signzy

API Marketplace

downArrow
Logo
Responsive

AI Is Turning Identity Fraud From a Forgery Problem Into a Systems Problem

By Ankit Ratan
By Ankit Ratan
September 8, 2026
8 minutes

In May 2026, I was in San Francisco with other founders at Marketplace Risk. We were discussing a simple change in fraud. Signzy described it this way: AI is making fraud faster, cheaper, and more convincing.

The conversation felt familiar.

When we started Signzy in 2015, banks already had useful technology. The problem was that their tools did not work together. Building one customer journey required expensive integrations and months of work. In a later conversation about Signzy's early years, I called this the "dirty work": connecting identity, underwriting, contracting, and other financial APIs into one workflow.

Back then, banks had coordination problems. Now AI is helping fraudsters coordinate their side too.

AI can create better fake documents, faces, and voices. But I think the larger change is the cost. A fraudster can now make several imperfect pieces agree with each other for less money and with less effort.

This means a bank cannot judge each piece on its own. It must decide whether the full story makes sense.

Better fakes are only part of the problem

Most discussions about AI fraud focus on detection accuracy.

Can a document tool find a generated ID?

Can liveness detection catch an altered face?

Can software recognize a cloned voice?

These questions matter when the attack involves one fake item. They are less helpful when the document, face, voice, device, and explanation all support the same false identity.

This way of selling fraud at scale existed before generative AI became common. In February 2026, the U.S. Department of Justice announced that the operator of OnlyFake had pleaded guilty. The service had been used to produce more than 10,000 digital fake identity documents. Customers could make the documents look like scans or photographs and buy packages containing as many as 1,000 IDs. The DOJ said people used these documents to bypass KYC programs and hide their identities.

The DOJ case does not say that generative AI created the documents. The case does show that fake identities were already being customized and sold in bulk, much like software.

AI can add more pieces to that service. It can help create a portrait, animate a face, copy a voice, change a written explanation, and keep the same story going across several conversations. If one attempt fails, another version can follow quickly.

The fake ID still matters. It is now one part of a larger identity story.

Fraudsters now follow the whole customer journey

Banks design customer journeys. Fraudsters look for weak points in those journeys.

A bank may check a document, compare a face, authenticate the account, monitor transactions, and later handle account recovery. Each check answers one question. It rarely answers every question the bank needs to ask.

A document check can show that an ID looks real and valid. It may not show that the applicant is its rightful owner.

Face matching can show that two images look like the same person. It cannot prove that either image came from a trusted source.

Liveness detection looks for signs of a live person. It may not catch video sent through a virtual camera or another injected feed.

The same problem continues after onboarding. Authentication shows that someone controls an approved login method. But an attacker may have replaced that method through account recovery. Transaction monitoring can find unusual behavior, but a real customer may still be following instructions from a fake voice, video, or message.

Each tool can work as designed while the bank still reaches the wrong decision.

AI makes it easier to connect these parts. A generated portrait can match an altered document. A synthetic video can show the same face during onboarding. A cloned voice can support a later recovery request. Generated text can keep the explanation consistent during a support call or chat.

The attack does not need to be perfect. Each part only needs to pass the check in front of it.

Every check can pass and the bank can still be wrong

Banks usually buy and test identity tools one at a time. Document tools are judged on document results. Biometric tools are judged on face matching and liveness. Device tools are judged on device risk. Transaction systems are judged on suspicious activity.

This focus has made each tool better. It can also hide problems between the tools.

NIST's final SP 800-63A-4 identity proofing guidance explains why several controls are needed. NIST calls for checks on altered media and evidence that media came from a real sensor. It also calls for protected communication channels, tests with both attack and genuine media, and manual review. A biometric comparison alone does not stop digital injection attacks.

In simple terms, a face model can work correctly even when the video reaching it is fake.

FinCEN's alert on deepfake media targeting financial institutions covers more than fake documents. It also discusses webcam plugins, conflicting customer information, refusal to use multifactor authentication, social engineering, business email compromise, and suspicious transactions.

FinCEN warns that one red flag does not prove fraud. The bank must look at the facts around it.

This is what one accuracy score misses. A result may look safe by itself and risky when combined with earlier events.

Specialist teams can miss the handoffs

Banks separate KYC, login security, fraud, AML, customer support, and cybersecurity for good reasons. Each area has different threats, skills, regulations, and owners.

But customers move through all these teams. Attackers do too.

A warning found during onboarding may never reach the account recovery team. A device linked to several failed applications may not affect how the bank treats a new payment beneficiary. A risky support call may remain hidden from the transaction system. A confirmed fraud case may close without warning future checks about the same document, phone number, address, device, or network.

An AI-assisted attack does not need to beat every control. It may only need the bank to forget something at the right moment.

Some banks already share risk information across teams and customer stages. Others still rely on separate dashboards that look healthy even when the handoffs are weak.

Ask what the system forgot

Building identity systems has changed the first question I ask when fraud gets through.

Teams naturally ask which document check failed, which biometric model missed the attack, or which rule should have fired. Those questions are useful. But they examine one part of the case at a time.

I now start with a different question:

What did the institution know earlier that the next decision was allowed to forget?

This question may reveal that a risky camera feed was forgotten after a face matched. It can connect an account recovery event to the payment that followed. It can also show that a rejected document, phone number, device, address, or beneficiary appeared again in another application.

An identity system needs enough memory to make these connections. It should know where a document or video came from, what the bank has already confirmed or rejected, and which results conflict with each other. The response should also match the risk. A small profile update and a high-value transfer should not be treated the same way.

This idea has shaped Signzy's product direction. One Touch KYC combines document checks, biometrics, liveness, screening, and decisions during onboarding. Deepfake Detection checks images, video, and voice for manipulation. Transaction Monitoring looks for risky behavior after an account has opened.

No platform can stop every AI-enabled fraud attempt. The useful test is whether a warning from one stage can change the next important decision.

Fraud is starting to work like software

I compare this change with the difference between a counterfeiter and a software platform.

A counterfeiter tries to make one object look real. A software platform connects several parts, handles failures, and makes it cheap to repeat the process. AI is pushing some identity fraud toward the second model.

The comparison has limits. Many attacks are still basic, and many generated fakes can be detected. Fraudsters still need personal data, technical access, infrastructure, and a way to take the money. AI does not provide all of this by itself.

But it can provide the same production and communication tools across different fraud schemes.

The FBI's 2025 IC3 Annual Report recorded 22,364 complaints containing AI-related information and more than $893 million in adjusted losses. These figures cover several types of crime and are not an identity fraud total. The report discusses AI in business email compromise, confidence schemes, employment scams, investment fraud, synthetic content, and voice cloning.

These crimes are different, but the tools used to create and run them are starting to overlap.

Better identity checks will still help

Standalone identity checks are improving. Better deepfake models, sensor checks, digital credentials that can be verified, national identity systems, phishing-resistant login methods, and passkeys can all make attacks harder. If banks use these controls widely and make them work together, the advantage for attackers may shrink.

I think this is possible. Better identity systems should improve security and reduce unnecessary steps for genuine customers.

Still, each check has limits. A real credential does not prove that the customer intends to make a payment. A trusted device does not prove that its owner has not been tricked. A real customer can be forced to act. Strong onboarding cannot protect an account forever if recovery is weak.

Sharing more data creates other risks. Banks must consider privacy, clear explanations, accessibility, and control over how the data is used. A system that treats every unusual customer as a fraudster will block real people and create alerts that staff stop trusting.

Banks do not need every possible signal. They need the right information for the decision in front of them, with extra checks that match the level of risk.

The metric I would watch for 24 months

False acceptance, false rejection, attack detection, speed, and customer abandonment will remain useful measures. I would add one more:

What percentage of confirmed fraud cases passed every control they encountered?

This number shows the gap between the performance of each tool and the bank's final result. It also gives us a clear way to test this argument.

Other measures can fill in the picture.

How many attacks cross more than one customer stage?

How long does it take to connect a case to related identities and devices?

How many genuine customers leave because new checks do not share context?

If more fraud cases pass the document, biometric, device, and authentication checks, then banks have a systems problem. If better standalone tools reduce these cases without information from other stages, then better detection may be enough.

Over the next 24 months, I expect the first pattern to become more common, though not at every bank or for every type of fraud. Documents, biometrics, and authentication will remain necessary. But banks will pay a higher price when their systems forget what earlier checks already learned.

The hardest task will be noticing when a real-looking document, face, device, and transaction no longer describe a real customer.

end
LinkedInX
Ankit Ratan

Ankit Ratan

Ankit Ratan is the Co-founder and CEO of Signzy, where he has spent over a decade building technology that helps financial institutions establish trust digitally — from customer identity and KYC to fraud prevention, AML and regulatory compliance. He co-founded Signzy in 2015 with the goal of making trust programmable, enabling banks and fintechs to verify customers and businesses, assess risk, and meet regulatory obligations without slowing down legitimate users. Under his leadership, Signzy has grown into a global trust infrastructure platform supporting *25M+ customer onboardings every month* and has verified *160M+ business profiles*. Its technology spans identity verification, fraud controls, compliance, underwriting and digital contracting, serving financial institutions across major global markets. An IIT Delhi Silver Medalist and Forbes India 30 Under 30 honoree, Ankit’s work has centred on a simple challenge: enabling financial services to scale digitally without weakening identity, compliance or trust.

The global API marketplace for KYC, KYB, & AML

Explore the end-to-end verification stack trusted by 1,000 businesses.

Get in touch