The ‘Klarna Glitch’ Wasn’t a Glitch: The Fraud Playbook That Bypassed Traditional KYC
In late 2025, a viral TikTok trend taught thousands of fraudsters how to “glitch” BNPL platforms for high-value electronics and cash disbursements. They didn’t use sophisticated hacking – they used stolen identity data and freshly minted email accounts that looked just legitimate enough to bypass traditional verification checks.

Download the full research
Thank you. Your research is ready.
Open the report (opens in a new tab)Executive summary
Analysis of how stolen-but-valid identities and newly created digital profiles exploited structural blind spots in traditional verification, with a step-by-step fraud path and the external identity signals that can expose it.
Reverse engineering
The exact fraud path that bypassed traditional KYC – step by step.
The structural blind spot
Why stolen-but-valid identities passed automated verification at scale.
The detection signals
The real-time web-intelligence signals that stopped the attack.
The forward risk
What this incident reveals about the next wave of first-party and socially amplified fraud.
While legacy systems saw a “verified” customer, Heka saw a digital ghost.


