Invest1 distinct publisher3 min readUpdated
Resistant AI's threat intelligence team counted more than 100 storefronts and 50 Telegram channels selling verified accounts with matching paperwork. Onboarding checks are now priced, not defeated.
The Investor · Invest desk
Compiled by The InvestorSomething wrong?How this is made
Resistant AI's threat intelligence team says it has catalogued more than 100 standalone websites and more than 50 Telegram channels advertising access to verified accounts at everything from mainstream banking apps to crypto exchanges, remittance services and online marketplaces [3]. Listings ran into the hundreds of thousands at an average price of about $344, with more than 3,000 institutions affected [4][6][5], which reframes onboarding: a check you run once at account opening is a check an attacker can buy past rather than beat.
The unit of sale is not a login. Packages routinely ship with the supporting file that makes the account survive a second look: proof of address, proof of income, source of wealth documents or business records [7]. That is a product decision, and it tells you where the reviewer is weakest.
On the consumer side, the majority of supply appears to be willing money mules reselling their own verified account data, according to Resistant AI [8], with the remainder made up of synthetic identities assembled from breach data and fully fabricated personas built on generated documents [9]. Business accounts arrive as shell registrations, forged incorporation papers, or claims of ownership over companies that already exist [10]. Sellers without real documents buy layouts from template farms, sites that sell ready-to-edit official formats [11]. Resistant AI says it has logged tools that swap faces onto selfies and defeat motion checks with deepfakes, and that when technical evasion fails the seller can simply message the original reseller to supply live proof on demand [12].
The economics are the point. Authorised push payment fraud needs thousands of accounts to layer funds through, and farms supply them [15]; at the reported average, a thousand accounts is roughly $344,000 of input cost for a layering network [21]. On the sell side, 100,000 listings at $344 is $34.4m of gross listed value, and the count reported is in the hundreds of thousands [19].
Exposure differs by model for structural reasons. Neobanks are targeted because they value low-friction, fast onboarding, so a discovered weakness can be worked at the same speed [13]. Remittance is targeted because lighter checks on the receiving side make offloading illicit funds straightforward [14].
Resistant AI's own prescription is worth separating from its sales pitch, because it sells document fraud detection and transaction monitoring [2]. The useful part is diagnostic: institutions overweight identity documents, while proof of address and proof of income files get reviewed less rigorously, which is precisely why forgers aim there [16]. The detectable patterns are repetition rather than forgery quality: the same document across multiple applications, near-identical company names already sitting in your own book, and accounts created in batches from shared devices, locations or repeated security answers [17]. The hard case is the honest document. When a real customer sells a genuinely verified account, the paperwork is authentic and a document check has nothing to find, so the evidence moves to behaviour after onboarding [18].
Two caveats. This is one vendor's count of its own crawl, and the source gives no methodology for de-duplicating storefronts or verifying that advertised inventory exists; scam-the-scammer listings are a known feature of these markets and are not separated out here [3][4].
What to watch: whether any second party corroborates the storefront and listing counts; whether the reported majority-mule mix on consumer accounts holds, since that share determines how much of the problem document checks can reach at all [8]; and, internally, what a serial-document sweep across your existing book returns, because that number is available today without buying anything [17].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Account farms create fake, synthetic or stolen online user profiles and sell consumer and business accounts through standalone websites, priced and packaged like a product.
Resistant AI is a document fraud detection and transaction monitoring software company that uses AI to uncover hidden document fraud, financial crime and money laundering.
A sale rarely stops at basic login credentials; the purchased package often includes supporting paperwork such as proof of address, proof of income, sources of wealth documents or business records, so accounts continue to look legitimate under scrutiny.
With consumer accounts, the majority appear to be willing money mules reselling their own verified account data.
Other consumer supply includes synthetic identities assembled from breach data and entirely fake personas assembled from generated documents.
Business accounts come from shell registrations, forged incorporation papers, or claims of ownership over companies that already exist.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single vendor-branded source, no disclosed methodology
All claims trace to one article on sifted.eu whose research is supplied by Resistant AI, the vendor selling the detection remedy, and whose URL slug marks it as branded content. The quantitative core — storefront and channel counts, hundreds of thousands of listings, 3,000-plus affected institutions, a ~$344 average price — arrives with no sampling window, deduplication rule, definition of 'affected', or data release, and no second source in the cluster corroborates it. The qualitative mechanics (bundled supporting paperwork, mule resale, template farms, deepfake liveness bypass, sector-specific weaknesses) are internally consistent and non-extraordinary, which keeps the score above floor.
No adoption or deployment data supplied
The cluster contains no release, deployment, benchmark, pricing, licensing or usage disclosure. There is no evidence of how many institutions use the described detection controls, no vendor customer or volume figures, and no verified transaction data showing that listed accounts are actually bought and used at the stated scale. Listing counts advertised by criminal storefronts are supply-side assertions, not observed adoption, so this dimension is left unmeasured rather than inferred.
Headline precision outruns the underlying data
The framing that a verified account 'costs about $344' and that KYC is therefore a purchase rests on a single vendor's average of advertised prices, with no evidence of completed sales, no methodology behind the storefront and institution counts, and derived value figures that only scale those unverified inputs. The direction of the story — that onboarding controls are testable and repeatable at volume, and that under-reviewed non-ID documents plus willing mule resale defeat document checks — is plausible and consistent with the described mechanics, so the gap is one of overstated precision and certainty rather than a fabricated phenomenon.
Vendor-branded placement promoting its own remedy
The research, the threat framing and the prescribed controls all come from Resistant AI, which sells document fraud detection and transaction monitoring; the article names its product as the tool that compares documents across submissions, and closes with a call to action asking institutions what they are doing about the problem. The placement is branded content on sifted.eu (slug '-brnd'), and larger reported counts and prices directly increase perceived urgency for the vendor's category. No countervailing source, customer voice or competing tool appears.
Mechanics credible, numbers unconfirmed
Confidence is limited by single-source, vendor-incentivised reporting and the absence of any adoption or outcome data. The qualitative account-farm mechanics are coherent and match well-documented mule and synthetic-identity patterns, and the operational advice is independently checkable inside an institution's own data, so moderate confidence attaches to the direction of the story while the specific scale and price figures should be treated as unverified.
build
A session that read "finished" and "still executing" was a slow queue, not a dropped handshake1 distinct publisher
security
Aeternum puts botnet C2 on Polygon, and leaves defenders no domain to seize1 distinct publisher
build
The AI-training bans live on the big infrastructure blogs, not the small publications1 distinct publisher
build
The 84% a wallet will not show you: DFK Chain's sunset is an address problem1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 17, 2026