← All posts
Security

Fraud Patterns We Block in 2026 (And How They Evolved)

An honest look at the fraud patterns that target digital marketplaces, how they have changed over the past three years, and how we defend against them.

KYC Marts Trust & Safety··10 min read

Fraud in digital marketplaces is a moving target. Patterns that dominated three years ago are mostly extinct. Patterns that were exotic in 2024 are now the standard playbook. Anyone running a serious marketplace has to keep up, because every dollar of fraud that gets through is paid for by honest users in the form of higher costs and worse experience. This post is an honest look at what we are seeing in 2026 and what we do about it.

Pattern one: account takeover via reused credentials

Credential reuse is the oldest threat on the internet, and it is still the most common entry point for account takeover. Attackers run lists of email-password pairs leaked from unrelated breaches against any platform that accepts them. The hit rate is low per attempt and devastating in aggregate. The user reused a password from a forum that was breached in 2022, and three years later that password unlocks their marketplace account.

We defend against this by refusing common passwords at signup, requiring multi-factor authentication for sensitive actions, running passive checks against known breach corpora, and aggressively rate-limiting login attempts at the IP, device, and account level. We also force a password reset whenever we detect a credential pattern that matches a fresh leak. None of these defences are individually exotic; together they neutralise the vast majority of takeover attempts before they cause damage.

Pattern two: synthetic identity at signup

Synthetic identity is the practice of building a "person" out of stitched-together data points: a real-looking name, a believable address, a phone number that passes verification, a face that comes from a generative model. The synthetic identity then onboards onto the platform and is used either to commit fraud directly or to launder fraudulent activity through clean-looking accounts.

The generative-AI era has made this attack significantly cheaper and significantly more convincing. Selfie verification that worked in 2023 fails routinely against modern synthetic faces. Document verification that worked in 2023 fails against modern forged documents. We have responded by layering liveness checks that test for behavioural signals harder to spoof than appearance, by cross-referencing identity data against multiple authoritative sources, and by treating any single-source verification as preliminary rather than complete.

Pattern three: handover-window deception

This pattern is specific to our category. A seller delivers an account that initially appears to match the listing. The buyer inspects it, sees what they expected, and releases the escrow. Hours or days later, the account changes in some way - a recovery email gets triggered, a flagged review escalates, a previously-hidden restriction surfaces - and the buyer realises they paid for something that does not actually work the way it appeared to.

We defend against this by extending dispute windows on high-risk categories, by requiring sellers to provide evidence of account health that goes beyond surface appearance, and by monitoring post-release activity for signs of seller-side sabotage. We also blacklist sellers who exhibit even a single instance of this pattern. The economics of catching it once and pricing it into the rest of the platform are simply better than tolerating it.

Pattern four: collusion rings

Collusion rings involve multiple accounts coordinating to inflate trust signals - fake reviews, fake purchases, fake disputes designed to extract refunds. These rings used to be obvious because the accounts behaved too similarly. Modern rings deliberately vary their behaviour to evade detection, using residential proxies, varied device fingerprints, and randomised activity schedules.

Detection here is statistical rather than per-account. We look at the graph of relationships between accounts, the timing of activity, the consistency of writing style across reviews, and the correlation of trades that should be independent. When a cluster of accounts behaves more like one entity than several, we investigate. When we confirm collusion, we remove the entire cluster simultaneously rather than picking off accounts individually, because partial enforcement only teaches the ring how to hide better next time.

Pattern five: social engineering against support

The customer support channel is one of the most attractive attack surfaces in any platform, because a successful social engineering attempt against a support agent can bypass technical controls that would otherwise hold. Attackers research target accounts, craft plausible stories, and apply emotional pressure to convince agents to bypass verification, reset credentials, or release funds.

We defend against this with a rigid script that gives support agents no discretion on sensitive actions, with separation of duties so that no single agent can complete a sensitive change alone, and with continuous training on the latest social-engineering patterns. We also run periodic red-team exercises where our own staff attempts to social-engineer our own support team. The results are uncomfortable and instructive in equal measure.

Pattern six: laundering through legitimate trades

Some attackers do not want to defraud the platform; they want to use the platform to legitimise funds that came from elsewhere. They buy and sell at face value, treat the marketplace as a cleaning step, and disappear once the funds have moved through. This is harder to detect than direct fraud because every individual trade looks normal.

Detection here relies on behavioural patterns over time, on relationships between accounts that should be unrelated, and on screening against the same sanctions and adverse-media data sources that banks use. We file reports with the relevant authorities when patterns rise above a threshold. The platform has no interest in being a laundering venue, and we are happy to lose the volume to keep the platform clean.

What we are watching for in late 2026

Emerging patterns include AI-generated phishing campaigns targeting specific users with personalised lures, deepfake video evidence in support tickets, and increasingly sophisticated bot networks that mimic human navigation patterns with near-perfect accuracy. We are investing in detection for each of these, and we expect to write more publicly as the patterns mature and as our defences solidify.

What you can do

Use a unique, strong password for the platform. Turn on multi-factor authentication. Never share credentials with anyone, including someone claiming to be from our support team. Verify any unusual instructions through a known channel before acting. Report suspicious behaviour as soon as you see it, even if you are not sure.

Most fraud is opportunistic. The minute you make yourself harder to target than the next person, the attacker moves on. Basic hygiene does almost all of the work, and the platform's controls handle the rest. We will keep improving our side of the equation. The combination is what keeps the marketplace clean.

Ready to buy or sell on KYC Marts?

Browse verified listings or contact us on WhatsApp at +44 7474 711525 or Telegram @verifiedmarts to confirm an order.

Continue reading