Instant payment platforms like Pix in Brazil and CoDi in Mexico have transformed how money moves. What once took days now happens instantly. For consumers and businesses, that speed delivers real benefits: lower fees, fewer intermediaries, and payments that simply work. It is no surprise these systems are now embedded in everyday economic life, from street vendors to large retailers.
The faster and more seamless a payment becomes, the more valuable it is to criminals who rely on urgency, social engineering, and misdirection. Fraud adapts to the intricacies of instant payment platforms, and this is not a Latin American story alone. It is playing out wherever instant payment rails become the default, from Brazil and Mexico to the US, India, and the eurozone. Increasingly common scams on Pix and CoDi show how traditional fraud controls struggle when there is no meaningful window to intervene after a payment is sent.
Pix is Brazil's national instant payment system, launched by the Central Bank of Brazil in November 2020. It enables real-time, 24/7 account-to-account transfers between individuals and businesses, with payments settling in seconds rather than days.
Users initiate transfers using phone numbers, email addresses, national ID numbers, or QR codes, typically free of charge for consumers. Pix is deeply integrated into Brazilian banking apps and widely used for everyday transactions, from utility bills to peer-to-peer payments. By 2025, Pix processed 79.8 billion transactions for the year, moving roughly R$35.4 trillion, and monthly volume was approaching 8 billion transactions by year-end. It now reaches an estimated 93% of Brazil's adult population, more than 175 million users.
CoDi (Cobro Digital) plays a similar role in Mexico. Developed by Banco de México, it allows users to make payments via QR codes using their existing bank accounts, processed through Mexico's SPEI real-time interbank payment system, so funds move instantly between banks.
Unlike Pix, CoDi's adoption has been slow relative to its ambitions. Launched in 2019 with a target of 18 million users within a year, CoDi had reached only 21.8 million validated accounts and 17.8 million cumulative transactions by September 2025, six years after launch, an average of just 875 pesos per transaction across the platform's lifetime. Recognizing CoDi's limited traction, Banco de México introduced Dinero Móvil (DiMo) in 2023, a simpler phone-number-based transfer system that has grown faster, surpassing 7 million users in its first year. Both run on the same underlying SPEI infrastructure and share the same fraud dynamics described in this article.
From a technical and operational standpoint, both systems share several defining characteristics:
These features make Pix and CoDi popular, but they also reshape the fraud landscape.
The point of failure shifts upstream, to how users are prompted, manipulated, or misdirected before they ever tap “send.”
Pix and CoDi are useful case studies precisely because they are not unique. More than 80 countries now operate some form of real-time payment scheme, and the same structural weakness, irrevocable settlement with no meaningful recovery window, shows up on every one of them.
|
Platform |
Region |
Scale |
Fraud pressure point |
|---|---|---|---|
|
Pix |
Brazil |
79.8 billion transactions in 2025, 93% of adults |
28 million Pix-related fraud cases, Jan to Sept 2025 |
|
CoDi and DiMo |
Mexico |
21.8 million CoDi accounts, DiMo growing faster since 2023 |
Social engineering via QR manipulation and fake receipts |
|
FedNow and RTP |
United States |
Over 1,000 institutions live on FedNow, RTP supports transfers up to $10 million |
Some institutions report as little as a six-second window to authorize a transaction |
|
UPI |
India |
Roughly 49% of global real-time payment volume, over 700 million transactions a day |
Roughly 10.64 lakh (1.06 million) fraud incidents reported in FY26 through November |
|
SEPA Instant |
Eurozone |
Mandatory receiving since January 2025, mandatory sending and Verification of Payee since October 2025 |
EBA warns fraud risk can run up to 10 times higher on instant rails than on standard transfers |
The Pix model is also spreading directly. Colombia's Bre-B, launched in June 2025, was modeled explicitly on Pix, and instant payment infrastructure is expanding across Panama, Peru, Bolivia, Paraguay, Venezuela, and Ecuador through regional partnerships. We covered how that regional shift is playing out for fraud teams in scam prevention, bank collaboration, and instant payments in Mexico and Colombia.
For banks and PSPs, the takeaway is not that any one platform is unusually vulnerable. It is that instant settlement itself, wherever it is deployed, removes the buffer that traditional fraud controls were built around.
A recent Tiinside Brasil story highlighted a report by Brazil’s Association for the Defense of Personal and Consumer Data (ADDP) that Pix-related cases reached 28 million cases between January and September 2025, significantly outpacing other reported scam categories.
Source: ADDP survey data (Jan–Sept 2025), reported by Tiinside Brasil. Categories may not be mutually exclusive.
The same report found financial fraud accounts for roughly 47% of all digital crime reported in Brazil, and that adults over 50 make up around 53% of victims.
Fraud on platforms like Pix and CoDi relies on tactics like persuasion, urgency, and the fact that the victim is the one initiating the payment. That distinction places these scams firmly in the category of authorized push payment (APP) fraud, which is notoriously hard for banks and financial institutions to detect.
One common pattern is impersonation-driven urgency. Victims are contacted by someone posing as bank support, a merchant, or a trusted service provider and told that an issue must be resolved immediately. The solution, almost invariably, involves sending a Pix or CoDi transfer to a “temporary” or “safe” account.
An interesting one is the fake receipt scam. Fraudsters send victims a forged confirmation screen or PDF that closely resembles a legitimate Pix transfer receipt, often via WhatsApp. Sellers are persuaded that payment has already been made and release goods or services before checking their balance.
Another frequent pattern involves marketplace and rental scams. Fraudsters advertise goods or services on legitimate platforms, move the conversation to private messaging, and request payment via Pix or CoDi to secure the deal. Once funds are sent, the seller disappears.
There’s also the potential to manipulate QR codes in online listings or physical locations. Fraudsters can then temporarily redirect payments for goods or services to accounts they control. Users might believe they’re paying legitimate merchants, but instead they send funds directly to criminals.
The scale this can reach was demonstrated in October 2025, when Brazil's Federal Police executed the second phase of Operation Magna Fraus, dismantling a group accused of diverting more than R$813 million from accounts across multiple banks and payment institutions by exploiting gaps in Pix transfers. A single organized operation moving over R$800 million illustrates why these are not isolated consumer scams so much as an organized fraud economy built around instant rails.
Regulators across every major instant payment market are converging on the same conclusion from different directions: detection has to move earlier than the transaction, because reimbursement alone cannot keep pace with irrevocable settlement.
Brazil's central bank created the Pix Special Refund Mechanism (MED) in 2021, allowing fraud victims to formally request a refund, with funds blocked at the receiving institution once a claim is filed and both banks given seven days to evaluate it. Under BCB Resolution 589, all Pix participants were required to offer self-service MED functionality within their apps by October 2025, and an upgrade known as MED 2.0, expected in early 2026, is designed to trace and block fraudulent transfers across up to five layers of accounts, a direct response to how quickly funds get layered across mule accounts once they land.
In the eurozone, the EU's Instant Payments Regulation made receiving instant euro transfers mandatory from January 2025 and made sending them, alongside a Verification of Payee (VoP) check that confirms a payee's name matches their account before a transfer is authorized, mandatory from October 2025. The European Banking Authority has been explicit that fraud risk on instant rails can run up to ten times higher than on standard transfers, which is exactly why VoP was made a mandatory pillar of the regulation rather than an optional control.
The UK took a different route, mandating shared liability between sending and receiving banks for authorized push payment fraud rather than a verification check alone. We go deeper on how that scheme has performed since launch, and what it reveals about the limits of reimbursement as a strategy, in APP fraud reimbursement covers losses without preventing fraud. In the US, the picture is different again: there is no federal reimbursement mandate, but Nacha's 2026 credit-push fraud monitoring rules now require both sending and receiving institutions on the ACH network to actively monitor for fraud, a shift we cover for US financial institutions specifically, along with the wider liability question playing out through litigation in section 230, scam liability, and what it means for US banks.
Four different regulatory paths, one shared diagnosis: verification, liability-sharing, and monitoring mandates are all attempts to compensate for the fact that once an instant payment settles, there is essentially nothing left to intervene on.
Platforms like Pix and CoDi have good intentions behind them, and it is worth noting that they are not uniquely vulnerable to fraud. However, the popularity of platforms like these exposes structural weaknesses that will surface wherever instant payments become the default. Here are five important takeaways:
Changes in behavior, interaction patterns, counterparty relationships, and account usage often precede fraud on Pix and CoDi by days or weeks. But for banks and PSPs, these indicators are fragmented across internal systems, customer touchpoints, and external signals.
This is where pre-fraud intelligence becomes essential. Rather than asking whether a single outgoing payment from a bank account looks risky, fraud teams need the ability to assess whether an account is becoming risky, whether it is drifting toward victimhood, mule activity, or laundering use. We cover how that shift changes existing transaction monitoring and strengthen transaction monitoring with continuous account intelligence.
We designed our Continuous Account Intelligence Platform for exactly this challenge. By continuously monitoring accounts and evaluating events across channels and counterparties, we help banks and payment providers classify accounts based on emerging risk. This makes it possible to intervene earlier, apply friction proportionately, and take action before fraudulent instant payments are ever initiated.
The core difference is the recovery window. Traditional payment rails leave hours or days between initiation and settlement, giving banks time to flag and hold suspicious transfers. Instant payment platforms like Pix, CoDi, FedNow, and SEPA Instant settle in seconds, so by the time a fraud signal is recognized, the funds have often already been layered across several accounts or converted into cryptocurrency.
Every major platform faces the same structural exposure, though the scale differs. Brazil's Pix recorded 28 million fraud-related cases between January and September 2025 alone, reflecting its scale as the world's most widely adopted instant payment system. India's UPI, which handles roughly half of global real-time payment volume, reported over a million fraud incidents in the most recent fiscal year. The common factor is not the platform's design so much as the size and speed of the rail it runs on.
It helps, but it is not a complete solution. Verification of Payee, mandatory in the eurozone since October 2025 and used in various forms elsewhere, confirms that an account number matches the stated recipient's name, which catches misdirected payments and some impersonation scams. It does nothing to stop a victim who has been socially engineered into knowingly sending money to an account that genuinely belongs to a fraudster or a mule, which is the more common pattern behind Pix and CoDi scams.
Almost every instant payment scam still needs somewhere for the money to land before it disappears further. Mule accounts absorb, fragment, and disperse funds within the narrow window before recovery becomes possible. Because a mule account's inbound and outbound activity can look identical to legitimate use, distinguishing an unwitting victim from a witting or complicit participant requires looking at the account's broader behavioral history, not just the transaction itself.
The shift has to happen upstream of the payment. That means continuously classifying accounts based on behavioral drift, counterparty patterns, and cross-channel signals, rather than scoring each transaction in isolation at the moment it is initiated. Institutions that build this capability can intervene while there is still time to act, rather than processing a claim after the funds are already gone.