TL;DR
- A deepfake is AI-generated or altered media that passes as a real person or event.
- Generating the fake is only half the attack, it still has to reach a camera.
- Synthetic identity led AI fraud in 2025 at 42.3% of incidents.
- Human reviewers can no longer reliably spot a live video deepfake.
- EU labelling duties for deepfake content apply from 2 August 2026.
Since 2 August 2026, the European Union’s transparency rules for AI-generated content take effect, and any deepfake published in the bloc has to be visibly disclosed as synthetic. This deadline is nearing because it is no longer expensive or relatively difficult to create a fake.
Up until a few years ago, a believable fake face needed a skilled editor and hours of work, whereas today an attacker feeds one photograph or a text prompt into a generative model and receives back a face that blinks, turns its head, lip-syncs, and reacts in real time. This dramatic shift is why deepfake-powered identity fraud is projected to rise 495% in 2026 over 2025.
What is a deepfake?
A deepfake is a video, image, or audio recording in which artificial intelligence has fabricated or altered a person’s likeness or voice so convincingly that it passes as authentic. The EU AI Act puts a legal boundary around the same idea in Article 3(60), defining a deepfake as AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places or events and would falsely appear to a person to be authentic or truthful.
The word itself is a compression of “deep learning” and “fake”, and it all dates back to a Reddit account that began posting face-swapped videos in late 2017. The label has since widened well past its origin and has grown common across the world. It now covers a fully synthetic face that belongs to nobody, a real executive’s voice cloned from a conference recording, a passport image assembled by a diffusion model, and a live video stream in which an attacker’s face is replaced frame by frame during a verification call.
That breadth of the situation matters operationally, because a fraud team defending against one of those is not defending against the others. A rather cheap manipulation like a slowed-down clip or a mislabelled photograph, sometimes called a cheapfake, does not require any sort of AI at all and is caught by different controls. The useful working definition for anyone running onboarding or identity verification is narrower than the cultural one. A deepfake is synthetic media generated or altered by a model, presented as genuine, and aimed at a system or a person that has to decide whether to trust it.
How does deepfake technology actually work?
Deepfake AI works by training a neural network on enough images or audio of a target so that the model learns the underlying pattern of that face or voice, then reproduces it in situations that never happened. Four generation methods do most of the work in circulation today, and they differ in what they need, what they cost, and what they leave behind for a detector to find.
Generative adversarial networks and the forger-versus-inspector loop
A generative adversarial network, or GAN, trains two models against each other. The generator produces candidate faces, and the discriminator judges whether each one looks real or manufactured. Every time the discriminator catches a flaw, the generator adjusts, and the loop repeats for millions of rounds until the generator produces output the discriminator can no longer separate from genuine photographs.
The US Government Accountability Office describes this adversarial process as the core mechanism behind convincing synthetic faces. GANs are what produce the fully synthetic person, a face with no real-world counterpart, and that output feeds directly into synthetic identity fraud.
Diffusion models and the collapse in Attacker Effort
Diffusion models often opt for a different route. They usually start from random noise and remove it step by step, guided by a text prompt or a reference image; this continues until a coherent picture emerges. The practical consequence is that a deepfake image now takes seconds and a sentence rather than a curated training set.
Deepfake AI image-to-video tools extend the same principle across frames, animating a single still photograph into a moving, speaking person. That collapse in effort is the reason attack volume rose so sharply, because a technique that once demanded skill now demands only a prompt and a source image scraped from a public profile.
Face swaps and expression reenactment
Face-swap systems map a victim’s face onto an attacker’s head in real time, so the attacker’s own head movement, lighting, and background remain genuine while the identity on top is borrowed. Expression reenactment does the inverse and drives a target’s face with a puppeteer’s movements. Both these techniques are built to be able to survive a live call rather than a static upload, which is why they show up in video verification sessions rather than in document folders.
Face swaps accounted for 17.6% of AI-enabled fraud incidents tracked in 2025, and that share matters because a swap leaves its evidence at the seam where the borrowed face meets a real jawline.
Voice cloning and audio deepfakes
Audio deepfakes clone a voice from a sample of recorded speech and then generate new sentences the speaker never said. Voice is the cheapest modality to fake and the hardest for a listener to challenge, because a phone call carries no visual cue to check against.
In practice, audio rarely travels alone. It is paired with a spoofed number, a plausible pretext, and time pressure, so the target hears a familiar voice in a situation engineered to discourage a callback.
How does a deepfake actually reach the camera?
A generated face is inert until somebody delivers it into a live feed, and that delivery step is where most detection actually happens.
Tom Gadsden, VP of Product at Shufti, frames it as the part attackers cannot avoid, because a deepfake has to be shipped into the physical world through a virtual camera or a phone held up to another phone, and catching that hand-off is a core defence. Almost every explainer stops at generation, yet a fraud team never sees the model. It sees whatever arrived at the endpoint, and the route it took leaves signatures of its own.
Presentation attacks, holding the fake up to a real lens
A presentation attack puts the artifact in front of a genuine camera. That artefact might be a silicone mask, a printed photograph, a screen replaying a deepfake video, or a second phone displaying an animated face. The camera behaves normally and captures exactly what it is shown, so the attack succeeds or fails on whether the system can tell a live human face from a flat, re-photographed one. Depth cues, the way real skin responds to light, and screen-replay artefacts such as moiré patterns are the signals that separate the two.
Injection attacks, skipping the lens entirely
An injection attack bypasses the camera altogether and pipes an AI-generated feed straight into the verification app through virtual-camera or emulator software. Nothing is ever held up to a lens, so every control that inspects the image alone is looking at a clean, well-lit, perfectly framed fake. Defence has to move upstream to the hardware path, confirming that the video genuinely originates from a physical smartphone sensor rather than from software pretending to be one. This is the attack route that punishes vendors whose entire liveness story rests on analysing pixels after capture.
Deepfake-enabled synthetic identity creation
The third route stitches a generated face to fabricated documents and manufactures a person who has never existed. There is no victim to notice the theft and no real identity to cross-check, which is why synthetic identity fraud is so durable once an account is open.
Synthetic identity accounted for 42.3% of AI-enabled fraud incidents in 2025, the largest single share of the four attack types, and those accounts often behave impeccably for months before they are used, so the loss surfaces long after onboarding closed the file.
Real campaigns rarely stay in one lane. An attacker will inject a synthetic face to open the account, then use a presentation attack at the step-up check months later, which is why a control that blocks one route in isolation buys less protection than its test results suggest.

The best-known deepfake examples
The clearest deepfake examples are the ones where the fake had a measurable consequence, because they show which control failed rather than only how good the artefact looked.
The Arup video call: This happened in early 2024 when a finance employee at the engineering firm Arup joined what appeared to be a routine video call with the company’s chief financial officer and several colleagues, then approved 15 transfers worth roughly $25 million. Every other participant on that call was synthetic. The World Economic Forum documented the case as a turning point precisely because no system was breached. The control that failed was a human being trusting a familiar face on a screen.
The Pentagon image: On 22 May 2023, an AI-generated photograph depicted an explosion near the Pentagon which spread wide across social media, and Bloomberg reported that the S&P 500 fell roughly 0.3% to a session low before police confirmed no explosion had occurred and the index recovered. A single deepfake image, circulated for minutes, moved a major index. The dip was small and brief, though it established a clear message that synthetic media can reach markets before verification does.
The fake job interview: Alex Wood, a reformed fraudster who now advises on scam prevention, describes a technique in which fraudsters run a bogus job interview over video and record the candidate’s “piece to camera”. The recording is not an interview at all. It is a live bank-account application, and the victim supplies the biometric capture voluntarily. The example is worth carrying because it shows social engineering and synthetic media working together rather than one substituting for the other.
Which industries face the greatest risk from deepfakes?
The industries most exposed to deepfakes share three traits, which are remote-only onboarding, an account that converts quickly into money or credit, and a regulatory obligation to know exactly who the customer is. Where all three overlap, a successful synthetic identity pays immediately, and the compliance penalty for missing it is separate from the fraud loss.
| Sector | Why it is exposed | Dominant attack pattern |
| Crypto and digital assets | Fully remote onboarding, fast liquidity, pseudonymous downstream flow | Synthetic identity at account opening |
| Fintech and neobanks | High-volume digital origination, instant account issuance, mule demand | Injection attacks during selfie checks |
| Lending and BNPL | Credit extended before any repayment behaviour exists | Synthetic identity plus document deepfakes |
| Traditional banking | Remote channels bolted onto legacy identity records | Face swaps at step-up authentication |
| iGaming and betting | Age and identity duties, bonus abuse, multi-accounting incentives | Presentation attacks and multi-accounting |
| Insurance | Claims evidence submitted as photo and video files | Document and media deepfakes in claims |
How do deepfakes affect businesses?
Deepfakes hit businesses in three distinct places, and the defences for each sit in different parts of the organisation. Companies that treat all three as one “AI fraud” problem tend to buy a detection tool for the onboarding funnel while the actual loss arrives through the finance team’s inbox.
Identity theft and fraudulent account opening
The commonest commercial use of a deepfake is opening an account in somebody else’s name, or in nobody’s name at all. An attacker scrapes a public photograph, animates it, pairs it with a real or fabricated document, and passes selfie check that was built to confirm a human is present rather than to confirm the human is genuine. Once open, the account funds transfers, receives fraudulent credit, or sits quietly as a mule. Document deepfakes are the fastest-growing input to this pattern, projected up nearly 3,892% year over year in 2026, and the consequence is that document review teams face volumes of synthetic paperwork that no manual process anticipated.
Market Manipulation
Synthetic media moves markets, one of the sharpest deepfake finance risks, by manufacturing an event that never happened, or by putting words in the mouth of somebody whose words carry price sensitivity. The Pentagon image showed the mechanism at index level in 2023. The same technique aimed at a single listed company, timed around an earnings window or a takeover rumour, needs no index-wide reaction to be profitable for whoever is positioned ahead of it. Regulators treat the resulting trades as market abuse regardless of how the false statement was produced, so the exposure for a company is reputational and legal at once.
Corporate defamation and impersonation
A convincing fake of an executive saying something they never said damages a company in ways a correction rarely repairs. The clip spreads faster than the denial, and it seeds doubt that persists after the fake is debunked. Impersonation fraud also runs in the other direction, where an attacker poses as the company itself to defraud its customers, and the business absorbs the reputational cost of a scam it never touched. Thees Buschmann, a compliance consultant who has spoken on Shufti panels, makes the uncomfortable observation that current tooling reliably catches the amateur while sophisticated actors buy the same tools everyone else has and are only visible in the rear-view mirror.
Can you still spot a deepfake by eye?
Not reliably, and that answer has changed within the past two years. Unnatural blinking, mismatched lighting, blurred edges around the hairline, and lips that drift out of sync still appear in low-effort fakes. Current-generation models fix most of them by default. Shufti’s own analysis of the threat found that people are markedly worse at detecting a live video deepfake than a still deepfake image, and that most people overestimate how good they are at either, which makes manual review an unreliable backstop rather than a safety net.
That does not make the human eye worthless. Tom Gadsden’s position is that machines have to fight machines at this scale, though the human option deserves to stay in the workflow because a trained reviewer still notices what is incongruous about a situation even when the face itself is flawless. The signal a person catches is context, such as a caller whose story does not fit the account, rather than a pixel-level artefact.
Automated deepfake detection tools compensate by stacking independent checks an attacker has to beat simultaneously, which is Shufti’s three-layer approach:
- Capture integrity: The system checks the hardware path first and confirms the video originates from a genuine smartphone lens rather than an injected stream. This is the layer that answers injection attacks, and it works before any analysis of the image itself.
- Liveness: Passive cues such as three-dimensional head depth and the way real skin responds to light combine with active challenges such as tracking a moving dot or blinking on command, neither of which a pre-recorded stream can improvise.
- Forensics: The final layer hunts artefacts humans miss, including unnatural pixel blends where a swapped face meets a jawline, the loss of a camera sensor’s unique noise fingerprint, and broken cryptographic provenance in the file.
No single layer is sufficient on its own. An injected feed defeats pure image analysis, a high-quality replay defeats naive liveness detection, and a well-blended swap defeats forensics tuned only for obvious seams.
What does the law now require of AI-generated media?
From 2 August 2026, Article 50 of the EU AI Act requires that deepfake content be visibly disclosed and that AI-generated or manipulated audio, image, video and text be marked in a machine-readable format. The European Commission’s guidance on deepfake laws is explicit that content resembling a real person must be labelled even where no deception was intended and even where no identifiable individual is depicted. A limited grace period applies only to systems placed on the market before that date and only for the marking and detection obligation, with compliance required from 2 December 2026.
The practical effect for regulated businesses is that provenance stops being a nice-to-have. If lawful synthetic content carries machine-readable marking, then unmarked synthetic content arriving at a verification endpoint becomes a stronger signal than it was, and the absence of provenance starts to carry evidential weight. Synthetic-input detection is moving from a competitive differentiator toward a baseline expectation, which is the direction supervisory attention has been travelling for two years.
How does Shufti handle deepfakes at the point of capture?
If you run KYC verification, the uncomfortable part of a deepfake is not the artefact. It is that a synthetic face arrives through a channel you do not control, in a stream that looks clean by the time your system sees it.
Shufti deepfake detection works at the point of capture rather than only on the finished image, so capture-integrity checks confirm the feed came from a real smartphone sensor before any face verification runs, and an injected stream from virtual-camera software fails at that gate regardless of how convincing the face is. The biometric stack behind it is proprietary end-to-end, with no third-party models in the chain, which means a new attack pattern is answered on Shufti’s own release timeline. Independent validation sits behind it in the form of iBeta Level 3 passive liveness conformance under ISO/IEC 30107-3, across both iOS and Android.
Frequently Asked Questions
What are the most common signs of a deepfake?
There is no longer a single reliable sign. Older fakes showed unnatural blinking, mismatched lighting, and lips drifting out of sync, though current models correct these by default. Context is now the stronger tell, such as urgency, an unusual payment request, or a story that does not match the account.
How are deepfakes commonly used in identity theft?
Attackers animate a scraped photograph into a moving face, pair it with a stolen or fabricated document, and pass a selfie check at onboarding. The account is then used for transfers, fraudulent credit, or mule activity. Fully synthetic identities work the same way with no real victim behind them.
How can deepfakes be used to manipulate financial markets?
Attackers fabricate a price-sensitive event or statement. An AI-generated image of an explosion near the Pentagon briefly pushed the S&P 500 down about 0.3% on 22 May 2023. Aimed at one listed company around earnings or a takeover rumour, the same technique can profit whoever traded ahead of it.
How can deepfake content be used for corporate defamation?
A synthetic clip of an executive saying something damaging spreads faster than any correction and seeds doubt that survives the debunk. Attackers also impersonate the company itself to defraud its customers, leaving the business with reputational damage from a scam it never touched.















