How Deepfakes Break eKYC in High-Volume Markets

At scale, the automation, speed, and low friction that make eKYC work are exactly what deepfakes exploit. Here is how they break eKYC in high-volume markets, and how to stop them.
By Adya Tewari
September 11, 2026
l
14
 min read
What are deepfakes — business risk overview article
Table of Content
No items found.

Electronic KYC is the engine of financial inclusion. Across the world's highest-growth markets, from India to Southeast Asia to Latin America, hundreds of millions of people have opened their first bank account, wallet, or SIM through a phone and a selfie, in minutes, with no branch visit. The scale is staggering, and it is exactly the point. But that same scale is now the vulnerability, because the features that let eKYC serve a mass market, full automation, speed, low cost, and minimal friction, are precisely the features deepfakes exploit.

This piece explains how deepfakes break eKYC in high-volume markets: what makes a market high-volume, why scale itself is the weakness rather than any single flawed check, how deepfakes exploit the specific conditions of mass onboarding, the tension between inclusion and assurance that shapes the whole problem, and what it takes to secure eKYC without slowing it down. It is written for the fraud, risk, and compliance teams operating verification at a scale where even a small failure rate means a large absolute number of fraudulent accounts.

The scale of the threat matches the scale of the systems. Deepfake incidents across Asia-Pacific rose more than 1,500% in a single year, and the attacks are aimed squarely at the mass onboarding channels that high-volume markets depend on.

At a glance

Mass eKYC is how hundreds of millions get their first account. It's also where deepfakes now scale — targeting the automation, speed, and low friction that make mass onboarding possible.

+0%
Rise in APAC deepfake incidents
In a single year, aimed at mass-onboarding channels
$0B+
Indian digital-wallet market
Built on Aadhaar-based mass eKYC, still growing at double digits
0humans
In the loop of a fully automated pipeline
A deepfake that clears the model is simply admitted
Jan '26
Vietnam's biometric mandate takes effect
Regulators from Vietnam to Singapore now push toward assurance
  • eKYC powers mass digital onboarding and financial inclusion across high-growth markets, and at volume its core economics become its main vulnerability.
  • The features that make high-volume eKYC work, full automation, speed, low cost, and low friction, are exactly what deepfakes exploit.
  • Full automation removes the human backstop, so a deepfake that clears the algorithm is onboarded with no one to catch it.
  • Mobile-first onboarding on diverse and rooted or emulated devices widens the surface for injection attacks that bypass the camera.
  • At scale, thousands of fraudulent onboardings hide among millions of legitimate ones, and loosely tuned thresholds let more through.
  • Asia-Pacific deepfake incidents rose more than 1,500% in a single year, and national eKYC systems and wallets are prime targets.
  • There is a structural tension between inclusion, which needs low friction, and assurance, which needs strong checks; regulators from Vietnam to Singapore are pushing toward assurance.
  • Securing eKYC at volume means adding deepfake and injection detection that is low-latency, low-cost, device-agnostic, risk-based, and extended beyond onboarding.

What "High-Volume" Means for eKYC

eKYC is remote, automated identity verification: an applicant photographs an ID, takes a selfie, passes a liveness check, and is matched against records, all in software. A high-volume market is one where this happens at enormous scale, typically in fast-digitizing economies where mobile-first onboarding has leapfrogged branch banking. India is the archetype, where Aadhaar-based eKYC enabled mass account opening and a digital-wallet market worth well over ten billion dollars, growing at double-digit rates. Southeast Asia, Latin America, and Africa show the same pattern across fintech, telecom SIM registration, and crypto, often built on national digital-identity systems.

What unites these markets is that verification is designed for throughput. It runs on mobile apps across a huge range of devices, it is tuned for speed and minimal friction so it can reach first-time and rural users, and it operates at a volume where manual review of every applicant is impossible. Those design choices are entirely rational for the goal of financial inclusion. They also define the attack surface, because each one, examined from a fraudster's point of view, is an opening.

Why Scale Itself Is the Vulnerability

Scale is the paradox

Every strength of high-volume eKYC is also a weakness

Full automation, low friction, cheap-per-check, mobile-first: these are the design choices mass onboarding needs to serve first-time and rural users. They are also, from the fraudster's side, the opening.

↑ Why it works
the scale factor
How it's exploited ↓
Millions of checks at near-zero marginal cost
Full automation
No human backstop to catch a deepfake that clears the model
Keeps onboarding fast and inclusive for first-time users
Speed & low friction
Lighter, faster checks are weaker against convincing synthetic faces
Lowest workable cost per check, needed at mass-market pricing
Cost pressure
The cheapest tools are often not deepfake-aware or injection-aware
Reaches users on any phone, in any market, over any network
Mobile-first,
diverse devices
Rooted, emulated, and virtual-camera injection widens the surface
Serves a mass market at the scale financial inclusion demands
Sheer volume
Thousands of fakes hide among millions of legitimate sign-ups

The important shift in thinking is that high-volume eKYC is not vulnerable because of one weak check; it is vulnerable because of the properties that make it work at all. Full automation is the clearest example. When millions of onboardings run with no human in the loop, a deepfake that clears the algorithm is simply admitted, because there is no reviewer to notice the subtle wrongness a person might catch. Speed and low friction compound it: the lighter and faster the check, the weaker it tends to be against a convincing synthetic face. Cost pressure pushes the same way, because at a mass-market price per check, the cheapest workable verification is often not deepfake-aware or injection-aware at all.

Two more factors are specific to these markets. The device landscape is mobile-first and enormously varied, including older, rooted, and emulated devices, which widens the surface for injection attacks that feed a synthetic stream past the camera. And sheer volume provides cover: a few thousand fraudulent onboardings disappear among millions of legitimate ones, and because false positives at that scale are expensive and exclusionary, detection thresholds are often tuned loose, letting more fakes through. Add limited fraud awareness among frontline staff and first-time users, and the result is an environment where deepfakes can operate quietly and at industrial scale.

Scale Factor Why It Is Necessary How Deepfakes Exploit It
Full automation Millions of checks at near-zero marginal cost No human backstop for a fake that clears the model
Speed and low friction Keeps onboarding fast and inclusive Lighter checks are weaker against deepfakes
Cost pressure Lowest workable cost per check The cheapest tools are often not deepfake-aware
Mobile-first, diverse devices Reaches users on any phone Rooted, emulated, and virtual-camera injection
Sheer volume Serves a mass market Thousands of fakes hide among millions of real sign-ups

Table 1: At scale, the features that make eKYC work become the surface deepfakes exploit.

How Deepfakes Exploit High-Volume eKYC

The techniques are the familiar ones, but scale changes how they are used. A deepfake selfie, a face-swap or AI-generated face, is submitted to pass the selfie-to-ID match, a method covered in our guide to how deepfakes bypass KYC. Injection attacks are especially potent here, because a mobile-first, rooted, and emulated device base makes it easier to run virtual-camera software that pipes a synthetic stream directly into the app, bypassing the camera, the vector detailed in how injection attacks feed deepfakes into verification. AI-forged documents supply valid-looking IDs, and where document security varies by market, they clear more easily. And synthetic identities, assembled from real and fabricated data, are onboarded in bulk, the process in how synthetic identities are generated.

What makes the high-volume context distinct is industrialization. These are not one-off attempts; deepfake toolkits circulate openly, with enforcement cases across Southeast Asia tied to kits sold on Telegram, and fraud is run as a service that mass-produces accounts. The end product is often a fleet of mule accounts and synthetic-identity wallets used to launder money and move illicit funds, and analysts tracking crypto crime have identified deepfake-facilitated onboarding as a key enabler of exchange account takeovers and synthetic wallet creation. The uncomfortable reality, as fraud leaders put it at a 2026 industry summit, is that many institutions already have a large number of synthetic identities enrolled today.

Attack At Scale It Looks Like Outcome
Deepfake selfie A normal face-to-ID match An account for a stolen or synthetic identity
Injection via mobile A routine mobile onboarding A synthetic feed slipped past the camera
AI-forged documents A valid-looking ID upload A fabricated identity cleared
Synthetic identities at scale Ordinary new customers Mass accounts already enrolled
Mass mule accounts Legitimate-looking sign-ups Money-laundering and payout infrastructure

Table 2: The attacks that scale with high-volume eKYC, and what they produce.

The Inclusion-vs-Assurance Tension, and What Is at Stake

Underneath all of this sits a genuine dilemma that high-volume markets feel more acutely than anyone. The entire purpose of mass eKYC is inclusion, bringing unbanked and underserved people into the financial system, and that requires low friction, because every added step excludes some legitimate users who lack documents, connectivity, or digital fluency. But low friction is also what deepfakes exploit. For years the balance tilted toward access; now the cost of that tilt is showing, and regulators are responding by pushing toward assurance without abandoning inclusion.

The regulatory movement is concrete and worth tracking. Vietnam's central bank has made biometric identity checks mandatory for opening any new bank account or payment card as of January 2026. Singapore's monetary authority now expects digital identity verification to include liveness that is demonstrably robust against injection attacks, and Hong Kong's has emphasized multi-factor and behavioural authentication. India's central bank frameworks push financial institutions to red-team high-volume onboarding channels specifically. And the global standard-setter FATF has flagged generative AI as a material risk amplifier, singling out jurisdictions that over-rely on selfie-based or document-centric verification without layered authentication as particularly exposed. The same direction is visible in the EU AI Act's transparency rules and in US regulatory attention, so this is a global convergence, not a regional one. What is at stake if it fails is not only fraud losses and laundering, but the trust that financial inclusion itself depends on.

How to Secure eKYC at Volume

The goal is to close the deepfake gap without reintroducing the friction that excludes legitimate users, which rules out simply making every check heavier. The answer is targeted, risk-based, and built for scale. First, add dedicated deepfake and injection detection, because selfie-and-document verification alone is the vulnerable design FATF warns about; the media itself has to be checked for synthesis, and the feed has to be confirmed as coming from a real camera. Second, that detection has to run at low latency and low cost per check, on the low-end and diverse devices these markets use, or it will not survive contact with millions of onboardings. Third, it should be risk-based, adding step-up friction only where signals warrant, so the vast majority of genuine users pass smoothly and inclusion is protected. Fourth, it should extend beyond onboarding to re-authentication and high-value events, since synthetic identities that got in must still be caught later. And it should be explainable, so the relatively small number flagged among millions can be reviewed efficiently.

This is the profile DuckDuckGoose, based in Delft, builds DeepDetector to fit: automated analysis of images and video for the signatures of synthetic media, designed to run at the speed and scale of a live onboarding pipeline, with explainable output and ISO 27001, SOC 2, and GDPR compliance, and EU data residency that also suits markets with data-localization rules. It adds the deepfake-detection layer that high-volume eKYC most often lacks, without forcing a trade-off against the inclusion these markets exist to deliver.

Requirement Why It Matters at Scale
Deepfake and injection detection Selfie-and-document checks alone are the vulnerable design
Low latency and low cost per check It must run on millions of onboardings without slowing them
Works on low-end and diverse devices The user base is mobile-first and varied
Risk-based step-up Add friction only where signals warrant, to protect inclusion
Coverage beyond onboarding Extend to re-authentication and high-value events
Explainable output So the few flagged among millions can be reviewed

Table 3: What deepfake detection needs to work in high-volume eKYC.

Frequently Asked Questions

How do deepfakes break eKYC in high-volume markets?
By exploiting the features that make mass eKYC work: full automation with no human review, speed and low friction, low cost per check, and mobile-first onboarding on diverse devices. A deepfake selfie or an injected synthetic stream clears the automated check, and at scale thousands of such fakes hide among millions of legitimate sign-ups.

Why is scale itself the vulnerability?
Because high-volume eKYC is designed for throughput, and every design choice that enables throughput also creates an opening. Automation removes the human backstop, low friction weakens the checks, cost pressure favors cheaper and less deepfake-aware tools, and sheer volume lets fraud blend in. It is not one weak check but the properties of scale that create the exposure.

Which markets are most affected?
Fast-digitizing, mobile-first economies with mass onboarding, prominently India, Southeast Asia, Latin America, and Africa, across banking, fintech, telecom SIM registration, and crypto. Asia-Pacific deepfake incidents rose more than 1,500% in a single year, and national eKYC systems and digital wallets are prime targets, though the pattern applies to any high-volume onboarding channel.

What is the tension between inclusion and assurance?
Mass eKYC exists to include underserved people, which requires low friction, because every extra step excludes some legitimate users. But low friction is what deepfakes exploit. Historically the balance favored access; now regulators from Vietnam to Singapore are pushing toward stronger assurance, and the challenge is to add security without losing the inclusion the systems were built for.

Can liveness checks stop deepfakes in eKYC?
Not on their own. A real-time face swap can pass liveness because it is driven by a live person, and injection attacks bypass the camera entirely, which is why regulators like Singapore's now require liveness demonstrably robust against injection. Stopping these attacks needs dedicated deepfake detection and injection detection layered on top of liveness.

How do you add deepfake detection without hurting inclusion?
By making it risk-based and built for scale. Detection should run at low latency and low cost on low-end devices, apply to every onboarding, but only add step-up friction where risk signals warrant, so genuine users pass smoothly. That preserves low friction for the many while catching the few, and it should extend to re-authentication so synthetic identities are caught even after onboarding.

Are synthetic identities already in high-volume systems?
Very likely, yes. Fraud leaders have observed that many institutions already have a significant number of synthetic identities enrolled, because they were onboarded before deepfake-aware detection was in place. This is why detection needs to extend beyond onboarding to ongoing re-authentication and high-value events, not only screen new applicants.

By Adya Tewari
DuckDuckGoose AI

About the author

By Adya Tewari
DuckDuckGoose AI

Discover the Power of Explainable AI (XAI) Deepfake Detection

Schedule a free demo today to experience how our solutions can safeguard your organization from fraud, identity theft, misinformation & more