I worked in the fraud and security department of a financial company, We detect our unwanted ex-customers creating new accounts by:
Device
IP address
Credit card or other deposit method info
Location
Similar passwords, email addresses...
We also often ban users on VPN, throwaway or weird email domains...
We didn't have photos, but modern technology can find two similar faces just by calculating the distance between the eyes... Hope that helps!