Fraud Prevention / Digital Trust
July 9, 2026
10 minutes

The Saúde Sim Case Shows Why Digital Fraud Threatens SMB Survival

This article was developed based on the documentary A Nova Economia do Engano (The New Economy of Deception), produced by Prosa Press. The content brings together experts in fraud prevention, digital security, and business strategy, including Marcelo Souza, VP of Product at Certta; Leonardo Sica, president of the São Paulo Bar Association (OAB SP), Ergon Cugler, FGV researcher, Bruno Araújo, former Operations Director at Saúde Sim, José Oliveira, CTO at Certta, and Victor Thomazetti, Head of Digital Security at Itaú Unibanco.

In just a few years, Saúde Sim built an operation serving close to 72,000 members and moving approximately R$120 million a year. The business model expanded access to supplementary health coverage. The structure looked solid. Then a series of frauds began to compromise the operation's sustainability, including:

  • Reimbursement fraud
  • Manipulation of clinical records
  • Misuse of health plans
  • Schemes to improperly inflate billing

According to the Instituto de Estudos de Saúde Suplementar, in partnership with Ernst & Young, losses caused by fraud in the supplementary health sector reached R$34 billion in 2023.

The number helps gauge the size of a problem that goes beyond recorded cases. Many companies shut down before the impact is even captured in the statistics.

The reality is not limited to healthcare either. IBM Security research shows that 62% of cyberattacks target small and medium businesses. The reason is not just financial resources. Smaller operations tend to run on leaner structures, less integration between systems, and reduced capacity to respond quickly when a suspicious pattern appears. It is exactly this combination that turns fraud into an operational problem before it becomes a financial one.

A problem that goes beyond healthcare

Contrary to popular belief, companies rarely fail because of a single major scam. The wear happens gradually. Each instance of fraud raises operating costs, erodes trust among customers, partners, and suppliers, requires new checks, and slows down processes that used to be simple.

Once that cycle sets in, the damage stops being confined to the bottom line. It starts to affect the company's own ability to operate.

The documentary A Nova Economia do Engano uses the Saúde Sim case to discuss exactly this shift. Fraud is no longer a risk handled only by security or technology teams. Today, it influences business decisions, customer experience, financial sustainability, and operational continuity.

Drawing on the analysis by experts featured in the documentary, this article discusses how digital crime became professionalized, why small and medium-sized businesses became preferred targets, and what role a trust infrastructure plays in building operations that can respond to a constantly changing environment.

How Fraud Destroys an Operation from Within

Companies rarely go into crisis after a single fraud incident.

The wear is gradual, not sudden.

Most of the time, the wear happens little by little. An improper payment triggers an audit. A tampered document leads to another review step. An irregular registration increases the volume of manual checks. Processes that used to run smoothly come to depend on constant verification, while operating costs climb and trust among the parties involved begins to break down.

The impact goes beyond financial losses. When fraud becomes recurring:

  • Decisions start being made under suspicion
  • Teams spend more time validating cases than growing the operation
  • Partners get monitored more closely
  • Customers face slower processes

The entire environment becomes more expensive and less efficient.

What Happened at Saúde Sim

In the documentary A Nova Economia do Engano, Bruno Araújo, the company's former Operations Director, says the warning signs showed up in different forms:

  • Providers who altered the weight of cancer patients to inflate billing for high-cost medication
  • Cases of twins using the same health plan
  • Charges for consultations that never took place

"We found everything from cases where a provider altered a cancer patient's weight to bill more for medication, to cases of one twin using the other's health plan. The company's sustainability was corroded by these scams, one after another." — Bruno Araújo, former Operations Director at Saúde Sim

None of these incidents, on its own, explained the scenario the insurer faced. The problem was how often they came up and their cumulative effect on the operation. Each new case demanded more checks, more controls, and more resources to confirm what had once been treated as routine. As financial losses grew, so did the effort needed to keep the operation running.

Bruno Araújo sums up this process by saying fraud changes the relationship between everyone in the chain.

"We were passionate about the mission of expanding access to healthcare. But once trust is broken, every invoice becomes a question mark, and the damage becomes systemic."

This might be one of the least discussed effects of fraud. It does not just hit financial metrics. It compromises the predictability of the operation. Once trust disappears, every new interaction needs confirmation, every document demands more scrutiny, and every process starts taking longer than it should.

That is the point where fraud stops being a security incident and starts affecting the company's ability to grow, serve customers, and sustain the business itself.

Fraud as a Service: The Professionalization of Digital Crime

For a long time, running a large-scale scam required technical knowledge, infrastructure, and time. That barrier has dropped.

Fraud as a Service: An Organized Market

Today, tools, databases, forged documents, and attack templates circulate freely in specialized communities, cutting the effort needed to run increasingly sophisticated frauds. The result is a landscape where new variations emerge quickly and can be replicated by different groups almost immediately.

Ergon Cugler, a researcher at FGV's DesinfoPop Lab, tracks this shift by analyzing underground markets operating on digital platforms.

"We used to talk about one individual selling to another. Now we see communities selling to large audiences, which results in much better executed scams."

According to the researcher, on Telegram alone, the supply of counterfeit medication and fraudulent medical documents has grown more than twentyfold since 2018. 

The figure shows how digital crime stopped relying on isolated efforts and started operating as an organized network for distributing tools, information, and services.

In the security market, this model became known as Fraud as a Service. In this format, specialized groups develop different stages of the fraud and make them available to third parties:

  • Leaked databases
  • Forged documents
  • Bot infrastructure
  • Phishing campaigns
  • Ready-to-use synthetic identities

Whoever executes the scam no longer needs to master the entire process, they just need to combine these pieces. This specialization has sped up how quickly new techniques reach live operations.

Why Small and Medium Businesses Are More Exposed

Large companies have spent the past few years strengthening their prevention structures, driven by transaction volume, regulatory requirements, and the financial impact fraud represents. Small and medium businesses, on the other hand, tend to run with smaller teams, less integration between systems, and less capacity to keep up at the same pace.

That gap in maturity creates an especially favorable environment for fraudsters. The lower the ability to spot patterns, share risk signals, and respond quickly to new approaches, the higher the operation's exposure tends to be. The challenge stops being about blocking a specific attack and becomes about keeping up with an evolving threat.

Fraud and Scams Call for Different Responses, but They Are Part of the Same Problem

Not every financial loss happens the same way. In some cases, the criminal directly compromises a system. In others, they convince a person to make a decision that favors the attack. Both situations cause damage, but they call for different forms of prevention.

Two Examples, One Verification Gap

In the documentary A Nova Economia do Engano, this difference recurs.

At Saúde Sim, part of the irregularities involved manipulating billing information. Changes to medical records, registration inconsistencies, and misuse of identities exploited weaknesses in validation processes and in how information moved between different systems.

In the legal sector, the mechanism usually follows a different path. Leonardo Sica, president of the São Paulo Bar Association, says one of the most common scams happens when criminals contact clients pretending to be the lawyer handling their case and ask for payments via Pix, citing court fees or the release of funds as justification.

"The most common scam is someone posing as your lawyer, reaching out to you, and asking for fees or court costs. It takes advantage of speed. A WhatsApp message, a Pix transfer, and it is done in seconds."

Although they use different strategies, both examples share one thing in common. Both exploit verification gaps. In the first case, there are no mechanisms in place to validate critical information before it produces financial effects. In the second, the victim lacks enough elements to confirm whether the person on the other end of the conversation is really who they claim to be.

What Is a Trust Infrastructure

This scenario shows that protecting an operation is not just about blocking intrusions or spotting forged documents. It also requires validating identities, reading behavioral signals, and analyzing the context in which each interaction happens. This combination is exactly what supports a trust infrastructure.

Instead of relying on a single technology or a single validation step, a trust infrastructure brings together different signals to support each decision. Documents, identity, behavior, device, usage history, and transaction context stop being analyzed in isolation and begin to form a single risk assessment.

This approach lets the level of verification match the situation at hand. A low-risk interaction can proceed with little to no friction. A request that carries unusual signals may require additional validation before it goes through.

Balancing Friction and Experience

Marcelo Souza, VP of Product at Certta, sums up this balance when discussing one of the main challenges fraud prevention teams face.

"It is a tradeoff between the amount of friction and layers of protection versus usability. The ideal world is one where we can run silent fraud prevention, silent authentication. I would not necessarily need to ask the user to do anything. I have the data, I have the technology, I could run all these cross-checks behind the scenes. That is even technically feasible at this point, but part of our job is finding the best balance between friction and experience."

This balance explains why more mature operations stopped concentrating their efforts on a single layer of protection. The challenge became coordinating different verification mechanisms to respond to the risk each interaction presents, while preserving the experience for legitimate users and improving the ability to spot out-of-pattern behavior before it turns into a loss.

An Integrated Operation Reduces Blind Spots, Regardless of Industry

Fraud takes a different shape depending on the segment it targets. The mechanisms used against a health insurer are not exactly the same ones seen at a law firm or a financial institution. Even so, a pattern repeats itself.

Attacks thrive when important information stays siloed, when systems do not share context, and when decisions get made from incomplete signals.

The Scale of the Problem

In the first half of 2025, Brazil recorded more than 314 billion cyberattack attempts. 

Beyond the direct impact of fraud, studies show that every real lost tends to generate additional costs tied to investigation, operational recovery, legal expenses, and support for affected customers.

For large organizations, these losses tend to get absorbed by more robust structures. For small and medium businesses, the reality is usually different. The same incident can eat into resources meant for growth or disrupt processes essential to running the business.

This is the vulnerability the Saúde Sim case brought to light. Throughout the documentary, Bruno Araújo describes how the string of frauds affected not just the company's financial results but also the relationships among everyone involved in the operation.

"The provider wants to bill more, the insurer needs to control costs, and the patient needs care. Once trust is compromised, the entire operation ends up working under pressure."

The Same Pattern Across Different Sectors

This logic is not limited to the healthcare sector:

  • Legal sector: criminals use fake identities to pose as lawyers and request improper payments, in some cases going as far as setting up fictitious law firms with forged professional records
  • Real estate: cloned documents and professional records lend an appearance of legitimacy to fraudulent deals
  • Financial sector: synthetic identities, compromised devices, and stolen credentials continue to be used to open accounts, request credit, and move funds improperly

The examples change. The principle stays the same: the lower the ability to gather scattered information and read it together, the higher the odds that important signals go unnoticed.

Reducing Blind Spots with Integrated Verification

It is precisely to reduce these blind spots that more mature operations have adopted an integrated approach to verification. Instead of analyzing identity, documents, behavior, and devices as separate steps, a trust infrastructure consolidates these signals into a single decision layer. The goal is not to add checks indiscriminately, but to use the available context to define which validations actually make sense for each interaction.

This approach makes it possible to respond in proportion to the risk presented, cutting friction for legitimate users while expanding the ability to spot behavior inconsistent with the operation's history. More than adding new tools, resilient operations depend on the ability to make these tools share context and produce consistent decisions. This integration is what turns isolated signals into operational intelligence before they turn into losses.

When Artificial Intelligence Speeds Up Both Sides of the Fight

Artificial Intelligence has changed the speed at which fraud evolves. Activities that once required technical knowledge, time, and access to specialized tools can now be performed by many more people. Synthetic documents, personalized messages, fake identities, and social engineering campaigns can be produced in minutes and adapted quickly based on how victims or companies respond.

AI Lowered the Barrier to Entry for Crime

José Oliveira, CTO at Certta, notes that this shift has lowered the barrier to entry for anyone looking to run a scam.

"What we see in the market is high adoption of the most modern technologies among fraudsters. They were already doing this, but access used to be far more limited, more costly, and required more technical knowledge. Today, with generative AI, anyone can create synthetic documents and identities quickly and easily, which democratizes access to the technology, for better and for worse."

This shift changes the logic of fraud prevention. If attacks can change in a matter of minutes, responses based solely on manual review or static rules begin to lose effectiveness. The gap between a new technique emerging and the ability to identify it keeps shrinking.

Why Defense Needs AI Too

For this reason, more mature operations have also started building Artificial Intelligence into their prevention strategies. Not to replace specialists or automate every decision, but to expand the ability to analyze signals, spot behavioral deviations, and adapt verification mechanisms as new risks emerge.

Victor Thomazetti, Head of Digital Security at Itaú Unibanco, explains that this principle already guides how the institution develops its digital products.

"Today, in a modern security function, you cannot think about fraud prevention and security without keeping usability and customer experience in mind. We need to find the sweet spot, where we deliver the best security, the best perceived security, and the best user experience."


The same Artificial Intelligence that expands what fraudsters can do can also strengthen prevention when it is applied to read risk signals, cut down on manual review, and adjust decisions based on the behavior observed in the operation.

The deciding factor is no longer simply using AI. It becomes the ability to combine data, context, and different verification mechanisms to respond to new fraud attempts at the speed they emerge.

This coordination is exactly what turns Artificial Intelligence into part of a trust infrastructure rather than treating it as a standalone tool.

Digital Fraud Is No Longer Just a Security Problem

The Saúde Sim case shows that fraud rarely brings down a company all at once. The impact tends to build up through slower processes, higher operating costs, eroded trust, and less predictable decision-making.

This pattern shows up across different industries. Healthcare, the legal market, financial institutions, and service companies all face attacks that exploit technical and behavioral weaknesses, using tools that become increasingly accessible and sophisticated.

In this landscape, adding more checks does not solve the problem by itself. Resilient operations depend on the ability to gather scattered information, read risk signals, and adjust decisions based on the context of each interaction. This principle is what drives a trust infrastructure.

When identity, documents, behavior, and context get analyzed together, prevention stops depending on a single technology and becomes part of the operation's own architecture.

As digital crime keeps evolving, the difference between companies that can respond to this landscape and those that keep piling up losses will depend less on how many tools they use and more on how well they coordinate them.

Fraud Prevention Starts Before the First Incident

Learn how Certta brings identity, documents, behavior, and context together into a single trust infrastructure, letting different verification mechanisms work in coordination across the entire operation.

Explore Certta's Verification Intelligence Hub

FAQ

What happened to Saúde Sim?

Saúde Sim was a popular health insurance provider based in Brasília that served around 72,000 members at its peak. The documentary A Nova Economia do Engano shows how different types of fraud contributed to undermining the operation's sustainability, turning the case into an example of the challenges mid-sized companies face.

What is Fraud as a Service?

Fraud as a Service is a model where specialized groups offer tools for running scams, such as leaked databases, forged documents, bot infrastructure, and social engineering campaigns. It lowers the technical barrier for new criminals and speeds up how fast fraud evolves.

Why are small and medium businesses targeted more?

Smaller companies tend to run with fewer staff, less integration between systems, and fewer resources to respond quickly to new threats. These traits increase exposure to attacks and make recovery harder once an incident happens.

Does biometrics solve digital fraud?

Not on its own. Biometrics is an important verification layer, but it works best combined with other signals, such as document validation, behavioral analysis, transaction history, and device information.

What is a trust infrastructure?

A trust infrastructure brings together different verification mechanisms into a single decision architecture. Instead of analyzing documents, identity, and behavior separately, these signals get evaluated together to define the right level of verification for each interaction.

How does Artificial Intelligence affect fraud prevention?

Artificial Intelligence accelerates both the evolution of attacks and their identification. When built into a prevention strategy, it helps read risk signals, spot unusual patterns, and adapt verification based on the behavior observed in the operation.

Glossary

Trust infrastructure: An architecture that brings together different verification mechanisms into a single decision layer, allowing identity, documents, behavior, and context to be analyzed together.

Fraud as a Service: A business model used by criminal groups that offer tools, data, and infrastructure for running fraud at scale.

Social engineering: A set of techniques used to get people to share information, make payments, or take actions that favor an attack.

Synthetic identity: An identity built by combining real and fake information to simulate a legitimate user during registration, authentication, or credit applications.

Identity verification: A process that combines different evidence to confirm whether a person really is who they claim to be during a digital interaction.

Silent authentication: A strategy that uses signals collected during browsing and user behavior to validate identity without requiring extra steps whenever possible.

Verification Intelligence Hub: The model Certta uses to coordinate different verification technologies within a single trust infrastructure, allowing decisions to adjust based on the risk each interaction presents.

Sources and Studies Cited

  • Prosa Press. A Nova Economia do Engano.
  • Instituto de Estudos de Saúde Suplementar (IESS), in partnership with Ernst & Young (EY). Study on losses caused by fraud in the supplementary health sector.
  • IBM Security. Report on cyber threats targeting small and medium businesses.
  • Fundação Getulio Vargas (FGV). Research from the DesinfoPop Lab on illicit digital markets and disinformation.
  • Interviews given by Marcelo Souza (Certta), Bruno Araújo (Saúde Sim), Leonardo Sica (OAB São Paulo), José Oliveira (Certta), and Victor Thomazetti (Itaú Unibanco) for the documentary A Nova Economia do Engano.