NEW YORK--Facial recognition and liveness detection have become standard defenses against digital identity fraud, but fraud experts say a new generation of inexpensive artificial intelligence tools is rapidly eroding those protections, allowing organized criminal rings to create synthetic borrowers capable of evading detection for months—or even years.
During a recent interview with BankInfoSecurity, Matt Vega, chief fraud strategist at Point Predictive, said one of the most alarming developments is the emergence of "camera injection" kits that allow criminals to bypass facial liveness checks altogether.
"Facial liveness checks are the foundation for mobile device verification. But now injection kits selling for about $30 enable fraud rings to hot-wire a mobile device's camera feed or inject a deepfake stream into the verification process, bypassing checks many institutions still rely on," Vega said.
Unlike earlier deepfake attacks that attempted to fool a camera by mimicking facial movements, camera injection attacks feed manipulated video directly into a device's camera pipeline, preventing many liveness detection systems from ever seeing a genuine image.
According to Point Predictive's Fraud Risk Intelligence Report, these attacks have evolved rapidly from specialized hacking techniques into inexpensive commercial products marketed through Telegram channels and underground forums. Point Predictive cited reporting by MIT Technology Review, which documented dozens of online marketplaces openly selling AI-powered camera injection tools and biometric bypass software, dramatically lowering the technical expertise required to conduct sophisticated identity fraud.
Criminals Are Playing The Long Game
Vega told BankInfoSecurity that bypassing onboarding is only the beginning of today's fraud schemes.
"Once an injection kit clears that first gate, the fraud doesn't stop at onboarding and the identity keeps building," Vega said. "Synthetic profiles typically take six to 18 months to mature, using agentic artificial intelligence to automate payments on secured cards and micro trade lines to build a healthy repayment history that pushes the profile into prime or super-prime territory."
Rather than immediately stealing funds, organized fraud rings patiently establish legitimate-looking credit histories by opening secured credit cards, adding small tradelines and making on-time payments through automated AI agents. According to Point Predictive, many of those synthetic identities eventually qualify for large unsecured loans before being used in coordinated "bust-out" fraud schemes in which criminals simultaneously default across multiple lenders.
"A sudden jump from a dormant credit file to strong repayment is itself a warning sign, and that patience makes the fraud hard to catch on the credit side," Vega said.
Vega also warned BankInfoSecurity that deferred first-payment loan programs can unintentionally provide fraud rings with additional time to strengthen synthetic identities before lenders receive the first indication that something may be wrong.
Losses Continue To Climb
The financial impact is becoming increasingly significant.
According to a 2026 study by Mitek Systems and Datos Insights, 84% of fraud executives now view synthetic identities as either a high or moderate application-fraud risk. The firms estimated that U.S. lenders suffered approximately $2.94 billion in unsecured credit losses tied to synthetic identity fraud during 2025, up sharply from roughly $1.8 billion five years earlier.
The same research found that about 40% of financial institutions are already seeing AI increase the volume or sophistication of fraud attacks, with generative AI dramatically reducing the time and expertise required to create convincing fake identities.
Separate research by MeridianLink found that fraudsters increasingly are using generative AI to create realistic employment verification letters, pay stubs, bank statements and other supporting documentation submitted during digital loan applications, making manual review substantially more difficult.
Beyond Deepfakes
The fraud landscape is also shifting beyond conventional deepfake videos.
Cybersecurity firm Group-IB has reported a sharp increase in biometric injection attacks in which AI-generated images are injected directly into Know Your Customer (KYC) verification systems instead of attempting to deceive facial recognition cameras. Those findings were later detailed by Biometric Update and cybersecurity company Proof, both of which reported that fraudsters are increasingly purchasing "deepfake-as-a-service" offerings that bundle biometric bypass tools with synthetic identity packages.
Vega said future defenses will likely depend less on facial images alone and more on physiological indicators that are much harder to fabricate.
During the BankInfoSecurity interview, he pointed to technologies capable of analyzing heartbeat signals, subtle blood-flow changes and pupil dilation to determine whether a live human is actually interacting with a device.
No Silver Bullet
Even so, Vega cautioned that no single technology will stop modern AI-enabled fraud.
"No single technology stops these attacks. Multi-layered verification, income checks and continuous monitoring catch most synthetic identities before they reach major credit lines," he said.
He also emphasized the importance of collaborative fraud intelligence.
"It's hard because in data consortium models, you get herd immunity," Vega said. "If there's an attack on one, the immune system responds and builds up the defenses for everyone else within the consortium. But it usually comes down to good old-fashioned rule engines. Old-school rule engines can knock out a lot of the high-risk fraud that's out there. The more advanced the attack vector, usually the more basic the control is to mitigate it."
