For years, banks leaned on a simple idea: if you can see a customer's face or hear their voice, you can trust who you are dealing with. Generative AI has broken that idea. Today, anyone with a laptop and a few minutes of someone's audio or video can create a convincing fake, and fraudsters are using those fakes to open accounts, take over existing ones and trick staff into moving money.
That is why deepfake fraud has become one of the most searched topics in financial services this year. It is no longer a future threat. It is a daily operational problem.
What is deepfake fraud?
Deepfake fraud uses AI-generated or AI-altered video, images or audio to impersonate a real person, or to invent a person who does not exist. In banking, it usually shows up in four ways:
Onboarding fraud: fake selfies or videos, paired with forged or stolen ID documents, used to pass remote KYC checks and open accounts.
Synthetic identities: entirely invented people, built from a mix of real and fake data, with AI-generated faces to match.
Voice cloning: a cloned voice calls a bank's contact centre, or a family member, to reset credentials or request an urgent transfer.
Executive impersonation: a fake CFO or CEO on a video call instructs a finance team to make a payment.
The last one made global headlines in 2024, when an employee at the engineering firm Arup in Hong Kong transferred about US$25 million after a video call in which every other participant, including the “CFO”, was a deepfake. In the same year, the US Treasury's FinCEN issued a formal alert warning financial institutions about fraud schemes that use deepfake media.
Why traditional defences are struggling
1. Selfie checks were built for a different era
Many remote onboarding flows compare a selfie to an ID photo. That works against someone holding up a printed photo. It works much less well against a real-time face swap or a video fed directly into the camera stream, known as an injection attack.
2. Voice is no longer a reliable password
Voice biometrics and “verify by phone” steps assume a voice is hard to copy. Modern voice-cloning tools need only a short sample, often taken from social media or a recorded voicemail.
3. Social engineering scales with AI
Scammers can now write fluent messages in any language, clone voices and generate fake documents in bulk. Attacks that once needed a skilled team can be run by one person with the right tools.
4. Customers are the target, not just the bank
In authorised push payment (APP) scams, the real customer makes the transfer, believing they are paying a relative, an investment manager or a bank official. Because the customer authenticated correctly, the bank's controls see nothing unusual.
Old controls vs. what works now
Area | Old approach | Stronger approach |
|---|---|---|
Onboarding | Selfie matched to an ID photo | Liveness detection, injection-attack detection and document forensics working together |
Contact centre | Voice match or security questions | Device and network signals, call-back to a known number, voice-deepfake detection |
High-value payments | Approval on a call or video meeting | Out-of-band confirmation through a separate, pre-agreed channel |
Fraud monitoring | Checks at login and payment only | Behavioural analytics across the whole session |
Customer protection | Generic fraud warnings | Real-time, context-specific warnings and payment “cooling-off” periods |
A practical playbook for banks and fintechs
Layer your identity checks. No single signal is enough. Combine document checks, liveness, device intelligence and behavioural data so that faking one layer is not enough to get through.
Defend the camera and microphone pipeline. Detect virtual cameras, emulators and tampered video streams, not just the face on screen.
Stop trusting a single channel. Any request to move large sums or change payment details should be confirmed through a separate channel that the requester did not choose.
Train staff with real examples. Show finance and contact-centre teams what deepfakes look and sound like, and give them permission to slow down and verify, even when the “boss” is on the line.
Share intelligence. Fraud rings reuse faces, devices and mule accounts across institutions. Industry data-sharing networks catch patterns a single bank cannot see.
Educate customers. Encourage families to agree on a “safe word” for urgent money requests, and remind customers that the bank will never ask them to move money to a “safe account”.
The role of AI on the defence side
The same technology that powers deepfakes also powers detection. Machine-learning models can spot tiny visual artefacts, unnatural audio patterns and behavioural signals, such as how a user types or holds a phone, that humans would miss. The key is to treat detection as a moving target: models must be retrained often, because attackers are improving just as quickly.
The bottom line
Deepfakes have turned identity, the foundation of banking, into something that can be faked on demand. Banks and fintechs that respond with layered verification, out-of-band confirmation and well-trained staff will keep the trust of their customers. Those that still rely on “I saw their face” or “I heard their voice” will keep paying for it.
In the age of AI, trust is not something you see. It is something you verify.
