AI-Generated Face
A 90-second hack. A $300 toolkit. A virtual camera feed. And a bank's facial recognition system is defeated.
This is not a movie plot. This is happening right now, and it is happening at scale.
There is an active underground market on Telegram that is openly selling AI-powered tools that can help avoid banks’ face recognition, KYC, and identification checks.
These tools are affordable, accessible, and unbelievably efficient. Some kits sell for as little as $300 and can defeat a bank's identity verification in under five minutes.
Let me show you how this works, why it is so dangerous, and what it means for the future of digital identity.
The 90-Second Hack
In a video shared with MIT Technology Review, a scammer in a Cambodian money-laundering center opened a popular banking app on his phone. The app asked him to upload a photo. He clicked a picture of a stranger.
Next, the app requested a video "liveness" check. The scammer held up a static image of a person bearing no resemblance to the account owner. After a 90-second wait as the app told him to readjust the face inside the frame he was in.
The attack worked because of virtual camera software one of a growing range of illicit hacking services readily available for purchase on Telegram. The software replaced the live phone camera feed with a pre-recorded video or photo, fooling the bank's liveness detection system.
The Underground Marketplace
Criminals are operating largely in the open on Telegram. TD Bank cybersecurity expert Eric Huber showcased such exploit techniques in his live demo at the 2026 RSAC Conference. He showed how criminals sell fake documents, stolen identities, AI generators, and training courses on how to circumvent banking customer verification.
Some channels had thousands of subscribers and posted bullet points listing their services. "All kinds of KYC verification services" was a common offering. The channels also posted videos purporting to show successful hacks, proving to potential buyers that their kits actually work.
"We can't ignore the AI threat," Huber said. "It's not hype. It's real."
How the Attacks Work
Security researchers have documented multiple techniques used to bypass biometric verification.
Injection of Virtual Camera:
Rather than relying on real-time footage from the camera phone for the liveness test, attackers employ a virtual camera that substitutes the video stream with pre-recorded videos or images.
The native virtual camera acts on the mobile phone, helping the attacker inject the pre-recorded or artificial video content into applications which are making use of the camera on the mobile phone. iProov reveals an increase of 2,665% in the use of this attack method between 2023 and 2024.
Generation of Deepfakes:
The attackers generate the deepfake video in real time by utilizing the generative AI tools. They gather the user’s identity information along with high-resolution facial photos of the individual and generate the deepfake video using software.
While performing the identity verification process, the deepfake video is streamed using the virtual camera.
ProKYC kits:
Another popular piece of software, referred to as ProKYC, is designed explicitly to undermine the process of remote identification and liveness testing used by banks and cryptocurrency exchange platforms.
This particular software bypasses the process through three steps:
- Creating a fake document through use of personal data and face generated by an artificial intelligence
- Creating a deepfake video in which the AI-generated face is mapped on expected motions
- Using a virtual camera to feed this manipulated video directly into the institution's live verification portal
During his presentation, Huber showed a video of the software defeating an exchange's liveness check in just five minutes.
The Fraud-as-a-Service Economy
The criminal underground has evolved into an educational hub where bad actors sell online classes on how to bypass security measures. Comprehensive tutorials on how to create fake IDs that pass through KYC verification process, falsify bank statements and utilities bills, and how to produce scannable bar codes are provided by the sellers.
All these tools can be purchased for a couple of hundred dollars, even via a Telegram account:
- Social security number: $20
- Full background report: $100
- KYC bypass package: $300
- Synthetic passport/ID: $15
- Deepfake imagery services: $10-$50
It is also possible for fraudsters to fabricate physical documents using the same materials and process used by governmental institutions themselves. Fraudsters employ a substrate known as Teslin which is used to print authentic passports and IDs.
The Synthetic Borrower Problem
The threat extends beyond account opening. Fraudsters are now building entire synthetic borrowers algorithmically optimized consumers designed to survive onboarding checks, satisfy underwriting models, and disappear once loans are funded.
Synthetic identity fraud is projected to exceed $3.1 billion in U.S. unsecured credit losses in 2026, growing at roughly 16% annually. Four in ten financial institutions surveyed said they are already observing increased attack rates linked to AI.
What makes this harder to address than traditional fraud is the time dimension. Synthetic identities are "cultivated over time to build credit histories before being used," then deployed across multiple products and channels simultaneously.
By the time a synthetic identity executes fraud, it may have a year or more of clean transaction history behind it.
Why Banks Are Vulnerable
Traditional biometric verification systems relying solely on facial recognition and basic liveness checks are increasingly vulnerable to AI-driven spoofing. An injection attack poses a higher level of danger since such attacks overcome the physical security of a device, and thus normal anti-spoofing methods prove to be useless.
The difference between a presentation attack and injection attack is very important:
- Presentation attack: The attacker shows a picture, video display, or silicone mask to the camera. The normal method of PAD can detect such attacks.
- Injection attack: The attacker sends a recorded or live synthesized video into the verification process through a virtual camera or some modifications of the app. The physical camera is never used.
Liveness detection that only evaluates a presented image cannot see an injected stream. The feed looks like a live human because a generative model rendered it that way. This is why deepfake KYC bypass succeeds against tools marketed as "liveness-enabled."
How Banks Are Fighting Back
Financial institutions are now resorting to multilayered security measures. The measures that could be used to counter injection attacks include application hardening and RASP which detect root/jailbreak, emulation environment, and camera API injection.
Some advanced liveness detection techniques include challenge response prompts, biometric detection, device fingerprinting, and injection attack detection.
The combination of identity verification with document verification, device intelligence, geolocation and transaction risk scoring provides for a multilayered defense.
Fraud detection systems that flag abnormal onboarding patterns, repeated device fingerprints, synthetic identity indicators, or automation artifacts are also being deployed.
Huber laid out a specific road map for financial institutions:
- Within one week: Designate an AI point person
- Within three months: Map the attack surface
- Within six months: Update risk frameworks and execute operational changes
"With the right people, processes, and tools, we can protect our organizations and our customers."
The Scale of the Problem
The threat is not isolated. As reported by the FBI in the 2025 Internet Crime Report:
- More than $17.7 billion lost due to fraud facilitated through cyber means and targeting US victims in 2025
- 22,364 AI-enabled cyber crime complaints with losses exceeding $893 million
- Over 1 million complaints received, an average of almost 3,000 complaints a day
The FBI noted that "AI-enabled synthetic content is becoming increasingly difficult to detect and easier to make, which allows criminal actors to potentially conduct successful fraud schemes against individuals, businesses and financial institutions."
The Bottom Line
The threat is real. The tools are cheap. And the attackers are already inside your bank's verification flow.
You cannot rely on facial recognition alone. You cannot assume that because a face looks real, it is real. And you cannot wait to act.
The AI arms race in identity verification has begun. The attackers are moving fast. Your defenses must move faster.
FAQ Section
How do AI-generated faces pass KYC checks?
Attackers use virtual camera software to replace a phone's live camera feed with pre-recorded videos or AI-generated deepfakes. Face Liveness Technology recognizes the "live" face and allows for authentication to be carried out.
What is a Virtual Camera Attack?
Virtual camera attack replaces the live stream from the user’s device with the recorded video/picture. The application takes it for a real-life stream of a person when in fact it receives synthesized or recorded content.
How expensive are these KYC bypass kits?
Some complete bypass kits sell for as little as $300 on Telegram. Individual components like fake IDs or stolen biometric data can cost as little as $15-$20.
Are Banks Able to Detect AI-Generated Faces?
Although some banks use multi-layered solutions such as challenges-and-response questions, behavioral biometrics, device fingerprinting, and injection attack detection, others continue using facial recognition that can be bypassed effortlessly.
How Often Do Attacks Occur?
The native virtual camera attacks rose by 2,665% in 2024. In 2025, the FBI received more than 22,000 cases involving AI-enabled cyber crimes for which victims lost over $893 million.