Your Face Just Failed as a Password — and Crooks Paid $20 to Prove It
Your Face Just Failed as a Password — and Crooks Paid $20 to Prove It
This episode is based on our article:
Read the full article →Your Face Just Failed as a Password — and Crooks Paid $20 to Prove It
Full Episode Transcript
For less than the price of a fast-food lunch, a criminal can buy a fake face that fools your bank.
Not a stolen photo
Not a stolen photo. A brand-new, computer-generated face — built to walk right past the scan your bank uses to prove you're really you.
About twenty dollars. Roughly thirty minutes. No hacking skills required.
If you've ever opened a bank account with your phone — held your face up to the camera and waited for that little green checkmark — this story is about you.
That checkmark felt like a locked door. Like proof only you could get in.
Security researchers now say criminals are buying the key for pocket change. Ready-made fraud kits, sold openly on messaging apps, let a low-skill crook generate a fake face, forge a document, and open an account under a real person's name in minutes.
The bank scan says "verified." The person behind it never existed.
If your face was the password — what happens now
So if your face was the password — what happens now that anyone can print a new one?
Let's start with the number that reframes everything.
According to a demonstration by TD Bank's adversarial intelligence team, everything a fraudster needs to defeat a bank's identity check costs less than three hundred dollars total.
That bundle includes the AI face generator. It includes tools to forge identity documents. And the whole thing runs in under five minutes.
The head of that team put it plainly. He said the AI threat is real, and banks can't ignore it.
For fraud investigators, that rewrites the math on every case. For you, it means an account with your name on it could've been opened by someone you'll never meet.
The part that surprised me most isn't that the
Now, the part that surprised me most isn't that the technology got better. It's how ordinary it became.
Researchers at DuckDuckGoose describe ready-made kits — one's called ProKYC — that turn a specialized attack into a point-and-click purchase. No coding. No expertise. You buy it like an app.
Some sellers even include training courses. Step-by-step lessons on how to fool a specific bank's checks.
That's the shift. Fooling a face scan used to require a skilled attacker. Now it requires a credit card and an afternoon.
The next time you get an alert about a new account, remember — the person who opened it may have spent less than you did on coffee.
And the scale is moving fast.
According to the fraud-prevention firm Sumsub,
According to the fraud-prevention firm Sumsub, deepfake fraud jumped more than tenfold in a single year. Ten times.
Sumsub also documented a criminal ring — fourteen people — using computer-generated faces to slip past bank systems.
That's not one lone hacker. That's a small business built on fake faces.
Where does this lead? Deloitte's Center for Financial Services ran the projection.
They estimate AI-driven fraud could push U.S. losses from about twelve billion dollars a few years ago to roughly forty billion by twenty twenty-seven.
More than triple. And they point to one driver above all — account-opening fraud. The exact thing these cheap kits enable.
The industry sees it coming, too
The industry sees it coming, too. Gartner predicts that this year, nearly a third of companies will stop trusting a standalone face check on its own.
Here's the reframe. The problem was never that facial recognition is weak. For years, the real barrier wasn't the technology — it was the skill required to beat it.
That barrier just collapsed. When beating a bank's face scan costs twenty dollars and needs no talent, the lock isn't broken. The lock is being handed out for free.
So let me bring this all the way down.
For years we treated a face scan like a magic door only you could open. Criminals now buy a fake face for the price of a sandwich, and walk straight through.
The scan isn't useless — it's just one lock, and it can't stand alone anymore.
The Bottom Line
Whether you protect a bank's systems or just unlock your own phone, the takeaway's the same. Your face was never meant to be your only password — and now everyone knows it.
You're not powerless here. Turn on the extra alerts your bank offers. Add a second layer wherever you can. Those small steps matter more now than the scan ever did.
The full breakdown's in the show notes if you want the deep dive.
Ready for forensic-grade facial comparison?
Full forensic reports with detailed similarity scoring. Results in seconds.
Run My First SearchMore Episodes
Ratan Tata Told Her It Was Safe. It Cost Her ₹4 Lakh.
A nurse in Pune watched a video of Ratan Tata telling her an investment was safe. She trusted it. Over eleven separate transfers, she sent away more than four lakh rupees — her savings — to people she
PodcastYour Face Isn't a Password. One Country Just Made That the Law.
Regulators in the Philippines just shut down a company that was scanning people's eyes in exchange for cryptocurrency. The national privacy watchdog said the consent was worthless — because people only agreed to hand over
PodcastStop Watching the Face: 3 Places Deepfakes Quietly Fall Apart
You've probably watched a video and thought, that face looks real, so it must be real. But the face is actually the easiest part of a fake to get right. The lie hides somewhere you're not looking — the mouth, the shadows, and the tiny edges a
