In February 2024, a finance employee at a Hong Kong-based multinational transferred HK$200 million — roughly US$25 million — after joining a video call with people who appeared to be his company's CFO and several colleagues. Every face on the call was a deepfake, generated from publicly available video and audio of the real executives. That case is now a standard citation in fraud training decks. What gets discussed far less is what happened to the underlying technology in the two years since: it got cheaper, faster, and far more accessible — and the primary target shifted from one-off executive impersonation toward something with much higher volume and much closer relevance to compliance teams. Remote identity verification at account opening.
Where a boardroom deepfake requires planning, target research, and a live human operator, onboarding fraud can be automated. Off-the-shelf face-swap and voice-clone tooling, combined with virtual camera software that injects synthetic video directly into a browser's webcam feed, lets a single operator run dozens of fraudulent onboarding attempts a day against banks, money service businesses, and fintech apps that rely on remote video KYC. Financial institutions that built their onboarding pipeline around passive liveness detection and single-frame face-match — still the industry default — are finding that control was designed for a threat model that no longer matches reality.
Two Attack Types Compliance Teams Need to Distinguish
Not all deepfake identity fraud works the same way, and the distinction matters for control design.
Presentation attacks involve showing a synthetic image or video to a physical camera — holding a phone or tablet playing a deepfake video up to a laptop's webcam, for example. These are the older, more detectable category: lighting artefacts, screen reflections, and moiré patterns from photographing a screen are all identifiable with modern presentation-attack-detection (PAD) technology.
Injection attacks bypass the physical camera entirely, using virtual camera drivers or emulator software to feed synthetic video directly into the verification application's video stream. There is no screen to photograph and no reflection to detect — the deepfake is delivered as if it were genuine camera input. Injection attacks are now the dominant vector in documented onboarding fraud cases, and standard liveness checks that only analyse the image itself, without verifying the integrity of the capture pipeline, cannot see them.
Why Passive Liveness Alone No Longer Proves Anything
Most eKYC vendors still market "liveness detection" as a single checkbox — blink, smile, turn your head. Real-time generative video tools now respond to exactly these challenge-response prompts convincingly enough to pass. The uncomfortable implication for compliance teams is that a green checkmark from a liveness vendor is no longer sufficient evidence that a real, present human completed onboarding. It is evidence that something responded correctly to a scripted prompt — which is precisely what a well-resourced synthetic-identity operation is built to produce.
Why This Lands Harder on Remote-First and Diaspora-Serving Institutions
Financial institutions that depend heavily on remote onboarding carry disproportionate exposure — and that describes a large share of Caribbean banking, remittance, and fintech relationships. Diaspora banking, cross-border remittance corridors, and digitally native MSBs serving customers across the Caribbean and wider Latin America routinely onboard clients who never visit a branch. That is a legitimate and important business model, not a red flag in itself — but it means the institution's entire identity-assurance chain rests on the video and document capture pipeline being trustworthy, with no in-person fallback to catch what the pipeline misses. Regulators including the Central Bank of Barbados and the Barbados FSC increasingly expect institutions to be able to explain, specifically, how their remote CDD process addresses synthetic identity and deepfake risk — a generic reference to "video KYC" in a policy manual is no longer an adequate answer at inspection.
Red Flags for Onboarding and Transaction Monitoring Teams
- Unnaturally consistent lighting or micro-expression patterns across a liveness check, with no natural variation frame to frame.
- Audio-video lip-sync drift that increases under network stress — a common artefact of real-time deepfake rendering.
- Device or browser fingerprints inconsistent with a genuine mobile camera capture — indicators of virtual camera or emulator software.
- Identical background, framing, or lighting setup across multiple, apparently unrelated applicants.
- Document images that pass automated OCR but show inconsistent font kerning, security-feature rendering, or edge artefacts under magnification.
- New accounts that pass onboarding but show no genuine transactional behaviour for weeks, consistent with identity being banked for later use rather than active customer relationships.
Building Controls That Match the Current Threat
The fix is not a single new vendor — it is layering. Injection-attack detection (verifying the integrity of the capture pipeline itself, not just the resulting image) needs to sit alongside presentation-attack detection. Device and behavioural biometrics — typing cadence, device history, session behaviour — add a second, harder-to-synthesise signal. Enhanced due diligence triggers should extend beyond the moment of onboarding into the first weeks of the relationship, since synthetic identities are frequently built to sit dormant before use. And staff who review onboarding exceptions need specific training on injection-attack indicators, because these cases will not look like the presentation-attack examples in older fraud training materials.
Real-time typology and enforcement intelligence matters here more than in most areas of AML, because the tooling driving this fraud evolves in months, not years. amlx.io tracks emerging identity-fraud typologies and enforcement actions alongside broader AML/CFT intelligence, giving compliance teams a current reference point between formal control reviews.
If your institution's onboarding controls were designed before generative AI became commercially accessible, they were designed for a different threat. The Four CCCC team works with banks, MSBs, and fintechs across Barbados and the wider Caribbean on KYC programme reviews, control gap assessments, and inspection-ready documentation that reflects current identity-fraud typologies — not the ones from three years ago.