By NHI Mgmt Group Editorial TeamDomain: Identity Beyond IAMSource: IncodePublished September 9, 2026

TL;DR: AI-assisted fraud sessions on its platform rose from 2% in Q1 2023 to 32% in early 2026, while the cost of producing a convincing deepfake fell to US$1 and 18 seconds, making older detection economics inadequate according to Incode. The shift matters because identity verification now has to defeat synthetic media, bot behaviour, and device tampering at the same time, not one control failure in isolation.


At a glance

What this is: Incode’s award submission argues that deepfake fraud now requires layered detection because attackers can defeat single-point controls too easily.

Why it matters: This matters to identity, fraud, and IAM teams because verification, step-up checks, and onboarding controls must assume synthetic media and automation are part of the attack path.

By the numbers:

👉 Read Incode's analysis of AI-driven deepfake fraud and multimodal detection


Context

Deepfake-enabled fraud now sits inside the identity verification workflow rather than outside it. When synthetic faces, voices, documents, and device signals can be generated cheaply and quickly, a single verification layer is no longer enough to establish trust. That changes the governance problem for identity verification, fraud prevention, and any IAM-linked onboarding flow that depends on proof at capture time.

Incode’s award announcement is useful because it shows the operating conditions, not just the claim. The article describes a shift from conventional fraud detection toward multi-layer identity assurance, which is the right direction for teams managing human identity, fraud risk, and the downstream access decisions that depend on identity proofing.


Key questions

Q: How should security teams handle deepfake risk in identity workflows?

A: Security teams should treat deepfakes as a trust and verification problem inside identity workflows. The right response is to require out-of-band verification for high-risk actions, separate request initiation from approval, and harden help-desk and finance procedures so a convincing voice or video cannot authorize access on its own.

Q: Why does cheaper deepfake generation increase fraud risk so quickly?

A: Because attacker economics have shifted. When convincing synthetic media can be produced in seconds for about a dollar, fraud becomes scalable and repeatable rather than slow and specialised. That lowers the barrier for testing controls at volume, which means identity verification teams face more attempts, more adaptation, and shorter time to compromise.

Q: What are the signs that fraud controls are failing to catch synthetic identity attacks?

A: Common warning signs include accounts that clear initial verification but later show unusual device patterns, inconsistent behavior, or rapid takeover activity. A rising share of suspicious accounts that look normal at signup is another signal. Teams should treat those patterns as evidence that checks are too shallow, risk scoring is too permissive, or fraud review is happening too late.

Q: Should organisations prioritise liveness checks or document verification first?

A: Neither should be treated as sufficient on its own. Liveness helps when the attacker uses a fake human presence, while document verification helps when the attacker starts with forged credentials or identity evidence. The better decision is to sequence both inside one risk-based flow, then add behaviour and device checks where fraud pressure is highest.


Technical breakdown

Why multimodal deepfake detection needs layered verification

Deepfake detection fails when it relies on one signal class alone. Multimodal systems combine RGB, depth, and motion to catch inconsistencies that generative tools often preserve only imperfectly across modalities. That matters because a realistic fake can look strong in a single frame yet still fail when the system evaluates temporal motion or three-dimensional cues. In identity verification, the goal is not perfect classification from one model but a decision stack that forces attackers to evade multiple independent checks at once. This is closer to control fusion than to one-shot media analysis.

Practical implication: combine face, motion, device, and document signals so one evasion path does not collapse the entire verification decision.

How behavioural and integrity checks change fraud detection

Behavioural detection looks for automation patterns, such as repetitive timing, unnatural navigation, and farm-like interaction sequences that differ from genuine user sessions. Integrity checks sit lower in the stack and inspect whether the capture environment itself is manipulated through emulators, virtual cameras, or tampered devices. These are different control layers because one addresses what the user appears to be doing and the other addresses whether the sensor input can be trusted at all. Together, they reduce the chance that fraudsters can simply inject synthetic evidence into a valid-looking session.

Practical implication: validate both user behaviour and capture integrity before allowing a verification result to influence access or onboarding.

Why document verification now needs vision-language reasoning

Document fraud is no longer just about spotting template misuse or obvious pixel artefacts. A domain-specific vision-language model can reason across layout, extracted text, metadata, and visual anomalies together, which is important when attackers generate documents that are internally consistent but operationally false. This matters in IDV because many fraud cases now combine forged documents with synthetic portraits and manipulated device context. A model that can explain why a document failed also improves analyst trust and review quality, especially when teams need to defend a rejection decision.

Practical implication: use document controls that compare structural, textual, and visual evidence instead of relying on OCR or image checks alone.


Threat narrative

Attacker objective: The attacker’s objective is to convert synthetic identity evidence into a trusted onboarding or access decision.

  1. Entry begins when an attacker uses a synthetic face, voice, or document to enter a verification flow that was designed for human-present evidence.
  2. Escalation occurs when bot-like automation and manipulated capture environments bypass single-layer checks and obtain a trusted session or approved identity record.
  3. Impact follows when the fraudulent identity is used to open accounts, pass onboarding, or unlock access that should have been denied.

NHI Mgmt Group analysis

Deepfake fraud has become an identity governance problem, not just a fraud problem. The article shows that the attack surface now spans capture, verification, and decisioning, which means identity teams cannot treat liveness as a single gate. Once synthetic media and manipulated devices enter the flow, the quality of the identity proof becomes a control issue for the whole access lifecycle. Teams should govern verification as a layered assurance process, not a binary pass or fail.

Multi-signal verification is becoming the named control pattern for synthetic identity pressure. A useful way to describe the shift is verification trust gap: the distance between what an identity flow assumes is human-authored evidence and what attackers can now fabricate cheaply. That gap widens as generation cost falls and attacker speed rises. Practitioners should treat the trust gap as a measurable governance problem that must be reduced across capture, behaviour, and device integrity.

Identity verification now needs fraud telemetry that can survive adversarial adaptation. The article describes continuous retraining and spoof testing, which reflects the reality that synthetic fraud tools evolve on short cycles. That means static policy tuning is insufficient because attackers adapt faster than governance reviews. Security and identity leaders should build feedback loops that connect fraud detections, model updates, and approval thresholds into one operational control plane.

Human identity assurance is increasingly tied to downstream IAM outcomes. When verification fails, the consequence is not only fraud loss but also polluted identity records, weak account recovery, and compromised entitlement decisions. That makes the boundary between fraud prevention and IAM governance thinner than many programmes assume. Practitioners should align identity proofing standards with the access decisions that depend on them.

Regulated identity environments will keep pushing for explainable verification decisions. The more a control influences onboarding, age checks, and customer access, the more regulators and internal reviewers will expect a defensible reason for rejection or approval. Explainability is therefore not a cosmetic feature but part of the audit trail. Teams should ensure verification controls produce reviewable evidence that can support compliance, dispute handling, and fraud investigation.

What this signals

The identity verification market is converging with fraud operations, and that means programme owners need controls that can absorb adversarial adaptation rather than merely detect obvious spoofing. The practical signal for practitioners is that verification assurance, fraud telemetry, and downstream access decisions now need to be managed as one governed chain, not as separate teams with separate thresholds.

Verification trust gap: as synthetic content becomes cheap and fast, the real programme risk is not a single failed check but the widening distance between user-reported identity and evidence the system can still trust. Teams should expect more pressure on explainability, auditability, and continuous tuning, especially where verified identity gates customer onboarding or privileged access. For identity teams, that means the operating model must evolve from static policy to adversarially tested assurance.

For practitioners who already manage NHI and agentic AI exposure, this is the same governance lesson in a human identity context: if proof at capture time is weak, everything downstream inherits that weakness. Connect identity proofing outcomes to access policy, fraud review, and incident response, and use the Ultimate Guide to NHIs to ground lifecycle thinking in broader identity governance.


For practitioners

  • Separate capture integrity from identity confidence Treat device tampering, emulator use, and virtual camera injection as distinct failure modes with separate detection and escalation paths.
  • Add behavioural signals to fraud scoring Use session timing, interaction patterns, and farm-like automation indicators alongside biometric and document checks before granting trust.
  • Instrument document review for multimodal evidence Require document checks to evaluate layout, text, metadata, and visual artefacts together so one weak signal does not dominate the decision.
  • Run recurring spoof testing against live controls Continuously test your verification flow with synthetic faces, manipulated documents, and adversarial device conditions, then feed failures back into tuning and review.

Key takeaways

  • Deepfake fraud now challenges the whole identity verification chain, not just one biometric check.
  • The economics shifted sharply, with synthetic content now cheap enough to make repeated attacks practical at scale.
  • Layered verification, behavioural telemetry, and device integrity are the controls that change the outcome.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack surface, NIST SP 800-63, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, and GDPR define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-63SP 800-63A — Enrollment and Identity ProofingThe article focuses on identity proofing and fraud-resistant verification.
Recommendation — Apply SP 800-63A to strengthen identity proofing against synthetic and manipulated evidence.
NIST CSF 2.0PR.AC-4 — Access Permissions and AuthorisationsVerification outcomes feed later access decisions and trust assignment.
Recommendation — Map verification outcomes to PR.AC-4 and ensure access decisions only follow trusted identity evidence.
NIST SP 800-53 Rev 5IA-2 — Identification and AuthenticationThe flow is fundamentally about proving and authenticating identity before trust is granted.
Recommendation — Use IA-2 to require stronger authentication steps when identity evidence is uncertain.
GDPRArt. 32 — Security of ProcessingBiometric and identity data processing requires appropriate safeguards and accountability.
Recommendation — Apply Art. 32 controls to protect identity data used in verification and fraud prevention.
MITRE ATT&CKTA0001;TA0005 — Initial Access; Defense EvasionSynthetic identity fraud often begins with deceptive initial access and evasion of controls.
Recommendation — Map synthetic identity attacks to TA0001 and TA0005 to improve detection coverage.

Key terms

  • Deepfake: Synthetic or altered media created with AI or machine learning so that a person appears to say or do something they never did. In security terms, deepfakes are trust attacks that can distort identity verification, approval workflows, and fraud detection.
  • Identity proofing: The process of verifying that a person is who they claim to be before granting or restoring access. In higher-risk recovery paths, proofing can include stronger evidence checks such as government ID validation or liveness-based facial verification so the assurance level matches the sensitivity of the request.
  • Activation Trust Gap: The activation trust gap is the difference between trusting data because it is protected and governing it because it is being reused. It appears when organisations move data from backup or archival systems into AI pipelines without reapplying access, sensitivity, and consumer controls.
  • Capture Integrity: Capture integrity is the trustworthiness of the device, camera, and input pipeline used during identity verification. If the capture path is controlled by an attacker through emulation or injected streams, even accurate biometric analysis can be built on poisoned inputs.

What's in the full article

Incode's full article covers the operational detail this post intentionally leaves for the source:

  • Independent benchmark results across real deepfake incidents and commercial tools
  • The three-layer Deepsight decision flow and how each layer contributes to fraud screening
  • Details of the spoof bounty program and how retraining is fed by adversarial attempts
  • Deployment outcomes across banking, fintech, gaming, telecommunications, and social media

👉 Incode's full post covers the benchmark results, detection layers, and deployment outcomes behind Deepsight.

Deepen your knowledge

NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It helps practitioners connect identity assurance to the broader access and fraud decisions their programmes depend on.
NHIMG Editorial Note
Published by the NHIMG editorial team on September 11, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org