Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

KYC fraud, deepfakes, and biometric bypasses: are controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18004
Topic starter  

TL;DR: Identity fraud attempts have surged by 74% over three years and deepfakes now account for 6.5% of fraud attempts, according to Jscrambler, as generative AI and organized criminal groups accelerate forged documents, account takeovers, and biometric bypasses. The governance problem is no longer just verification accuracy, but how to protect the full identity flow across browser, mobile, and data handling paths.

NHIMG editorial — based on content published by Jscrambler: KYC, biometric, and user data threats in the age of deepfakes

By the numbers:

Questions worth separating out

Q: How should security teams handle deepfake risk in identity workflows?

A: Security teams should treat deepfakes as a trust and verification problem inside identity workflows.

Q: Why do stolen KYC records create long-lived identity risk?

A: Because identity evidence can be reused.

Q: What breaks when browser-side tampering is not controlled in identity verification?

A: The application may accept manipulated inputs, spoofed camera feeds, or modified scripts as if they were legitimate identity evidence.

Practitioner guidance

  • Harden identity proofing around channel integrity Add controls that verify the browser session, SDK integrity, and device context before accepting biometric or document evidence.
  • Separate verification signals into independent decisions Score document authenticity, biometric match, liveness, and device trust separately so one weak signal cannot overrule the rest.
  • Limit the reuse of identity evidence Apply strict retention, access, and offboarding rules to KYC artefacts, biometric records, and supporting documents.

What's in the full article

Jscrambler's full article covers the operational detail this post intentionally leaves for the source:

  • Benchmarks on fraud attempts, deepfake share, and stolen data pricing that can support board and risk reporting.
  • Specific client-side attack modes in the browser flow, including script injection, reverse engineering, monkey patching, and virtual camera bypass.
  • The case study details behind biometric SDK protection across web and mobile channels, including implementation and testing context.
  • The webinar agenda on securing the full IDV flow across browser and mobile environments, with standards references and practitioner discussion.

👉 Read Jscrambler's analysis of KYC fraud, deepfakes, and biometric bypasses →

KYC fraud, deepfakes, and biometric bypasses: are controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 17593
 

KYC fraud is becoming an identity governance problem, not only a fraud problem. The article shows that attackers are increasingly industrialising forged identity evidence, which means the quality of proofing inputs now shapes downstream access decisions. When verification feeds customer onboarding, account recovery, or entitlement creation, a weak proofing step becomes an IAM issue as much as a fraud issue. Practitioners should treat fraud assurance and identity governance as one control chain.

A question worth separating out:

Q: Who is accountable when mobile KYC fraud succeeds?

A: Accountability sits across identity verification, application security, fraud operations, and the business owner of onboarding. If the mobile app can be tampered with or manipulated, that is not a single-team failure. Governance should assign explicit ownership for input integrity, anti-tamper controls, and fraud response so the gap does not fall between teams.

👉 Read our full editorial: KYC and biometric fraud are outpacing identity verification controls



   
ReplyQuote
Share: