Digital Trust / Fraud Prevention
July 15, 2026
7 minutos

When Fraud Moves Faster Than the Operation: Intelligent Adaptation During Traffic Spikes

Traffic spikes and professional fraudsters put operations at risk. Learn what it takes to keep fraud from staying one step ahead.

This article draws on the Special Edition "The Architecture of Intelligent Verification," produced by TEC Institute in partnership with Certta and published by MIT Technology Review Brasil. The report brings together specialists in digital security, fraud prevention, and consumer behavior, including Fabiana Rivero, Superintendent of Registration Governance and Risk, Marcelo Sousa, VP of Product at Certta, and Juliana Silveira D'Addio, security culture specialist.

Black Friday, major concerts, highly anticipated launches, year end. During periods of peak demand, companies used to concentrate their efforts on scaling capacity, ensuring availability, and tracking performance indicators. Today, that planning has gained a new variable: the advance of fraud, pushing companies to rethink their strategies both in daily operations and in moments of elevated risk.

While consumers shop, travel, register, or try to secure a ticket, fraudsters adjust their attacks almost as fast as user behavior changes. Artificial intelligence has cut the time needed to build new campaigns, adapt approaches, and test variations at scale. According to the World Economic Forum, 72% of companies reported an increase in cyber risk over the past year, with digital fraud, phishing, and identity theft among the top threats.

In a landscape where operations need to respond to constant change, response capacity is what now separates prepared operations from those still relying on models built for a more predictable environment.

When Traffic Spikes Stop Being the Biggest Problem

Companies that operate acquiring businesses handle large transaction volumes every day. High demand dates increase that load, but rarely represent a completely new scenario. What really changes is the speed at which the operation's behavior starts to fluctuate.

Within minutes, new purchase patterns emerge: unusual access times, spikes concentrated in specific regions, and a higher volume of fraud attempts riding along with that movement.

Major events act as a standing test of security architecture. They reveal how far an operation can go in responding when volume, behavior, and risk shift at the same time.

Fabiana Rivero, Superintendent of Registration Governance and Risk, sums up this challenge from the perspective of someone who needs to keep an operation running exactly when it is under the most pressure.

"Over the years, we have built our structure around strong partners and a resilient architecture, because acquiring cannot go down at year end or during that concert or event when the customer needs to swipe a card at the terminal." — Fabiana Rivero, Superintendent of Registration Governance and Risk

Rule based models start losing effectiveness in exactly this kind of situation. They were built to recognize relatively stable patterns. Today, those patterns can shift several times within a single day.

This problem is no longer occasional or limited to specific sectors. Attacks are growing not just in volume, but in variety and unpredictability.

Part of that variety goes beyond transactional fraud. Traffic spikes also open the door to infrastructure attacks such as DDoS (distributed denial of service) and malicious bot traffic, which overload systems and can hide fraud attempts inside a high volume of legitimate access. Addressing transactional fraud alone leaves the operation exposed to this other type of attack precisely during the moments of highest risk.

Fraud as a Service: When Running a Scam Becomes a Scalable Business

The speed at which attacks evolve does not depend on artificial intelligence alone. It also reflects a shift in how digital crime now operates.

In recent years, digital crime has stopped concentrating every stage of an attack within a single specialized group. Instead, an underground market has emerged where different services can be bought separately. Some sellers offer leaked databases, others provide infrastructure for phishing campaigns, bot networks, ready made fake pages, and even message templates built with generative AI.

This model became known as Fraud as a Service.

In practice, running a scam now requires far less technical skill than it did a few years ago. Much of the infrastructure is already available, packaged for purchase and adaptable to different targets. That lowers the barrier to entry for new criminals and speeds up the emergence of new attack variations.

For fraud prevention teams, the consequence shows up directly in the operation. Attempts stop following a relatively known set of patterns and start changing far more often. A strategy that worked last week can lose its effectiveness within days.

The Role of Verification Intelligence Hubs in the Digital Economy

In this scenario, adding new tools does not always increase protection. In many cases, it only adds more integrations, rules, and decisions that need to be coordinated. That fragmentation is exactly what a Verification Intelligence Hub is built to reduce.

Instead of connecting dozens of solutions independently, the hub brings together signals from different technologies to support a single decision logic. That lets the operation respond more consistently as risk changes, without relying on isolated adjustments from each vendor.

This approach also improves visibility into what is happening across the operation. When different layers share information, it becomes easier to spot behavior changes, revise rules, and adapt responses before a fraud pattern spreads.

Trust infrastructure stops depending solely on the efficiency of each individual tool. It starts depending on the ability to make those tools work as one integrated system.

This coordination logic also extends to more specific layers of protection, such as tokenization of sensitive data and multi factor authentication (MFA). Rather than operating in isolation, these technologies become additional signals within the same decision architecture, strengthening protection without multiplying the integrations the operation has to manage.

World Cup 2026: An Environment That Concentrates Behavior Change

The 2026 World Cup brings together conditions that make any digital operation more complex. For the first time, the tournament is held simultaneously across three countries, with different time zones, regulations, payment methods, and travel patterns.

Over just a few weeks, millions of people book flights, reserve accommodations, buy insurance, exchange currency, purchase tickets, and access digital services in unfamiliar locations. Much of this happens under time pressure, on mobile devices, and on unfamiliar networks.

This combination deeply changes the operation's expected behavior. The rise in transactions matters, but it does not explain the complexity of the period on its own.

Brazilian media has already been covering this trend. A NordVPN survey found that 34% of people reported contact with scams linked to the 2026 World Cup, compared with 19% before the 2022 tournament, nearly double in four years. This is exactly the kind of scenario Certta executives, including Marcelo Sousa, have been asked about by the press.

For companies that handle identity, payments, or registration every day, telling a legitimate behavior change apart from a fraud attempt becomes an even more delicate task.

A Verification Intelligence Hub contributes exactly at this point. By combining different risk signals within a single trust infrastructure, it allows decisions to adjust to the behavior observed in the operation, preserving the user experience without giving up security.

Intelligent Verification Also Improves the Experience on the Other Side

When an operation tries to solve every risk by adding new verification steps, user experience is usually the first thing to suffer.

More questions, more screens, and more interruptions do not always mean more security. In many cases, they only increase drop off and create friction points that affect legitimate users.

That is why an intelligent verification strategy does not depend only on the quality of the technologies used. It depends on the ability to choose the right verification for each situation.

Marcelo Sousa, VP of Product at Certta, describes this principle as follows.

"Intelligent verification means using the best tools available to prevent fraud in a coordinated way, with solutions adjusted to each user's risk profile, taking the specific transaction and context into account." — Marcelo Sousa, VP of Product at Certta

This logic changes how decisions get made. Instead of applying the same flow to everyone, the operation starts to consider who the user is, the type of transaction, the history of that interaction, and the signals observed at that moment.

This approach also directly shapes the user experience. As Certta's products evolved, the team found that most of that drop off traced back to how information was presented rather than to the verification technology itself.

"We noticed that for Gen Z users, if the button on the screen isn't clear, they tend to give up or even tap the wrong one. So we started removing certain text from the journey and focusing more on the experience itself, with intuitive buttons and smoother flows." — Marcelo Sousa

The fix wasn't about adding new steps. It was about removing obstacles.

User research, focus groups, A/B tests, and successive adjustments simplified navigation and reduced confusion throughout the journey. According to Sousa, this work raised onboarding conversion by nearly twenty percentage points.

The result shows that security and experience do not have to compete. When decisions are better distributed across the operation, legitimate users face fewer barriers, while fraud attempts receive verification matched to the level of risk they present.

The Human Factor Is Also Part of Fraud Prevention Strategy

Not every fraud exploits a technical flaw. Many exploit something far more predictable: how people make decisions, especially under pressure. Lines, travel, time zone changes, notifications arriving all at once, fear of missing out on a purchase, and pressure to act fast all shrink the time available to think things through calmly.

This is exactly the kind of environment where fraudulent messages find room to work. A fake payment alert, a link promising priority access to tickets, or a supposed booking update all take advantage of a moment when the user is more likely to act before checking.

Juliana Silveira D'Addio, security culture specialist, draws attention to this dynamic when discussing how behavioral factors have moved to the center of protection strategies.

When Fast Decisions Raise the Operation's Risk

To explain this behavior, Juliana draws on the model psychologist Daniel Kahneman presents in "Thinking, Fast and Slow."

According to Kahneman, the mind switches between two modes of decision making. One is automatic, fast, and based on familiar patterns. The other demands more attention, compares information, and weighs alternatives before reaching a conclusion.

For most of the day, we rely on the automatic mode. It lets us handle simple tasks without constant effort. The problem shows up when a high pressure context demands exactly the opposite.

Fraudsters know this mechanism and build approaches designed to cut down reflection time. Messages with a sense of urgency, unexpected notifications, and requests for immediate confirmation all share one goal: prompting an impulsive response before the user questions the situation.

The shorter the gap between receiving information and acting on it, the higher these attacks tend to succeed.

Small Pauses Can Prevent Big Losses

That is why a prevention strategy cannot rely on detecting suspicious behavior alone. It can also create openings for the user to interrupt a decision made on impulse.

This is where nudges come in, a concept popularized by economist Richard Thaler. Instead of restricting choices, a nudge reorganizes the environment to favor safer decisions.

In practice, that can mean highlighting the cancel button on an operation flagged as unusual, requesting an extra confirmation before an atypical transfer, or explaining in plain language why a given action requires additional verification.

These are small changes, but they raise the odds that the user will notice signals that might have gone unseen just seconds earlier.

Technology still plays an essential role. The difference is that it no longer operates only behind the scenes of the operation. It also accounts for how people perceive information and make decisions.

Security Is Also Learned

This logic applies to consumers and internal teams alike.

Campaigns built solely on alerts or risk lists tend to lose their effect over time. When every message conveys the same sense of urgency, people stop paying attention.

Juliana argues for a different approach. Rather than relying on fear, awareness initiatives tend to work better when they use examples close to the audience's own reality, explain how specific scams operate, and point out which signals deserve attention.

The goal is helping users recognize situations that fall outside the norm before they share sensitive information, complete a payment, or click an unexpected link, without needing to become security experts themselves.

The same logic strengthens security culture inside organizations. When technology, process, and behavior become part of the same strategy, prevention stops depending on tools alone and starts involving everyone who takes part in the operation.

Integration Becomes an Operational Decision

The World Economic Forum's report reflects this shift. While 66% of organizations expect artificial intelligence to have the biggest impact on cybersecurity over the next 12 months, only 37% say they have structured processes to assess the security of these tools before deployment.

That gap points to a growing challenge: coordinating information, integrating different verification mechanisms, and adjusting decisions as operational behavior becomes a determining factor in sustaining digital trust.

Events like Black Friday, major concerts, or the World Cup only make this scenario more visible. They compress into a few days changes that many operations already face continuously.

As attacks reorganize at a growing pace, resilient operations depend on an infrastructure capable of interpreting signals, sharing context across different technologies, and adjusting responses without compromising the experience of legitimate users.

This is the logic behind a Verification Intelligence Hub. Instead of concentrating protection in a single technology or a fixed validation flow, it coordinates different layers of verification so each decision accounts for the risk present at that moment.

Once that responsiveness becomes part of the architecture, security stops depending solely on the efficiency of one specific tool. It starts depending on the whole operation's ability to respond to change with consistency.

Frequently Asked Questions

What is a Verification Intelligence Hub?

A Verification Intelligence Hub brings together different verification technologies within a single trust infrastructure. Instead of connecting isolated solutions, it coordinates risk signals, integrates data, and adapts decisions based on the transaction profile and the behavior observed in the operation.

What does Fraud as a Service mean?

Fraud as a Service describes a model in which criminals offer ready made infrastructure for running scams. Leaked databases, phishing kits, bot networks, and AI powered tools can all be rented by different groups, lowering the technical barrier for new attacks.

Why do major events increase fraud risk?

Events like Black Friday, major concerts, and the World Cup concentrate millions of transactions, registrations, and logins in a short window. Beyond the rise in volume, these moments change user behavior, creating openings for social engineering attacks and other types of fraud.

How does artificial intelligence influence digital fraud?

Artificial intelligence makes it possible to build phishing campaigns, adapt messages, and test different approaches within minutes. This speeds up how fast attacks evolve and shortens the window operations have to adjust their prevention strategies.

Can security and user experience coexist?

Yes. When a verification strategy accounts for the risk of each operation, legitimate users face less friction while suspicious cases receive additional verification. The goal is distributing validation intelligently rather than applying the same flow to everyone.

How does neuroscience contribute to fraud prevention?

Research on decision making helps explain how factors like urgency, distraction, and information overload increase vulnerability to scams. This knowledge guides the design of journeys that favor more conscious decisions and reduce impulsive action.

Do traffic spikes also increase the risk of attacks like DDoS and malicious bots?

Yes. Beyond transactional fraud, traffic spikes attract infrastructure attacks such as DDoS (distributed denial of service) and malicious bot traffic, which can overload systems and hide fraud attempts within a high volume of legitimate access.

Concepts Covered in This Article

Multi factor authentication (MFA): requiring more than one verification factor (something the user knows, has, or is) to confirm an identity, reducing the risk of unauthorized access even when a password is compromised.

Tokenization:
replacing sensitive data, such as a card number, with a code (token) that holds no value outside the context of that transaction, reducing exposure of real information in the event of a breach.

DDoS (distributed denial of service):
an attack that overwhelms a system with a massive volume of requests, usually distributed across a network of compromised devices (bots), making services slow or unavailable right when access peaks.

Verification Intelligence Hub:
an architecture that centralizes different identity, document, and behavior verification technologies and signals within a single decision layer, enabling faster and more consistent responses to changing risk.

Trust infrastructure:
the set of processes, data, and technologies that sustain continuous verification of identities and transactions, treating digital trust as a structural part of the operation rather than an additional layer of security.

Fraud as a Service:
an underground business model in which criminal groups sell or rent infrastructure for running scams, including leaked databases, phishing kits, and generative AI tools, reducing the technical knowledge needed to commit fraud.

Social engineering:
an attack technique based on psychological manipulation, in which the scammer builds a convincing narrative to get the victim to hand over data, credentials, or money voluntarily, without exploiting any technical system flaw.

Generative AI:
a category of artificial intelligence capable of creating original content, such as text, images, audio, or video, based on patterns learned from large volumes of data. In the context of fraud, it is used both to build more sophisticated attacks and to strengthen defense systems.

Nudges:
small changes to the design of an interface or process that steer users toward safer decisions without restricting their choices, such as highlighting a cancel button or requiring extra confirmation for unusual transactions.

System 1 and System 2:
a model proposed by psychologist Daniel Kahneman to describe two modes of human thinking. System 1 is fast, automatic, and intuitive. System 2 is slow, deliberate, and analytical. Decisions made under pressure tend to rely on System 1, which increases vulnerability to scams.

A/B testing:
an experimentation method in which two versions of a product or flow are tested at the same time with different user groups, making it possible to identify which one performs better before a final decision.

Phishing:
a fraud technique that uses fake messages, emails, or websites to get victims to hand over personal data, login credentials, or financial information, usually by posing as a trusted institution.

Digital onboarding:
the process of registering and verifying a new user on a digital platform, including steps like identity validation, document collection, and account setup. It is one of the most sensitive points for balancing security and experience.

Sources and Studies Cited

MIT Technology Review Brasil, Special Edition "The Architecture of Intelligent Verification," produced by TEC.Institute in partnership with Certta.

Agência Brasil, on fraud linked to major international sporting events and the 2026 World Cup: https://agenciabrasil.ebc.com.br/economia/noticia/2026-06/fraudes-ligadas-copa-quase-dobram-e-acendem-alerta-para-2026

NordVPN survey on scams linked to the 2026 World Cup: 34% of people reported contact with this type of scam, compared with 19% before the 2022 World Cup.

World Economic Forum, Global Cybersecurity Outlook 2025: data on cyber risk, third party and vendor risk management, and AI adoption in cybersecurity. Read more at: https://reports.weforum.org/docs/WEF_Global_Cybersecurity_Outlook_2025.pdf

Daniel Kahneman, Thinking, Fast and Slow.

Richard Thaler, the concept of nudges applied to behavioral economics.

See how Certta's Verification Intelligence Hub brings together different verification technologies within a single trust infrastructure, capable of adapting decisions to the operation's behavior.

Talk to a Specialist