SardineCon SF/2026

Learn More
The Saturday Fraud Strategist

Servicios de la dark web eluden verificaciones KYC por 150 dólares

5 min

Hace un año y medio, escribí que por unos 150 dólares cualquiera podía comprar en la dark web un servicio que eludía a un proveedor de KYC.

La gente quedó en shock.

¿Hoy? Honestamente, ya no tanto.

Ahora la amenaza es más barata, más rápida y más difícil de detectar. Las verificaciones de documentos se pueden eludir. Las selfies se pueden eludir. Incluso las pruebas de vida 3D, las que hace no tanto parecían imbatibles, se pueden eludir.

No da buena imagen.

Así que en este episodio quiero hablar de qué hacen realmente los equipos antifraude después. Porque si tu estrategia de prevención del fraude KYC todavía asume que un KYC aprobado significa un usuario limpio, ya vas atrasado.

La respuesta es la defensa en capas. Pero no la versión perezosa en la que solo compras más proveedores de KYC y esperas que alguno te salve. Hablo de una verdadera defensa antifraude multicapa: inteligencia de dispositivos, biometría del comportamiento, señales de comportamiento, inteligencia de identidad, telemetría de dispositivos, monitoreo del fraude posterior al registro y orquestación de proveedores KYC usados en la secuencia correcta.

Porque una verificación KYC es una señal. No es un veredicto.

Lo que escucharás en este episodio:

  • Un análisis de por qué prevenir la elusión del KYC se ha vuelto más difícil a medida que los kits de fraude se abaratan y se especializan
  • Por qué las verificaciones KYC, los chequeos de documentos, las selfies y la prueba de vida 3D ya no pueden cargar con toda la estrategia de prevención del fraude
  • Cómo la inteligencia de dispositivos hace preguntas distintas a las de un proveedor de KYC
  • Por qué las señales de comportamiento y la biometría del comportamiento pueden exponer lo que un chequeo de documentos pasa por alto
  • Cómo la inteligencia de identidad ayuda a conectar correos, números de teléfono, direcciones y documentación en una imagen más cohesiva
  • Por qué el monitoreo del fraude posterior al registro y el monitoreo de usuarios de alto riesgo importan después de la apertura de la cuenta
  • Cómo la verificación reforzada puede añadir fricción solo cuando el riesgo realmente lo justifica
  • Por qué la orquestación de proveedores KYC puede ser útil para un segmento pequeño de alto riesgo
  • Cómo cambia el ROI del estafador cuando los equipos antifraude dejan de depender de un único punto de falla

Una conversación práctica sobre defensa antifraude en capas, puntos ciegos operativos y por qué la detección moderna del fraude KYC depende de conectar señales en lugar de confiar en un único resultado de onboarding.

Quién debería escucharlo:

  • Líderes y operadores antifraude
  • Equipos de riesgo y cumplimiento
  • Equipos de fintech que gestionan el fraude en el onboarding y la apertura de cuentas
  • Profesionales de confianza y seguridad
  • Equipos de verificación de identidad y KYC
  • Equipos que evalúan biometría del comportamiento, inteligencia de dispositivos y detección de identidades sintéticas

Básicamente, si tu stack antifraude todavía depende en gran medida de un solo proveedor de KYC, o si la telemetría de dispositivos se recolecta pero apenas se usa, o si los equipos de onboarding y de monitoreo de transacciones siguen operando en silos, este episodio probablemente te resultará incómodamente familiar.

Honestamente, ese stack tarde o temprano falla siempre.

Notas del episodio

La detección del fraude KYC está cambiando

Los equipos antifraude necesitan dejar de tratar las verificaciones KYC como una respuesta definitiva.

El problema no es que el KYC sea inútil. El problema es que los estafadores ahora tienen kits operativos diseñados específicamente para vencer ciertos flujos de onboarding.

Si toda tu defensa depende de la estrategia de un solo proveedor de KYC, has creado un único punto de falla.

Defensa en capas

La inteligencia de dispositivos hace preguntas distintas a las de la verificación de documentos. Las señales de comportamiento hacen preguntas distintas a las de la inteligencia de identidad.

Cuando combinas esas señales con el monitoreo del fraude posterior al registro, el monitoreo de usuarios de alto riesgo y la verificación reforzada, empiezas a forzar a los atacantes a una posición operativa mucho más difícil.

Orquestación de proveedores KYC

Usar un segundo proveedor para un segmento muy pequeño de alto riesgo puede tener sentido económico real.

Conclusión clave

El fraude es economía.

Un kit de elusión de 150 dólares solo funciona si las cuentas le cierran al estafador. Cada capa que agregas es un impuesto al ROI del estafador.

Apila suficientes capas, y quizá se lleven su negocio a otra parte. Al menos esa es la idea.

¿Estoy siendo demasiado optimista? Probablemente.

Pero ese sigue siendo el juego.

¿No quieres que termine la conversación sobre mi tema favorito (y espero que también el tuyo)? Suscríbete al boletín The Saturday Fraud Strategist.

Episode transcript
Chen Zamir
Chen Zamir
00:09
A year and a half ago, I wrote that for 150 bucks, anyone could buy a service on the dark web that bypassed your KYC vendor. People were shocked. Today, nobody's shocked. It's just another Tuesday. Actually, actually, today, it's even worse. The threat got cheaper, faster, and harder to spot. The question then is, what should fraud teams do about it? Today, I want to talk about the word layering and how it can mean several things. All of them are worth considering. So let's get the easy part out of the way. Document checks can be bypassed. Selfies can be bypassed. 3D liveness checks, the ones vendors who were unbeatable just two years ago, can be bypassed. The grant rate is $150 to $600 per verified account, depending on the vendor and how many checks need to be bypassed. The fidelity is good, really good. I've seen examples of fraudsters generating high quality 3D video from faded 2D photos. So if you're still building your fraud strategy on the assumption that a clean KYC pass means a clean user, you're already behind. But that's the part nobody really disputes anymore. The harder question is, now, what? And the answer to, how do I stop these kits? Is one word: layering. Layering doesn't mean buy more KYC vendors. Layering means introducing different approaches, defenses that ask different questions about the user. Think about like this. Your KYC vendor asks one set of questions, does this face match this document? Does this document pass as a genuine one? And so on. Now, let's take device intelligence as an example. It asks something completely different. Have we seen this device before? What was it doing? Was the device tampered with? Where was it located? The fraudster who beat the document check doesn't necessarily control the device the way they think they do. Different example, behavioral signals. Does this user act like a human? Type in rhythm, pasting versus typing hesitation. I'll give you another example. Identity intelligence. Do the email, phone, and address present a cohesive identity that matches what appears in the documentation? Does it match the device intelligence with layering different detection signals? We challenge the fraudster to a level of sophistication their tools might struggle to overcome. Now there's also another kind of layering we can resort to, one that has to do with the sequence of our defenses and specifically monitoring new accounts and how they behave after sign up. What is the user actually doing, funding an account at 3am requesting a payout from a high risk foreign country. If something suspicious surfaces, you should escalate it before you allow them to exit funds from your platform. Additional friction, additional verification, or a manual reviewer who looks at it with human eyes. Now, if you've done all of that, you cover the basics, and you're starting to look at optimization. In that case, you may want to think of another layering approach that involves orchestration. Here's the thing, once you've layered your defenses, your system can do something most in skip it can identify a small segment of users who are genuinely high risk, let's say 5% or less of your total onboarding events. That's a population worth spending extra money on. For that segment, what you can do is send those events to a second KYC vendor. Now, I realize it may sound like the opposite of optimization, but hear me out. These KYC bypass kits are designed to attack specific vendors. It's very likely that they would be much less successful against others. So not only that, you run two checks, but you also run a check that the fraudster doesn't expect and isn't prepared for. And if you're able to do so quite accurately again, targeting that small, high risk segment, then you can really mess with fraudsters ROI while keeping your costs relatively low. Now let me tell you what I usually see under the hood when I look at FinTech on a KYC vendor doing all the work, device intelligence that is collected but only used, best case for multi accounting prevention silo teams that manage onboarding and transaction separately, that stack fails every time, because, let's face it, the economics of fraud are getting better for the attacker every day, a stack that is designed around a single point of failure and KYC checks are just an example will eventually meet a kit designed to defeat that specific defense. So if you only remember three things from this video, remember this, one, a KYC check is a signal, not a verdict. A clean task should raise your confidence in the user, but it shouldn't close the case. Pair it with at least two other approaches before you treat someone as trusted. Two, don't treat the different signals as check boxes you need to tick, compare identity, intelligence to your KYC results, device telemetry to known addresses. It's about cross referencing signals and building a 360, degrees cohesive view of your user. And three, if you cover the above already consider vendor orchestration. Get the layer defenses in place first. Then for that small, high risk segment, those signals identified send it through a second KYC vendor, that's where the extra cost can earn its keep. Remember, a 150 bucks kit only works if the math works for the fraudster. That means that every layer you add is a tax on their ROI stack. Enough of them, and they take their business somewhere else. And that's the whole game. I'll see you in the next one.