Skip to main content
Category: Predicate Offenses

Deepfake Fraud

Also known as: AI-generated impersonation fraud, synthetic media fraud
Simply put

Deepfake fraud is a type of cybercrime in which criminals use artificial intelligence to create or alter audio, video, or images so that a person appears to say or do something they never actually did. Fraudsters typically use this fabricated media to convincingly impersonate a real individual and deceive victims, for example by making a fraudulent transaction appear legitimate. Because AI tools can now be tailored to specific targets, this form of fraud has reportedly been carried out on a large, or 'industrial,' scale.

Formal definition

Deepfake fraud refers to the fraudulent use of synthetic or manipulated media, audio, video, or images generated or altered by artificial intelligence, to impersonate an individual and deceive a target for illicit gain. In an AML and fraud-prevention context, such techniques may be deployed to defeat identity verification and authentication controls, to socially engineer authorization of payments, or to create the appearance of a legitimate transaction or instruction. The evidence available here characterizes deepfake fraud at a general, operational level rather than as a defined term within any specific regulatory instrument; where the technique bears on obligations such as customer due diligence, transaction monitoring, or authentication, the applicable requirements derive from the relevant jurisdiction's AML and fraud frameworks, which should be confirmed against the governing regulation. As a typology, deepfake fraud describes a method of deception and is not, in itself, a legal test; the presence of AI-manipulated media indicates a potential fraud vector rather than establishing that any particular loss or offense has occurred.

Why it matters

Deepfake fraud is significant because it directly undermines controls that AML and fraud-prevention programs have long relied upon, including identity verification, authentication, and the human judgment applied when authorizing payments or acting on instructions from senior personnel or customers. Where a criminal can fabricate convincing audio, video, or images to impersonate a real individual, obliged entities may find that traditional assurance measures, such as recognizing a known voice, confirming an instruction by video call, or relying on a facial image at onboarding, no longer provide the confidence they once did. This is an operational risk to the integrity of customer due diligence and payment authorization rather than a newly defined regulatory obligation.

The risk is heightened by the reported scaling of these techniques. According to an analysis published by AI experts and reported in February 2026, deepfake fraud has gone "industrial," with tools available to create tailored and even personalized scams. When impersonation can be produced at scale and customized to specific targets, the exposure for financial institutions and their customers broadens correspondingly, and controls designed around one-off or low-volume deception may be tested more frequently.

It is important to treat deepfake fraud as a method of deception rather than as a legal test in itself. The presence of AI-manipulated media points to a potential fraud vector; it does not establish that a particular loss has occurred or that any specific offense has been committed. Where such techniques bear on obligations such as customer due diligence, transaction monitoring, or authentication, the applicable requirements derive from the governing AML and fraud frameworks of the relevant jurisdiction, and exact obligations and thresholds should be confirmed against those instruments.

Who it's relevant to

Fraud Prevention and Financial Crime Teams
Teams responsible for detecting and mitigating fraud should be aware that AI-generated media can be used to impersonate individuals and to create the appearance of legitimate transactions or instructions. This may require reassessing how impersonation risk is managed within existing detection and authorization controls, treating deepfake media as a potential fraud vector rather than as proof that a loss or offense has occurred.
Identity Verification and Onboarding Functions
Functions that rely on audio, video, or images to verify or authenticate a customer's identity should recognize that such media may be synthetically generated or altered. Where these techniques bear on customer due diligence or authentication, the relevant requirements derive from the applicable jurisdiction's AML and fraud frameworks, which should be confirmed against the governing regulation.
Payments and Treasury Operations
Personnel who authorize or execute payments and act on instructions may be targeted through impersonation of trusted individuals. Awareness that fabricated media can create the illusion of a legitimate transaction is relevant to how payment authorization and instruction-verification processes are designed and applied.
Compliance and Risk Officers
Those responsible for AML and fraud risk management should factor the reported scaling of deepfake techniques into their assessment of impersonation and authentication risk. Controls in this area serve to detect, deter, and mitigate risk; they do not guarantee prevention, and no single control eliminates the exposure.

Inside Deepfake Fraud

Synthetic Media Generation
The use of artificial intelligence, typically generative adversarial networks or similar machine-learning techniques, to create fabricated audio, video, or images that convincingly imitate a real person's likeness or voice. In a fraud context, this fabricated media is the core instrument used to deceive a victim or a control.
Impersonation Vector
The specific identity being spoofed, which may be a senior executive (for business email compromise-style schemes), a customer (to defeat identity verification), or a public figure (in investment or endorsement scams). The chosen impersonation vector generally determines which controls are targeted.
Targeted Control or Process
The point of attack, such as remote customer onboarding and identity verification, video-based liveness checks, voice authentication systems, or payment authorization workflows. Deepfake fraud typically exploits processes that rely on the presumed authenticity of biometric or audiovisual signals.
Predicate Conduct
In criminal-law terms, deepfake fraud may constitute an offence such as fraud, forgery, or identity theft depending on the jurisdiction, and proceeds derived from it can become the subject of a money laundering offence. The deepfake itself is a means of commission, not a separate universally defined offence.
AML/CFT Relevance
From a compliance standpoint, deepfake techniques are relevant primarily where they undermine customer due diligence, defeat identity verification during onboarding, or facilitate unauthorized transactions, and where resulting proceeds must be detected and reported under applicable suspicious activity or suspicious transaction reporting regimes.

Common questions

Answers to the questions practitioners most commonly ask about Deepfake Fraud.

Is a deepfake the same thing as any digitally edited or 'photoshopped' image or video?
No. While both involve manipulated media, deepfakes specifically refer to synthetic media generated or substantially altered using artificial intelligence techniques, typically deep learning models, to convincingly fabricate a person's likeness, voice, or actions. Conventional editing (cropping, retouching, splicing) does not rely on generative AI to synthesize new content. In a financial crime context, the distinction matters because deepfakes can defeat controls that assume a live human presence, such as liveness checks in remote onboarding, whereas simpler edits are more often caught by document-integrity checks. That said, the boundary is not always sharp operationally, and controls should be assessed against the specific manipulation technique of concern rather than a single label.
Does detecting or being targeted by a deepfake automatically mean money laundering or another predicate offence has occurred?
No. Identifying a deepfake, or flagging suspected synthetic media during onboarding or a transaction, is an operational and risk-management event, not a determination of criminal wrongdoing. A deepfake may be used to facilitate fraud, impersonation, sanctions evasion, or laundering, but its detection alone does not establish that any offence has been committed or by whom. As with other alerts, a match or suspicion may support further review and, where thresholds are met, the filing of a suspicious activity or transaction report under the applicable regime, but the criminal-law question of guilt is separate and determined through investigation and legal process. Firms should avoid treating a detection as proof of criminality in internal records or reporting.
Where in an AML/CFT program are deepfake risks most likely to arise?
Deepfake risks are commonly considered at points that rely on verifying a person's identity or authorizing an instruction remotely. These may include remote customer due diligence and onboarding (where synthetic video or documents could undermine identity verification and liveness detection), authentication for account access or high-value instructions, and voice-based authorization channels. The relevant exposure depends on which channels an obliged entity uses and how heavily it relies on biometric or remote verification. Firms should map deepfake risk to their own CDD, authentication, and payment-authorization processes rather than assuming a uniform impact across the program.
How can deepfake risk be reflected in a risk-based approach and customer risk assessment?
Under a risk-based approach, deepfake exposure can be treated as a factor influencing the design and calibration of identity-verification and authentication controls, rather than a standalone customer risk rating. Firms may consider the channels used (for example, fully remote onboarding), the reliance placed on biometric or video verification, and the value or sensitivity of transactions authorized through vulnerable channels. Where risk is assessed as higher, enhanced measures such as additional verification steps may be applied. These measures are intended to detect, deter, and mitigate risk; they do not eliminate it. Exact expectations depend on the applicable regime and should be confirmed against local requirements and any relevant regulatory guidance.
What controls can help mitigate deepfake-enabled fraud during remote onboarding and authentication?
Commonly discussed mitigations include layered verification that does not rely on a single biometric signal, liveness and presentation-attack detection, cross-checks against independent or authoritative data sources, out-of-band confirmation for high-value or high-risk instructions, and callback or dual-authorization procedures for payment changes. Staff awareness and escalation procedures can also help where automated detection is uncertain. No single control should be presented as a guarantee against deepfake fraud; the objective is to manage and reduce risk through defense in depth. The appropriate combination depends on the entity's risk profile, channels, and regulatory obligations.
If a deepfake is suspected in connection with a customer or transaction, what reporting considerations apply?
Suspicion arising from a suspected deepfake is handled through an obliged entity's normal suspicious activity assessment process. Where the applicable threshold for suspicion is met, a report may need to be filed with the relevant financial intelligence unit, for example a suspicious activity report or suspicious transaction report depending on the jurisdiction and regime. The specific triggers, timelines, and formats differ by jurisdiction and should be confirmed against the applicable rules. Internal records should describe the detection and the basis for suspicion factually, without characterizing the matter as established criminal conduct, and firms should follow their tipping-off and confidentiality obligations under the relevant regime.

Common misconceptions

A liveness check or biometric verification step guarantees that deepfake fraud cannot succeed.
No single control eliminates financial crime risk. Liveness detection and biometric verification are measures that can mitigate and help detect synthetic-media attacks, but sophisticated deepfakes may defeat individual controls, which is why a layered, risk-based approach is generally recommended.
Detecting a suspected deepfake or generating an alert establishes that a customer or counterparty has committed a crime.
A detection, alert, or verification failure is an operational risk indicator, not proof of wrongdoing. Whether criminal fraud has occurred is a matter for investigation and, ultimately, the courts; a compliance filing such as a SAR or STR reflects suspicion, not a finding of guilt.
There is a single global rule specifically governing deepfake fraud that obliged entities must follow.
Requirements are not uniform. Obligations typically derive from existing frameworks addressing customer due diligence, identity verification, fraud, and suspicious activity reporting, which vary across regimes such as the FATF Recommendations (standards, not binding law), EU AML instruments, the US Bank Secrecy Act and FinCEN rules, and the UK Money Laundering Regulations. Specific treatment of synthetic media should be confirmed against the applicable regulation.

Best practices

Adopt a layered, risk-based approach to identity verification during onboarding rather than relying on any single biometric or audiovisual signal, recognizing that individual controls can be defeated by sophisticated synthetic media.
Incorporate deepfake and synthetic-media scenarios into fraud and AML risk assessments, and calibrate enhanced verification measures to higher-risk channels such as fully remote onboarding and video-based verification.
Strengthen payment authorization and executive-instruction workflows with out-of-band or multi-factor confirmation so that a single spoofed voice or video cannot by itself authorize a transaction.
Train staff, particularly onboarding, customer-facing, and payments personnel, to treat audiovisual authenticity as fallible and to escalate anomalies through established suspicious activity procedures.
Ensure that suspected deepfake-enabled fraud is assessed for reporting under the applicable suspicious activity or suspicious transaction reporting regime, documenting the basis for suspicion without characterizing an alert as proof of a criminal offence.
Confirm specific obligations, thresholds, and permissible verification methods against the regulations applicable in each operating jurisdiction, as treatment of synthetic media and remote verification diverges across regimes.