Fraud has always evolved alongside technology. But advances in artificial intelligence (AI) have made it easier than ever for criminals to create convincing fake identities, manipulate identity documents, and even impersonate real people at scale.
Deepfake technology uses machine learning to create or alter images, videos, and documents that appear real and believable. While it’s mostly used for harmless videos, like showing celebrities in a boxing match, fraudsters are increasingly using it to bypass identity verification, take over customer accounts, and trick employees into authorizing fraudulent payments.
As these attacks become more convincing, financial institutions need new ways to verify identities and distinguish legitimate customers from fraudsters.
What is deepfake fraud?
Deepfake fraud uses AI to create or manipulate images, audio, video, or documents to impersonate a real person or create a fake, believable identity. In financial crime, deepfakes are often used to alter identity documents, generate fraudulent selfies, or clone a person's appearance to bypass security checks. Once fraudsters have access to an account, they can take over the account, authorize fraudulent transactions, or even launch other fraud attacks.
Unlike traditional identity fraud, which typically relies on stolen log-in information or manually edited documents, deepfake fraud uses generative AI to create highly-realistic media at scale. These AI-generated images, videos, and documents can be difficult for both people and traditional fraud systems to identify.
How big is the problem?
According to Deloitte, generative AI-enabled fraud losses in the U.S. could reach $40 billion annually by 2027, up from an estimated $12.3 billion in 2023.
Several high-profile incidents have shown how quickly these attacks can happen. In 2024, scammers used a deepfake video of company executives during a video conference to convince an employee at Arup to transfer approximately $25 million to fraudulent accounts.
In another case, fraudsters used a deepfake video of Bombay Stock Exchange (BSE)’s CEO Sundararaman Ramamurthy offering stock advice to fraudulently pump up the price of specific stocks. These incidents show that deepfake fraud is no longer limited to individual account fraud, like doctoring income statements on a loan application. It now affects multiple points in the financial lifecycle.
How deepfake fraud shows up in financial crime
Although deepfake technology is often associated with fake celebrity videos or misinformation, in financial services it's used for targeted attacks in areas like:
Onboarding / KYC bypass
Many financial institutions rely on identity verification during onboarding to confirm that a new customer is who they claim to be. Deepfake technology allows fraudsters to manipulate identity documents or generate convincing selfies and videos to mimic real people and open fraudulent accounts.
These attacks are designed to trick Know Your Customer (KYC) and identity verification checks, allowing criminals to access financial products or establish accounts that can later be used for money laundering or other financial crimes.
Account takeover via voice cloning or fake selfies
Deepfake tools can replicate a person's speech or verification selfies using just a short sample, enabling fraudsters to impersonate customers during phone or video based-authentication. A convincing synthetic voice can be used to persuade call center agents to reset passwords, change account details, or bypass security questions. Combined with stolen personal information, deepfakes can make account takeover attacks significantly more convincing than social engineering alone.
Payment authorization / executive impersonation fraud
Deepfake fraud also targets payment workflows. Criminals may use AI-generated audio or video to impersonate executives, business partners, or trusted colleagues and pressure employees into approving wire transfers, ACH payments, or other high-value transactions.
These attacks often create a sense of urgency—for example, requesting an immediate payment during a video meeting or phone call—and may be paired with compromised email accounts or other social engineering tactics to further appear legitimate.
Rethinking fraud in the AI era
AI is reshaping fraud. It’s time to rethink trust.
How to detect and prevent deepfake fraud
No single control can reliably stop every deepfake attack. As deepfakes become more convincing, organizations need to take multiple steps to detect deepfakes and limit their fraud risk.
Use technical controls to detect deepfake fraud
Modern fraud platforms can identify signals of deepfake attacks that might slip past humans or legacy detection tools. Key capabilities include:
Liveness detection: Liveness detection helps determine whether a real person is physically present during identity verification rather than a photo, recording, or AI-generated image.
Biometric verification: Compares multiple identity signals, such as a government-issued ID, a live selfie, and facial biometrics to detect synthetic media or fraudulent documents.
Device and behavioral intelligence: Evaluates signals such as unfamiliar devices, unusual locations, rapid account changes, and suspicious transaction patterns to identify activity that doesn't match a customer's expected behavior.
Meta data analysis: Inspects the metadata behind submitted images or documents for signs of digital editing or AI generation.
Watch out for common red flags
In addition to technical controls, the Financial Crimes Enforcement Network (FinCEN) advises financial institutions to watch for common indicators of potential deepfake fraud, including:
Identity documents or photos that are inconsistent with each other or with other customer information.
Customers who refuse to use multifactor authentication or attempt to switch devices during the process.
Use of third-party webcam software or repeated technical issues during remote identity verification.
Images that match known AI-generated faces or are flagged by deepfake detection tools.
Newly opened or low-activity accounts that quickly begin sending high volumes of payments or transferring funds to higher-risk recipients.
Train employees to spot suspicious activity
Technology should also be supported by trained employees who can spot the signs of deepfakes. Train employees to recognize the signs of deepfake attacks, like urgent requests or odd gaps in speech. Require secondary approval through another channel for high value payments.
Build a layered fraud prevention strategy
Deepfakes are designed to exploit gaps in fraud prevention. Organizations can reduce the risk by building a layered approach that evaluates identity verification alongside device intelligence, behavioral patterns, account ownership, and transaction activity.
Applying additional verification during high-risk events—such as account recovery, password resets, or payment authorization—can also help stop fraud before it succeeds. Finally, establish an incident response plan so teams can quickly contain and respond to attacks if they do occur.
How Plaid helps organizations limit deepfake fraud risk
Plaid helps organizations strengthen their fraud prevention using AI-powered tools to fight back. For example, Plaid Identity Verification helps organizations verify customers during onboarding and high-risk moments by confirming identity attributes and evaluating sophisticated identity and behavioral signals in less than 10 seconds. It can also help spot fraudulent verification images or AI-altered ID documents.
Plaid Protect is an AI-powered fraud intelligence platform built on the Plaid Network. It evaluates more than 10,000 different fraud risk signals, including financial behavior, devices, and account activity, to help teams identify suspicious patterns that may indicate fraud.
As deepfake attacks become more sophisticated, stopping fraud requires more than detecting manipulated images or videos. By combining identity verification with broader risk signals, organizations can make more informed decisions while reducing friction for legitimate customers.
Frequently asked questions about deepfake fraud prevention
Find out how Plaid can help your business grow
Learn more
Recommended reading
Readiness Check for Nacha Fraud Monitoring Rule Changes
Healthcare fraud prevention across the care lifecycle
ACH fraud is on the rise. Here are 5 ways to reduce it.
