Skip to content

Invest1 publisher3 min readPublished

A verified account costs about $344, which makes onboarding KYC a purchase, not an obstacle

Resistant AI's threat intelligence team counted more than 100 storefronts and 50 Telegram channels selling verified accounts with matching paperwork. Onboarding checks are now priced, not defeated.

The Investor · Invest desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • Account farms create fake, synthetic or stolen online user profiles and sell consumer and business accounts through standalone websites, priced and packaged like a product.
  • Resistant AI is a document fraud detection and transaction monitoring software company that uses AI to uncover hidden document fraud, financial crime and money laundering.
  • Resistant AI's threat intelligence team found more than 100 standalone sites and more than 50 Telegram channels falsely advertising access to a range of platforms, from mainstream banking apps to crypto exchanges, remittance services and online marketplaces.
  • Product listings ran into the hundreds of thousands.
  • More than 3,000 institutions were affected.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

Resistant AI's threat intelligence team says it has catalogued more than 100 standalone websites and more than 50 Telegram channels advertising access to verified accounts at everything from mainstream banking apps to crypto exchanges, remittance services and online marketplaces [3]. Listings ran into the hundreds of thousands at an average price of about $344, with more than 3,000 institutions affected [4][6][5], which reframes onboarding: a check you run once at account opening is a check an attacker can buy past rather than beat.

The unit of sale is not a login. Packages routinely ship with the supporting file that makes the account survive a second look: proof of address, proof of income, source of wealth documents or business records [7]. That is a product decision, and it tells you where the reviewer is weakest.

On the consumer side, the majority of supply appears to be willing money mules reselling their own verified account data, according to Resistant AI [8], with the remainder made up of synthetic identities assembled from breach data and fully fabricated personas built on generated documents [9]. Business accounts arrive as shell registrations, forged incorporation papers, or claims of ownership over companies that already exist [10]. Sellers without real documents buy layouts from template farms, sites that sell ready-to-edit official formats [11]. Resistant AI says it has logged tools that swap faces onto selfies and defeat motion checks with deepfakes, and that when technical evasion fails the seller can simply message the original reseller to supply live proof on demand [12].

The economics are the point. Authorised push payment fraud needs thousands of accounts to layer funds through, and farms supply them [15]; at the reported average, a thousand accounts is roughly $344,000 of input cost for a layering network [21]. On the sell side, 100,000 listings at $344 is $34.4m of gross listed value, and the count reported is in the hundreds of thousands [19].

Exposure differs by model for structural reasons. Neobanks are targeted because they value low-friction, fast onboarding, so a discovered weakness can be worked at the same speed [13]. Remittance is targeted because lighter checks on the receiving side make offloading illicit funds straightforward [14].

Resistant AI's own prescription is worth separating from its sales pitch, because it sells document fraud detection and transaction monitoring [2]. The useful part is diagnostic: institutions overweight identity documents, while proof of address and proof of income files get reviewed less rigorously, which is precisely why forgers aim there [16]. The detectable patterns are repetition rather than forgery quality: the same document across multiple applications, near-identical company names already sitting in your own book, and accounts created in batches from shared devices, locations or repeated security answers [17]. The hard case is the honest document. When a real customer sells a genuinely verified account, the paperwork is authentic and a document check has nothing to find, so the evidence moves to behaviour after onboarding [18].

Two caveats. This is one vendor's count of its own crawl, and the source gives no methodology for de-duplicating storefronts or verifying that advertised inventory exists; scam-the-scammer listings are a known feature of these markets and are not separated out here [3][4].

What to watch: whether any second party corroborates the storefront and listing counts; whether the reported majority-mule mix on consumer accounts holds, since that share determines how much of the problem document checks can reach at all [8]; and, internally, what a serial-document sweep across your existing book returns, because that number is available today without buying anything [17].

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories