Acoru Blog & Fraud Insights

Pix, CoDi, and the evolution of instant payment fraud

Written by Acoru | Feb 23, 2026, 2:45:01 PM

Instant payment platforms like Pix in Brazil and CoDi in Mexico have transformed how money moves. What once took days now happens instantly. For consumers and businesses, that speed delivers real benefits: lower fees, fewer intermediaries, and payments that simply work. It is no surprise these systems are now embedded in everyday economic life, from street vendors to large retailers.

The faster and more seamless a payment becomes, the more valuable it is to criminals who rely on urgency, social engineering, and misdirection. Fraud adapts to the intricacies of instant payment platforms, and this is not a Latin American story alone. It is playing out wherever instant payment rails become the default, from Brazil and Mexico to the US, India, and the eurozone. Increasingly common scams on Pix and CoDi show how traditional fraud controls struggle when there is no meaningful window to intervene after a payment is sent.

Key takeaways

  • Instant payment fraud is structurally different from traditional payment fraud. Once funds settle, which now happens in seconds, post-transaction recovery and reimbursement processes become blunt instruments.
  • This is a global pattern, not a regional one. More than 80 countries now operate real-time payment schemes, and every major rail, Pix, CoDi, FedNow, RTP, UPI, and SEPA Instant, is dealing with some version of the same fraud problem.
  • Brazil recorded 28 million Pix-related fraud cases between January and September 2025 alone, according to Brazil's Association for the Defense of Personal and Consumer Data.
  • Authorization is no longer a reliable indicator of legitimacy. Victims are frequently the ones initiating the transfer, which places most instant payment fraud in the authorized push payment category, historically the hardest kind for banks to detect.
  • Regulators are converging on the same answer from different directions: Brazil's MED refund mechanism, the EU's Verification of Payee mandate, the UK's APP reimbursement regime, and the US's Nacha credit-push monitoring rules all push the same message, prevention has to move earlier than the transaction itself.
  • Mule activity becomes harder to distinguish from normal behavior on instant rails. Without account-level classification, victims, witting participants, and complicit mules can all look identical in a single transaction.

How Pix and CoDi Work

 

Pix is Brazil's national instant payment system, launched by the Central Bank of Brazil in November 2020. It enables real-time, 24/7 account-to-account transfers between individuals and businesses, with payments settling in seconds rather than days.

Users initiate transfers using phone numbers, email addresses, national ID numbers, or QR codes, typically free of charge for consumers. Pix is deeply integrated into Brazilian banking apps and widely used for everyday transactions, from utility bills to peer-to-peer payments. By 2025, Pix processed 79.8 billion transactions for the year, moving roughly R$35.4 trillion, and monthly volume was approaching 8 billion transactions by year-end. It now reaches an estimated 93% of Brazil's adult population, more than 175 million users.

CoDi (Cobro Digital) plays a similar role in Mexico. Developed by Banco de México, it allows users to make payments via QR codes using their existing bank accounts, processed through Mexico's SPEI real-time interbank payment system, so funds move instantly between banks.

Unlike Pix, CoDi's adoption has been slow relative to its ambitions. Launched in 2019 with a target of 18 million users within a year, CoDi had reached only 21.8 million validated accounts and 17.8 million cumulative transactions by September 2025, six years after launch, an average of just 875 pesos per transaction across the platform's lifetime. Recognizing CoDi's limited traction, Banco de México introduced Dinero Móvil (DiMo) in 2023, a simpler phone-number-based transfer system that has grown faster, surpassing 7 million users in its first year. Both run on the same underlying SPEI infrastructure and share the same fraud dynamics described in this article.

From a technical and operational standpoint, both systems share several defining characteristics:

  • Immediate settlement, with no meaningful recall window once a payment is sent
  • Strong authentication, typically via bank-app credentials and device binding
  • Broad accessibility, requiring no separate wallets or third-party apps
  • High transaction velocity, enabling frequent, low-value transfers at scale

These features make Pix and CoDi popular, but they also reshape the fraud landscape.
The point of failure shifts upstream, to how users are prompted, manipulated, or misdirected before they ever tap “send.”

Instant payment fraud is a global pattern, not a regional one

Pix and CoDi are useful case studies precisely because they are not unique. More than 80 countries now operate some form of real-time payment scheme, and the same structural weakness, irrevocable settlement with no meaningful recovery window, shows up on every one of them.

Platform

Region

Scale

Fraud pressure point

Pix

Brazil

79.8 billion transactions in 2025, 93% of adults

28 million Pix-related fraud cases, Jan to Sept 2025

CoDi and DiMo

Mexico

21.8 million CoDi accounts, DiMo growing faster since 2023

Social engineering via QR manipulation and fake receipts

FedNow and RTP

United States

Over 1,000 institutions live on FedNow, RTP supports transfers up to $10 million

Some institutions report as little as a six-second window to authorize a transaction

UPI

India

Roughly 49% of global real-time payment volume, over 700 million transactions a day

Roughly 10.64 lakh (1.06 million) fraud incidents reported in FY26 through November

SEPA Instant

Eurozone

Mandatory receiving since January 2025, mandatory sending and Verification of Payee since October 2025

EBA warns fraud risk can run up to 10 times higher on instant rails than on standard transfers

 

The Pix model is also spreading directly. Colombia's Bre-B, launched in June 2025, was modeled explicitly on Pix, and instant payment infrastructure is expanding across Panama, Peru, Bolivia, Paraguay, Venezuela, and Ecuador through regional partnerships. We covered how that regional shift is playing out for fraud teams in scam prevention, bank collaboration, and instant payments in Mexico and Colombia.

For banks and PSPs, the takeaway is not that any one platform is unusually vulnerable. It is that instant settlement itself, wherever it is deployed, removes the buffer that traditional fraud controls were built around.

Common Pix and CoDi Scam Patterns

 

A recent Tiinside Brasil story highlighted a report by Brazil’s Association for the Defense of Personal and Consumer Data (ADDP) that Pix-related cases reached 28 million cases between January and September 2025, significantly outpacing other reported scam categories.


Source: ADDP survey data (Jan–Sept 2025), reported by Tiinside Brasil. Categories may not be mutually exclusive.

The same report found financial fraud accounts for roughly 47% of all digital crime reported in Brazil, and that adults over 50 make up around 53% of victims.

Fraud on platforms like Pix and CoDi relies on tactics like persuasion, urgency, and the fact that the victim is the one initiating the payment. That distinction places these scams firmly in the category of authorized push payment (APP) fraud, which is notoriously hard for banks and financial institutions to detect.

 

Impersonation-driven scams

One common pattern is impersonation-driven urgency. Victims are contacted by someone posing as bank support, a merchant, or a trusted service provider and told that an issue must be resolved immediately. The solution, almost invariably, involves sending a Pix or CoDi transfer to a “temporary” or “safe” account.

 

Fake receipt scams

An interesting one is the fake receipt scam. Fraudsters send victims a forged confirmation screen or PDF that closely resembles a legitimate Pix transfer receipt, often via WhatsApp. Sellers are persuaded that payment has already been made and release goods or services before checking their balance.

 

Marketplace and rental scams

Another frequent pattern involves marketplace and rental scams. Fraudsters advertise goods or services on legitimate platforms, move the conversation to private messaging, and request payment via Pix or CoDi to secure the deal. Once funds are sent, the seller disappears.

 

QR code manipulation

There’s also the potential to manipulate QR codes in online listings or physical locations. Fraudsters can then temporarily redirect payments for goods or services to accounts they control. Users might believe they’re paying legitimate merchants, but instead they send funds directly to criminals.

The scale this can reach was demonstrated in October 2025, when Brazil's Federal Police executed the second phase of Operation Magna Fraus, dismantling a group accused of diverting more than R$813 million from accounts across multiple banks and payment institutions by exploiting gaps in Pix transfers. A single organized operation moving over R$800 million illustrates why these are not isolated consumer scams so much as an organized fraud economy built around instant rails.

 

How regulators are responding

Regulators across every major instant payment market are converging on the same conclusion from different directions: detection has to move earlier than the transaction, because reimbursement alone cannot keep pace with irrevocable settlement.

Brazil's central bank created the Pix Special Refund Mechanism (MED) in 2021, allowing fraud victims to formally request a refund, with funds blocked at the receiving institution once a claim is filed and both banks given seven days to evaluate it. Under BCB Resolution 589, all Pix participants were required to offer self-service MED functionality within their apps by October 2025, and an upgrade known as MED 2.0, expected in early 2026, is designed to trace and block fraudulent transfers across up to five layers of accounts, a direct response to how quickly funds get layered across mule accounts once they land.

In the eurozone, the EU's Instant Payments Regulation made receiving instant euro transfers mandatory from January 2025 and made sending them, alongside a Verification of Payee (VoP) check that confirms a payee's name matches their account before a transfer is authorized, mandatory from October 2025. The European Banking Authority has been explicit that fraud risk on instant rails can run up to ten times higher than on standard transfers, which is exactly why VoP was made a mandatory pillar of the regulation rather than an optional control.

The UK took a different route, mandating shared liability between sending and receiving banks for authorized push payment fraud rather than a verification check alone. We go deeper on how that scheme has performed since launch, and what it reveals about the limits of reimbursement as a strategy, in APP fraud reimbursement covers losses without preventing fraud. In the US, the picture is different again: there is no federal reimbursement mandate, but Nacha's 2026 credit-push fraud monitoring rules now require both sending and receiving institutions on the ACH network to actively monitor for fraud, a shift we cover for US financial institutions specifically, along with the wider liability question playing out through litigation in section 230, scam liability, and what it means for US banks.

Four different regulatory paths, one shared diagnosis: verification, liability-sharing, and monitoring mandates are all attempts to compensate for the fact that once an instant payment settles, there is essentially nothing left to intervene on.

Lessons for instant payment fraud prevention

Platforms like Pix and CoDi have good intentions behind them, and it is worth noting that they are not uniquely vulnerable to fraud. However, the popularity of platforms like these exposes structural weaknesses that will surface wherever instant payments become the default. Here are five important takeaways:

  1. Speed collapses recovery
    When payments settle in seconds, post-transaction controls and reimbursement processes become blunt instruments. Once funds move, the opportunity to intervene is largely gone.
  2. Authorisation is no longer a reliable indicator of legitimacy
    Pix and CoDi scams show how easily users can be manipulated into initiating transfers themselves. Strong authentication, device binding, and verified identities do little to help when the victim is convinced that sending money is the correct action. From the system’s perspective, nothing is technically wrong. The payment is legitimate in form, even if fraudulent in substance.
  3. The most meaningful fraud signals appear upstream
    Sudden urgency, changes in payment patterns, new counterparties, or account activity that reflects social engineering rather than organic use, transaction monitoring alone struggles to capture this context. We break down what those upstream indicators typically look like in payment fraud red flags.
  4. Mule activity becomes harder to distinguish from normal behaviour
    Victims, witting participants, and complicit mules may all initiate legitimate-looking payments. Without account-level classification and longitudinal analysis, financial institutions are left reacting to outcomes rather than understanding intent.
  5. Pix and CoDi demonstrate that fraud is increasingly ecosystem-wide
    Scams originate across messaging apps, marketplaces, and social platforms. For banks and PSPs watching the growth of instant payments globally, the challenge is clearly adapting fraud prevention to this new dynamic, a theme we explore further in reframing fraud prevention around the full customer journey.


Account-level signals that precede instant payment fraud

Changes in behavior, interaction patterns, counterparty relationships, and account usage often precede fraud on Pix and CoDi by days or weeks. But for banks and PSPs, these indicators are fragmented across internal systems, customer touchpoints, and external signals.

This is where pre-fraud intelligence becomes essential. Rather than asking whether a single outgoing payment from a bank account looks risky, fraud teams need the ability to assess whether an account is becoming risky, whether it is drifting toward victimhood, mule activity, or laundering use. We cover how that shift changes existing transaction monitoring and strengthen transaction monitoring with continuous account intelligence.

We designed our Continuous Account Intelligence Platform for exactly this challenge. By continuously monitoring accounts and evaluating events across channels and counterparties, we help banks and payment providers classify accounts based on emerging risk. This makes it possible to intervene earlier, apply friction proportionately, and take action before fraudulent instant payments are ever initiated.

Get your demo here.

 

Frequently asked questions

What makes instant payment fraud different from traditional payment fraud?

The core difference is the recovery window. Traditional payment rails leave hours or days between initiation and settlement, giving banks time to flag and hold suspicious transfers. Instant payment platforms like Pix, CoDi, FedNow, and SEPA Instant settle in seconds, so by the time a fraud signal is recognized, the funds have often already been layered across several accounts or converted into cryptocurrency.

Which instant payment platforms are most affected by fraud?

Every major platform faces the same structural exposure, though the scale differs. Brazil's Pix recorded 28 million fraud-related cases between January and September 2025 alone, reflecting its scale as the world's most widely adopted instant payment system. India's UPI, which handles roughly half of global real-time payment volume, reported over a million fraud incidents in the most recent fiscal year. The common factor is not the platform's design so much as the size and speed of the rail it runs on.

Does verifying the payee's name prevent instant payment fraud?

It helps, but it is not a complete solution. Verification of Payee, mandatory in the eurozone since October 2025 and used in various forms elsewhere, confirms that an account number matches the stated recipient's name, which catches misdirected payments and some impersonation scams. It does nothing to stop a victim who has been socially engineered into knowingly sending money to an account that genuinely belongs to a fraudster or a mule, which is the more common pattern behind Pix and CoDi scams.

How does mule activity fit into instant payment fraud?

Almost every instant payment scam still needs somewhere for the money to land before it disappears further. Mule accounts absorb, fragment, and disperse funds within the narrow window before recovery becomes possible. Because a mule account's inbound and outbound activity can look identical to legitimate use, distinguishing an unwitting victim from a witting or complicit participant requires looking at the account's broader behavioral history, not just the transaction itself.

What can financial institutions do if they cannot rely on post-transaction controls?

The shift has to happen upstream of the payment. That means continuously classifying accounts based on behavioral drift, counterparty patterns, and cross-channel signals, rather than scoring each transaction in isolation at the moment it is initiated. Institutions that build this capability can intervene while there is still time to act, rather than processing a claim after the funds are already gone.