When a clean fraud funnel is the warning sign
- Kevin Jones

- 43 minutes ago
- 5 min read
Gerardo Prieto, Chief Information Security Officer at The Mill Adventure, argues that a falling fraud-catch rate may mean controls have stopped seeing the sophisticated attacks, not that they have stopped arriving.

Identity checks in regulated gambling were built around cost: faking a document and a face at the same time used to be slow and expensive. Gerardo Prieto argues that cost has collapsed.
Prieto is CISO at The Mill Adventure, so his prescription of AI-driven behavioural monitoring sits close to what his side of the market sells. He describes deepfake video injected into selfie flows through virtual cameras, defeating passive liveness checks, and treats the synthetic identity that passes verification as the more dangerous case, because to a legacy system it looks like a good customer.
The economics, he says, have changed. Attacks costing a few dollars can produce six-figure losses, tightening thresholds converts false positives into lost revenue, and he puts onboarding abandonment at up to 40%.
The Q&A covers coordinated multi-step attacks, bot farms and mule networks, identity as a continuous state rather than a one-off gate, and the signals he reads as fraud rather than marketing spend.
He frames this as a problem for the rest of 2026, not a forecast.
Gaming Eminence: You've suggested traditional KYC is breaking down. Which parts are actually failing today?
Gerardo Prieto: "KYC as a regulatory obligation isn't going anywhere, but what’s breaking are the technical assumptions under it.
The clearest failure is liveness at onboarding. The old equation — document plus selfie equals verified human — worked when faking both was slow and expensive, but it isn't anymore. Attackers feed a deepfake stream into the selfie flow through a virtual camera, and passive liveness checks can't tell a real face from a synthetic overlay. Tested against live selfie flows, those injection attacks bypass a wide range of implementations.
The second failure is the one-time gate. An operator will check at the door, wave the player through, and stop looking — but the dangerous behaviour happens after onboarding, at the bonus claim and the withdrawal.
The worst one of all occurs when synthetic identities don't fail checks but pass them. They slip past the checks themselves, as opposed to tired analysts, because the systems were built for a fraud world that no longer exists. To a legacy system, a synthetic identity with a valid document looks like a good customer. That's the part that should keep operators up at night, and it’s a battle that will only intensify as technology advances."
Gaming Eminence: Which fraud techniques are rising fastest in regulated gambling right now?
Gerardo Prieto: "The boring stuff is still the biggest: bonus abuse and multi-accounting. The fastest rising trend is the coordinated, multi-step attack that chains techniques together: bonus abuse plus synthetic identity plus laundering. It breaks single-purpose controls by design.
The mechanics have also evolved. Abusers have moved from manual multi-accounting to bot farms running thousands of accounts with unique fingerprints, while mule networks run deposit-withdraw cycles that mimic legitimate players. It is the same old playbook that operators have always encountered, but the modern bad actor has a machine to run it a thousand times."
Gaming Eminence: How is AI-enabled fraud changing the cost equation for operators?
Gerardo Prieto: "The shift isn't that deepfakes got better. It's that they got cheaper and that's the whole game.
Deepfake-as-a-service and synthetic identities now cost almost nothing to produce. When attacks are so cheap, the maths inverts: operators defend against something that cost a few dollars to launch while absorbing six-figure losses per incident.
It’s asymmetric warfare where you have to block every attack, whereas they only need one to land.
This means three things. Volume is no longer a barrier for the bad guys, false positives rise as thresholds are tightened in terms of real revenue lost, and spend has to move from the open door to the lifecycle. The direction isn't in doubt: attacking got cheaper faster than defending did.
The only honest answer to cheap, scaled, AI-driven fraud is to fight it with AI of your own. Operators can't beat machine-speed attacks with manual review and static rules. Defence has to match the attacker's tooling, with AI models that score behaviour and device signals in real time, spot synthetic patterns a human would miss, and adapt as the attacks do.
Operators still relying purely on human teams and fixed rules are bringing a knife to a gunfight."
Gaming Eminence: Where are operators still relying on frameworks no longer fit for purpose?
Gerardo Prieto: "I would argue in three places. Treating identity as an event, not a state — "verified at onboarding = trusted forever." But behavioural shifts, odd transactions and sudden detail changes all signal takeover or mule activity a one-off gate never sees.
Over-trusting a single strong check is another. Defence now comes down to how well controls work together. If an operator is reliant solely on one check, attackers will learn to bypass it.
And the final example is assuming the document is the source of truth. In a synthetic world that's backwards logic. When the document is technically valid, the only reliable signal is the inconsistency footprint across signals, not document quality."
Gaming Eminence: How should operators balance stronger verification with onboarding friction?
Gerardo Prieto: "This tension is real, because friction is churn that operators can measure. Bad KYC flows can push up to 40% of users to abandon onboarding. Adding more checks isn't a serious answer.
The fix is risk-based, not uniform. Keep the default path light and trigger heavy verification only when a risk signal or threshold fires, using single-session flows. Then shift effort to the lifecycle: document and biometric checks at onboarding, plus device and behavioural monitoring during play and AML screening throughout. That lets operators keep a light front door without going blind.
My framing for commercial colleagues is that friction isn't the cost — misplaced friction is. A good system is invisible to 95% of players and brutal to the 5% who deserve it."
Gaming Eminence: What early warning signals should executives monitor?
Gerardo Prieto: "I have compiled a shortlist below of key touchpoints to monitor. Focus on these and an operator will know when they are slipping.
Watch bonus and promotional spending. This fraud is quiet: the losses build with no single event loud enough to trigger an alert, and by the time the network has been mapped, weeks of payouts have already cleared. If money going out on promotions is climbing and nobody can fully explain why, that's often fraud, not marketing.
Watch the gap between sign-ups and real depositing players. Some operators have found that up to 30% of registrations have been estimated as fraud. Lots of new accounts but few who actually deposit and play means someone's farming accounts at scale.
Watch for approvals that look too smooth. A falling fraud-catch rate isn't always good news because synthetic identities are built to pass, so a suspiciously clean funnel can mean controls have stopped seeing the sophisticated stuff.
Be honest about readiness: 63% of organisations have spent nothing on deepfake defence, and only 5% have a real strategy. If you don't know which group you're in, you're already behind.
The goal for the rest of 2026 must be to assume the attacker's tools are cheaper and faster than yours. The correct response is to build your monitoring as if compromise is always happening, because it is."



