Invest1 distinct publisher3 min readPublished
Q6 Cyber logged 216.2 million confirmed compromises in eighteen months, and Verafin will route them into a queue designed around transactions that already settled. The average stolen-check listing surfaces ten days early.
The Investor · Invest desk
Compiled by The InvestorSomething wrong?How this is made
A queue is a scheduling problem before it is a detection problem, and Q6's own tally sets the scale: 1.2 million compromised checks, 57 million unique credentials and 158 million payment cards over eighteen months [4] comes to 216.2 million findings [14], roughly 395,000 a day [15], and divided evenly across the 2,800-plus members of Verafin's consortium [5] that is about 141 items per institution per day [16]. Even division is the wrong model, obviously, since a member holding the consortium average of about $4.6bn in assets [17] and roughly 304,000 counterparties [18] will match only a thin slice of any day's haul. The useful point is that the matching layer, not the collection, decides how much of this ever reaches a human.
That is the mechanism worth watching, or rather the more interesting version of it. An AML alert normally arrives bolted to a transaction, which hands the investigator both a trigger and an exit: clear it or escalate it. A validated dark-web listing arrives with neither. What Verafin describes doing with the lead time (flag accounts, tighten controls, warn customers [20]) is not investigation so much as servicing, and servicing gets paid for in reissued cards and outbound calls. Ten days [7] is the whole budget for that work, and because the companies say intelligence reaches investigators within minutes to hours of a listing appearing [10], almost all of the window survives the plumbing.
Check fraud is the sensible wedge typology, since Verafin's own 2026 report puts its growth at a 20.4 per cent annualized rate over two years [6], which compounds to about 45 per cent cumulatively [19], and a returned item is one of the few fraud events where the instrument is physically in transit long enough for ten days to be actionable.
The most likely outcomes split three ways. The signals could arrive as their own high-risk alerts inside the fraud and AML workflow [3], in which case the queue genuinely acquires a pre-transaction lane with its own staffing and its own metrics; they could arrive as enrichment fields on transaction alerts that were already firing, in which case what is being sold is a better-sourced risk score, precisely the thing Eli Dominitz says Q6 does not sell [12]; or the match rate could run high enough that servicing cost outruns avoided loss and clients quietly throttle the feed. My read, and it may be wrong, is that the second is the base case for year one and the first is the two-year product, because the enrichment path needs no new headcount and the standalone path needs a new job description.
The falsifier is narrow and named. Ten days [7] comes from a proof-of-concept average, and the reported announcement carries no pricing, no adoption count and no avoided-loss figure [21] to confirm it survives contact with production volume. Note also what Verafin declined to fund: a decade of proprietary source-building of the kind Dominitz describes [12], spending instead on the counterparty graph it already owns. Until someone publishes an action rate, 216.2 million findings [14] measures supply; it says nothing yet about value.
Ranked by verification strength, evidence, and original report placement.
Nasdaq Verafin has formed a partnership with Q6 Cyber to fold dark-web fraud intelligence into the same platform banks and credit unions already use for investigations.
Nasdaq Verafin will surface Q6 Cyber's information as high-risk alerts inside its fraud and anti-money-laundering workflow, so investigators do not have to leave the system they already use.
Q6 Cyber watches hundreds of thousands of underground sources around the clock and over the past 18 months has collected more than 1.2 million compromised checks, 57 million unique credentials and 158 million payment cards.
Nasdaq Verafin contributes a consortium network of more than 2,800 financial institutions and over 850 million counterparties, plus transaction-level context that helps teams decide which alerts deserve immediate action.
Nasdaq Verafin's 2026 Global Financial Crime Report notes that check fraud has grown at an annualized rate of 20.4 per cent over two years.
Nasdaq Verafin serves more than 2,800 institutions that together hold about $13 trillion in assets.
Distinct publishers with included, body-backed reporting in this cluster.
Follow any of these and your For You feed starts watching them — no settings page required.
invest
Alpha Modus hands 91% of itself to ten investors carrying 3,170 bitcoin1 distinct publisher
invest
IPO proceeds tripled to $205.1B, but the deal count barely moved1 distinct publisher
build
The $559M-versus-$12.3B quarter matters more than the $65B run rate4 distinct publishers
product
Pasqal reaches Nasdaq with $140m less than its filings projected1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One trade write-up of what the two sellers said
Every figure that carries this story — 216.2 million findings, ten days of warning, $13 trillion in member assets, 20.4 percent check fraud growth — arrives through a single Crowdfund Insider account of the companies' own announcement, and the growth rate is cited to Verafin's own report. The two quoted voices are the vendor's product lead and the supplier's CEO. The one measurement that would matter operationally, the ten-day average, comes from a proof-of-concept with no stated sample, period or participants.
Announced into a large installed base, used by nobody named
The distribution channel is real and large — Verafin already sits in the workflow of more than 2,800 institutions — but the reporting shows no one actually receiving the feed. No launch date, no pilot participants beyond an anonymous proof-of-concept, no count of clients enabling it, no dollar of loss avoided. What exists today is a signed partnership and a described capability.
Sober framing wrapped around unaudited numbers
Credit where due: the story explicitly declines to promise the end of financial crime, and 'minutes to hours' is a delivery claim rather than a prevention claim. The overstatement sits in the arithmetic nobody interrogates. Two hundred sixteen million findings sounds like coverage until you divide it — roughly 395,000 a day, about 141 per member institution if evenly spread — at which point the unanswered question is how many become alerts a human sees. And a ten-day average from one unsized pilot is doing the work of a product guarantee in the headline number.
Both sides sell it; the market statistic is house-made
Q6 Cyber gains a route into 2,800 institutions it could not reach alone; Verafin gains a differentiator in the typology its own annual report identifies as the fastest-growing. The only people speaking are Colin Parsons and Eli Dominitz, and the number establishing the urgency comes from Verafin's 2026 report. Nothing that would cost either party anything to admit — price, expected alert volume, false-positive rate — is in the record.
Sure what was announced, unsure what it does
The shape of the deal is not in doubt: two named firms, three data categories, alerts inside an existing investigation platform, no terms. Our confidence drops sharply the moment the story moves from what was signed to what it changes, because that leap rests on one pilot and one publisher.