Continental Postal Services of Hebland

World Cup traffic stress-tests Jumio’s identity verification

World Cup traffic tested the capacity and resilience of identity verification systems.

The FIFA World Cup gave Jumio little margin for a bad capacity assumption. Identity checks had to keep pace with sudden betting traffic without delaying users or compromising security.

In this interview, Bala Kumar, President and Chief Product and Technology Officer at Jumio, discusses how the company prepared for that test, what it observed during the tournament, and how the experience informs broader questions about automation and trust in identity verification.

How did identity verification remain reliable during FIFA World Cup traffic peaks?

Reliability depended first on speed. Our system’s speed allowed us to process tens of millions of transactions across our global gaming client base without introducing latency that would frustrate users. From an operational perspective, reliability came down to stability metrics. We maintained 100% uptime across all our data centres during the World Cup, with no critical system outages. We achieved this by planning and provisioning additional capacity in anticipation of the increased server load, allowing us to absorb large traffic spikes with almost no throttling.

– Advertisement –

An equally important factor was our system’s ability to redistribute server loads dynamically across regions. During the World Cup, traffic shifted rapidly depending on which teams were playing and where fans were logging in. On our five peak match days, June 11, 13, 17, 24, and 30, we recorded large, concurrent traffic spikes associated with matches involving Brazil, England, France, and Mexico. Dynamic scaling helped us maintain consistent speed and stability under sustained, heavy loads.

Which infrastructure decisions mattered most during the World Cup’s busiest traffic periods?

The most important infrastructure decisions were those we made before the World Cup, as we were in full execution mode during the tournament. We wanted to ensure our systems were operating at our sharpest, fastest, and most stable.

We deployed servers that could scale up to absorb large, unpredictable surges in sports-betting traffic and scale back down during quieter periods. We did not rely on this elasticity without testing it rigorously beforehand. In the weeks leading up to the tournament, we conducted simulated load tests. For example, we subjected our infrastructure to extreme traffic spikes so that we could optimise each component before the World Cup began.

What surprised you most about identity verification patterns during the tournament?

What surprised us most was how closely digital traffic mirrored the emotional highs and lows on the pitch. It was fascinating to see the massive regional influence on platform activity: Brazil was a primary driver of transaction volume in the earlier stages of the World Cup, but traffic patterns shifted after the team’s exit on July 5.

Another surprise was the unpredictability of match-day traffic. Consumer behaviour did not always correspond to the prominence of the matches. For example, the final on July 19 produced only the seventh-busiest day, while the third-place match on July 18 fell on the tournament’s third-quietest day. Our monitoring also detected unexpected traffic spikes from non-gaming businesses running television adverts and promotions during match broadcasts.

We also saw a notable influx of first-time users going through onboarding during peak match windows.

What can organisations learn from World Cup digital demand surges?

Bala Kumar, President and Chief Product and Technology Officer, Jumio. Image courtesy of Jumio.

The primary lesson is to plan for spikes rather than average demand. Available server capacity is meaningless if the system can’t scale quickly enough to process high volumes without compromising security or transaction speed. For global events like the World Cup, organisations need continuous monitoring across time zones to maintain performance around the clock.

They also cannot wait until a high-demand event to test their systems. If a system averages two or three transactions per second (TPS), the organisation needs to know what will happen when traffic reaches 50, 75, 100, or more TPS. These bursts can appear and disappear quickly. If the infrastructure is designed around average demand and cannot scale in time, slower performance may frustrate users and cause them to abandon the platform.

Where does AI help and fall short in identity verification?

AI has helped us automate identity-document checks and compare a person’s live face with the image in an identity document. This allows businesses to establish identity more quickly and securely while reducing unnecessary steps for legitimate users.

AI also helps detect signs of injection attacks, in which fraudsters bypass physical cameras and feed synthetic or prerecorded videos directly into the verification system. We also use AI for liveness detection to distinguish real users from deepfakes, replays, and physical 3D masks.

AI still falls short when it encounters entirely new fraud patterns for the first time. Machine-learning models perform best against known threat patterns. At Jumio, we address this limitation by combining multiple models, our identity graph, and additional risk signals rather than relying on a single check. This layered approach is intended to improve the detection of new and emerging attack patterns, but maintaining its accuracy requires continuous model retraining as fraud tactics evolve.

When can a verified digital identity be trusted beyond the first transaction?

Beyond the first transaction, a verified digital identity should be trusted only when that trust is continuously reassessed.

Trust begins with robust initial verification that pairs a government-issued identity document with a live biometric selfie. However, this initial check is not sufficient on its own because an account can subsequently be shared, stolen, or compromised. A reusable identity is only as reliable as the system supporting it.

For trust to persist, the identity system must evaluate relevant risk signals across transactions and over time. This can include comparing identity-risk signals across customers and monitoring for changes after onboarding. These checks help organisations determine when trust can be extended and when additional verification is necessary.

The assurance provided by a single verification declines over time. Independent validation of the underlying technology is also important. Level 2 presentation attack detection assessments, for example, can evaluate how well a system resists spoofing attempts involving physical masks or digital photographs presented to a camera.

Overall, long-term trust requires continuous, contextual, and connected intelligence. This approach allows organisations to extend trust while balancing fraud detection, user friction, and conversion, and protecting users after onboarding.

Where should human review be mandatory in automated identity decisions?

Human review should not be treated as mandatory for every digital identity decision and should instead be reserved for compliance requirements.

Fraud operations have changed substantially. Historically, fraud analysts manually wrote SQL queries to search for suspicious patterns. Today, AI can analyse large volumes of data, identify patterns, and produce a more focused set of suspicious cases for investigation.

Human review should therefore be required only when mandated by applicable laws, regulations, or an organisation’s compliance policies.

– Advertisement –

Crédito: Link de origem

Leave A Reply

Your email address will not be published.