Probably geo IP and calculating feasible travel times. E.g. if 2 clients connect that are 50 miles away within 5 minutes creds are obviously being shared.
That would give way WAY too many false positives. If I'm watching on the bus while my wife watches at home it would trigger. Similar if we have 2 homes etc. It would also rule out anyone using VPNs etc. Seems like a complete no-go and would see a huge chunk of paying users go simply because the product is now much worse for people who are not sharing accounts. That just can't be it.
Probably they recognize ips so they'll realize that you are sharing if you are logging in from another ip over time. I think it's like at least once every 30 days or so, that'll protect most people from false positives when travelling.
They probably also fingerprint devices as well and correlate those times the devices are in the same area, etc. With user agents/device IDs, IPs and time you can work out quite a few relationships.
If I'm ever blocked on some fuzzy reason I'd leave the service in a heartbeat. If they have clear rules then at least I can somehow learn to avoid the traps, such as having to connect from an IP or having a specified number of devices. But if I can get kicked out of the service right before/in the middle of a game, then I'd quit my subscription in a hurry. They just can't use some method similar to how financial fraud is detected. But while fuzzy rules don't fly, I can't see any rigid rules that also wouldn't be a hassle for paying customers.
If you and a partner share an account and live in the same household, and someone goes on a trip and takes their phone/laptop. What then?