Identity fraud is entering a new phase. The person applying to become your customer may appear completely legitimate. Their identity document looks authentic. Their photograph matches. They answer verification questions confidently. They may even complete a live video verification process without raising concerns.
The problem is that the person may not exist. Advances in artificial intelligence have made it easier for criminals to create synthetic identities, generate convincing deepfakes and launch highly personalised scams at scale. Fraudsters can now combine stolen personal information, fabricated details, AI-generated documents and synthetic biometric data to create identities that appear genuine to both humans and technology.
For banks, fintechs, payment providers, insurers and online platforms, verifying identity has become significantly more complex. In the past, organisations primarily focused on detecting forged documents and stolen identities. Today, they must answer three separate questions:
The answers are no longer as straightforward as they once were.
Synthetic identity fraud occurs when criminals combine genuine and fabricated information to create a new identity.
A fraudster may combine:
The resulting identity can appear legitimate because some of the information is genuine.
Traditional verification processes often focus on validating individual data points. If a document appears authentic and certain details match trusted databases, the application may proceed without identifying deeper inconsistencies.
Generative AI has significantly increased the scale of this threat. Previously, building a convincing synthetic identity required substantial time and technical expertise. Today, fraudsters can create multiple synthetic profiles rapidly and test them across different organisations.
Many synthetic fraud schemes follow a gradual approach.
The fraudster may:
Once the identity appears credible, it can be used for:
By the time suspicious activity becomes visible, the synthetic identity may have been active for months or years.
Synthetic identity fraud can result in:
It may also require organisations to investigate connected accounts, identify linked activity and demonstrate to regulators that appropriate controls were in place.
Deepfakes use artificial intelligence to create or manipulate images, videos and audio recordings. They can make a real person appear to say or do something that never occurred. They can also create entirely fictional individuals who have never existed.
Early deepfakes often contained obvious flaws:
Modern deepfakes are significantly more convincing.
Criminals can now:
The technology continues to improve at a rapid pace.
Deepfakes create significant challenges for organisations that rely on:
A fraudster may use a deepfake to impersonate the owner of a stolen identity document during customer onboarding.
The same technology can later be used to:
Deepfake technology also presents risks beyond customer onboarding.
Criminals can impersonate:
A cloned voice or manipulated video could be used to request urgent payments, change supplier details or obtain confidential information.
Organisations should no longer assume that visual or audio evidence alone proves identity.
Phishing, impersonation fraud and investment scams are not new.
What has changed is the speed, scale and sophistication with which criminals can operate. Artificial intelligence enables fraudsters to create highly personalised scams that are difficult to distinguish from genuine communications.
Fraudsters can now:
AI allows criminals to adapt their tactics in real time. If a victim asks questions or raises concerns, the fraudster can immediately generate persuasive responses.
There is no single solution capable of detecting every form of identity fraud. Effective fraud prevention requires multiple controls working together.
Validates customer information and confirms document authenticity.
Determines whether a real person is present during verification.
Identifies manipulated images, videos and biometric data.
Detects connections between applications, devices and suspicious activity.
Identifies unusual patterns and changes in customer behaviour.
Detects suspicious activity after onboarding and throughout the customer relationship.
A document may appear legitimate when viewed in isolation.
The risk may only become apparent when organisations identify:
Fraud often becomes visible only when information from multiple systems is combined.
Fraudsters actively test onboarding and verification systems. Once they understand how a control works, they adapt their methods to avoid detection.
This means organisations should regularly assess whether their controls can identify:
Testing should be an ongoing process rather than a one-time exercise. Controls that were effective last year may no longer provide the same level of protection today.
Synthetic identities, deepfakes and AI-enabled scams are reshaping the fraud landscape. Organisations can no longer rely solely on document verification or traditional onboarding controls. Fraudsters now use artificial intelligence to create convincing identities, manipulate biometric verification processes and conduct sophisticated scams at scale.
The challenge is no longer simply verifying a document. It is establishing that the identity document is genuine, the person presenting it is real, and the identity itself belongs to a legitimate individual.
Organisations that combine identity verification, biometric authentication, behavioural analytics, device intelligence and ongoing monitoring will be better positioned to identify emerging threats and strengthen their fraud prevention capabilities.
Synthetic identity fraud occurs when criminals combine genuine and fabricated information to create a new identity that appears legitimate. These identities are often used to open accounts, obtain credit or facilitate financial crime.
A deepfake is AI-generated or AI-manipulated audio, video or image content designed to imitate a real person or create a fictional individual.
Some deepfakes can bypass basic verification controls. Organisations increasingly use liveness detection, presentation attack detection and deepfake detection technologies to address this risk.
AI-enabled scams use artificial intelligence to create personalised fraud campaigns, including phishing attacks, business email compromise, impersonation fraud and investment scams.
Detection often requires combining document verification, identity verification, device intelligence, behavioural analytics, network analysis and ongoing monitoring.