Fintech built its front door around a face

Cyberette founder Julia Jakimenko on the deepfake fraudster who opened 46 ABN AMRO accounts, five ways to beat a face check, and why the EU AI Act stops none.

A modern operations center with bright natural light from windows features a large curved video wall displaying global maps, data, and code across multiple screens, alongside several ergonomic chairs and sleek curved desks.

A man in the Netherlands has been convicted of opening 46 accounts at ABN AMRO using passports harvested from a fake Amsterdam flat listing and deepfake software that blended his own features with each stolen photograph. No detection system flagged him. The contributed piece below starts from that case and argues that the face-based onboarding checks the financial industry has built its front door around are now its weakest point rather than its strongest.

The author, who previously worked in enterprise security at a large Dutch bank and now runs a media forensics company, walks through five distinct attack methods, explains why the EU AI Act's new transparency rules will not touch any of them, and sets out four things a firm can require of its verification vendor today without waiting for a regulator to require them first.

Julia Jakimenko is the founder and chief executive of Cyberette, an Amsterdam media forensics company backed by Rabobank and a member of NVIDIA Inception. She is trained in both law and computer science and previously worked in enterprise security, risk and compliance at one of the Netherlands' largest banks. The article that follows is a contributed piece and presents her opinion.

If you were flat-hunting in Amsterdam last year, you might have recognised the listing. The apartment had a decent square footage and a view of Amsterdam's famous canal. It was also priced well: not too good to be true, but just optimistic enough to be believable.

Applicants were asked to share the same types of ID they typically do when it comes to renting property. A passport, a payslip. Proof you were good for the rent. The only thing is, the flat did not exist. The documents sent by prospective tenants, however, were entirely real.

The man collecting those documents has now been convicted after using deepfake software to blend his own features with the faces on those passport photos. He then used these to successfully open 46 bank accounts at ABN AMRO.

What I find most interesting about this case is not that he got through the bank's checks. It is how he was eventually caught. No detection system flagged him. In fact, it was not even technology that got to the bottom of this scam. It was a human. One application paired a woman's ID with a man's selfie and someone noticed the mismatch.

In the UK, fraud losses hit £1.28 billion last year, with authorised push payment losses up 19 per cent and investment fraud up 40 per cent in a single year. Yet 60 per cent of financial institutions still have no dedicated response plan or forensic tools for investigating AI-driven fraud.

In other words, the fraud is getting better at getting in. The banks are still relying on workflows designed for a different kind of criminal. So what happens when the face at the front door is not really the person behind it?

The methods have moved on. The checks mostly have not.

There is a tendency to talk about deepfake fraud as one thing. But there are a number of different ways to fake an identity using AI, each targeted at a different part of the verification process. If you do not know which attack you are dealing with, you cannot know whether your vendor can actually stop it.

Document morphing

The attacker starts with a genuine identity document, usually stolen, and blends their own facial features with the photo on it. The result is a face that looks enough like the person on the document to pass a match, but enough like the attacker to pass a selfie check. That is what happened at ABN AMRO.

The trick works because most onboarding systems are answering a narrower question than we think. They are not really asking: who is this person? But: does this face look enough like that photo? A morph is designed to sit right in the middle.

Virtual camera injection

Here, the attacker does not need to fool the camera at all. They replace it. A virtual camera driver intercepts the video feed and sends a synthetic stream instead. The fake applicant can blink, turn their head and follow every instruction on screen. To the verification system, it looks like a normal live video. Except it is not.

API-level injection

This is the more advanced version, and the one I would worry about most. Instead of faking what the camera sees, the attacker intercepts the data travelling between the customer's app and the verification service. They then replace the genuine image with a forged one after the point of capture.

There is no camera to monitor. The camera can be working perfectly. That means the question for your provider should be whether it can prove that the image it received is the same image the customer actually captured. If your provider cannot explain how it protects that chain, I would assume there is a gap.

Voice cloning

Three years ago a Vice reporter broke into his own bank account using a free online voice tool. It took him several attempts and a fair amount of source audio. Today it takes seconds of speech and no technical skill whatsoever. Researchers have defeated voice authentication with up to 99 per cent success in six attempts.

Voice was sold to this industry as a convenience feature that happened to be secure. It was only ever the first of those things.

Live video impersonation

Real-time face and voice synthesis now runs well enough to hold a video call. Deployed against video KYC it produces a co-operative applicant who does not exist. Deployed against your finance team it produces an executive who does, asking for a payment that is urgent, plausible and irreversible.

Notably, the near-misses I am aware of were not caught by software. They were caught by someone who asked an unscripted question and did not like the answer.

What the new EU rules do, and whether they reach you

Article 50 of the EU AI Act came into force at the beginning of August. It requires providers to mark synthetic content in machine-readable form and requires deployers to disclose deepfakes, with penalties of up to €15 million or 3 per cent of worldwide turnover.

Two things UK firms are getting wrong about it. The first is assuming it does not apply to them. The Act reaches providers and deployers established outside the EU where they place systems on the EU market or where the output of the system is used in the EU. You do not need an EU entity to be in scope. A UK fintech serving EU customers, or generating synthetic content that lands in front of them, is caught. Content produced by generative systems already on the market has until 2 December to comply with the marking requirements.

The second mistake is more consequential, and it is assuming that compliance with Article 50 does anything for your fraud exposure. Article 50 governs deepfakes that are meant to be seen. Synthetic influencers, for instance, or AI-generated advertising. Against that category I think it will do a great deal of good, because the organisations producing that content have legal teams, compliance functions and a great deal to lose if they do not follow these new laws.

Fraud runs on precisely the opposite logic, though. It wants to be unremarkable. Nobody morphing a stolen passport photo is going to attach a machine-readable tag announcing it. Expecting a labelling regime to address covert misuse is a category error, and I would rather the industry recognised that now than discovered it during an incident.

What to do while the rules catch up

I should be clear about my own position here. I have built a career on detecting synthetic media, and can tell you plainly that detection alone is a race you cannot win by design. Deepfake technology is developing far too quickly. What holds up is being able to establish how, why and where a piece of content was altered. That is what survives a dispute or an investigation. A real-or-fake score does not.

There are four things within your control now.

First, ask your verification vendor a harder question. Ask how they detect virtual camera injection, and what their performance looks like under adversarial testing rather than controlled demonstration. Put the answers in the contract. Most of what a regulator would eventually require, you can require yourself today.

Second, treat certification as procurement criteria. The trust framework only means something if buyers use it.

Third, assume onboarding is a monitoring problem, not a gate. The ABN AMRO accounts were only caught by a pattern across applications. If you are treating verification as a one-time checkpoint, you are relying on the single control most likely to have been defeated.

Fourth, build the forensic capability now. If 60 per cent of institutions cannot investigate this properly, the question is not whether you will be targeted but whether you will be able to explain what happened when you are.

Europe has made a real start on the deepfakes that want to be noticed. The ones that do not are still out there, working in the space these rules leave behind. In fintech, that space is your front door.