Eat have announced stronger rider identity checks while expanding the use of facial verification and fraud detection technologies.
Similar changes are taking place in the United States. DoorDash has also expanded selfie-based identity verification and introduced additional authentication when suspicious account activity or unfamiliar login environments are detected.
These changes reflect a broader shift across the industry.
The goal is no longer simply verifying who created the account.
It is increasingly about verifying who is actually using the account when work begins.
Delivery platforms are now asking two different questions.
Who registered this rider account?
and
Is the person delivering today the same person who originally registered?
Onboarding verification answers the first question.
Facial re-authentication answers the second.
How Can a Legitimately Verified Account End Up in Someone Else's Hands?
Most delivery platforms collect multiple forms of identity information during rider registration.
Identity documents help verify a rider's name, date of birth, nationality, and government-issued identity credentials.
Mobile verification confirms access to the registered phone number, while payout account information ensures that earnings are transferred to the correct account holder.
These controls are highly effective during onboarding.
The problem is that they typically happen only once.
A rider may legitimately create an account using their own identity, then later share login credentials or rent the account to another person.
From the platform's perspective, nothing appears unusual.
The identity documents remain valid.
The registered phone number hasn't changed.
The payout account still belongs to the verified rider.
Yet the individual actually completing deliveries may now be someone entirely different.
Initial identity verification successfully establishes who created the account.
It does not continuously verify who is using the account today.
Identity Verification and User Authentication Are Two Different Things
Many organizations use the terms Identity Verification and Authentication interchangeably.
In reality, they solve two very different problems.
Identity Verification takes place during onboarding.
It confirms who the applicant is by validating government-issued identity documents, checking document authenticity, and comparing the ID portrait with a live selfie.
Its purpose is straightforward.
Who created this account?
Authentication happens after onboarding.
Whenever a previously verified rider logs in, starts work, or performs a sensitive action, the platform needs to determine whether the current user is still the original account owner.
Authentication answers a different question.
Is the person using this account today the same rider who originally registered?
Account sharing becomes possible whenever platforms can answer the first question but not the second.
Even the strongest onboarding process cannot prevent account rental if the platform never confirms the rider's identity again.
For delivery platforms, identity verification should not end when registration is complete.
Platforms Need to Verify the Person Performing the Delivery
Unlike office employees, delivery riders do not check into a physical workplace where someone can visually confirm their identity.
They simply open an app, go online, and begin accepting delivery requests.
That makes the moment before a rider starts working one of the most important opportunities for identity verification.
Instead of relying solely on the onboarding process, platforms can request a quick selfie before the rider begins accepting orders.
The newly captured selfie can then be compared against the facial profile created during registration.
If both faces match, the rider can immediately begin working.
If they do not match—or if suspicious signals are detected—the platform can request additional verification or temporarily block access.
This approach dramatically reduces the value of account sharing.
Someone may receive the username and password.
But without matching the registered rider's face, they cannot easily begin working.
Why Facial Re-Authentication Matters
Facial re-authentication extends identity verification beyond onboarding.
Instead of asking riders to repeatedly upload identity documents, platforms can simply verify the rider's face before work begins.
A quick selfie is often enough to compare the current user with the original enrollment record.
When implemented efficiently, facial authentication strengthens account security without interrupting the rider's workflow.
More importantly, it addresses the exact problem account sharing creates.
Identity documents can be borrowed.
Passwords can be shared.
Usernames can be transferred.
A person's face cannot.
By verifying the rider immediately before work begins, platforms gain a much stronger signal that the individual using the account is the person originally verified.
Should Every Delivery Require Facial Authentication?
Probably not.
Requiring riders to complete facial authentication before every single delivery would introduce unnecessary friction and slow down legitimate users.
Instead, authentication should follow a risk-based approach.
Additional verification can be triggered when:
A rider starts work for the first time that day
The account logs in after a long period of inactivity
A new device is used
Login occurs from an unusual location
Multiple devices access the same account within a short period
The password has been reset
The payout account has changed
Multiple authentication failures occur
For normal rider activity, authentication should remain fast and seamless.
For higher-risk situations, stronger verification helps reduce account misuse without creating unnecessary friction for legitimate riders.
Identity Verification Should Extend Beyond Onboarding
Preventing rider account sharing is not about adding more verification features.
What matters is creating a connected identity verification workflow that spans the entire rider journey.
During onboarding, platforms establish a rider's identity by verifying government-issued ID documents and matching them with the rider's face.
Before a rider begins accepting deliveries, the platform should authenticate the current user through Face Authentication.
If suspicious activity or risk signals are detected, the platform should be able to trigger additional authentication or route the case for manual review.
In other words, identity verification should not be treated as a series of isolated security checks.
Instead, it should function as a connected workflow:
Onboarding → Shift Start → Risk Detection → Additional Verification
Ultimately, platforms should focus on verifying the person behind the account, not just the account itself.
From Verifying Registered Riders to Verifying Active Riders
The reason global delivery platforms are expanding facial authentication is not because onboarding verification has failed.
It's because the person using an account can change after registration.
The question platforms need to answer is no longer:
"Who registered this account?"
Instead, they need to ask:
"Is the person making deliveries today the same rider who originally registered?"
Answering that question requires connecting Identity Verification during onboarding with Face Authentication when a rider begins work.
However, adding a simple selfie check does not solve every problem.
Attackers may still attempt to bypass facial authentication using printed photos, replayed videos, or even AI-generated deepfakes.
In the next article, we'll explore how delivery platforms can defend against these presentation attacks and why Face Authentication should be combined with Liveness Detection to build a stronger identity verification workflow.