Deepfakes and Identity Theft: How AI Is Changing Online Fraud and How to Stay Safe

We tend to trust what we see and hear on the screen. But artificial intelligence (AI) is gradually changing this rule. Today, a few photos or a few seconds of a voice recording can be enough to create a convincing digital double.

We are increasingly using smartphones to communicate, work, manage our finances, and travel, while staying connected through services like eSIM Plus. Therefore, protecting our digital identities is becoming just as important as protecting our passwords and banking information.

Let’s look at how modern deepfakes work, how scammers use them, and what can be done to avoid becoming a victim.

How Deepfake Fraud Is Evolving

The cyber threat landscape is changing rapidly. Attackers no longer spend weeks preparing a single attack targeting a specific executive. Thanks to open-source resources, including hundreds of repositories on GitHub and cloud computing, the process of creating synthetic content has been industrialized. Now scammers can automate the collection of victims’ data from open sources (OSINT), and then use AI to generate a personalized attack scenario.

The most common deepfake fraud schemes show a clear shift. Attackers are increasingly shifting from ‘pinpoint’ attacks to scalable, hybrid campaigns. The key trend is the industrialization of fraud: Deepfake-as-a-Service tools and kits are emerging, and AI SaaS enables AI-powered deception as a service. Attackers use pre-recorded audio and generate synthetic speech with a latency of less than 0.3–0.5 seconds, allowing them to engage in conversations almost in real time.

How Scammers Use Deepfakes

 

In the corporate sector, classic business email compromise (BEC) has gained new momentum. Messages asking employees to ‘pay the bill urgently’ have long raised suspicion among vigilant employees. However, when the same text is reinforced by a voice message or a short video call from the CEO, the victim’s critical thinking is often impaired by the pressure of authority.

Scammers readily use deepfakes in so-called FakeBoss schemes. They generate a short video to convince the victim that the person contacting them is their real supervisor. Most often, these videos contain no audio, so the attackers then continue the conversation in writing. Experts have documented cases in which a company’s accountant receives a call from someone claiming to be the founder and is asked to make a payment to a new business partner. If the employee does not verify the request through another channel, the company could suffer financial losses.

In parallel, digital identity verification systems are also facing large-scale attacks (KYC — Know Your Customer). Banks, microfinance organizations, and carsharing services are increasingly dealing with attackers who create large numbers of accounts using stolen passport data, successfully bypassing liveness checks.

At the digital identity verification level, attacks have become more technically sophisticated and can bypass several layers of verification at once. We can identify three main scenarios: the generation of a fully synthetic document, face replacement during a selfie check with an identity document, and a deepfake video used to pass a liveness check through a virtual camera.

Can You Tell If a Deepfake Is Real?

Whether reliable tools exist for detecting AI-generated content remains a subject of intense debate in the professional community. Theoretically, deepfake detection algorithms analyze the spectral characteristics of sound and look for unnatural artifacts in video (for example, a lack of blinking, blurring at the borders of the face, and out-of-sync lips and sound).

However, in practice, a serious problem arises: most attacks occur through popular instant messengers (Telegram and WhatsApp) or video conferencing platforms (Zoom or Teams). These services aggressively compress media files to save traffic, which destroys the very microscopic artifacts that the detectors rely on.

How to Protect Yourself and Your Business

Since the technological arms race between attackers and defenders is progressing with mixed results and technology cannot provide an absolute guarantee, organizational measures are becoming increasingly important. Companies need to recognize this new reality: traditional communication channels should be treated as potentially compromised.

The concept of Zero Trust, which was previously applied to network architecture, must now be extended to human communication. Any non-standard request related to finances, access, or confidential information should be considered a potential attack, even if it appears to come from someone you can see and hear.

Practical Steps to Stay Safe:

  1. Do not rely on biometrics as the sole authentication factor: a person’s voice and face are no longer indisputable proof of identity. They should only be used alongside other authentication factors.
  2. Implement the ‘two-person rule’: any financial transaction, change to a counterparty’s bank details, or granting critical access rights must be independently verified by at least two independent employees.
  3. Double verification through independent channels: if an urgent message or call is received from a director through a messaging app with an unusual request, company policy should require the employee to call back using a regular phone call, send an email to the corporate address or verify the request through a secure internal chat.
  4. Use hardware security keys (tokens or smart cards): critical transactions must be confirmed through secure corporate systems using cryptographic mechanisms that cannot be bypassed through social engineering alone.
  5. Separation of duties: business processes should be designed so that no employee (even a top manager) has the technical ability to make a large, unusual payment single-handedly without going through the required compliance procedures.
  6. Code phrases: Return to the old but highly effective practice of using predefined code words to verify identity over the phone when discussing sensitive topics.

What Comes Next? Synthetic Identities and AI Scams

Based on current trends, experts agree that we are only at the beginning of this trend. In the coming years, deepfake attacks are likely to become even more sophisticated. The emergence of so-called ‘synthetic personalities’ is expected to become more common — entirely fictional digital identities that exist only in databases and AI systems, yet can still pass verification, take out loans, open accounts, and interact with real people.

The main trend in the coming years is the industrialization of deepfake fraud and the rise of synthetic identities. A set of source data is collected, for example, enough data to create a complete artificial identity with a fabricated appearance, documents, contact information, and a digital footprint are then built around it. The synthetic identity can then be used to open accounts, withdraw funds, and commit financial or credit fraud.

Moreover, the involvement of a human fraudster may soon become optional. The development of large language models (LLMs) combined with voice-generation technology will lead to autonomous systems capable of conducting social-engineering attacks independently.