How a $5 deepfake beats your KYC — and what banks must do next

In one eight-month stretch, a single financial institution logged 8,065 attempts to slip past its liveness checks using AI-generated deepfake images. The tool behind that kind of attack now costs a fraudster as little as $5. That is the uncomfortable reality for every bank, fintech and telecom running biometric onboarding: the identity check you deployed to stop fraud has quietly become the front door fraudsters walk through.
The economics of fraud just inverted
For years, biometric onboarding worked because faking a convincing face or voice was hard and expensive. Generative AI erased that moat. In 2026, deepfakes account for 11% of all global fraudulent activity, up from 7% in 2024, and deepfake biometric fraud has surged 58% year over year. Identity-verification vendor iProov has logged a staggering 2,665% spike in virtual-camera injection attacks in a single year.
When a working deepfake that defeats a standard biometric check costs roughly $5, attackers no longer need skill or scale — just a browser and a stolen ID photo. Global identity-fraud losses topped $50 billion in 2025, and early 2026 indicators point higher.
How deepfake injection attacks bypass onboarding
Most onboarding flows ask a new user to take a selfie or short video to prove they are a live human who matches their ID document. Injection attacks defeat this by feeding synthetic media directly into the verification pipeline, bypassing the physical camera entirely. The most common techniques include:
- Virtual-camera feeds: software cameras pipe a pre-rendered deepfake video into the check as if it came from a real device.
- Face-swap and reenactment: a stolen ID photo is animated to blink, smile and turn on cue, defeating naive liveness prompts.
- Real-time voice cloning: synthetic speech passes voice-based verification and call-center identity challenges.
- Synthetic identities: AI-generated faces and documents that belong to no real person, stitched together to open accounts at scale.
Regulators have stopped waiting
Supervisors have shifted from advisory guidance to enforceable expectation. Firms that cannot demonstrate effective deepfake detection are now facing supervisory letters and thematic reviews. In June 2026, FinCEN issued fresh guidance on fraud information sharing, while Mitek and Datos Insights warned that synthetic identity fraud is emerging as the defining fraud threat of 2026. No single rule names "deepfake detection" outright, but the obligation flows from existing AML and customer-due-diligence requirements — and examiners now expect controls that match the threat.
Why one-and-done verification fails
The industry consensus is blunt: one-and-done eKYC is no longer sufficient. A single identity check at signup assumes the person who onboarded is the person who keeps using the account — an assumption deepfakes shatter. Verification has to become continuous, and it has to look at signals a face-swap cannot easily fake.
A more resilient defense layers several controls:
- Injection-attack detection that flags virtual cameras and manipulated media streams, not just static image quality.
- Multimodal biometrics that cross-check voice against face, so a spoof has to defeat two independent signals at once.
- Continuous re-verification triggered by risk events rather than a one-time gate at enrollment.
- Passive liveness and provenance analysis that detect generative artifacts invisible to the human eye.
Closing the gap
Deepfake fraud is scaling faster than most onboarding stacks were designed to handle, and the $5 price tag means the volume will only grow. The banks and platforms that stay ahead will be the ones that stop treating identity as a one-time checkbox and start treating it as a signal to monitor for life. Corsound AI's deepfake and voice-analysis technology is built for exactly this fight — detecting synthetic audio and video in real time and matching a voice to a face without a database. See how Corsound AI helps prevent identity fraud at onboarding and beyond.
Photo: cottonbro studio / Pexels
See Corsound AI Voice Intelligence In Action

