SardineCon SF/2026

Learn More
The Saturday Fraud Strategist

Serviços da dark web burlam verificações KYC por US$ 150

5 min

Um ano e meio atrás, escrevi que por cerca de 150 dólares qualquer pessoa podia comprar na dark web um serviço que burlava um fornecedor de KYC.

As pessoas ficaram chocadas.

Hoje? Honestamente, nem tanto.

Agora a ameaça é mais barata, mais rápida e mais difícil de detectar. Verificações de documentos podem ser burladas. Selfies podem ser burladas. Até as provas de vida 3D, aquelas que pareciam imbatíveis não faz tanto tempo, podem ser burladas.

Não pega bem.

Então, neste episódio, quero falar sobre o que as equipes antifraude realmente fazem em seguida. Porque se a sua estratégia de prevenção de fraudes KYC ainda assume que um KYC aprovado significa um usuário limpo, você já está atrasado.

A resposta é a defesa em camadas. Mas não a versão preguiçosa em que você só compra mais fornecedores de KYC e torce para que algum te salve. Falo de uma verdadeira defesa antifraude multicamada: inteligência de dispositivos, biometria comportamental, sinais comportamentais, inteligência de identidade, telemetria de dispositivos, monitoramento de fraudes pós-cadastro e orquestração de fornecedores KYC usados na sequência certa.

Porque uma verificação KYC é um sinal. Não é um veredicto.

O que você vai ouvir neste episódio:

  • Uma análise de por que prevenir o bypass de KYC ficou mais difícil à medida que os kits de fraude ficam mais baratos e especializados
  • Por que verificações KYC, checagens de documentos, selfies e prova de vida 3D não conseguem mais carregar sozinhas a estratégia de prevenção de fraudes
  • Como a inteligência de dispositivos faz perguntas diferentes das de um fornecedor de KYC
  • Por que sinais comportamentais e biometria comportamental podem expor o que uma checagem de documentos deixa passar
  • Como a inteligência de identidade ajuda a conectar e-mails, telefones, endereços e documentação em um quadro mais coeso
  • Por que o monitoramento de fraudes pós-cadastro e o monitoramento de usuários de alto risco importam depois da abertura da conta
  • Como a verificação step-up pode adicionar fricção apenas quando o risco realmente justifica
  • Por que a orquestração de fornecedores KYC pode ser útil para um segmento pequeno de alto risco
  • Como o ROI do fraudador muda quando as equipes antifraude param de depender de um único ponto de falha

Uma conversa prática sobre defesa antifraude em camadas, pontos cegos operacionais e por que a detecção moderna de fraudes KYC depende de conectar sinais em vez de confiar em um único resultado de onboarding.

Quem deveria ouvir:

  • Líderes e operadores antifraude
  • Equipes de risco e compliance
  • Equipes de fintech que gerenciam fraudes no onboarding e na abertura de contas
  • Profissionais de trust & safety
  • Equipes de verificação de identidade e KYC
  • Equipes avaliando biometria comportamental, inteligência de dispositivos e detecção de identidades sintéticas

Basicamente, se o seu stack antifraude ainda depende fortemente de um único fornecedor de KYC, ou se a telemetria de dispositivos é coletada mas quase não é usada, ou se as equipes de onboarding e de monitoramento de transações ainda operam em silos, este episódio provavelmente vai soar desconfortavelmente familiar.

Honestamente, esse stack sempre acaba falhando.

Notas do episódio

A detecção de fraudes KYC está mudando

As equipes antifraude precisam parar de tratar as verificações KYC como uma resposta final.

O problema não é que o KYC seja inútil. O problema é que os fraudadores agora têm kits operacionais projetados especificamente para vencer certos fluxos de onboarding.

Se toda a sua defesa depende da estratégia de um único fornecedor de KYC, você criou um único ponto de falha.

Defesa em camadas

A inteligência de dispositivos faz perguntas diferentes das da verificação de documentos. Os sinais comportamentais fazem perguntas diferentes das da inteligência de identidade.

Quando você combina esses sinais com o monitoramento de fraudes pós-cadastro, o monitoramento de usuários de alto risco e a verificação step-up, começa a forçar os atacantes a uma posição operacional muito mais difícil.

Orquestração de fornecedores KYC

Usar um segundo fornecedor para um segmento muito pequeno de alto risco pode fazer sentido econômico de verdade.

Principal conclusão

Fraude é economia.

Um kit de bypass de 150 dólares só funciona se a conta fechar para o fraudador. Cada camada que você adiciona é um imposto sobre o ROI do fraudador.

Empilhe camadas suficientes, e talvez eles levem o negócio deles para outro lugar. Pelo menos essa é a ideia.

Estou sendo otimista demais? Provavelmente.

Mas o jogo ainda é esse.

Ainda não quer encerrar a conversa sobre o meu assunto favorito (e, espero, o seu também)? Assine a newsletter The Saturday Fraud Strategist.

Episode transcript
Chen Zamir
Chen Zamir
00:09
A year and a half ago, I wrote that for 150 bucks, anyone could buy a service on the dark web that bypassed your KYC vendor. People were shocked. Today, nobody's shocked. It's just another Tuesday. Actually, actually, today, it's even worse. The threat got cheaper, faster, and harder to spot. The question then is, what should fraud teams do about it? Today, I want to talk about the word layering and how it can mean several things. All of them are worth considering. So let's get the easy part out of the way. Document checks can be bypassed. Selfies can be bypassed. 3D liveness checks, the ones vendors who were unbeatable just two years ago, can be bypassed. The grant rate is $150 to $600 per verified account, depending on the vendor and how many checks need to be bypassed. The fidelity is good, really good. I've seen examples of fraudsters generating high quality 3D video from faded 2D photos. So if you're still building your fraud strategy on the assumption that a clean KYC pass means a clean user, you're already behind. But that's the part nobody really disputes anymore. The harder question is, now, what? And the answer to, how do I stop these kits? Is one word: layering. Layering doesn't mean buy more KYC vendors. Layering means introducing different approaches, defenses that ask different questions about the user. Think about like this. Your KYC vendor asks one set of questions, does this face match this document? Does this document pass as a genuine one? And so on. Now, let's take device intelligence as an example. It asks something completely different. Have we seen this device before? What was it doing? Was the device tampered with? Where was it located? The fraudster who beat the document check doesn't necessarily control the device the way they think they do. Different example, behavioral signals. Does this user act like a human? Type in rhythm, pasting versus typing hesitation. I'll give you another example. Identity intelligence. Do the email, phone, and address present a cohesive identity that matches what appears in the documentation? Does it match the device intelligence with layering different detection signals? We challenge the fraudster to a level of sophistication their tools might struggle to overcome. Now there's also another kind of layering we can resort to, one that has to do with the sequence of our defenses and specifically monitoring new accounts and how they behave after sign up. What is the user actually doing, funding an account at 3am requesting a payout from a high risk foreign country. If something suspicious surfaces, you should escalate it before you allow them to exit funds from your platform. Additional friction, additional verification, or a manual reviewer who looks at it with human eyes. Now, if you've done all of that, you cover the basics, and you're starting to look at optimization. In that case, you may want to think of another layering approach that involves orchestration. Here's the thing, once you've layered your defenses, your system can do something most in skip it can identify a small segment of users who are genuinely high risk, let's say 5% or less of your total onboarding events. That's a population worth spending extra money on. For that segment, what you can do is send those events to a second KYC vendor. Now, I realize it may sound like the opposite of optimization, but hear me out. These KYC bypass kits are designed to attack specific vendors. It's very likely that they would be much less successful against others. So not only that, you run two checks, but you also run a check that the fraudster doesn't expect and isn't prepared for. And if you're able to do so quite accurately again, targeting that small, high risk segment, then you can really mess with fraudsters ROI while keeping your costs relatively low. Now let me tell you what I usually see under the hood when I look at FinTech on a KYC vendor doing all the work, device intelligence that is collected but only used, best case for multi accounting prevention silo teams that manage onboarding and transaction separately, that stack fails every time, because, let's face it, the economics of fraud are getting better for the attacker every day, a stack that is designed around a single point of failure and KYC checks are just an example will eventually meet a kit designed to defeat that specific defense. So if you only remember three things from this video, remember this, one, a KYC check is a signal, not a verdict. A clean task should raise your confidence in the user, but it shouldn't close the case. Pair it with at least two other approaches before you treat someone as trusted. Two, don't treat the different signals as check boxes you need to tick, compare identity, intelligence to your KYC results, device telemetry to known addresses. It's about cross referencing signals and building a 360, degrees cohesive view of your user. And three, if you cover the above already consider vendor orchestration. Get the layer defenses in place first. Then for that small, high risk segment, those signals identified send it through a second KYC vendor, that's where the extra cost can earn its keep. Remember, a 150 bucks kit only works if the math works for the fraudster. That means that every layer you add is a tax on their ROI stack. Enough of them, and they take their business somewhere else. And that's the whole game. I'll see you in the next one.