SardineCon SF/2026

Learn More
The Saturday Fraud Strategist

ダークウェブのサービスがKYCチェックを150ドルで回避

5 min

1年半前、私は「150ドルほどで、誰でもダークウェブでKYCベンダーを回避するサービスを買える」と書きました。

人々は衝撃を受けました。

今は?正直なところ、それほどでもありません。

今や脅威はより安く、より速く、より見つけにくくなっています。書類チェックは回避できます。セルフィーも回避できます。少し前までは無敵に見えた3Dライブネスチェックですら、回避できるのです。

格好がつきません。

そこでこのエピソードでは、不正対策チームが次に実際何をすべきかを話したいと思います。あなたのKYC不正対策戦略が「KYCを通過した=クリーンなユーザー」といまだに想定しているなら、すでに後れを取っています。

答えは多層化です。ただし、KYCベンダーを買い足してどれかが救ってくれることを祈るだけの怠惰なバージョンではありません。本当の多層不正防御のことです。デバイスインテリジェンス、行動バイオメトリクス、行動シグナル、アイデンティティインテリジェンス、デバイステレメトリー、登録後の不正モニタリング、そして正しい順序で使うKYCベンダーオーケストレーション。

KYCチェックはシグナルであって、最終判定ではないからです。

このエピソードで聞けること:

  • 不正キットが安価化・専門化するにつれてKYC回避の防止が難しくなった理由の分析
  • KYCチェック、書類チェック、セルフィー、3Dライブネスだけでは不正対策戦略全体を支えきれなくなった理由
  • デバイスインテリジェンスがKYCベンダーとは異なる問いを投げかける仕組み
  • 行動シグナルと行動バイオメトリクスが書類チェックの見落としを暴ける理由
  • アイデンティティインテリジェンスがメール、電話番号、住所、書類をより一貫した全体像へつなげる仕組み
  • 口座開設後に登録後の不正モニタリングと高リスクユーザーモニタリングが重要な理由
  • リスクが本当に正当化する場合にのみ、ステップアップ認証でフリクションを追加する方法
  • KYCベンダーオーケストレーションが小規模な高リスクセグメントに有効な理由
  • 不正対策チームが単一障害点への依存をやめると詐欺師のROIがどう変わるか

多層的な不正防御、運用上の盲点、そして現代のKYC不正検知が単一のオンボーディング結果を信じることではなくシグナルをつなぐことに依存する理由についての実践的な対話。

こんな方におすすめ:

  • 不正対策のリーダーと実務担当者
  • リスク・コンプライアンスチーム
  • オンボーディングと口座開設の不正を管理するフィンテックチーム
  • トラスト&セーフティの専門家
  • 本人確認・KYCチーム
  • 行動バイオメトリクス、デバイスインテリジェンス、合成ID検知を評価しているチーム

要するに、あなたの不正対策スタックがいまだに1社のKYCベンダーに大きく依存しているなら、デバイステレメトリーを収集してもほとんど使っていないなら、あるいはオンボーディングチームと取引モニタリングチームがいまだに縦割りで動いているなら——このエピソードは不快なほど身に覚えのある話になるでしょう。

正直なところ、そのスタックは遅かれ早かれ必ず破綻します。

エピソードノート

KYC不正検知は変わりつつある

不正対策チームは、KYCチェックを最終回答のように扱うのをやめる必要があります。

問題はKYCが無意味だということではありません。問題は、詐欺師が今や特定のオンボーディングフローを打ち破るために特化した実用キットを持っていることです。

防御のすべてが1社のKYCベンダー戦略に依存しているなら、単一障害点を自ら作ったことになります。

多層化

デバイスインテリジェンスは書類確認とは異なる問いを投げかけます。行動シグナルはアイデンティティインテリジェンスとは異なる問いを投げかけます。

これらのシグナルを登録後の不正モニタリング、高リスクユーザーモニタリング、ステップアップ認証と組み合わせれば、攻撃者を運用面ではるかに苦しい立場へ追い込み始められます。

KYCベンダーオーケストレーション

ごく小さな高リスクセグメントに2社目のベンダーを使うことは、経済的に十分理にかなう場合があります。

キーポイント

不正は経済です。

150ドルの回避キットは、詐欺師にとって計算が合う場合にしか機能しません。追加するレイヤーの一つひとつが、詐欺師のROIへの課税になります。

十分に積み重ねれば、彼らは商売を別の場所へ持っていくかもしれません。少なくとも、それが狙いです。

楽観的すぎるでしょうか?おそらくそうでしょう。

それでも、これがこのゲームなのです。

私の(そして願わくばあなたの)お気に入りのテーマについて、まだ話し足りませんか?ニュースレターThe Saturday Fraud Strategistの購読をどうぞ。

Episode transcript
Chen Zamir
Chen Zamir
00:09
A year and a half ago, I wrote that for 150 bucks, anyone could buy a service on the dark web that bypassed your KYC vendor. People were shocked. Today, nobody's shocked. It's just another Tuesday. Actually, actually, today, it's even worse. The threat got cheaper, faster, and harder to spot. The question then is, what should fraud teams do about it? Today, I want to talk about the word layering and how it can mean several things. All of them are worth considering. So let's get the easy part out of the way. Document checks can be bypassed. Selfies can be bypassed. 3D liveness checks, the ones vendors who were unbeatable just two years ago, can be bypassed. The grant rate is $150 to $600 per verified account, depending on the vendor and how many checks need to be bypassed. The fidelity is good, really good. I've seen examples of fraudsters generating high quality 3D video from faded 2D photos. So if you're still building your fraud strategy on the assumption that a clean KYC pass means a clean user, you're already behind. But that's the part nobody really disputes anymore. The harder question is, now, what? And the answer to, how do I stop these kits? Is one word: layering. Layering doesn't mean buy more KYC vendors. Layering means introducing different approaches, defenses that ask different questions about the user. Think about like this. Your KYC vendor asks one set of questions, does this face match this document? Does this document pass as a genuine one? And so on. Now, let's take device intelligence as an example. It asks something completely different. Have we seen this device before? What was it doing? Was the device tampered with? Where was it located? The fraudster who beat the document check doesn't necessarily control the device the way they think they do. Different example, behavioral signals. Does this user act like a human? Type in rhythm, pasting versus typing hesitation. I'll give you another example. Identity intelligence. Do the email, phone, and address present a cohesive identity that matches what appears in the documentation? Does it match the device intelligence with layering different detection signals? We challenge the fraudster to a level of sophistication their tools might struggle to overcome. Now there's also another kind of layering we can resort to, one that has to do with the sequence of our defenses and specifically monitoring new accounts and how they behave after sign up. What is the user actually doing, funding an account at 3am requesting a payout from a high risk foreign country. If something suspicious surfaces, you should escalate it before you allow them to exit funds from your platform. Additional friction, additional verification, or a manual reviewer who looks at it with human eyes. Now, if you've done all of that, you cover the basics, and you're starting to look at optimization. In that case, you may want to think of another layering approach that involves orchestration. Here's the thing, once you've layered your defenses, your system can do something most in skip it can identify a small segment of users who are genuinely high risk, let's say 5% or less of your total onboarding events. That's a population worth spending extra money on. For that segment, what you can do is send those events to a second KYC vendor. Now, I realize it may sound like the opposite of optimization, but hear me out. These KYC bypass kits are designed to attack specific vendors. It's very likely that they would be much less successful against others. So not only that, you run two checks, but you also run a check that the fraudster doesn't expect and isn't prepared for. And if you're able to do so quite accurately again, targeting that small, high risk segment, then you can really mess with fraudsters ROI while keeping your costs relatively low. Now let me tell you what I usually see under the hood when I look at FinTech on a KYC vendor doing all the work, device intelligence that is collected but only used, best case for multi accounting prevention silo teams that manage onboarding and transaction separately, that stack fails every time, because, let's face it, the economics of fraud are getting better for the attacker every day, a stack that is designed around a single point of failure and KYC checks are just an example will eventually meet a kit designed to defeat that specific defense. So if you only remember three things from this video, remember this, one, a KYC check is a signal, not a verdict. A clean task should raise your confidence in the user, but it shouldn't close the case. Pair it with at least two other approaches before you treat someone as trusted. Two, don't treat the different signals as check boxes you need to tick, compare identity, intelligence to your KYC results, device telemetry to known addresses. It's about cross referencing signals and building a 360, degrees cohesive view of your user. And three, if you cover the above already consider vendor orchestration. Get the layer defenses in place first. Then for that small, high risk segment, those signals identified send it through a second KYC vendor, that's where the extra cost can earn its keep. Remember, a 150 bucks kit only works if the math works for the fraudster. That means that every layer you add is a tax on their ROI stack. Enough of them, and they take their business somewhere else. And that's the whole game. I'll see you in the next one.