Deepfake fraud is now organized crime, and banks are footing the bill

One bank logged 8,065 deepfake attempts in eight months, resulting in $347 million in verified losses. That single data point, from a new intelligence report by Liminal and Unico, captures how quickly deepfake fraud has moved from novelty to industrialized threat. Generative AI has pushed global fraud losses past $400 billion a year, and financial institutions are no longer facing lone scammers — they're facing coordinated fraud networks that treat identity theft as a scalable business.
Fraud is no longer opportunistic — it's organized
The same report maps out a "fraud sophistication ladder" showing how attacks against banks are distributed: physical presentation attacks account for 30.9% of cases, simple injection attacks make up the bulk at 45.8%, and advanced deepfake or manipulated-monitor attacks represent 23.3% — the fastest-growing and most damaging tier.
What makes this shift dangerous isn't just the technology. It's the coordination behind it. Investigators traced a single fraud entity to 949 identity documents used to target 30 different businesses. Because banks largely operate in isolation, the same repeat offender can appear as a "first-time customer" at every institution they touch — slipping past defenses that were never designed to talk to each other.
Synthetic identity is the fastest-growing threat
Synthetic identity fraud — blending real and fabricated personal data to create a convincing but fictitious identity — now accounts for 11% of global fraud, an eightfold increase year over year. Latin America is the current epicenter, with synthetic identities driving 48.3% of regional fraud cases and institutions there blocking more than 500,000 deepfake attempts in a single deployment. The U.S. isn't far behind: synthetic identity exposure reached $3.3 billion in 2024, and account takeover attacks affected six million victims that year, up 141% since 2021. Deepfake-enabled account takeovers now cost organizations an average of $280,000 per incident.
Why static checks keep failing
Traditional identity verification was built for a world of static signals — a photo ID, a one-time selfie, a password. That model breaks down against attackers who can generate a convincing face or voice on demand. Injection and deepfake attacks together now represent nearly 70% of the sophistication ladder, meaning most fraud attempts are actively trying to fool the verification step itself, not just steal a credential.
Banks are moving to continuous, networked verification
The response taking shape across the industry involves two shifts: verifying identity continuously rather than once, and connecting verification data across institutions rather than keeping it siloed.
- Continuous authentication: U.S. banking technology firm YEO Messaging recently partnered with consultancy ReconIQ to bring on-device, continuous facial verification to American banks — addressing the fact that Federal Reserve data shows account takeover losses hit $15.6 billion in 2024, up from $12.7 billion the year before.
- Verification at every touchpoint: Czechia's Air Bank now requires face verification for mobile app pairing, closing a gap that PSD2's strong customer authentication rules were designed to prevent but that static checks alone couldn't fully secure.
- Network-level intelligence: Liminal and Unico argue that only connected verification networks — with strong correction mechanisms to avoid wrongful flags following innocent customers — can catch repeat fraud entities before they reach a 30th victim institution.
The common thread is that identity verification can no longer be a single checkpoint at onboarding. It has to be continuous, layered, and capable of detecting synthetic or manipulated media in real time — across voice, face, and video, not just static images.
What this means for fraud and security teams
Fraud teams now rank AI-generated synthetic content as their top concern, and forecasts suggest financial institution losses could rise 121% by 2030 if defenses don't keep pace. That means the institutions getting ahead of this shift are the ones investing now in detection technology built specifically for deepfakes and voice clones — not repurposed liveness checks designed for an earlier generation of fraud.
Corsound AI's Deepfake Detect and Voice-to-Face AI are built for exactly this environment — real-time detection of manipulated audio and video, and voice-based identity matching that doesn't rely on a pre-existing database. For banks and financial institutions looking to move beyond static, single-checkpoint verification, explore how Corsound AI supports fraud prevention in banking and finance.
Photo: Tima Miroshnichenko / Pexels
See Corsound AI Voice Intelligence In Action

