ResearchIdentity Fraud

The ‘Klarna Glitch’ Wasn’t a Glitch: The Fraud Playbook That Bypassed Traditional KYC

In late 2025, a viral TikTok trend taught thousands of fraudsters how to “glitch” BNPL platforms for high-value electronics and cash disbursements. They didn’t use sophisticated hacking – they used stolen identity data and freshly minted email accounts that looked just legitimate enough to bypass traditional verification checks.

Editorial artwork: The ‘Klarna Glitch’ Wasn’t a Glitch: The Fraud Playbook That Bypassed Traditional KYC

Download the full research

Use your work email.

Executive summary

Analysis of how stolen-but-valid identities and newly created digital profiles exploited structural blind spots in traditional verification, with a step-by-step fraud path and the external identity signals that can expose it.

  1. Reverse engineering

    The exact fraud path that bypassed traditional KYC – step by step.

  2. The structural blind spot

    Why stolen-but-valid identities passed automated verification at scale.

  3. The detection signals

    The real-time web-intelligence signals that stopped the attack.

  4. The forward risk

    What this incident reveals about the next wave of first-party and socially amplified fraud.

While legacy systems saw a “verified” customer, Heka saw a digital ghost.