Deepfake Fraud Is Breaking KYC: What Firms Must Know
AI-generated deepfakes have crossed from novelty into criminal infrastructure. Losses from deepfake scams in the first months of 2026 already exceeded the full-year 2025 total by 263%, according to TRM Labs' AI Crime Index, which tracks AI's growing role in illicit activity on a scale of 0 to 100. That index stood at 28 in 2024. By 2026 it had risen to 54. For accounting firms, auditors, and CFOs operating in the digital asset space, this is not a background technology story. It is a direct and measurable threat to client funds, internal wire controls, and the KYC processes that regulated businesses depend on.
Why Deepfakes Became a Criminal Tool So Quickly
The technology itself is not new. What changed is the cost and skill required to produce a convincing fake, and the speed at which that barrier collapsed.
From specialist skill to consumer product
Producing a credible face swap or voice clone once required custom machine-learning models and meaningful technical expertise. That is no longer true. Consumer-grade tools can now generate a real-time video impersonation from a single screenshot, or clone a voice from a few seconds of audio scraped from social media. Digital forensics researcher Hany Farid at the University of California, Berkeley demonstrated this publicly: using a USD 10 piece of software and one screenshot, he produced a real-time video impersonation running at 30 frames per second. The output does not need to fool an automated detector. It only needs to fool a person under time pressure.
Packaged crime-as-a-service
Deepfake generation has also become a packaged criminal service. TRM Labs identified two named providers in its research. NiMingZhe sells a single AI face-swap and voice-cloning model for approximately USD 500, and a full year of deepfake tooling for about USD 3,000. Novin Verify sells synthetic identity documents including fabricated passports, proof-of-address letters, and attestation letters, built specifically to pass regulated verification checks. The marginal cost of running a large-scale fraud operation has dropped to the point where criminal groups can operate at volume against many targets simultaneously.
Deloitte's projection underlines the trajectory: generative AI is expected to push fraud losses in the United States from USD 12.3 billion in 2023 to USD 40 billion by 2027, a 32% compound annual growth rate driven largely by synthetic media.
The Attack Patterns Compliance Teams Are Seeing
TRM Labs identifies several distinct typologies. Each has direct implications for how accounting firms and financial institutions design their controls.
Corporate video-call fraud
The most documented example of large-scale corporate deepfake fraud occurred in January 2024, when an employee at engineering firm Arup joined a video call with five apparent colleagues, including the company's UK-based Chief Financial Officer. Every person on the call except the employee was a deepfake. Acting on instructions received during that call, the employee transferred USD 25 million to fraudulent accounts. The scheme worked because it replicated the exact context in which employees are trained to trust instructions: a multi-person video call with known colleagues, including a senior authority figure.
Similar schemes have targeted senior US officials. The FBI warned in 2025 and 2026 that criminals have used AI-generated voice memos and messages to build false rapport with associates before requesting authentication codes, sensitive information, or wire transfers.
Voice cloning and family impersonation
Voice cloning has updated one of the oldest social-engineering scripts. Rather than a stranger claiming vaguely to be a relative in distress, criminals now clone the actual voice of a grandchild or family member from audio pulled from public social media, then call an older relative claiming to need urgent bail money or medical funds. The FBI has recommended establishing a family "secret word" as a verification method, acknowledging that recognizing a familiar voice is no longer a reliable identity check.
Romance scams augmented by AI
Romance scams reported to the US Federal Trade Commission caused substantial losses in the first nine months of 2025, with a median individual loss of USD 2,218 in the third quarter of that year. These operations are still largely run by human operators, but AI increasingly supplements the human element. Generated photos and videos substitute for in-person or video appearances, and chat-assistance tools allow operators to sustain simultaneous conversations with far more victims than a single scammer could manage manually.
Law enforcement impersonation targeting prior victims
In July 2026, the FBI's Internet Crime Complaint Center warned that criminals were using deepfake personas to direct victims to spoofed versions of the IC3 website itself. The scheme targets people who had already lost money to a prior scam and were actively searching for help recovering it, exploiting the moment when a victim is most likely to trust an authority figure.
Synthetic identity and KYC bypass
Beyond impersonating real people, criminals also fabricate people who do not exist, or use AI-generated faces and manipulated identity documents to defeat photo-based and selfie-video identity verification checks. Farid's research found that video-only identity checks at a major crypto exchange, with no human review in the loop, could be spoofed using synthetic video alone. His conclusion: any KYC process that relies on a single channel, whether voice only or video only, should be treated as structurally vulnerable.
Accounting and AML Implications for Regulated Firms
For accounting firms, auditors, and compliance teams serving digital asset businesses, deepfake fraud creates obligations and exposures across several dimensions.
Customer due diligence and KYC controls
The Financial Crimes Enforcement Network (FinCEN) and the broader Bank Secrecy Act framework require covered financial institutions to verify customer identity and maintain controls that detect suspicious activity. If a firm's KYC process relies on a video selfie or a voice check as its primary or sole means of liveness detection, the research above demonstrates that it is potentially bypassable with commercially available tools. Multi-channel verification, human review at onboarding, and periodic re-verification for high-risk relationships are no longer optional enhancements. They are defensible practice in an environment where regulators have been explicitly warned about this vulnerability.
Firms advising clients on how blockchain behavioral detection flags suspect wallets in pig-butchering cases will recognize the parallel: the entry point for many fraud schemes is an identity that passed initial onboarding. Strengthening that gate is the first line of defense.
Internal wire transfer authorization
The Arup case is the clearest illustration of what happens when wire-transfer controls depend entirely on visual and auditory confirmation of an instruction source. Firms should review whether their payment authorization procedures require an independent, out-of-band confirmation step for any transfer above a defined threshold, regardless of how convincing the instruction appears. A phone call to a known direct number, not a number supplied in the message requesting the transfer, is the standard the FBI recommends.
Suspicious activity reporting obligations
Where a firm becomes aware that a client or counterparty may have been targeted by or involved in deepfake-enabled fraud, existing suspicious activity reporting obligations under the Bank Secrecy Act apply. The relevant question for compliance teams is whether the fraud typology is adequately described in the firm's AML program and whether staff training covers AI-generated impersonation as a recognized method. Regulators have been clear that AML programs must evolve to reflect current threat environments. The FBI and FinCEN have both issued public guidance on synthetic media fraud, which means the argument that this threat was not foreseeable is no longer available.
Audit and financial statement considerations
For auditors, the Arup case raises a direct question about management override controls. A deepfake attack on a CFO's identity is, in effect, a sophisticated management override: a fraudulent instruction that appears to come from an authorized authority. Auditors evaluating the design of controls over disbursements and wire transfers should consider whether the control environment assumes that multi-person video confirmation is a reliable authorization method, and document their assessment accordingly. The FBI's Huione takedown demonstrated how quickly criminal infrastructure can scale when regulatory controls have gaps. The same principle applies here.
How reliable is human judgment at spotting deepfakes
Farid's research produced a finding that should inform training design directly: human ability to distinguish real from synthetic video is close to chance, and higher confidence in a judgment tends to correlate with lower accuracy. This means that briefing staff to "look carefully for signs" is not a control. It is a false assurance. The FBI's guidance on visual tells, distorted hands, unnatural facial movement, audio lag, and blurring at the edges of the face, remains a useful starting check, but it is not a substitute for procedural controls that do not depend on human detection at all.
Reliable crypto accounting software and digital asset accounting software systems provide an independent record of authorized transactions that can be reconciled against instructions received. When a firm's books reflect a transfer that cannot be matched to a properly authorized instruction verified through an out-of-band process, that discrepancy becomes visible. The ledger is not fooled by a deepfake. That is precisely why procedural controls anchored in the accounting record matter.
Practical Steps for Firms Right Now
The FBI's guidance across its 2025 and 2026 alerts converges on a small set of procedural recommendations that do not require technology investment to implement immediately.
What the FBI recommends
- Establish a family or team "secret word" for identity verification in high-stakes situations. Do not rely on voice or face recognition alone.
- For any request involving a wire transfer, authentication code, or sensitive data, call back on a pre-verified number, not one provided in the suspicious communication.
- Watch for requests that create artificial urgency or pressure immediate action. Time pressure is a deliberate tool in these schemes.
- Treat video-only or voice-only identity verification in onboarding as a single channel that should be supplemented by at least one independent check.
- Be aware that impersonation of law enforcement, including the IC3 itself, is an active fraud typology targeting people who have already been defrauded once.
For firm-level AML programs
- Update the firm's AML risk assessment to include AI-generated synthetic media as a named threat vector.
- Review KYC onboarding procedures to confirm that liveness detection relies on more than a single channel.
- Ensure that suspicious activity report narratives can describe deepfake-enabled fraud accurately when reporting to FinCEN.
- Consider whether disbursement authorization controls require revision to mandate out-of-band confirmation for high-value transfers.
- Document staff training on this typology, given that regulators have issued explicit public warnings, the absence of training is a compliance gap.
Source: TRM Labs
Frequently Asked Questions
Does a deepfake attack trigger SAR filing obligations for a crypto firm?
If the firm knows or has reason to suspect that a transaction involved fraud, including fraud facilitated by AI-generated impersonation, the Bank Secrecy Act's suspicious activity reporting requirements apply in the usual way. The method of fraud does not create an exception. Firms should ensure their SAR narratives can describe the deepfake typology clearly so that FinCEN analysts can identify the pattern.
Is video-based KYC now considered insufficient for regulated businesses?
Researchers, including Hany Farid at UC Berkeley, have demonstrated that video-only liveness checks at a major crypto exchange could be defeated using synthetic video with no human review in the process. Regulators have not yet issued updated technical standards in response, but the FBI and FinCEN have issued warnings about AI bypass of identity verification. Prudent practice is to supplement video checks with at least one independent channel and to include human review for higher-risk onboarding cases.
How should an auditor treat the risk of deepfake-enabled management override?
A deepfake instruction that impersonates a CFO or other authorized signatory is, in effect, a fraudulent override of authorization controls. Auditors evaluating disbursement controls should assess whether multi-person video confirmation is treated as a reliable authorization mechanism and whether out-of-band verification is required for high-value transfers. Documenting this assessment in the audit file is appropriate given the public warnings now on record from both the FBI and FinCEN.
What is the cost of access to deepfake criminal tools?
TRM Labs identified two named providers. NiMingZhe sells a single AI face-swap and voice-cloning model for approximately USD 500 and a full deepfake tooling package for about USD 3,000 per year. Novin Verify sells synthetic identity documents designed to pass regulated KYC checks. The low price point means that access is not limited to sophisticated actors, which is why the threat is scaling so rapidly.
What is the projected scale of deepfake-driven fraud losses?
Deloitte projects that generative AI will drive US fraud losses from USD 12.3 billion in 2023 to USD 40 billion by 2027, a compound annual growth rate of 32%. TRM Labs reports that deepfake-scam losses in the first months of 2026 already exceeded the full-year 2025 total by 263%. These are the figures on record from primary sources. The underlying trajectory makes this a material risk management issue rather than a reputational one.
