PIX Fraud 2026: Are Your Fraud Controls Ready for the Next Generation of Instant Payment Scams?
Pix Fraud 2026
Are Your Fraud Controls Ready For The Next Generation Of Instant Payment Scams?
The Irreversibility Problem
By the time a Pix alert fires, the money has already gone. The rail settles in seconds and leaves almost nothing to recover, so the control has to sit before the money moves.
Since 13 October 2025, Banco Central has made that compulsory. Resolução BCB nº 501 created a duty to reject payment transactions addressed to demand deposit, savings or prepaid payment accounts where there is founded suspicion of fraud.
Join Shufti for a 60 minute session built for senior fraud and risk leaders at Brazilian banks, neobanks, payment institutions, digital wallets and acquirers. We look at what has already taken effect, why fraud on this rail defeats controls that passed the audit, and how to test whether your own detection is ready?
Why does this matter?
The duty to reject has been live for almost a year
Art. 2º-A puts the obligation on the receiving institution and requires the account holder to be notified. Most fraud teams have spent the past year choosing founded suspicion factors, documenting them, getting them signed off, and rebuilding the complaints process around payments that were wrongly rejected.
2026 has been a schedule rather than a forecast
Layered tracking became mandatory under MED 2.0 in February. Resoluções BCB nº 552 and 553 took effect in March. Sections of the DICT Operational Manual v8.5 came into force on 1 September. A control programme still planning against next year is already behind.
Pix fraud passes identity checks you currently run
This is authorised fraud. The real customer, on a known device, completes a real authentication, and every identity control returns a pass. Engenharia social is the driver, and adding more identity verification does not address with it. A threshold makes a statement about a transaction. Pix fraud makes a statement about a person.
The account that received the money belongs to someone in the room
A conta laranja is a customer of a regulated institution, and the duty to reject now reaches that end of the transfer too. The money rarely stops at the first account, so a control that closes the case at the block never sees where it went. Fraud teams and AML teams are usually looking at two ends of the same account, and what falls in the gap between them is the part nobody owns.
Reserve your spot
Related Events
LIVE EVENT
PIX Fraud 2026: Are Your Fraud Controls Ready for the Next Generation of Instant Payment Scams?
LIVE EVENT
First Annual Fintech Executive Roundtable in Cyprus | 2025
LIVE EVENT
Innovation Roundtable Summit 2025: Build vs Buy vs Partner vs Prompt
LIVE EVENT
Meet Shufti at the UK AI Showcase, London Tech Week 2026
LIVE EVENT
Built by Shufti: A Podcast on Compliance Lifecycle
20th August
Online
LIVE EVENT
The Lifecycle of a Compliant Crypto Transfer : Travel Rule, Wallet Verification & Counterparty Risk
LIVE EVENT
Beyond the First Check: How AMLR Extends KYC Across the Customer Lifecycle
Launch Verification Instantly
Get access to Shufti’s Self-Service Portal and start verifying users with flexible, usage-based pricing.
Get Started



















