TL;DR: Deepfake fraud has moved from edge-case novelty to routine operational risk, with Trusona citing Signicat, Sumsub, Pindrop, iProov, Mandiant, McAfee and the FBI in the article showing rapid growth in fraud share, voice-phishing-driven intrusions, and losses already reaching hundreds of millions. The core issue is that human judgment and standalone verification cues are now too easy to spoof, so identity processes must verify the real person, not just the voice or face.
NHIMG editorial — based on content published by Trusona: deepfake fraud trends and the shift toward identity impersonation detection
By the numbers:
- Deepfakes account for about 6.5% of all fraud attempts, or 1 in 15, up from 0.1% three years earlier.
- The FBI logged about $893 million in AI-enabled fraud losses in 2025, its first year tracking AI as a category.
Questions worth separating out
Q: How should contact centers verify identity for high-risk customer requests?
A: Use layered verification, not a single check.
Q: Why do deepfakes and synthetic identities break traditional verification models?
A: Because traditional verification assumes identity evidence is stable, human-generated, and hard to reuse at scale.
Q: What signals indicate that identity verification is too weak for fraud prevention?
A: Frequent overrides, low-friction approvals for resets, repeated exceptions for known callers, and no transaction-bound verification are all warning signs.
Practitioner guidance
- Harden high-risk recovery workflows Require authoritative identity proof before password resets, MFA resets, payment approvals, or account recovery actions.
- Remove voice and face from primary trust decisions Stop using a familiar voice, live video, or document appearance as the main approval signal for sensitive actions.
- Classify contact-centre actions as privileged Map the actions your support teams can trigger, then apply privilege controls to the ones that change identity state, financial state, or delegation rights.
What's in the full report
Trusona's full analysis covers the operational detail this post intentionally leaves for the source:
- The full breakdown of deepfake fraud statistics by source, region, and attack type
- Specific examples of voice cloning, document fraud, and contact-centre abuse patterns
- The identity verification logic behind Identity Impersonation Detection in high-risk workflows
- Practical signals that help teams recognise when a caller, applicant, or approver is synthetic
👉 Read Trusona's analysis of deepfake fraud trends and identity verification risk →
Deepfake fraud is forcing identity verification beyond trust cues?
Explore further
Deepfake fraud is now a governance problem, not a fringe fraud tactic. The article shows that synthetic identity attacks have crossed the threshold from novelty to daily operational exposure across contact centres, finance, and hiring. That changes the governance question from "can staff spot a fake" to "can the process prove the requester is real." For identity leaders, the control boundary has moved from people to verification design.
A question worth separating out:
Q: Who is accountable when a deepfake scam succeeds through a support workflow?
A: Accountability usually sits with the business owner of the workflow, the identity team that defined the controls, and the operations manager who allowed exceptions to become normal. Frameworks such as NIST CSF and NIST 800-53 expect clear ownership of access and authentication controls. If the process can alter identity state, someone must own the risk end to end.
👉 Read our full editorial: Deepfake fraud is forcing identity verification beyond trust cues