AI Identity Verification: 8,065 Deepfakes Hit One Bank
AI Identity Verification: 8,065 Deepfakes Hit One Bank
This episode is based on our article:
Read the full article →AI Identity Verification: 8,065 Deepfakes Hit One Bank
Full Episode Transcript
Between January and August of this year, one bank got hit with eight thousand and sixty-five deepfake attacks. Not eight thousand suspicious logins. Eight thousand attempts to fool the camera with an A.I.-generated face. All aimed at a single financial institution.
If you've ever opened a bank account with your
If you've ever opened a bank account with your phone, you know that moment where it asks you to take a selfie? That selfie check is supposed to prove you're really you. And most of us assume it's one simple test. Snap a photo, match it to your I.D., done. But that assumption is exactly what fraudsters are counting on. Because a selfie check isn't one security test, it's two completely separate problems. And missing that difference is why deepfakes are winning right now. So how does that actually work?
Let's start with the two questions any identity check has to answer. Question one, is there a real, live human in front of this camera right now? Not a photo. Not a video playing on a screen. A breathing person. Question two, does that person's face match the photo on their I.D.? Those sound similar. They're not.
Picture a security guard at a checkpoint. First, the guard has to confirm you're an actual person standing there, not a face on a tablet someone's holding up. Then, separately, the guard checks your face against the photo on your I.D. The guard could nail one and completely miss the other. A real person holding a fake I.D. A perfect I.D. match, displayed on a screen by a deepfake.
The first check has a name, liveness detection
The first check has a name, liveness detection. It's the software's way of asking, "am I looking at a live person, or a trick?" And independent labs test it at two levels. Level one catches printed photos and screen replays. Level two is the hard one, it catches three-D masks and sophisticated fakes. That's the standard serious companies aim for.
Now the part that surprises people. The face-matching software, the part that compares your selfie to your I.D., was built assuming the selfie is real. It has no ability to tell if that face is a deepfake. None. That's a whole separate layer. Which is why research across hundreds of these systems found something striking. According to that research, more than seventy percent of advanced fraud attempts need multiple detection layers to stop them. One check alone won't do it.
So why do so many companies still get this wrong? Because face-matching is mature and easy to explain. "We matched your face to your I.D.", everyone gets that. Liveness is newer and harder to describe, so it gets treated as optional. And the numbers show it. Forty-two percent of organizations rely on liveness detection alone. But liveness has a blind spot, it can't catch an injection attack. That's when a fraudster skips the camera entirely and feeds a fake video stream straight into the system.
The Bottom Line
And this isn't rare anymore. According to Wall Street Journal reporting, deepfake fraud attempts jumped more than thirteen hundred percent in a single year. The tools got cheap. Almost anyone can try it now.
So here's what clicks it all into place. A perfect face match can be wrong in two completely different ways, and you need two completely different checks to catch each one. Matching a face proves the face belongs to the I.D. It says nothing about whether that face is real.
Let me leave you with the simple version. A selfie identity check has to answer two questions, not one. Is this a real live person? And does their face match their I.D.? Skip either question, and a deepfake walks right through. If that eight thousand number rattled you, it should, but now you know the actual weakness, and how the good systems close it. Whether you're protecting a bank or just protecting your own account, understanding those two checks is real power. The written version goes deeper, link's below.
Ready for forensic-grade facial comparison?
Full forensic reports with detailed similarity scoring. Results in seconds.
Run My First SearchMore Episodes
Biometric Data Definition: 3 Questions a Face Scan Must Answer
Right now, in Scotland, there's a camera scanning shoppers as they walk into a store — and there's no rule on the books that clearly says it can't. The only official strategy governing public surveillance cameras there wa
PodcastWhat Is Voice Cloning: 3 Seconds of Audio Fakes a Family Call
Three seconds. That's all it takes. Three seconds of your voice — from a voicemail greeting, a TikTok clip, even a few words you say when you pick up a wrong number — and a stranger can clone how you sound. The F.B.I. says
PodcastAI deepfake images: gangs blackmail 49% of schools
Criminals took photos straight off a school's public website. Ordinary class pictures. Faces from a school events page. Then they used A.I. to twist those photos into more than a hundred fake sexual i
