Fraud Article

Fraud rings don’t start with payments, they start with identities

Fraud doesn’t start with money – it starts with identity. Criminal rings scale their attacks by stealing and weaponizing “people,” long before a transaction ever happens. Stop the identity, and you stop the fraud at its source.

When we think about fraud, we often picture the final act: the drained bank account, the unauthorized credit card charge, or the massive chargeback hitting a merchant’s bottom line. We fixate on the money leaving the building. But by the time a transaction alert triggers, the damage is already done. The real crime happened days, weeks, or even months earlier.

The genesis of modern fraud rings isn’t financial, it’s existential. It starts with a stolen identity.

Sophisticated criminal organizations understand that money is just the output; identity is the input. To scale their operations, they don’t just need stolen credit cards; they need the “people” to use them. This shift in tactics has turned identity verification into the critical battleground for fraud prevention. If you can stop the fake or compromised identity at the door, you don’t just stop a transaction; you dismantle the ring.

What is a fraud ring?

A fraud ring is an organized group of criminals who work together to defraud banks, businesses, and consumers. Members split the work: some steal or buy identity information, some build synthetic identities, some open and age accounts, and others move the money or make fraudulent purchases. Because each account in the scheme looks like a separate, legitimate customer, fraud rings are much harder to spot than a single fraudster.

Common examples include account takeover rings, money mule rings that move funds through drop accounts, marketplace rings built on refund and promo abuse, and synthetic identity rings that build up credit before cashing out. Every one of these schemes depends on identities that can pass onboarding checks, which makes onboarding the best place to stop them.

The raw materials: How identities are compromised

Before a fraud ring launches an attack on a fintech platform or a marketplace, they need fuel. That fuel comes in the form of legitimate user data. The path from a real person to a tool for criminals usually begins with three primary vectors: credential stuffing, malware, and synthetic identity creation.

Credential stuffing: The brute force approach

Credential stuffing is the digital equivalent of trying every key on a keyring until one turns the lock. Because so many users recycle passwords across multiple sites, a breach at a low-security forum can compromise a high-security banking login. Fraudsters use automated bots to test millions of stolen username/password pairs against high-value targets.

When a match is found, they don’t just empty the account immediately. They often “incubate” the account, learning the user’s behavior, or sell the validated credentials on the dark web to specialized fraud rings looking for aged, legitimate accounts to launder money.

Malware: The silent observer

Malware provides a more insidious route. Info-stealers and Remote Access Trojans (RATs) infect a user’s device, silently siphoning off cookies, session tokens, and saved passwords. This allows fraudsters to bypass multi-factor authentication (MFA) by mimicking the user’s actual device and digital fingerprint.

Once they control the digital identity, the fraud ring possesses something far more valuable than a credit card number: they have a “mule” persona that looks, acts, and verifies like a real citizen.

Synthetic identities: The built-from-parts approach

A synthetic identity doesn’t belong to any one real person. Fraudsters combine stolen identity information, such as a real national ID or Social Security number, with a made-up name, address, and forged documents to create a new “person” who can pass basic checks. Fraud rings often use these identities to open credit accounts, make small purchases, and pay on time for months. Once the credit limits are high enough, the ring maxes out every account at once and disappears, leaving banks and other financial institutions with the losses. The real people whose numbers were used are victims too, and they often don’t find out for years.

Veriff Identity Fraud Report 2027

Coming this November

Learn how verified credentials are stolen, rented, and reused across platforms, and how to stop the cycle.

The lifecycle of a zombie identity

Once a fraud ring controls a set of compromised identities, they don’t limit themselves to a single industry. They maximize the return on investment (ROI) for every stolen profile. A single compromised identity often lives a triple life across different sectors, creating a tangled web of fraudulent activity.

1. The fintech beachhead

The journey often starts in fintech. Fraudsters use the stolen identity (or a synthetic one built from stolen parts) to open “drop” accounts. These are valid bank accounts used to receive and move illicit funds. Because the identity belongs to a real person with a credit history, it passes initial automated checks. These accounts become the plumbing for the entire fraud operation.

2. The crypto laundromat

To obscure the money trail, the identity moves to the crypto sector. The fraud ring opens accounts on exchanges to convert fiat currency from the fintech drop accounts into cryptocurrency. This “layering” stage makes the funds nearly impossible to trace. The strict KYC (Know Your Customer) requirements in crypto are hurdles, but armed with high-quality stolen documents and deepfake technology, rings are increasingly successful at scaling these walls.

3. The marketplace exploitation

Finally, the identity hits marketplaces and gig economy platforms. Here, the goal might be different. They might create fake seller accounts to scam buyers, or fake buyer accounts to defraud merchants. In gig economy scenarios, they might set up fake driver or courier accounts to facilitate other crimes or simply to farm referral bonuses and incentives. Common marketplace schemes include fraudulent purchases with stolen cards followed by false claims for refunds, seller accounts that take payment for goods that never ship, and promo abuse, where one ring opens dozens of accounts to claim the same sign-up offer.

This cross-sector pollination is why siloed fraud prevention fails. A “customer” who looks risky to a crypto exchange might look perfectly fine to a ride-sharing app, even though it is the same bad actor pulling the strings.

These tactics – credential stuffing, malware exploitation, and synthetic identity creation – are not theoretical; they converge in real-world attacks like the one uncovered on a major marketplace platform, where seemingly legitimate users masked coordinated criminal operations.

Case study: Dismantling a fraud ring on a marketplace platform 

At Veriff, we don’t just verify documents; we look for the subtle connections that reveal organized crime. A recent investigation into an attack on one of our  marketplace customers perfectly illustrates how fraud rings operate—and how they can be taken down.

The “Ghost” in the machine

In late 2025, we detected an anomaly during a routine check of a verification. While reviewing session media, a Veriff Verification Specialist noticed the end-user’s video appeared normal, but additional background footage captured a reflection of an unauthorized third party, acting as a handler. This was not a technical glitch, but evidence of orchestrated fraud. 

The investigation

The investigation uncovered a sophisticated collusion scheme: legitimate individuals served as fronts, while third-party facilitators directed the onboarding process from behind the scenes. Device and network intelligence revealed the scale and sophistication of the operation, exposing multiple sessions tied to the same devices despite representing different users.

The takedown

The fraud team identified over 500 accounts linked to this fraudulent activity. To neutralize the threat, we deployed a fraud logic to instantly reject any future sessions exhibiting this behaviour. We also shared actionable intelligence with the customer, enabling them to proactively block compromised accounts before they could pose real-world risks.

This case underscores Veriff’s ability to detect, analyze, and disrupt organized fraud through behavioral insight, technical forensics, and rapid, scalable intervention.

The importance of KYC and KYB in fraud prevention

This customer case proves that identity verification is not just a compliance checkbox, it is the primary firewall against organized crime.

When we talk about KYC (Know Your Customer) and KYB (Know Your Business), we often talk about regulations. But in the context of fraud rings, these processes are about disruption.

Fraud rings rely on volume. They need hundreds or thousands of active accounts to make their economics work. Robust KYC introduces friction that kills this scalability. If a fraudster needs 15 minutes and a unique device to spoof a single verification, their ROI plummets.

Effective KYC isn’t just about looking at one ID card in a vacuum. It’s about network analysis. It’s about asking:

  • Has this device been seen before?
  • Is this IP address associated with other “different” users?
  • Does the velocity of sign-ups match human behavior, or bot behavior?
  • Do these accounts share addresses, documents, or payment data with accounts already tied to fraud?
  • Answering these questions is called link analysis, and it’s the basis of fraud ring detection. It maps the relationships between accounts, devices, and identity information, so a group of users who look unrelated shows up as one ring. Each account can look clean on its own. The connections between them are what give the ring away.

By analyzing these signals during the onboarding phase, we prevent the “zombie identity” from ever entering the ecosystem.

Conclusion

The battle against fraud is shifting upstream. We can no longer wait for the chargeback to tell us we have a problem. By the time the money moves, the fraudsters have already won.

To defeat fraud rings, businesses must embed proactive identity intelligence into their onboarding and monitoring systems. This means adopting AI-driven anomaly detection to spot subtle behavioral deviations, implementing robust device and network fingerprinting, and participating in cross-platform intelligence sharing to expose hidden links between seemingly unrelated accounts. By treating identity verification not just as a compliance requirement but as a strategic defense layer, organizations can disrupt fraud rings at inception – before a single transaction is made. 

Take the next step

  1. Stay ahead of fraud trends. Subscribe to our newsletter for the latest research, data, and industry insights.
  2. See Veriff in action. Try the Identity Verification live demo and experience exactly what your users see.
  3. Talk to our team. Book a personalized demo and get answers to your specific questions.

Subscribe for insights

CTA form illustration

Start building with Veriff for free

Your journey toward faster, more accurate identity verification starts here.