Deepfakes lower the cost of presenting a believable face during remote onboarding, so the attacker no longer needs to be physically present with a genuine identity. That increases the scale and repeatability of account-opening fraud, especially where the bank relies on selfie matching without strong liveness detection or device-side tamper resistance.
Why deepfakes change the fraud economics of mobile onboarding
Deepfakes matter here because they compress the attacker’s cost and increase scale. A fraudster no longer needs a live accomplice, a stolen physical document chain, or direct face-to-face presence to pass a remote check. That shifts onboarding from a one-off deception problem into a repeatable industrialised attack path, especially in high-volume consumer banking flows.
For banks, the real change is not just that a fake face can look convincing. It is that identity proofing assumptions are being tested in a channel where speed, automation and customer convenience are already under pressure. If the onboarding design treats a selfie as strong evidence by itself, deepfakes turn that design choice into a liability rather than a convenience feature.
Deepfake-enabled onboarding fraud also scales across jurisdictions and products. The same synthetic face or voice pattern can be reused, varied, or paired with different synthetic details to probe multiple institutions. That makes onboarding controls a target for repeatability, not just realism.
Where mobile onboarding breaks under synthetic media
The weak point is usually the verification stack, not the video alone. Selfie matching can confirm similarity between a face capture and an identity document, but it does not automatically prove the person is present, live, and acting for themselves. If liveness checks are weak, the bank may accept replayed media, screen-captured sessions, or generated imagery that satisfies a narrow similarity threshold.
mobile onboarding can also be fragile when device trust is assumed rather than tested. A compromised or emulated device, rooted phone, tampered app, or manipulated camera feed can let the attacker control what the bank sees. Where device-side signals are absent or weak, the bank loses an important layer of friction that would otherwise make synthetic media harder to operationalise.
That is why the control question is broader than biometrics. Banks need to think about document authenticity, device integrity, session continuity, behavioural consistency, and step-up verification together, because deepfakes exploit gaps between those checks rather than defeating only one of them.
Why banks should treat deepfakes as onboarding assurance risk, not just fraud content
For banks, deepfakes are an assurance problem because they undermine trust in the evidence used to create an account. Once a fraudulent account is opened, the consequence is not limited to a bad application record. The account can be used for mule activity, payment fraud, credit abuse, synthetic identity accumulation, or further impersonation inside downstream systems.
That is why remote onboarding should be measured by how hard it is to counterfeit the whole process, not by how realistic the face looks in isolation. Stronger systems raise attacker cost through layered evidence, out-of-band checks, device binding, document validation, and exception handling for high-risk cases. Banks that rely on a single visual check are assuming the attacker cannot cheaply iterate, and deepfakes prove that assumption is no longer safe.
Internal guidance on Deepfakes, Social Engineering and AI Impersonation is useful here because it ties synthetic media to the operational controls that actually interrupt fraud attempts.
Risk and Threat Considerations
Deepfakes increase both exposure and adversary efficiency. In mobile onboarding, the threat is not only that one applicant can be faked, but that the same playbook can be reused at scale across many banks, making manual review queues and weak liveness controls economically unattractive to defenders.
Failure mechanism: The attacker uses synthetic or replayed media to satisfy a narrow identity check, then pairs it with weak document, device, or session validation to complete account opening without a genuine human present.
Impact: Fraudulent accounts can be opened repeatedly, enabling mule activity, payment abuse, and later-stage identity misuse while the bank believes its onboarding evidence is trustworthy.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5, NIST SP 800-63 and OWASP ASVS set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | Deepfakes bypass remote identity proofing and weak liveness checks. |
| NHI-08 — Environment Isolation | Mobile onboarding depends on trusted device and session boundaries. | |
| NHI-10 — Human Use of NHI | Synthetic media can let humans misuse identity-bearing artefacts at scale. | |
| Recommendation — Strengthen onboarding with liveness, device trust, and step-up verification. Isolate onboarding sessions from rooted, emulated, or tampered device environments. Require out-of-band confirmation before accepting high-risk onboarding evidence. | ||
| NIST SP 800-53 Rev 5 | IA-8 — Identification and Authentication (Non-Organizational Users) | Bank customers and applicants are external users needing strong proofing. |
| IA-12 — Identity Proofing | Remote onboarding hinges on proving the applicant's identity, not just matching a face. | |
| IA-2 — Identification and Authentication (Organizational Users) | Onboarding workflows need trusted internal review access and exception handling. | |
| Recommendation — Use strong proofing and authentication controls for remote customer onboarding. Apply stronger identity proofing where selfie checks are insufficient. Protect reviewer access and approval paths with strong authentication. | ||
| NIST SP 800-63 | Digital Identity Guidelines | Digital identity assurance, proofing and authenticators directly frame remote onboarding. |
| Recommendation — Use digital identity assurance guidance to set onboarding proofing strength. | ||
| OWASP ASVS | V6 — Authentication | Selfie and liveness checks are part of authentication assurance in onboarding. |
| V8 — Authorization | Onboarding fraud becomes harmful when weak proofing grants account creation rights. | |
| Recommendation — Verify that authentication flows resist replay, spoofing, and synthetic media. Limit account creation and step-up decisions to validated onboarding states. | ||
| MITRE ATT&CK | T1585 — Establish Accounts | Fraudulent onboarding creates accounts that attackers can later abuse. |
| Recommendation — Monitor for account creation patterns that indicate fraudulent enrollment activity. | ||
Practitioner Guidance
What to prioritise: Treat high-risk onboarding as an evidence-corroboration problem. The strongest designs combine liveness, device integrity, document validation, and out-of-band challenge so that no single fake signal can carry the decision.
What to verify: Confirm that the bank can distinguish a live capture from replayed or generated media, and that step-up review triggers on anomalies such as device mismatch, repeated submission patterns, or inconsistent session behaviour. If those signals are missing, the onboarding control is too easy to game.
Common mistake: Assuming that better face matching alone solves synthetic identity fraud. Better similarity scores do not compensate for weak presence testing or untrusted devices.
Practitioner takeaway: Deepfakes make mobile onboarding riskier because they attack the trust model behind remote proofing, so the control objective should be to make the full onboarding path hard to counterfeit, not just the face.
Related resources from NHI Mgmt Group
- Why do deepfakes and agentic AI make onboarding risk harder to control?
- Why do emulators and deepfakes make mobile identity checks less reliable?
- Why do deepfake attacks make mobile biometric authentication riskier?
- Why do mobile-only offerings often make more sense than broad legacy transformation for traditional banks?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 10, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org