Here is a number that belongs in every age assurance design review and appears in almost none of them.
In the first quarter of 2026, KasadaIQ counted 13.2 million account sales on criminal marketplaces where the listing was advertised as verified, KYC-passed (know your customer) or with two-factor authentication already attached. Observed revenue was 24.6 million dollars. Divide one by the other and the blended price of a verified account is 1.86 dollars.
The benchmarked verticals sit above that line. Retail accounts averaged 2.49 dollars. Quick service restaurant accounts averaged 1.88 dollars. Hotel accounts with elite status averaged 6.86 dollars. Airline accounts averaged 11.54 dollars. Which also means the rest of the market, the part not broken out, is cheaper than any figure in that list.
Now put your own unit economics next to it. A document verification with optical character recognition and a face match is priced between 0.10 and 0.30 EUR, depending on your plan. Facial age estimation costs a fraction of that. So the thing your age gate produces, a user account carrying a verified adult age, resells for roughly six to a hundred times what it cost you to buy.
You are the cheapest step in someone else’s supply chain, and you are paying for it.
That framing is uncomfortable, and it is also the correct one. Most writing about age assurance circumvention treats the problem as an attack on the verification technology: spoofed faces, injected video streams, forged documents, borrowed identities. Those are real, and we have written about the binding problem that sits underneath them.
This post is about something else, and it is the part almost nobody instruments. A verification that worked perfectly, on a real adult, with genuine documents, produces an asset. Assets get sold. The sale happens months after your check passed, through a channel your fraud team is not watching, because the person who sold it is not complaining about it.
The asset you did not know you were minting
An unverified account is worth roughly nothing. Anyone can make one. A verified account is worth money for exactly one reason: it will not trip a step-up challenge mid-session.
So the value of the account is a direct function of how hard your gate is to pass. Tighten the gate and you raise the price. Raise the price and you fund better bypass tooling.
This is not a hypothetical loop. KasadaIQ tracks organised groups advertising bypass services across more than 50 platforms, and the catalogue reads like a product roadmap written against verification vendors:
- Selfie liveness bypass, including the head-rotation challenge used by tier-one platforms
- KYC bypass sold as an ongoing service rather than a one-off job, advertised across more than 250 countries and territories
- Passport templates and utility bills from more than 50 countries, used to seed accounts that pass document checks on the first try
- Ready-made accounts with two-factor authentication already set up
One tracked operator sells custom synthetic identities with established credit profiles for around 200 dollars. The add-ons are the part that should worry anyone who has designed a step-up flow. A postal address that will receive and forward confirmation mail. A physical bank card shipped to a drop location. A SIM card, so the buyer passes phone-based two-factor and account recovery. For 200 dollars and a few extras, somebody buys a person on paper who survives most of what a verification pipeline throws at them.
Be careful with the headline numbers here, because the coverage has been sloppy. Several write-ups reported that fabricated identities overtook identity theft globally in 2025. What LexisNexis Risk Solutions actually published, working from 116 billion transactions on its Digital Identity Network, is narrower. Synthetic identity fraud grew roughly eight-fold in 2025 and now accounts for about 11% of recorded fraud. That makes it the fastest-growing category, not the largest one. Fastest-growing and largest are different claims, and only the first is supported.
The number in that report that matters most for age assurance is neither of those. First-party fraud, where the legitimate account holder is the one doing it, is 38.3%. It is the largest single category by a wide margin. And first-party is exactly the shape of an account sale.
Account takeover has a victim. An account sale does not.
This is the whole post. Stated plainly:
Almost every fraud detection system in production rests on the assumption that somebody eventually notices and complains. The architecture follows from that assumption. You watch for failed logins, credential stuffing patterns, impossible travel, password resets the user did not request, chargebacks, and “was this you?” emails that come back marked no. You compare each account against its owner’s normal behaviour and you alert when the session diverges from it.
Now run a voluntary account sale through that machinery.
The seller logs in from their own device, using the correct password, and passes two-factor because they still hold the phone. They change the recovery email to one the buyer controls. They change the password to one the buyer supplied. They hand over the account, and sometimes the SIM card or the whole device with it. No login failed. No reset was unexpected. No chargeback was filed. No support ticket was opened, and none ever will be, because the only person who could file one was paid.
Your detection stack sees a healthy user doing routine account maintenance.
This is why age assurance is structurally harder than payment fraud rather than easier. In payment fraud, the buyer of a stolen account wants the stored value inside it, so they spend it fast. A rapid drain is a spike, and spikes are easy to alert on. The buyer of a verified age-gated account wants the opposite. They want to use the service normally, the way any other user would, for months. Slow, unremarkable use over a long period is the exact signature your anomaly detection was tuned to treat as healthy.
The price point removes the last barrier. Payment fraud economics need an account worth stealing. Age gate circumvention needs an account worth about two dollars, bought by someone who is fifteen.
There is one more asymmetry. In most age assurance cases the seller is not a criminal at all. It is an older brother. A university student clearing out a dormant gaming account. A parent who set the account up “just to get past the annoying bit” and never took it back. A stranger on a forum who wants beer money. None of those people think of themselves as fraudsters, none of them will ever be caught, and for the purposes of your compliance record the outcome is identical to a professional sale.
What the regulator is actually grading
It is tempting to file this under trust and safety and leave it out of the compliance conversation. That would be a mistake.
Ofcom’s test for highly effective age assurance under the Online Safety Act has four properties: technically accurate, robust, reliable and fair. Accuracy and reliability are properties of your vendor’s model, and a certificate evidences them. Robustness is not, and fairness is only partly. Robustness asks whether the method works in realistic scenarios. Ofcom has been explicit that services must take steps to detect and prevent underage users circumventing age assurance measures.
Read that against the resale market and the implication is uncomfortable but clear. The question being graded is not whether your check was accurate at the moment it ran. It is whether the population sitting behind your gate today is the population you verified. A vendor certificate answers the first question and is silent on the second. Only your own telemetry can answer the second, and almost nobody collects it.
Ofcom’s statutory report in July 2026 found adoption climbing fast, with tens of millions of checks running across the services in scope, and still asked for further attention during 2026 on whether the measures in use are working. We went through that report in detail here. If your evidence pack contains an accuracy certificate and no transfer data at all, you are answering a question that was not asked.
Four signals that a verified account changed hands, and one thing to go and look up
These are not account takeover signals. Takeover signals look for a failed authentication or a compromised credential. A transfer has neither. What a transfer has is discontinuity: the account is fine, the credentials are correct, and the human changed.
Recovery surface changes that cluster in time. Any single change is routine. People do change their email address. What is not routine is email, phone number, password and payment method all changing inside a short window, with no failed attempt anywhere in the sequence. That is not maintenance. It is a handover checklist. Takeover usually shows one or two of these, under pressure, with failures around them. A sale shows the complete set, calmly, from a legitimate session. Count the set, not the individual events.
Behavioural discontinuity from a clean login. The device fingerprint changes. The timezone changes. The session length pattern and the content preferences change with them. Every one of those changes arrives on a login that succeeded first try, with the right password and a passed second factor. Nothing failed, and that is the signal. Your existing anomaly model probably suppresses this case on purpose, because a successful authentication is treated as evidence that the anomaly is benign.
Drift between verified age and behavioural age. Many platforms already estimate a behavioural age cohort for every account. Recommendation systems use it, and so do advertising systems. What is rare is wiring that estimate back into the age decision as a contradiction check. An account verified at 34 whose usage pattern now sits squarely inside your 13 to 17 cohort is not proof of anything. It is a reason to ask again, and asking again is cheap.
Dormancy followed by full-credential reactivation from new hardware. This is the classic resale shape, and it falls out of how the market works. An account is created and verified, then left to age on the platform so it looks established, then sold, then reactivated by the buyer. Long quiet period, then a return with every credential correct from a device that has never been seen. Treat that combination as one signal rather than three weak ones.
Then go and look up your own price. Several threat intelligence vendors monitor these marketplaces. A quarterly sample, purchased by that vendor under your legal team’s sign-off rather than by your staff directly, tells you two things nothing else will. Whether your platform is listed at all, and what your accounts actually sell for. There is a third benefit if the purchase gives you a seeded account identifier, because you can then trace that account backwards through your own logs and find the cohort it came from.
Your price on the open market is the best single summary of how much your age gate is worth defeating. If you have never looked it up, you are estimating your risk from first principles when the number is published.
Three design changes, in order of how much they buy you
Make the credential worth less when it moves. The purpose of detecting a transfer is not to ban somebody. It is to make the thing being sold defective. If a bought account asks the buyer, on first use, to show a face that matches the one bound at verification time, the buyer has paid for something that does not work. Sellers who cannot deliver working accounts lose their listings.
The mechanism is a re-bind rather than a re-verify. You confirm that the same bound subject is present, using liveness and a match against the template established at verification. No second document scan.
This is where the cost structure decides whether the control exists at all. If re-binding costs the same as a full document verification, you will set the trigger threshold by budget rather than by risk. A control you can only afford to fire on a fraction of a percent of sessions is a control that sellers can work around.
Trigger on events, not on a calendar. Fixed re-verification cycles are the standard answer, and a poor one. A 90-day cycle catches a handover six weeks after it happened on average, charges you for every user who never moved, and has no relationship to when risk actually appeared. It is also predictable, so anyone selling accounts at volume can schedule around it.
Event-based triggers invert those properties. They cost nothing when nothing happens. They fire when the evidence appears rather than weeks later, and an attacker cannot know in advance which behaviour sets one off. The fixed calendar still has a role, as a fallback for accounts that generate no signals at all, but not as the primary control.
Record the transfer decision, not just the age decision. When a re-bind fires and fails, that is a compliance-relevant event. It belongs in your evidence, not in an application log that rotates after 30 days. Store what triggered the re-bind, what you asked the user for, what came back, what you decided, and which policy version was in force.
Then you can answer the question a regulator will actually ask. “We re-ran the binding check on 40,000 accounts last quarter on transfer signals. 11,000 failed it. 1,900 of those were restored on appeal and 9,100 were closed.” That is evidence your gate maintains a state, and the appeal number is evidence you are measuring your own error rate. A boolean column reading ageVerified: true is evidence that a check happened once, on a date, to somebody.
The arithmetic that should set your budget
Put the four numbers side by side, because the conclusion is not close.
Across all 13.2 million Q1 sales your verified account is worth 1.86 dollars, and in the benchmarked verticals it runs from 1.88 up to 11.54. A cheap re-bind costs 0.02 EUR on our Growth plan, 0.01 on Scale and 0.03 on Starter. A full document verification is ten times that on every plan. An Ofcom penalty under the Online Safety Act runs to 18 million pounds or 10% of qualifying worldwide revenue, whichever is greater.
Take an elite-status hotel account at 6.86 dollars, roughly 6.2 EUR. At 0.02 EUR you could re-bind that single account about three hundred times before you had spent what the buyer paid for it. You will not need three hundred. You need one, fired at the right moment, which is the whole argument for event triggers over a calendar.
The ratio is what matters here, not our specific numbers. Work out your own. If a re-bind costs you the same as an initial verification, the ratio collapses and this control is unaffordable at any useful frequency. That is a procurement problem rather than an engineering one, and you want to know which of the two you have before you design the trigger logic.
How Xident is built for this
Three things in our design exist for this problem.
The Check and Verification split is what makes re-binding affordable. A Verification is the document and identity path: optical character recognition on the document plus a face match. That is the expensive operation, and on every plan that offers it (Starter, Growth and Scale) it bills from the first one. A Check covers browser-based age checks, liveness, returning-user Xident ID lookup and OAuth, which is the delegated sign-in standard. On Growth those two are 0.20 EUR and 0.02 EUR, a factor of ten apart. On Scale they are 0.10 and 0.01.
That gap is the reason an event-triggered re-bind is a real control rather than a slide. You are not re-running the document path when a transfer signal fires. You are re-confirming the bound subject on the cheap path. If a vendor bills you one blended rate per interaction, re-binding costs the same as verifying, and the control quietly becomes unaffordable.
Every decision is a record, not a boolean. A check returns the outcome, the method, the predicate evaluated, the confidence, the policy version and the timestamp. A re-bind that fires on a transfer signal produces its own record, linked to the original verification. Months later you can reconstruct which signal fired, what was asked and what happened. That is the shape of evidence Ofcom’s record duties expect, and the shape an appeal needs.
Returning-user lookup is the cheap path that keeps the expensive path rare. The Xident ID lookup is a Check, not a Verification, so most returning sessions resolve there. The document path stays reserved for the cases that genuinely need it, which is what keeps your average cost low enough to afford being suspicious more often.
The free sandbox grants 1,000 Checks and 100 document Verifications as one-time allowances rather than a monthly quota. The 100 Verifications exist so you can run the document path end to end before paying for anything, including the branch where a re-bind fails and the user appeals. That branch is worth exercising against a real integration, because it is the one you will be asked about.
The short version
Your age gate produces an asset with a market price, and the price rises with the strength of the check that made it. In the first quarter of 2026 that market moved 13.2 million verified accounts for 24.6 million dollars.
The reason it survives undetected is not that the signals are subtle. Your detection stack is built around a victim who complains, and an account sale has no victim. The seller was paid. The buyer wants nothing more than to use your service quietly, for months, exactly like everybody else. First-party fraud is already the largest category in the LexisNexis data at 38.3%, and a voluntary handover of a verified account is a textbook instance of it.
So the useful shift is from asking “did this account get compromised?” to asking “is the person behind this account still the person we verified?” Those two questions need different signals, and the second set is the one nobody logs.
Ofcom is going to ask for evidence that your age assurance is robust in realistic scenarios. A verified user selling their account to a fifteen-year-old for six dollars is a realistic scenario. For most services today, the honest answer to “how many times has that happened?” is that nobody knows, because nobody instrumented the event.
The market publishes its prices every quarter. Go and find yours.
Xident provides age verification and age estimation infrastructure with a cheap Check path for returning users and liveness, and a separate document Verification path, so event-triggered re-binding is affordable rather than theoretical. Every decision is stored as a record with its method, predicate and policy version. The free sandbox includes a one-time allowance of 1,000 Checks and 100 document Verifications. Talk to us about what your accounts are worth before someone else tells you.