Shufti Sphere

Back
Knowledgebase

What Is Pix Fraud?

What Is Pix Fraud?
Amir RizwanAmir Rizwan OCTOBER 6, 2026 8 minutes read

What Is Pix Fraud? 

Pix changed the way payments move in Brazil. The instant payment system has allowed individuals and businesses to send and receive money within seconds at any time. However, it has also created opportunities for criminals. 

Pix fraud refers to fraudulent activity involving pix transactions, including scams that convince users to authorize payments, unauthorized transfers and misuse of accounts to receive stolen funds. Fraudsters use social engineering, account compromise, fake identities and mule accounts to move funds through the payment system.

Pix fraud is a form of real time payment fraud because criminals attempt to exploit the speed of instant transactions before suspicious activity can be identified. 

What is Pix? 

Pix is Brazil’s instant payment system developed by the Central Bank of Brazil. It enables real time transfers and payment between individuals, businesses and government entities through participating financial institutions. Pix operates continuously and allows payments to be completed immediately. The system was created to make payments faster, more accessible and easier to use across Brazil. 

Why Does Fraud Move Through Pix?

The same features that make Pix efficient for legitimate payments can also make it attractive for criminals. 

Because funds move almost instantly, fraudsters may attempt to: 

  • Trick customers into approving payments
  • Gain access to digital banking accounts
  • Use accounts controlled by criminals to receive and move funds

This creates challenges similar to other instant payment systems, including the US FedNow service, where payment speed can reduce the time available to identify and stop fraudulent activity.

How Pix Fraud Works

Pix Fraud can involve both the sender account and receiver account. 

The sending side: 

It involves the customer or account that initiates the pix transaction. 

Fraud can occur when: 

  • A customer is tricked into approving a payment through a scam or impersonation attempt. 
  • A criminal gains access to a customer’s account through account takeover fraud and initiates a Pix transfer without authorization. 

The receiving side:

The receiving side involves where fraudulent funds are sent.

Criminals may use:

  • Mule accounts to receive stolen funds 
  • Accounts created using false or stolen identity information
  • Multiple accounts to move funds and make tracing difficult

Common Types of Pix Fraud

Pix fraud can happen through different methods depending on how criminals target users and payment accounts.

Fraud Type How It Happens
Social engineering scams The sender is usually the victim. A criminal impersonates trusted people or organizations and convince the customer to authorize a pix payment. The funds are then sent to an account controlled by the fraudster. 
Account takeover fraud The sender account belongs to the victim but a criminal gains access to the account and makes the pix transfer without the customer’s knowledge. The transaction is then routed to an account used by the criminal to receive and move the funds. 
Fake payment scams Fraudsters create fake payment requests, QR codes or invoices and convince the customer to send funds to a fraudulent receiving account. 
Mule account fraud The receiving account is controlled by a mule or intermediary and is used to receive and move funds obtained through scam or unauthorized transactions. 
Identity fraud Criminals use stolen or fabricated identity information to create or access accounts that may later be used to send or receive fraudulent pix payments. 

Why is Pix Fraud Difficult to Reverse?

Pix payments are completed immediately, which means fraudulent funds can move from one  account to another within seconds. Once money has been transferred further through multiple accounts, recovering it becomes more difficult because institutions may need to trace where the funds moved after the original transaction.

If a customer believes they have been a victim of Pix fraud, they must contact their financial institution and request a return through the Special Return Mechanism (MED). The request must be submitted within 80 days of the Pix transaction. The institution then reviews the case and, if it meets the MED requirements, the receiving institution may block available funds and investigate the transaction.

Recovery is not automatic. If fraud is confirmed, the customer may receive the funds back in full or partially depending on whether money is still available in the accounts involved. If the available balance is insufficient, a full refund may not be possible.

The MED does not apply to every Pix-related issue. It is intended for fraud, scams or crimes and does not cover situations such as:

  • A customer sending Pix to the wrong person by mistake
  • Commercial disputes, such as disagreements over a product or service

Pix users should report suspected fraud as quickly as possible because faster reporting increases the possibility of blocking available funds before they are moved further. The Central Bank of Brazil has also introduced improvements to MED through MED 2.0, which aims to improve recovery by allowing institutions to trace fraudulent funds beyond the first receiving account, increasing visibility into where the money moves after the initial transfer.

What Does the Central Bank of Brazil Require for Pix Fraud Prevention?

The Central Bank of Brazil requires Pix participants to maintain fraud prevention controls designed to identify suspicious activity and reduce payment risks.

Security Controls and Fraud Risk Checks

Under Article 89 of the Pix Regulation, participants must adopt controls covering areas such as customer authentication, identifying receiving users, Pix initiation procedures, account opening, Pix key management, and the movement of funds through Pix transactions.

Participants must use fraud risk management solutions that include security information stored in DICT (Directory of Transactional Account Identifiers) and can identify atypical Pix transactions or activity that does not match a customer’s profile.

These solutions must support actions such as:

  • Applying additional authorization time for transactions suspected of fraud.
  • Rejecting transactions where there is reasonable suspicion of fraud.
  • Temporarily blocking funds linked to suspected fraudulent Pix transactions.

Participants must also maintain customer security information and update it at least every six months through consultations of security information stored in DICT. This update is separate from transaction monitoring: it keeps security information current whereas transaction monitoring focuses on identifying suspicious payment activity.

How Institutions Detect Pix Fraud

Pix fraud detection relies on analysing transaction behaviour and account information rather than reviewing payments in isolation. An unusual transaction does not automatically mean fraud. Institutions can assess unusual transfer patterns and linked account activity for investigation. Shufti’s AML transaction monitoring solution evaluates transfers against fraud and AML rules and presents alerts for review. 

Fraud checks can happen at different stages: 

Before payment authorization: institutions may assess a pix transaction before it is completed and apply additional controls if it appears unusual. 

After settlement: Institutions may investigate completed transactions using account links, fraud indicators, and transaction history. 

 

Signal What It May Indicate What the Institution May Assess Next
Unusual transaction pattern A payment may differ from the customer’s usual activity, such as a sudden change in amount, frequency or transaction behaviour.  Whether the activity has a legitimate explanation based on the customer profile and account history.
Change in customer behaviour The account activity may no longer align with previously observed usage patterns.  Whether there are signs of account compromise, customer manipulation or other risk factors. 
Links between accounts involved in suspicious activity Multiple accounts may be linked through unusual movement of funds,  Whether the linked accounts indicate coordinated fraudulent activity. 

Fraud transaction monitoring helps institutions identify activity that does not match expected behaviour and decide whether further review, additional controls or investigation is required.

Pix Fraud Compared With Other Payment Systems

Pix
(Brazil)
FedNow
(United State)
Traditional Card Payments
Payment model Instant account-to-account payments operated under the Central Bank of Brazil’s Pix framework. Instant account-to-account payments operated through the Federal Reserve’s FedNow Service.  Card payments processed through card networks, issuers and acquirers. 
Common fraud risks Social engineering scams, authorized push payment fraud, account misuse, and rapid movement of funds Fraud involving authorized and unauthorized activity in real-time transfers.  Card theft, unauthorized transactions and card-not-present fraud
Recovery process Recovery can be challenging after funds move between accounts. Eligible Pix fraud cases can be handled through the Special Return Mechanism (MED), where participating institutions review the case and process returns when conditions are met.   FedNow supports return requests between participating financial institutions. A sending institution can request the return of funds and the receiving institution reviews the request before accepting or rejecting it.  Card fraud is generally handled through dispute and chargeback processes involving the card issuer, merchant and card network. 
Fraud controls Fraud markers, account information, transaction analysis and Pix specific security measures.  Bank-level fraud controls, transaction monitoring and return request processes.  Issuer fraud monitoring network controls and dispute management processes. 

Conclusion

Pix has transformed payments in Brazil by making transfers faster and easier. However, instant payments also require strong fraud controls because criminals can move funds quickly after gaining access or manipulating users. Understanding how Pix fraud happens, how regulations address it, and how institutions detect suspicious activity helps create safer real-time payment systems.

Frequently Asked Questions

What Information Is Needed to Report Pix Fraud?

Provide the Pix transaction details and evidence of the fraud to your bank. The case can then be reported through the bank and where applicable, submitted under Special Return Mechanism (MED).

Who Is Responsible for Refunding a Fraudulent Pix Payment?

Eligible cases are handled through MED. The receiving institution may block available funds and when fraud is confirmed and funds remain available, return them to the victim. A full refund is not guaranteed if the funds are no longer available.

What Controls Help Businesses Prevent Pix Payment Fraud?

Pix participants use controls such as customer authentication, fraud risk checks, transaction analysis, additional authorized time, transaction rejection and temporary blocking of suspected fraudulent funds. They also use account DICT information to identify activity that differs from expected customer behaviour.

Disclaimer: The information provided here is for general informational purposes only and should not be treated as legal, regulatory, or business advice. Shufti Pro Limited accepts no liability for decisions or actions taken in reliance on this information.

Industry Partnerships That Create Real Value — BFC Bank, gemone, Bitget, IronFX, Rakuten, Zurich, Binance

Join Shufti’s partnership network to expand your connections, collaborate with industry leaders, and unlock new opportunities.

Pitch a piece and get a verified byline in the Media room.

Partnership Inquiries?
Email us at [email protected]

iBeta Level 1 — ISO 30107-3 Compliant iBeta Level 2 — ISO 30107-3 Compliant iBeta Level 3 — ISO 30107-3 Compliant PCI DSS SOC 2 Type 2 GDPR GDPR Fundamentals — Quality Guild KJM Age Verification CCPA / CPRA Cyber Essentials Cyber Essentials Plus
Copyright © 2026 Shufti. All rights reserved.