Zenoo
Learn/Deepfake detection in KYC: stopping AI-g…
AI threat and defence

Deepfake detection in KYC: stopping AI-generated identity fraud

Can your current KYC vendor actually catch a deepfake, how would you know, and how do you layer the detectors that can?

Last reviewed 1 July 202616 min read
In shortThe answer, first

Deepfake detection in KYC is the set of techniques that decide whether the face, voice, document, or video in an onboarding check is a genuine live person or AI-generated synthetic media. Because generative AI has made convincing fakes cheap and scalable, no single detector is enough. Strong defence layers document, liveness, injection, and behavioural checks and requires them to agree.

Key facts
  • The critical split is presentation attacks (fake shown to the camera) versus injection attacks (fake fed straight into the data stream, bypassing the camera entirely).
  • iProov's 2025 threat report (published April 2026) found iOS injection attacks up 741% year on year, with native virtual-camera attacks now the primary vector.
  • iBeta tests liveness against ISO/IEC 30107-3 presentation-attack levels 1, 2, and 3; certification proves presentation resistance, not injection resistance.
  • FinCEN issued alert FIN-2024-Alert004 in November 2024 and FATF published its Horizon Scan on AI and deepfakes in December 2025, both treating deepfakes as a direct threat to customer due diligence.
  • Deepfake detection is a consensus problem: single signals are individually defeatable, so detectors must run in parallel and agree.
  • Zenoo does not detect deepfakes; it orchestrates the specialist detectors you choose, combines their signals, and keeps one audit trail.

What is deepfake detection in KYC?

Deepfake detection in KYC is the set of techniques a verification system uses to decide whether the face, voice, document, or video presented during onboarding is a genuine live person or a piece of AI-generated synthetic media. It matters because generative AI has turned the remote selfie-and-document check that underpins modern account opening into an actively contested attack surface.

The controls most banks and fintechs rely on for remote onboarding, document capture, selfie match, and liveness, were designed for an era when the hardest attack was a printed photo or a silicone mask. Generative models changed the economics. Secondary reporting puts the cost of a usable face-swap or synthetic identity in the region of a few dollars to a few hundred, produced in under an hour on a laptop. Regulators now treat deepfakes as a direct threat to customer due diligence, not a fringe concern.

Common misconception
"Liveness detection stops deepfakes"
If our liveness check is certified, deepfakes cannot get through.
Presentation-based liveness only resists attacks shown to the camera, and only within its certified level. It does nothing about injection attacks, which bypass the camera entirely by feeding synthetic video straight into the verification stream. Liveness is necessary but no longer sufficient on its own.

The attack taxonomy: what fraudsters actually do

"Deepfake media" in KYC is broader than a swapped face on a video call. FinCEN defines it as synthetic content created with AI or machine learning to produce realistic but inauthentic videos, pictures, audio, and text that circumvent identity verification and authentication. That includes fabricated documents, AI-generated document photos, and fully synthetic faces of people who do not exist.

Face swaps, reenactment, and fully synthetic faces

A face swap maps a real target's face onto a fraudster's live video, so the fraudster can respond to prompts in real time while wearing the victim's face. Face reenactment (puppeteering) drives a still image or short clip of a real person with the fraudster's own expressions and head movements. A fully synthetic face is a photorealistic face of a non-existent person generated by a model, used to build a clean identity with no real victim behind it.

Synthetic and hybrid identities

A synthetic identity combines real stolen data, for example a genuine national ID number, with fabricated or AI-generated attributes and imagery. The identity is real enough to pass checks but ties to no real accountable person. This is a different problem from a single deepfake image, and it is the higher-volume KYC threat. See our explainer on synthetic identity fraud.

Document deepfakes and digital forgery

An AI-edited or AI-generated identity document image can defeat document checks. Entrust and Onfido's 2025 Identity Fraud Report found digital forgeries overtook physical counterfeits, reaching 57% of document fraud cases, with a 244% year-on-year rise.

Presentation attacks vs injection attacks: the distinction that matters most

This is the single most important concept to grasp, because most legacy defences only address the first type. A presentation attack shows the fake to the camera: a screen replaying a video, a printed photo, a 3D mask, or a phone held up to the verification device. An injection attack bypasses the camera entirely, feeding synthetic video directly into the verification data stream using a virtual camera, a manipulated app, an emulator, or an operating-system-level video interception tool. The camera layer never sees the attack, so camera-based liveness alone cannot catch it.

The industry inflection is that injection attacks have moved from niche to primary vector. Gartner noted injection attacks rose 200% in 2023. iProov's 2025 threat intelligence report, published April 2026, found iOS injection attacks up 741% year on year, and up 1,151% in the second half of 2025, with native virtual-camera attacks up 2,665% and now named the primary threat vector, partly through mainstream app-store infiltration. A stack that certified its liveness against presentation attacks years ago may have no defence against the attack that now dominates.

DimensionPresentation attackInjection attack
Where the fake entersShown to the camera (screen, print, mask)Fed into the data stream, bypassing the camera
Typical toolsReplayed video, printed photo, 3D silicone or resin maskVirtual camera, emulator, manipulated app, OS-level video interception
Detection disciplinePresentation attack detection (PAD)Injection attack detection (IAD)
Governing standardISO/IEC 30107 family, tested by labs such as iBetaNo single certification standard; data-integrity signals
Key signalsTexture, depth, reflectance, micro-motionDevice attestation, virtual-camera fingerprints, frame consistency
TrendMost common vector, but flat growthFast-rising; iProov reports iOS injection up 741% in 2025
Presentation vs injection: the distinction that matters
Camera-based liveness never sees an injection attack, now the primary vector.
Presentation attack
Fake📷 CameraPipeline
Tools: Replayed video, printed photo, 3D mask.
Caught by: Presentation attack detection (PAD), ISO/IEC 30107-3.
Injection attack
Fake✗ camera bypassedPipeline
Tools: Virtual camera, emulator, OS-level interception.
Caught by: Injection attack detection: device attestation, frame integrity.
Detection is a consensus problem: layers must agree
Document authPassive livenessActive livenessInjection detectionBiometric bindingForensicsBehaviouralProvenance

How deepfake detection actually works: the layered pipeline

Modern deepfake-resistant KYC runs several independent detectors in parallel and requires them to agree, because no single signal is sufficient. Detection is a consensus problem, not a single yes or no.

Document authentication and liveness

Document authentication checks security features, fonts, machine-readable-zone and checksum integrity, and looks for signs of digital manipulation or AI generation. Passive liveness analyses a single image or short capture for biological markers such as natural micro-expressions, skin-texture and reflectance variation, and 3D depth cues that flat replays cannot reproduce. State the limit honestly: current generative models can pass some pixel-level passive checks. Active liveness or challenge-response asks the user to perform real-time actions, such as following a randomised on-screen colour sequence, which pre-recorded footage cannot answer.

Injection detection, biometric binding, and forensics

Injection attack detection uses device attestation, virtual-camera and emulator detection, SDK integrity, and frame-level metadata analysis to confirm the feed came from a real sensor. Biometric binding cross-validates the face extracted from the document against the live biometric; both must independently pass authenticity checks and then match each other. Forensic artefact analysis examines texture, frequency-domain, and compression artefacts, plus temporal consistency across frames, to spot generation fingerprints.

Behavioural and provenance signals

Behavioural and contextual signals, including device reputation, network and IP signals, velocity, and behavioural biometrics, sit outside the image entirely and catch scaled rings that individually pass the image check. Provenance signals such as C2PA content credentials can record whether media was AI-generated, but note the limit clearly: C2PA records an assertion about provenance, it does not itself detect deepfakes, and it can be stripped.

  1. 1Document authentication: security features, MRZ and checksum integrity, signs of digital or AI manipulation.
  2. 2Passive liveness: single-capture biological markers; honest limit is that some generative models pass pixel-level checks.
  3. 3Active liveness / challenge-response: real-time, unpredictable prompts that replays cannot answer.
  4. 4Injection attack detection: device attestation, virtual-camera and emulator fingerprints, SDK integrity.
  5. 5Biometric binding: document face and live face each pass authenticity, then match each other.
  6. 6Forensic artefact analysis: frequency-domain, compression, and temporal-consistency checks.
  7. 7Behavioural and network signals: device reputation, velocity, behavioural biometrics.
  8. 8Provenance signals: C2PA content credentials that assert, but do not detect, and can be stripped.

Certification: reading "we do liveness" properly

Demand evidence, not marketing. The relevant standard for presentation attack detection is ISO/IEC 30107-3, tested independently by NIST or NVLAP-accredited labs such as iBeta. The levels describe how well-resourced an attacker the system was tested against.

The teaching point: PAD certification proves resistance to presentation attacks only. It does not, on its own, prove resistance to injection attacks, so a buyer must ask separately about injection coverage. Certification is also scoped and point-in-time, a result against a fast-moving threat rather than a permanent guarantee.

iBeta / ISO 30107-3 levelAttacker modelledWhat it proves
Level 1Low-effort attacks, materials up to roughly $30, limited time, no special expertiseResistance to basic presentation attacks
Level 2Higher-effort attacks, materials up to roughly $300, moderate expertiseResistance to more capable presentation attacks
Level 3Introduced 16 June 2025; hyper-realistic custom 3D masks, variable lighting, unlimited tools, experienced attackerResistance to a well-resourced presentation attacker; Incode reported being first to pass on iOS and Android with a 0% error rate in early 2026
Note
Certification is scoped and time-bound

An iBeta pass tells you which level and that it covers presentation attacks. It does not cover injection attacks, and it reflects the threat at the time of testing. Ask for the level, the date, and separate evidence of injection-attack detection before you rely on a single certificate.

Where we are now (2025 to 2026): the numbers

The figures below come from named vendor, analyst, and regulatory sources. Where analysts diverge, treat the numbers as directional and attributed, not as consensus fact.

  • Prevalence. Signicat reports deepfake fraud attempts rose 2,137% over three years, from about 0.1% to about 6.5% (roughly 1 in 15) of detected fraud attempts, based on Censuswide research across seven European markets (February 2025).
  • Document forgery. Entrust and Onfido recorded a deepfake attempt roughly every five minutes in 2024, a 244% year-on-year rise in digital document forgery, and digital forgeries reaching 57% of document-fraud cases.
  • Injection surge. iProov's 2025 threat report (published April 2026) found iOS injection attacks up 741% year on year, up 1,151% in the second half of 2025, with native virtual-camera attacks up 2,665% and now the primary vector; Southeast Asia saw a 720% spike in Q3 2025.
  • Losses (projection). Deloitte's Center for Financial Services projects US generative-AI-enabled fraud losses reaching about $40 billion by 2027, up from $12.3 billion in 2023, a roughly 32% annual growth rate; Deloitte also gives a more conservative scenario of about $22 billion, so $40 billion is the higher-end projection.
  • Losses (reported). Surfshark, aggregating publicly reported incidents from the AI Incident Database, Resemble.AI, and OECD data, estimates US deepfake-related fraud losses of about $1.1 billion in 2025, roughly triple the prior year; Surfshark frames this as a conservative estimate, not a government primary.
  • A named incident. In the Arup case, a Hong Kong finance employee was deceived by a deepfake video call impersonating the CFO and colleagues into making 15 transfers totalling about $25.6 million (HK$200m) in a single day; the funds were unrecovered as of early 2025.

What the regulators say: FATF, FinCEN, Gartner, and the EU AI Act

Supervisors have moved from silence to specific expectations. FinCEN issued alert FIN-2024-Alert004 on 13 November 2024 on generative-AI fraud schemes circumventing identity verification, authentication, and due-diligence controls, asking institutions to flag related suspicious activity reports with the key term "FIN-2024-DEEPFAKEFRAUD". FATF published its Horizon Scan on AI and Deepfakes on 22 December 2025, naming deepfakes a direct threat to customer due diligence and identity verification, flagging synthetic and hybrid identities, framing AI as dual-use, and urging firms to review their CDD and ID and verification control frameworks against AI-enabled impersonation.

Gartner predicted that by 2026, 30% of enterprises will no longer consider identity verification and authentication solutions reliable in isolation because of AI-generated deepfakes on face biometrics. Under the EU AI Act, deepfake transparency and labelling obligations apply from 2 August 2026, with content that looks or sounds like a real person requiring a label even without intent to deceive, and penalties up to €15 million or 3% of worldwide turnover.

DateDevelopmentWhat it means for a KYC team
13 Nov 2024FinCEN alert FIN-2024-Alert004Flag GenAI-enabled identity fraud in SARs; deepfakes are an explicit CDD concern
16 Jun 2025iBeta introduces PAD Level 3The presentation-attack bar rises to hyper-realistic custom masks
22 Dec 2025FATF Horizon Scan on AI and deepfakesReview CDD and ID&V frameworks for synthetic identities and impersonation
2 Aug 2026EU AI Act deepfake labelling obligations applyAI-generated media impersonating a real person must be labelled; penalties up to €15m or 3% of turnover

AI for good: how defensive AI helps

AI is not only the attacker's tool; it is the core of the defence. FATF explicitly frames AI as dual-use, able to increase efficiency in compliance and detection just as it can be weaponised. Defensive AI genuinely helps here: deep-learning models classify texture, depth, reflectance, and micro-motion to separate live faces from replays and masks (this is what ISO 30107-3 certification measures); machine-learning models learn the statistical fingerprints of virtual cameras and injected streams that a genuine sensor feed does not produce; frequency-domain and temporal-consistency models flag generation artefacts invisible to humans; and behavioural and network models catch scaled synthetic-identity rings. Humans are unreliable graders here: Sumsub cites a 2025 study finding people were 36% less likely to correctly spot a fake video than a fake image, even when warned.

AI on the defender’s side
Where Zenoo's AI honestly applies

Zenoo does not build a deepfake detector; it orchestrates the vendors that do, and its AI works on the decision and investigation layer, not the pixel layer. Zenoo runs 10 specialised AI agents across research, screening triage, and case work. After a detector returns a signal, Zenoo can pre-classify up to 80% of screening alerts with high confidence and cut per-alert disposition from 20 to 45 minutes down to 2 to 3 minutes, so a spike in deepfake-flagged cases does not overwhelm the team. Every decision is recorded in an immutable audit trail of 32 event types across 8 categories. The actual "is this face a deepfake?" decision is still made by the specialist detector Zenoo routes to.

AI for bad: how it is being weaponised

What needed a studio a few years ago now needs a laptop, a free open-source model, and under an hour. Deepfake-as-a-service turns this into a subscription. Secondary reporting puts synthetic identities at roughly $5 to $15, deepfake images at $10 to $50, human-assisted "verification pass" services at $100 to $500 per successful check, and face-swap software rentals at $1,000 to $10,000; treat these as indicative ranges, not precise figures. Injection attacks then feed these fakes into KYC APIs at scale, and synthetic and hybrid identities built from real stolen data plus AI-generated imagery pass onboarding, which FATF flags specifically.

Real incidents show the scale. Sumsub reports that in early 2025 Hong Kong police disrupted a deepfake ring linked to about $193 million in losses that merged fraudsters' faces with stolen IDs to bypass facial recognition, and a separate case saw a suspect open roughly 46 fraudulent accounts using stolen IDs and deepfakes against a bank's mobile onboarding flow. Executive impersonation, as in the Arup video-call fraud, shows deepfakes weaponised against payment authorisation as well as onboarding.

AI as the threat
The arms race favours layering, not any single detector

Attackers iterate against detectors, so a passing certification grade last year is not a defence this year. Sumsub reports a 180% year-on-year rise in sophisticated, multi-step fraud and expects agentic-AI-driven scams to surge in 2026. The defender's advantage is not one clever detector but the ability to layer many, monitor them, and swap them fast, which is exactly an orchestration argument.

What the future looks like

Standalone verification loses trust. Gartner's guidance is to choose vendors who monitor, classify, and quantify these attacks and go beyond current standards. Regulation tightens and converges: FATF's December 2025 Horizon Scan signals more supervisory attention to AI-enabled CDD circumvention, FinCEN's SAR flagging builds a data trail, and the EU AI Act's labelling regime lands in August 2026. Expect examiners to ask specifically how firms defend against injection attacks and synthetic identities.

Provenance and digital identity offer a longer-term shift from "detect the fake" to "prove the genuine." C2PA content credentials (v2.3 arrived around December 2025 to January 2026, with the Samsung Galaxy S25 signing at capture) and government digital identity such as the EU Digital Identity Wallet under Regulation (EU) 2024/1183 point that way, though provenance asserts rather than detects and can be stripped. Agentic AI will operate on both sides, and the deepfake-detection market continues to grow quickly, if by definition-dependent estimates (analysts cite roughly 40% to 48% annual growth ranges). More detectors and more differentiation strengthen the case for orchestrating between them rather than betting on one.

How to evaluate a deepfake-detection vendor

Use these questions to separate evidence from marketing when you assess a detector or a stack.

  • Which ISO/IEC 30107-3 PAD level are you certified to, by which lab, and on which date?
  • What is your injection attack detection coverage, and how is it evidenced separately from PAD?
  • Do you monitor, classify, and quantify live attacks, and update models as the threat moves?
  • How do you protect SDK integrity and detect virtual cameras, emulators, and OS-level interception?
  • How do you handle biometric binding between the document face and the live capture?
  • What behavioural and network signals do you provide to catch scaled synthetic-identity rings?
  • Can I combine your signals with other detectors, and export a full audit trail of every decision?

Where orchestration fits: your detectors plus Zenoo

Zenoo is a KYC, KYB, and AML orchestration platform. It does not detect deepfakes itself. It connects the specialist deepfake, liveness, and injection detectors you already trust or want to trial, and gives you routing, failover, one audit trail, and cost control across them, with UI freedom via Zenoo Studio. Because detection is a consensus problem, orchestrating multiple detectors and applying policy across their outputs is stronger than any single vendor. Zenoo's Marketplace exposes 240+ check types on the Enterprise tier and supports parallel execution, and lets you add or reroute to a new detector in under an hour instead of a 4 to 6 month integration, so you are not locked into a detector that has fallen behind the arms race. For continuous coverage after onboarding, pair this with ongoing monitoring and perpetual KYC.

Honest scope
Where Zenoo does not solve the problem

Say this plainly. Zenoo does not make the "is this a deepfake?" decision; that is the specialist detector's job. Zenoo cannot make a weak detector strong, only route to a better one and combine signals. Orchestration does not remove the need for certified PAD and injection-attack detection in your stack. The only Zenoo numbers used here come from the metrics registry, and no detection-accuracy or catch-rate claim is attributed to Zenoo.

Key takeaways
  • The critical split is presentation attacks (fake shown to the camera) versus injection attacks (fake fed straight into the data stream, bypassing the camera entirely).
  • iProov's 2025 threat report (published April 2026) found iOS injection attacks up 741% year on year, with native virtual-camera attacks now the primary vector.
  • iBeta tests liveness against ISO/IEC 30107-3 presentation-attack levels 1, 2, and 3; certification proves presentation resistance, not injection resistance.
  • FinCEN issued alert FIN-2024-Alert004 in November 2024 and FATF published its Horizon Scan on AI and deepfakes in December 2025, both treating deepfakes as a direct threat to customer due diligence.
  • Deepfake detection is a consensus problem: single signals are individually defeatable, so detectors must run in parallel and agree.
  • Zenoo does not detect deepfakes; it orchestrates the specialist detectors you choose, combines their signals, and keeps one audit trail.

Frequently asked questions

What is deepfake detection in KYC?

It is the set of techniques a verification system uses to decide whether the face, voice, document, or video in an onboarding check is a genuine live person or AI-generated synthetic media. Strong detection layers document authentication, liveness, injection detection, biometric binding, forensic analysis, and behavioural signals, and requires them to agree, because no single signal is enough.

Can deepfakes bypass KYC and liveness checks?

Yes, in two ways. Presentation attacks show a fake to the camera and can defeat liveness that is not certified for that attack type. Injection attacks bypass the camera entirely by feeding synthetic video into the verification stream, so camera-based liveness never sees them. iProov reports iOS injection attacks up 741% in 2025, with virtual-camera attacks now the primary vector.

What is the difference between a presentation attack and an injection attack?

A presentation attack is shown to the camera, such as a replayed video, a printed photo, or a 3D mask, and is countered by presentation attack detection (PAD) under ISO/IEC 30107. An injection attack bypasses the camera and feeds synthetic video into the data stream using a virtual camera or emulator, and is countered by injection attack detection using device-integrity signals.

Is liveness detection enough to stop deepfakes?

No. Presentation-based liveness only resists attacks shown to the camera, and only within its certified level. It does nothing about injection attacks, and current generative models can pass some pixel-level passive checks. Detection is a consensus problem, so liveness must sit alongside injection detection, document authentication, biometric binding, and behavioural signals.

What is ISO/IEC 30107-3 and what do iBeta Levels 1, 2, and 3 mean?

ISO/IEC 30107-3 is the standard for presentation attack detection, tested by accredited labs such as iBeta. Level 1 models low-effort attacks (materials up to about $30), Level 2 higher-effort attacks (up to about $300), and Level 3, introduced in June 2025, models a well-resourced attacker using hyper-realistic custom masks. Certification proves presentation resistance only, not injection resistance.

How much has deepfake fraud grown, and how much does it cost?

Signicat reports deepfake fraud attempts up 2,137% over three years, from about 0.1% to about 6.5% of detected fraud. Deloitte projects US generative-AI-enabled fraud losses reaching about $40 billion by 2027 (higher-end scenario) from $12.3 billion in 2023. Surfshark estimates about $1.1 billion in reported US deepfake losses in 2025. Treat these as attributed estimates.

What do FATF and FinCEN say about deepfakes and customer due diligence?

FinCEN issued alert FIN-2024-Alert004 in November 2024 on GenAI schemes circumventing identity verification, authentication, and due-diligence controls, with a SAR key term for deepfake fraud. FATF's December 2025 Horizon Scan names deepfakes a direct threat to customer due diligence, flags synthetic and hybrid identities, and urges firms to review their CDD and identity verification frameworks.
ZenooWhere this fits, honestly

Zenoo does not detect deepfakes. It orchestrates the specialist detectors you choose, combines their signals into one decision, keeps a single immutable audit trail, and lets you swap a detector in under an hour as the threat moves. Book a demo: 30 minutes, your data, no slides.

Sources

Last reviewed 1 July 2026. Every statistic is traceable to a named source.
  1. 01Shufti Pro: A guide to deepfake detection in KYC
  2. 02DuckDuckGoose: How fraudsters use deepfakes to bypass KYC
  3. 03iBeta / ISO 30107-3 PAD levels (Biometric Update)
  4. 04FATF Horizon Scan on AI and deepfakes (22 Dec 2025)
  5. 05FinCEN alert FIN-2024-Alert004 (13 Nov 2024)
  6. 06Entrust / Onfido 2025 Identity Fraud Report
  7. 07Gartner: 30% of enterprises to distrust standalone IDV by 2026
  8. 08iProov 2025 Threat Intelligence Report (Biometric Update)
  9. 09Arup deepfake video-call fraud (CNN)
  10. 10Sumsub Identity Fraud Report 2025-2026
  11. 11Signicat: Deepfake fraud attempts up 2,137% over three years
  12. 12Deloitte Center for Financial Services: deepfake banking fraud risk
  13. 13Surfshark: deepfake fraud losses by country
  14. 14EU AI Act deepfake transparency (European Commission)
  15. 15C2PA / Content Credentials specification
  16. 16Deepfake detection market size (Market.us)
Was this helpful?
Share