why banks are buying their way into deepfake defense

In the first week of August 2026, Visa agreed to pay $2.4 billion in cash for a company most consumers have never heard of: BioCatch, a behavioral biometrics firm that watches how you type, swipe, and hold your phone to tell a real customer from a fraudster. It was not an isolated deal. Within weeks, Socure acquired case-investigation platform Fravity and raised $156 million, Precise Biometrics merged with Fingerprint Cards, and Assa Abloy moved to acquire Gunnebo Entrance Control. Four separate acquisitions, one shared thesis: deepfake-era fraud has made single-point identity checks obsolete, and the companies that sell fraud prevention are racing to become full-stack identity platforms before their customers go looking for one.
A $2.4 billion signal from the world's largest payment network
Visa's acquisition of BioCatch is the clearest data point yet that fraud prevention has become boardroom-level spending. BioCatch already protects 1.8 billion devices and serves more than 350 banks in 21 countries, generating roughly $185 million in annual recurring revenue. Visa is not buying a startup; it is buying distribution and a decade of behavioral data, then folding it directly into the rails that move global payments.
That is a meaningful shift in how payment networks think about risk. Historically, card networks priced fraud in basis points and left detection to issuing banks. Now the network itself wants to own the signal that says, in real time, this is not the person it claims to be — because the fraud that slips through today is increasingly generated, not stolen.
Why point solutions stopped being enough
The 2026 Entrust Identity Fraud Report found that deepfakes now account for one in five biometric fraud attempts, that deepfake selfie attempts rose 58% year over year, and that injection attacks — feeding a manipulated image or audio stream directly into a verification pipeline — surged 40%. Those three trend lines explain why a single face scan, voice check, or document upload at onboarding is no longer a credible line of defense on its own.
A fraud team evaluating vendors in 2026 is really asking a different question than it asked in 2022. It used to be: "Can this tool verify identity at sign-up?" Now it has to be:
- Can it detect a synthetic voice, face, or video injected mid-session, not just at enrollment?
- Does it combine behavioral, biometric, and device signals, so a fraudster who beats one layer still trips another?
- Can it run continuously across a customer's lifecycle — onboarding, login, high-risk transaction, support call — instead of once at the door?
From "verify once" to continuous identity
Industry analysts at Liminal describe this as a move toward "continuous identity" — treating verification as an ongoing state rather than a one-time gate. That framing matches what Corsound AI sees across banking, telecom, and law enforcement customers: the moment of highest risk is rarely account opening. It is the wire transfer authorized by a voice on a phone call, the video interview conducted by a synthetic candidate, or the support-line password reset triggered by a cloned voice impersonating an executive.
Consolidation is the market's answer to that reality. Buyers increasingly want one platform that layers liveness detection, deepfake and injection-attack detection, document verification, and behavioral analytics — rather than stitching together four vendors and hoping the handoffs hold under attack.
What this means for fraud and security teams right now
None of these acquisitions close overnight — Visa's BioCatch deal is not expected to complete until Visa's fiscal Q2 2027 — so the coverage gap they are meant to close is open today. Fraud teams do not need to wait for consolidated platforms to reach the market before acting. The practical steps are the same ones this wave of M&A is trying to buy: audit where voice and video are trusted as sole proof of identity, add real-time deepfake detection at the moments of highest financial risk, and treat identity verification as continuous rather than a single checkpoint.
The bottom line for banks and fraud teams
When the world's largest payment network pays $2.4 billion for behavioral biometrics in the same quarter that three other fraud-prevention vendors merge or acquire, that is not noise — it is the market pricing in what security teams already know from experience: voice and video can no longer be trusted at face value. Corsound AI's Voice-to-Face AI and Deepfake Detect technologies were built for exactly this shift, giving banks, telecoms, and law enforcement a way to verify identity continuously and catch synthetic voices and faces before they cause a loss. If your organization is still relying on a single check at onboarding, explore how Corsound AI helps prevent identity fraud before the next $2.4 billion acquisition becomes the next headline you're reacting to instead of anticipating.
Photo: Towfiqu barbhuiya / Pexels
See Corsound AI Voice Intelligence In Action

