By NHI Mgmt Group Editorial TeamBased on iProov: “Deepfake Spoofs Dutch Bank’s KYC, Opening 46 Accounts. What Could Have Stopped It?” (April 24, 2026)

TL;DR: A 34-year-old suspect used stolen IDs, deepfakes, and ABN AMRO’s mobile onboarding flow to open 46 fraudulent bank accounts, according to iProov, exposing how selfie-to-ID checks can be defeated when liveness is weak. Static KYC verification no longer matches the scale or accessibility of synthetic identity attacks.


At a glance

What this is: This case shows how deepfake-assisted onboarding can defeat selfie-to-ID matching and create fraudulent bank accounts at scale.

Why it matters: IAM and KYC teams need stronger identity proofing and liveness controls because document matching alone no longer proves the applicant is a real, present person.

By the numbers:

  • A fraudster used stolen IDs and deepfakes to open 46 fraudulent bank accounts at ABN AMRO.

Context

Deepfake-enabled KYC fraud exploits a basic identity proofing assumption: that a face match means the applicant is real and entitled to the account. In practice, selfie-to-ID workflows verify image similarity, not human presence or document provenance.

This article is about the failure of mobile onboarding controls in a financial identity process, not about a single bank’s isolated mistake. The broader issue is that accessible generative tools now let attackers synthesize the appearance of legitimacy faster than legacy verification can detect it.

For IAM and KYC teams, the question is no longer whether document checks work in the abstract. The real question is whether the verification stack can distinguish a live applicant from a synthetic one at the point of capture.


Key questions

Q: What breaks when selfie-to-ID checks are the main KYC control?

A: They break because image similarity is not the same as identity proofing. A fraudster can pair stolen documents with synthetic or manipulated selfies and still pass a weak matching step, especially when the system does not verify liveness, document provenance or session integrity. The control proves resemblance, not that a real applicant is present.

Q: Why do deepfakes make mobile onboarding riskier for banks?

A: Deepfakes lower the cost of presenting a believable face during remote onboarding, so the attacker no longer needs to be physically present with a genuine identity. That increases the scale and repeatability of account-opening fraud, especially where the bank relies on selfie matching without strong liveness detection or device-side tamper resistance.

Q: How can security teams tell whether KYC verification is failing?

A: Look for approved accounts that later show inconsistent identity evidence, unusual cash-deposit behaviour, mule activity or a pattern of fraud cases where document matching passed but human review flagged anomalies. Those signals suggest the onboarding stack is measuring likeness too early and authenticating too little.

Q: What should banks do when synthetic media can mimic applicants?

A: Banks should move identity proofing toward layered assurance: document authenticity checks, liveness detection, fraud analytics and escalation paths for anomalies that simple selfie matching cannot resolve. The aim is to detect manipulation at capture time, before an account is created and before downstream AML controls have to clean up the failure.


Technical breakdown

Why selfie-to-ID matching is easy to defeat

Selfie-to-ID onboarding usually compares a live capture with a document portrait and treats similarity as proof of identity. That control is weak when an attacker can blend their own features onto stolen document photos or generate a synthetic face that matches the expected reference image. The system then validates resemblance, not authenticity. This is why document-centric checks can pass even when the applicant has no legitimate relationship to the identity being presented.

Practical implication: Treat face matching as one signal in identity proofing, not as evidence that the applicant is genuine.

What liveness detection adds to the verification path

Liveness detection is the missing control when a verification flow must distinguish a real person from a replay, presentation or injection attack. Proper liveness checks look for signs of real-time human presence during capture, rather than accepting a submitted image at face value. In mobile onboarding, this matters because the attack may never touch the camera feed in a normal way. The control is about proving presence, not just measuring visual similarity.

Practical implication: Add liveness verification to any onboarding flow that accepts photos, selfies or video as identity evidence.

Why generative AI changes the KYC risk model

Generative AI reduces the skill and cost required to manufacture credible identity artifacts, which means the threat model for onboarding has shifted from occasional fraud attempts to repeatable abuse at scale. When synthetic media becomes cheap, the bottleneck moves from producing fake evidence to finding controls that can detect it reliably. That raises the assurance bar for customer identity proofing and makes static rules increasingly obsolete.

Practical implication: Reassess onboarding assurance when synthetic media generation becomes trivial for attackers to use repeatedly.


Threat narrative

Attacker objective: Open fraudulent bank accounts that can be used for laundering and related financial abuse.

  1. Entry occurred through a fake rental listing that harvested genuine identity documents from prospective tenants.
  2. Credential and identity abuse followed when those stolen IDs were paired with deepfake imagery to satisfy the bank's selfie-to-ID flow.
  3. Impact came from approved fraudulent accounts that could then be used for laundering, cash deposits and account mule activity.
  • Arup deepfake fraud 2024: Deepfakes of Arup's CFO and colleagues on a video call led a Hong Kong employee to transfer HK$200 million (about US$25.6m) to fraudsters.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Selfie-to-ID matching has become an assurance threshold, not an identity proofing control: The article shows that a bank can compare a face to a document and still admit the wrong person. That happens because the control validates resemblance, not whether the applicant is live, present, and entitled to the identity. For identity programmes, the lesson is that document matching now sits below the assurance line needed for regulated onboarding.

Deepfake fraud collapses the assumption that a face is evidence of a person: Traditional KYC flows were designed for a world where the image presented by the applicant was hard to manipulate at scale. That assumption fails when synthetic media can be generated cheaply and repeatedly, because visual fidelity no longer implies authenticity. The implication is that identity proofing must stop treating imagery as a stable trust anchor.

Liveness is now the decisive control boundary in mobile onboarding: The breach pattern here is not a clever exception, but a predictable failure of controls that stop at face similarity. Once synthetic media can traverse the onboarding channel, every downstream control inherits the wrong identity. Identity teams should think in terms of proof of presence, not just proof of likeness.

Synthetic identity amplification: The real shift is not only that fake documents can be created, but that stolen documents can be made to look self-consistent through generated imagery. That turns a single harvested ID into a scalable onboarding attack vector across financial services. Practitioners should re-evaluate where their proofing stack relies on visual plausibility instead of cryptographic or behavioural evidence.

KYC governance now has an anti-synthetic-media requirement: Regulatory risk grows when onboarding systems cannot distinguish genuine applicants from manufactured ones, because fraud, AML exposure and sanctions evasion all begin with the same trusted entry point. The control problem is not limited to one bank or one geography. Identity governance teams should treat synthetic media detection as part of customer lifecycle assurance, not as a niche fraud feature.

What this signals

Deepfake onboarding is now a KYC governance problem, not just a fraud problem: Once synthetic media can impersonate a person well enough to clear an automated face match, the failure moves upstream into identity proofing. KYC teams should assume that any process built around a static selfie comparison is vulnerable to manipulation unless it can prove real-time presence and document integrity.

Identity proofing must be designed for adversarial media: The practical boundary is no longer whether a system recognises a face, but whether it can reject a face that was generated, blended or replayed. Programmes that still treat liveness as optional are operating with a control gap that attackers can exploit repeatedly.

Fraud, AML and sanctions exposure now share the same intake weakness: Weak onboarding lets false identities enter the perimeter, and once inside, the same account can support laundering, mule activity or evasion. The implication for practitioners is that customer onboarding controls and financial-crime controls have to be governed as one lifecycle, not as separate teams.


For practitioners

  • Strengthen identity proofing beyond document comparison Require onboarding flows to validate document authenticity, applicant presence and session integrity rather than relying on a selfie-to-ID match alone.
  • Add liveness detection to mobile onboarding Use controls that can detect presentation attacks, replay attempts and injected synthetic media during capture, especially where accounts can be opened remotely.
  • Review fraud paths that begin with legitimate documents Assume the document may be real even when the applicant is not, and test whether your process still approves the identity when the face evidence is synthetic.
  • Reassess onboarding assurance against deepfake abuse Test whether your verification stack can distinguish manipulated imagery from a live human across both Android and iOS mobile flows.
  • Align KYC controls with AML and sanctions exposure Treat weak onboarding as a first-stage control failure that can feed mule activity, laundering and sanctions evasion later in the account lifecycle.

Key takeaways

  • Deepfake-assisted onboarding exposes a control gap in selfie-to-ID verification, because visual matching alone cannot prove that the applicant is real.
  • The article describes 46 fraudulent ABN AMRO accounts and a broader pattern of synthetic identity abuse that can scale quickly when KYC is weak.
  • Liveness detection and stronger identity proofing are the controls that change the outcome, because they shift assurance from likeness to real-time presence.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-63 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationSelfie-to-ID matching failed because the onboarding flow authenticated appearance, not live identity.
NHI-02 — Secret LeakageThe fraud began with harvested identity documents that were reused as onboarding evidence.
Recommendation — Add liveness and authenticity checks to prevent synthetic media from satisfying onboarding authentication. Reduce exposure of identity documents and treat leaked IDs as reusable fraud inputs.
NIST SP 800-63SP 800-63A — Enrollment and Identity ProofingThe article centres on weak digital identity proofing during remote account enrolment.
SP 800-63B — AuthenticationThe case shows why authenticating a session or image is not enough without proof of a real user.
Recommendation — Use identity proofing requirements that verify evidence quality and applicant presence before account creation. Apply stronger authentication assurance where remote capture could be manipulated or replayed.
MITRE ATT&CKTA0006;TA0010 — Credential Access; ExfiltrationStolen IDs were harvested and then used to create accounts for downstream financial abuse.
Recommendation — Map the document harvest and account abuse pattern to credential access and exfiltration behaviour.

Key terms

  • Liveness Detection: Liveness detection is the mechanism that checks whether a biometric sample comes from a real, present person rather than a spoof such as a photo, screen, or mask. In identity programmes, it is a core defence against presentation attacks and should be tested under realistic operating conditions.
  • Synthetic Identity Document Fraud: Synthetic identity document fraud is the use of fabricated or AI-generated identity documents to impersonate a real or invented person. It targets verification workflows by presenting fake passports, driver’s licences, or IDs that can look credible enough to pass basic checks unless teams use stronger authenticity and anomaly detection controls.
  • Identity proofing: The process of verifying that a person is who they claim to be before granting or restoring access. In higher-risk recovery paths, proofing can include stronger evidence checks such as government ID validation or liveness-based facial verification so the assurance level matches the sensitivity of the request.
  • Digital Injection Attack: An attack in which manipulated or synthetic media is inserted into a verification pipeline instead of being captured directly from the camera. The goal is to make a fraudulent input look like a legitimate live session and pass identity checks without an actual person present.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org