Nasdaq Verafin partnered with Q6 Cyber on August 27, 2026, to feed dark web intelligence on stolen checks, compromised payment cards, and banking credentials directly into banks’ fraud investigation workflows. In an 18-month collection window, Q6 Cyber identified 1.2 million compromised checks, 158 million compromised payment cards, and 57 million unique compromised credentials.
A proof-of-concept found an average 10-day gap between a stolen check appearing on dark web markets and the first fraudulent return, a window banks can use to act before the fraud occurs.
What Nasdaq Verafin and Q6 Cyber are trying to do is move that discovery point much earlier, to the moment the stolen check first gets listed for sale on a dark web marketplace, not the moment it lands at a bank’s processing counter.
Their partnership, announced August 27, 2026, integrates Q6 Cyber’s dark web fraud intelligence directly into Nasdaq Verafin’s platform, which is already used by more than 2,800 financial institutions managing roughly $13 trillion in combined assets. The goal is to give banks a head start measured in days, not milliseconds.
The Problem With Catching Fraud at the Transaction
Banks are good at watching for fraud when it arrives. Transaction monitoring, behavioral analytics, and machine learning models- all of these tools get smarter every year at spotting suspicious activity the moment money starts moving.
The problem is the “moment money starts moving” is already late.
Colin Parsons, Head of Fraud Product Strategy at Nasdaq Verafin, put it directly in an interview with PYMNTS: “In the life cycle of a fraud or a scam, most of those fraudulent scenarios are happening outside of the banking system. The challenge really is that it only becomes visible to an institution at the time a transaction’s occurring, or money’s moving.”
A stolen check, for example, doesn’t become a fraud problem the moment it’s presented for deposit. It became a fraud problem weeks earlier, when someone stole it from a mailbox, photographed it, listed it for sale in an underground forum, and sold it to a buyer who’s been patiently waiting for the right window to deposit a convincing fake.
The bank sees the end of that chain. The dark web saw the beginning.
What Dark Web Financial Markets Actually Look Like
Understanding why this intelligence matters requires understanding how organized these underground markets are.
Stolen financial data doesn’t just circulate informally. It has a structured supply chain with specialized roles: some actors steal data, others broker its sale, counterfeiters create fraudulent instruments, mule recruiters source accounts for moving funds, and cash-out specialists handle the final extraction.
As Nasdaq Verafin’s blog describes, compromised checks enter these markets in two forms: uncashed originals and previously cashed items, with buyers acquiring either the physical check or just the image. From there, the check gets assessed for account information, altered or recreated, and positioned for deposit through ATM, mobile, or in-person channels.
The scale is significant. A single dark web marketplace has been estimated to generate $17.3 million in revenue on its own. The broader market for stolen financial data runs to considerably more. In the 18 months before the partnership announcement, Q6 Cyber collected more than 1.2 million compromised checks, 57 million unique compromised credentials, and 158 million compromised payment cards from the hundreds of thousands of criminal community sources it monitors.
That pipeline feeds directly into measurable, growing fraud losses. According to Nasdaq Verafin’s 2026 Global Financial Crime Report, check fraud losses reached $38.5 billion globally in 2025, with $33.6 billion attributed to the United States alone. This fraud type has grown at an annualized rate of 20.4% over the past two years.
These aren’t abstract numbers. The compromised data feeding this machine comes from exactly the kind of breaches we’ve been tracking throughout 2026. The 153 million US driver’s licences exposed through IDScan.net included names, addresses, and identifying details—the raw material for fabricating convincing fake checks. The CenterPoint Energy breach exposed account numbers and billing information. The Substack breach put credentials in criminal hands months before users knew. Every major data exposure feeds the supply chain these markets depend on.
The 10-Day Window: What It Actually Means for a Bank
The proof-of-concept behind the Verafin–Q6 Cyber partnership produced one finding that changes the calculus on fraud prevention.
The average time between Q6 Cyber detecting a stolen check listed on the dark web and the first fraudulent check being returned to a bank was 10 days.
Ten days is a long time in fraud prevention terms. It’s enough time to contact the account holder, flag the account for enhanced monitoring, or implement temporary protective measures before a single fraudulent transaction occurs.
Parsons described the logic: “You’re acting upstream, so you’re disrupting fewer transactions and allowing things to flow smoothly.” An institution that gets a specific alert about a specific account has a reason to look closely at that account, not a reason to add friction across thousands of transactions in hopes of catching the one bad one.
That precision is the key word here. Alert fatigue is a real problem in fraud operations. Investigators already work through large volumes of flags generated by transaction monitoring. A new source of intelligence is only useful if it identifies something specific enough to act on, rather than adding to the noise.
Eli Dominitz, CEO of Q6 Cyber, said: “You also get to focus on the things that really matter and not spend too much time just dealing with noise.” The firm’s approach, delivering confirmed compromise alerts rather than speculative scores, is what makes the intelligence actionable rather than another layer of uncertainty.
Q6: Cyber’s access to these markets can’t be replicated through a simple crawler. Dominitz noted that a decade of relationship-building inside criminal communities underpins the firm’s proprietary source access. Invite-only forums and encrypted channels don’t yield to automated scraping. The intelligence comes from being present inside those communities in ways that surface information as it’s posted, not after it’s already been used.
AI Is Making This More Urgent, Not Less
The conversation around this partnership isn’t happening in isolation from the broader AI shift in fraud.
Dominitz noted during his interview with PYMNTS that fraudsters are actively experimenting with AI tools and large language models to automate existing practices, make social engineering faster and more targeted, and test ways to defeat financial institutions’ fraud controls.
This connects directly to what we covered when looking at how Anthropic’s September threat intelligence report documented Chinese AI labs using AI to process and deploy stolen data at industrial scale. The same AI capabilities that enable sophisticated legitimate applications also enable fraudsters to personalize attacks and iterate faster on what defeats bank controls.
The asymmetry Dominitz identified is important: “We want to be right 100% of the time. They don’t have to be.” A fraudster only needs a small success rate across a large volume of attempts to turn a profit. A bank needs to block almost everything without disrupting legitimate customers. Dark web intelligence that narrows the target- this specific account, this specific credential- helps tip that asymmetry slightly back.
Both sides of the partnership are applying AI to their own workflows. Nasdaq Verafin uses machine learning models fed by its 2,800-institution consortium to identify fraud patterns before they surface in an individual bank’s data. Q6 Cyber uses AI to process intelligence faster and generate alerts with shorter lead times.
How the Combined Platform Works
The integration joins two views of the same fraud problem.
Q6 Cyber sees what’s happening in criminal communities before it reaches the financial system. Nasdaq Verafin sees what’s happening inside the financial system: transaction history, counterparty relationships, patterns across 850 million counterparties and more than 2,800 institutions. Separately, each view is valuable. Combined, they give investigators an external and internal picture at the same time.
Intelligence from Q6 Cyber surfaces as high-risk alerts inside Nasdaq Verafin’s existing fraud and AML platform, the same environment fraud investigators already work in. It doesn’t require a separate interface or a separate workflow. The alert arrives in context, alongside transaction history and counterparty information, giving investigators what they need to decide without switching systems.
The initial focus covers three categories: check fraud, payment card abuse, and online banking credential compromise. These represent the highest-volume and fastest-growing forms of financial institution fraud in the current environment. They’re all driven by the same underlying dynamic: stolen financial data circulating in criminal markets before it’s used.
The dark web intelligence market we covered recently is growing at over 21% annually. The Verafin–Q6 partnership is a textbook example of why: institutions are increasingly recognising that waiting for fraud to arrive at the door is no longer the only option, and that intelligence from where fraud originates is more valuable than better tools for catching it after it lands.
Why This Matters to Regular Banking Customers
For individual bank customers, this partnership’s practical significance is indirect but real.
Every stolen check, compromised card, and credential set circulating in dark web markets represents a real person’s real account that may be used for fraud. The damage, disputed transactions, frozen accounts, delayed resolution, and time spent disputing fraudulent activity fall on individual customers even when banks eventually make them whole.
Earlier detection means shorter exposure windows. A bank that receives an alert about a compromised account 10 days before a fraudulent deposit attempt has options it doesn’t have after the fact. Faster detection also means the data is less likely to be reused across multiple fraud attempts by multiple actors, the pattern the underground carding economy explicitly enables– where a single stolen piece of financial data can support multiple independent fraud attempts.
For context, the type of data driving check fraud- account numbers, routing information, payee details- is exactly the kind of information exposed in breaches like the CenterPoint Energy incident, where account numbers and billing details from potentially 7.49 million customers were posted publicly. The journey from a breach listing to a dark web fraud marketplace to a counterfeit check presented at a bank teller can happen within days, and that speed is what makes upstream detection valuable.
Understanding what to do when your financial data has already been exposed remains the consumer-side responsibility. But partnerships like this one represent the institutional-side response, and the two work together rather than replacing each other.
Frequently Asked Questions
What did Nasdaq Verafin and Q6 Cyber announce?
A partnership announced August 27, 2026, integrating Q6 Cyber’s dark web fraud intelligence into Nasdaq Verafin’s financial institution fraud platform, covering stolen checks, payment cards, and banking credentials.
What does Q6 Cyber actually monitor?
Hundreds of thousands of criminal community sources, including invite-only forums, carding shops, and encrypted channels. In 18 months, it collected 1.2 million compromised checks, 158 million compromised payment cards, and 57 million unique credentials.
What is the 10-day window?
A proof-of-concept found that the average gap between Q6 Cyber detecting a stolen check on the dark web and the first fraudulent return to a bank was 10 days, giving banks time to contact customers or take protective action before fraud occurs.
How large is check fraud in 2026?
Nasdaq Verafin’s 2026 Global Financial Crime Report estimates global check fraud losses reached $38.5 billion in 2025, with $33.6 billion in the US. The typology is growing at 20.4% annualized over the past two years.
How does the integration work in practice?
Q6: Cyber intelligence surfaces as high-risk alerts inside Nasdaq Verafin’s existing fraud and AML workflow, tied to specific institutions and accounts rather than general threat categories, so that investigators can act on confirmed compromises without additional noise.