Identity fraud is entering a new phase. The person applying to become your customer may appear completely legitimate. Their identity document looks authentic. Their photograph matches. They answer verification questions confidently. They may even complete a live video verification process without raising concerns.
The problem is that the person may not exist. Advances in artificial intelligence have made it easier for criminals to create synthetic identities, generate convincing deepfakes and launch highly personalised scams at scale. Fraudsters can now combine stolen personal information, fabricated details, AI-generated documents and synthetic biometric data to create identities that appear genuine to both humans and technology.
For banks, fintechs, payment providers, insurers and online platforms, verifying identity has become significantly more complex. In the past, organisations primarily focused on detecting forged documents and stolen identities. Today, they must answer three separate questions:
- Is the identity document genuine?
- Is a real person presenting the document?
- Does the identity belong to a real individual?
The answers are no longer as straightforward as they once were.
Synthetic Identity Fraud: When the Customer Does Not Exist
Synthetic identity fraud occurs when criminals combine genuine and fabricated information to create a new identity.
A fraudster may combine:
- A real identification number with a fictitious name
- A stolen address with an AI-generated photograph
- Genuine information from multiple individuals
- Fabricated contact details and employment records
The resulting identity can appear legitimate because some of the information is genuine.
Why Synthetic Identities Are Difficult to Detect
Traditional verification processes often focus on validating individual data points. If a document appears authentic and certain details match trusted databases, the application may proceed without identifying deeper inconsistencies.
Generative AI has significantly increased the scale of this threat. Previously, building a convincing synthetic identity required substantial time and technical expertise. Today, fraudsters can create multiple synthetic profiles rapidly and test them across different organisations.
How Synthetic Identity Fraud Works
Many synthetic fraud schemes follow a gradual approach.
The fraudster may:
- Open an account
- Conduct low-risk transactions
- Maintain balances
- Build transaction history
- Establish trust over time
Once the identity appears credible, it can be used for:
- Loan and credit fraud
- Account takeover activity
- Money mule operations
- Scam proceeds laundering
- Opening additional accounts
- Circumventing transaction limits
By the time suspicious activity becomes visible, the synthetic identity may have been active for months or years.
The Business Impact
Synthetic identity fraud can result in:
- Direct financial losses
- Chargebacks and reimbursement costs
- Regulatory scrutiny
- Increased operational expenses
- Customer remediation requirements
- Reputational damage
It may also require organisations to investigate connected accounts, identify linked activity and demonstrate to regulators that appropriate controls were in place.
Deepfake Fraud: When Seeing and Hearing Are No Longer Enough
Deepfakes use artificial intelligence to create or manipulate images, videos and audio recordings. They can make a real person appear to say or do something that never occurred. They can also create entirely fictional individuals who have never existed.
How Deepfakes Have Evolved
Early deepfakes often contained obvious flaws:
- Unnatural facial movements
- Poor lip synchronisation
- Robotic audio quality
- Visual distortions
Modern deepfakes are significantly more convincing.
Criminals can now:
- Clone voices from short audio samples
- Generate realistic facial expressions
- Manipulate live video streams
- Create synthetic identities with believable biometrics
The technology continues to improve at a rapid pace.
The Threat to Customer Onboarding
Deepfakes create significant challenges for organisations that rely on:
- Facial recognition
- Selfie verification
- Voice authentication
- Video-based onboarding
A fraudster may use a deepfake to impersonate the owner of a stolen identity document during customer onboarding.
The same technology can later be used to:
- Access existing accounts
- Circumvent account recovery processes
- Authorise transactions
- Bypass biometric controls
Internal Fraud Risks
Deepfake technology also presents risks beyond customer onboarding.
Criminals can impersonate:
- Senior executives
- Suppliers
- Business partners
- Internal employees
A cloned voice or manipulated video could be used to request urgent payments, change supplier details or obtain confidential information.
Organisations should no longer assume that visual or audio evidence alone proves identity.
AI-Enabled Scams Are Becoming More Sophisticated
Phishing, impersonation fraud and investment scams are not new.
What has changed is the speed, scale and sophistication with which criminals can operate. Artificial intelligence enables fraudsters to create highly personalised scams that are difficult to distinguish from genuine communications.
How AI Improves Scam Effectiveness
Fraudsters can now:
- Research victims automatically
- Generate convincing emails and messages
- Write in multiple languages
- Replicate communication styles
- Build fake websites
- Create fake social media profiles
- Simulate customer support interactions
AI allows criminals to adapt their tactics in real time. If a victim asks questions or raises concerns, the fraudster can immediately generate persuasive responses.
Detection Must Continue Beyond Onboarding
There is no single solution capable of detecting every form of identity fraud. Effective fraud prevention requires multiple controls working together.
Key Components of a Modern Fraud Prevention Framework
Identity Verification
Validates customer information and confirms document authenticity.
Biometric Verification and Liveness Detection
Determines whether a real person is present during verification.
Deepfake and Presentation Attack Detection
Identifies manipulated images, videos and biometric data.
Device Intelligence
Detects connections between applications, devices and suspicious activity.
Behavioural Analytics
Identifies unusual patterns and changes in customer behaviour.
Transaction Monitoring
Detects suspicious activity after onboarding and throughout the customer relationship.
Why Integrated Controls Matter
A document may appear legitimate when viewed in isolation.
The risk may only become apparent when organisations identify:
- Multiple applications from the same device
- Shared contact details
- Repeated addresses
- Common behavioural patterns
- Connections between customer accounts
Fraud often becomes visible only when information from multiple systems is combined.
Organisations Must Continuously Test Their Controls
Fraudsters actively test onboarding and verification systems. Once they understand how a control works, they adapt their methods to avoid detection.
This means organisations should regularly assess whether their controls can identify:
- Synthetic identities
- Deepfake attacks
- Account takeover attempts
- AI-enabled scams
- Emerging fraud typologies
Testing should be an ongoing process rather than a one-time exercise. Controls that were effective last year may no longer provide the same level of protection today.
Conclusion
Synthetic identities, deepfakes and AI-enabled scams are reshaping the fraud landscape. Organisations can no longer rely solely on document verification or traditional onboarding controls. Fraudsters now use artificial intelligence to create convincing identities, manipulate biometric verification processes and conduct sophisticated scams at scale.
The challenge is no longer simply verifying a document. It is establishing that the identity document is genuine, the person presenting it is real, and the identity itself belongs to a legitimate individual.
Organisations that combine identity verification, biometric authentication, behavioural analytics, device intelligence and ongoing monitoring will be better positioned to identify emerging threats and strengthen their fraud prevention capabilities.



