By NHI Mgmt Group Editorial TeamBased on SumSub: “Glovo's Fraud Playbook: From Free Lunches to Money Laundering” (June 8, 2026)

TL;DR: Delivery platforms are facing coupon abuse, refund fraud, merchant laundering, and SMS verification scams as fraud tactics spread through social media tutorials, according to SumSub. The real governance problem is that growth models built for frictionless checkout now depend on identity and transaction controls that can absorb abuse without punishing legitimate users.


At a glance

What this is: A SumSub discussion of delivery-platform fraud shows how coupon abuse, refund abuse, merchant laundering and SMS verification scams exploit frictionless growth models.

Why it matters: It matters because identity and transaction controls in on-demand platforms must reduce abuse without creating checkout friction that drives away legitimate users.


Context

On-demand delivery fraud is not a single control failure. It is the collision between growth designed for low-friction checkout and adversaries who learn quickly, share tactics publicly, and exploit every trust decision in the order, refund, and merchant lifecycle.

For IAM and fraud teams, the important lesson is that customer identity, merchant identity, and transaction controls now operate as one governance surface. If verification, refund policy, and merchant onboarding are tuned in isolation, fraud migrates to the weakest handoff rather than disappearing.


Key questions

Q: How should delivery platforms reduce fraud without hurting customer conversion?

A: They should use risk-tiered friction rather than blanket challenge. That means light-touch verification for low-risk activity, stronger checks for high-risk behaviour, and clear review paths for exceptions. The goal is to make abuse expensive while keeping legitimate users moving through the flow with minimal disruption.

Q: Why do coupon and refund controls fail in on-demand delivery apps?

A: They fail when the platform treats promotional and refund logic as simple transaction rules instead of identity and behaviour signals. Abusers can repeat legitimate-looking actions at scale, so weak linkage between customer identity, device signals, payment behaviour, and order history lets exploitation look normal until losses accumulate.

Q: What are the signs that delivery fraud is spreading through a platform?

A: Common signs include repeated abuse of the same promotion patterns, abnormal refund clustering, merchant accounts with inconsistent payout behaviour, and fraud tactics appearing in multiple markets at once. When abuse evolves faster than rule updates, the platform is likely reacting after the fact instead of governing the journey proactively.

Q: How do identity and fraud teams share accountability for delivery-platform abuse?

A: Identity teams own assurance at onboarding, recovery, and merchant access points, while fraud teams own detection and response across the transaction flow. The governance gap appears when those responsibilities are separated, because abuse then moves into the handoff between identity verification and transaction approval.


Technical breakdown

How social-platform fraud tutorials scale delivery abuse

The article points to a modern fraud economy in which attackers and opportunists learn through TikTok, Snapchat, and similar channels. That changes the tempo of abuse. Delivery fraud is no longer limited to isolated bad actors testing a single platform. It becomes repeatable tradecraft, distributed through tutorials that lower skill thresholds and standardise abuse patterns such as coupon exploitation, refund gaming, and verification bypass attempts. The result is faster attack diffusion across markets and a shorter window for manual fraud review to catch up. The underlying mechanism is social amplification of operational abuse, not just a rise in criminal intent.

Practical implication: treat social-channel fraud patterns as a signal for rule tuning and monitoring, not only as a law-enforcement problem.

Where frictionless checkout becomes fraud exposure

Delivery platforms optimise for conversion, speed, and minimal user friction, but every removed step also removes an opportunity to challenge suspicious behaviour. In practice, that means fraud controls must operate with risk-based precision rather than blanket blocking. Coupon abuse, refund fraud, and SMS verification scams all exploit moments where the platform trusts intent too early or too broadly. The governance challenge is that identity assurance, transaction monitoring, and customer experience are interdependent. If one control is tightened without understanding the full journey, the platform either leaks abuse or damages legitimate conversion.

Practical implication: map abuse scenarios to the exact journey points where trust is granted, then align verification and refund controls to those decision points.

Why merchant laundering and verification scams are governance problems

Merchant laundering in delivery ecosystems shows that fraud is not limited to customer behaviour. Merchant identity, payout pathways, and account legitimacy all become part of the control plane. SMS verification scams in Central Asia add another layer: identity proofing and account recovery can be manipulated when the system treats verification as a one-time gate instead of a lifecycle control. For identity and fraud teams, this is a reminder that onboarding, ongoing monitoring, and offboarding are connected. Weakness in any one of them can be converted into monetisation, not just access.

Practical implication: govern merchant and customer identities as lifecycle assets, with ongoing monitoring tied to payout, refund, and account recovery risk.


Threat narrative

Attacker objective: The objective is to extract value from delivery platforms through discounts, refunds, merchant payouts, or account abuse while staying inside normal-looking user journeys.

  1. Entry begins when fraudsters or opportunistic users encounter low-friction delivery journeys and learn abuse patterns through social media tutorials.
  2. Credential or trust abuse follows when coupon codes, refund flows, merchant onboarding, or SMS verification steps are manipulated to gain illegitimate benefit.
  3. Escalation occurs as repeatable tactics spread into organised networks that automate or industrialise the abuse across platforms and regions.
  4. Impact is lost revenue, distorted trust signals, and a security model that must absorb abuse without punishing legitimate customers.

NHI Mgmt Group analysis

Frictionless growth creates an identity governance debt: delivery platforms that optimise for conversion are implicitly accepting more trust at the point of order, refund, and merchant onboarding. That debt is not abstract. It shows up when the platform must decide whether convenience or abuse resistance defines the user experience. The practitioner conclusion is that abuse tolerance has to be designed, not discovered after losses appear.

Fraud is now a distributed learning problem, not just a detection problem: social platforms have turned delivery fraud into shareable tradecraft, which shortens the time between one successful exploit and widespread replication. That means static rules age quickly and manual review cannot remain the primary control. The field needs to treat fraud pattern diffusion as a governance input, not just an operations concern. The practitioner conclusion is to update controls at the speed of abuse-sharing channels.

Merchant identity is part of the fraud surface, not a back-office detail: merchant laundering and payout abuse show that delivery fraud crosses customer identity, business identity, and transaction identity. When those layers are governed separately, the platform can authenticate a user and still lose money through the merchant side of the workflow. The practitioner conclusion is to unify identity and transaction governance across the full delivery lifecycle.

Perfect fraud levels do not exist in the abstract: the relevant question is acceptable friction relative to abuse exposure. That framing is useful because it stops teams from treating every blocked action as a win or every seamless journey as a success. The practitioner conclusion is to measure controls by how well they preserve legitimate conversion while compressing the abuse window.

From our research library:

What this signals

Friction management has become a fraud-control discipline: delivery platforms are being forced to decide where a small amount of challenge is cheaper than broad abuse tolerance. That shift matters because the right control is rarely a blanket step-up check. It is usually a targeted policy at the point where abuse becomes monetisable.

Merchant onboarding deserves the same scrutiny as customer onboarding: merchant laundering shows that fraud can be operationalised through legitimate-looking business accounts, not just consumer abuse. Teams that separate merchant governance from customer identity are leaving a material gap in their fraud model.

Identity proofing and refund governance now intersect: a platform can authenticate a user and still be vulnerable if refund policy, account recovery, and payout logic do not share the same trust model. The practical move is to treat those controls as one lifecycle, not three unrelated workflows.


For practitioners

  • Model fraud by journey stage Break the delivery flow into customer acquisition, checkout, coupon use, refund, merchant onboarding, and payout stages, then map the fraud patterns that appear at each stage.
  • Tighten identity checks at high-abuse points Apply stronger verification where abuse yields immediate value, especially at coupon issuance, refund approval, and merchant enrolment.
  • Monitor social-channel fraud patterns Track tutorial-driven abuse tactics from public platforms and feed them into detection rules before they become common playbooks.
  • Govern merchant lifecycles continuously Reassess merchant accounts, payout behaviour, and account recovery signals after onboarding so laundering and synthetic relationships do not persist unchecked.

Key takeaways

  • Delivery fraud in on-demand apps is a governance problem as much as a loss problem, because low-friction growth expands the number of places abuse can hide.
  • The article links social-media fraud tutorials, coupon abuse, refund fraud, merchant laundering, and SMS verification scams to the same broad trust challenge.
  • Teams need controls that preserve conversion while tightening the exact points where abuse becomes monetisable, especially in onboarding, refunds, and payouts.

Key terms

  • Coupon Abuse: Coupon abuse is the repeated or manipulated use of promotional offers to obtain goods or discounts without legitimate entitlement. In delivery platforms, it often exploits weak linkage between identity, device, order history, and promotion logic, turning marketing controls into a fraud vector.
  • Refund Fraud: Refund fraud is the misuse of return or reimbursement processes to obtain money, product, or service without a valid basis. It can involve repeated claims, false delivery disputes, partial return manipulation, or fabricated tracking evidence. Effective controls rely on claim history, pattern analysis, and coordination between fraud and customer service teams.
  • Trust Laundering: Trust laundering is when untrusted content gains trusted authority simply by passing through a tool that assumes the source is safe. In AI-assisted development, that can happen when repository files or hooks silently shape what the model sees, turning evidence selection into a security control.
  • Acceptable Friction: Acceptable friction is the level of challenge a platform can introduce before legitimate users abandon the journey or conversion drops materially. In fraud governance, it is the practical boundary between security and usability, and it must be tuned to the specific abuse profile of the workflow.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org