CiberLATAMbywhalemate

Latin America Leads AI Synthetic ID Fraud

Latin America accounts for 48.3% of AI-driven synthetic identity fraud. Banks and fintechs face weaker remote onboarding controls.

Whalemate Labs · AI-assisted researchJul 13, 202638 min read

Latin America has become the leading region for AI-driven synthetic identity fraud, accounting for 48.3% of recorded cases in a report by Unico with Liminal, the highest share worldwide for this type of scheme. The figure does not stand alone: LexisNexis Risk Solutions estimates that synthetic identity already represents 11% of global fraud and is growing by about eight times a year, while vendor analysis and specialist reporting describe an attack chain that is increasingly mature, industrialized, and difficult to stop with traditional controls.

The consolidated material shows that the threat has moved beyond document fraud. It now combines real, fictitious, and altered data to build profiles capable of passing KYC, liveness checks, and biometric verification at banks, fintechs, digital merchants, and lending platforms. In remote workflows, attackers use everything from low-cost synthetic faces to voice deepfakes, video injection, and abuse of legacy APIs to bypass the first layers of scoring and then move toward higher-risk products. In Latin America, El Economista warns that this exposure has already become an operational risk for companies that open accounts, authorize payments, or verify customers online.

The regional evidence also shows a shift from security debate to regulation. Colombia reformed its Criminal Code in 2025 to penalize identity impersonation carried out with artificial intelligence and to explicitly recognize deepfakes, image, and digital identity. In Brazil, data cited by Exame indicates 830% growth in deepfake use between 2024 and 2025, with AI tools present in 42.5% of financial frauds recorded during that period. Bolivia, Mexico, and Colombia also show a strong layer of public and banking awareness around phishing, voice cloning, fake videos, and messages demanding credentials or sensitive documents.

The technical picture is consistent, synthetic identity exploits the gap between the presented person and the identity actually fabricated. Traditional KYC answers whether the applicant matches the document, but not whether the profile was built from scratch. That asymmetry, together with cheap deepfakes, stolen data, month-long maturation cycles, and AI-driven automation, explains why synthetic fraud is now listed among the critical trends for 2026 and why operational focus has shifted to stronger biometrics, liveness, deepfake detection, real-time analytics, and continuous verification beyond onboarding.

Executive Summary

The strongest finding in the source material is clear, Latin America accounts for 48.3% of AI-driven synthetic identity fraud cases, the highest share recorded globally for this type of fraud, according to Unico's Identity Fraud Intelligence Report with Liminal, as covered by El Economista and El Tiempo MX. The number places the region under extreme exposure to a scheme that no longer depends only on altered documents or stolen credentials, but on identities built from the ground up to pass remote account opening, payment, and customer verification checks.

The second key point is the global scale of the problem. LexisNexis Risk Solutions, cited by the outlets that reproduced the report, estimates that synthetic identity accounts for 11% of fraud cases worldwide and is growing by about eight times a year. That growth reflects more than volume. It also points to faster adaptation, more stolen personal data, stronger capabilities for generating fake faces, voices, and documents, and greater sophistication in the way attackers mature these identities before monetizing them.

The technical literature included in the material confirms that the fraud frontier has shifted to remote onboarding. DuckDuckGoose.ai documents that a convincing synthetic face can be generated for less than $20 in about 30 minutes, enough to get past selfie and liveness checks in document-plus-selfie workflows. The same analysis describes three dominant vectors, AI-generated faces paired with forged documents, presentation attacks using deepfake video, and video injection attacks through virtual cameras. Veriff, for its part, warns that criminals are targeting the API junctions of legacy verification systems and point-in-time checks, which shows the problem is not limited to end users, but also to integration architecture.

The material also shows a shift in the regional response cycle. iDenfy and MarketsandMarkets agree that defenses are moving toward stronger biometrics, liveness detection, real-time analytics, and automated document verification. Unico, a Brazilian company, reported an 84% increase in identity verification transactions in the first quarter of 2026 compared with the same period in 2025, while accelerating its regional expansion with products such as facial biometrics, liveness, and enhanced identification. The demand is not accidental. Deepfake fraud and synthetic profiles are already affecting the daily operations of banks and fintechs that rely on high-trust but low-human-supervision processes.

At the same time, the regulatory side is starting to catch up. Colombia approved a criminal law reform in 2025 that penalizes identity impersonation performed with artificial intelligence and explicitly recognizes concepts such as deepfake, image, and digital identity. In other countries in the region, including Mexico, the material reflects greater public and corporate awareness, but not comparable legal coverage in the consolidated research findings. The region, in short, faces an unfavorable mix, high digital-channel penetration, wider availability of generative AI for fraud, KYC controls that were not designed to prove ontological authenticity, and regulatory pressure that is moving more slowly than attackers' operational capabilities.

Timeline del fraude sintético con IAHitos clave entre 2025 y 2026 sobre fraude de identidad sintética en América Latina y respuestas técnicas y regulatorias.2025ColombiaAI worsensinimpersonation2025U.S. losses$27.3B identityfraud2026-06Brazil deepfakes+830% AI fraud42.5%2026-07DuckDuckGoosecheap faceremote KYC2026-07Latin America48.3% of casesglobal high2026-07Defenseliveness +deepfakeKYChardened
Milestones in AI-driven synthetic fraud — From criminal reform in Colombia to the region's 48.3% surge, with technical and defensive milestones from 2025 to 2026.

Context and Background

Synthetic identity fraud is not the same as directly impersonating an existing person. The pattern described consistently across Revista Selecciones, iDenfy, Jack Fitzpatrick, and other material in the corpus is more complex. Attackers mix real, fake, and modified data to build a new identity that can pass automated review and, in some cases, remain active for months until monetization begins. That identity may contain legitimate fragments from a real person, but it does not belong to a single identifiable victim. That distinction matters, because the harm does not necessarily happen the moment the profile is created, but when the system accepts it as trustworthy.

The Unico and Liminal report, according to coverage by El Economista and El Tiempo MX, places Latin America at 48.3% of AI-based synthetic identity cases, the highest global share observed in the study. The relevance of the number is not only in the percentage. The point is that the region leads a phenomenon that, at the international level, already represents a meaningful slice of total fraud. The LexisNexis Risk Solutions reference, reproduced by both outlets, adds a second layer of context: 11% of fraud cases worldwide already correspond to synthetic identity and annual growth is around eight times. It is a combination of regional concentration and global expansion.

That context overlaps with a high-loss base in the digital economy. FRPA, citing the Identity Fraud Study 2026 by Javelin Strategy & Research, reports that consumers in the United States lost $27.3 billion to traditional identity fraud in 2025, after a 19% jump in 2024. The figure is not from Latin America, but it serves as a benchmark for understanding that the identity crisis on which synthetic identity is built was already carrying very high costs. Synthetic fraud does not emerge in a vacuum, but on top of a mature and growing loss infrastructure.

The material also makes clear that detection and containment can no longer depend on a single control. In a technical post cited in the corpus, Unico notes that traditional KYC was designed to check whether the person requesting the service matches the evidence presented, not to determine whether that identity was fabricated. That line explains the structural problem. If the system verifies congruence between documents, selfie, and data, but not the genealogy of the profile, it leaves a gap open for highly consistent synthetic identities. The controls were built for a logic of matching, not one of origin authenticity.

Operational pressure also appears in reports from iDenfy, Veriff, and Fintech Global. iDenfy says identity fraud, which includes stolen, synthetic, and altered identities, became the main vector for companies with KYC obligations. Veriff warns that attackers use highly elaborate synthetic profiles to pass the first automated scoring layers. Fintech Global adds that more than 10% of banks surveyed reported losses above $1 million from deepfake incidents, with an average loss of $600,000 per incident, while the FBI recorded $893 million in losses linked to AI-related scams in 2025. The overall picture is not that of an emerging threat in an experimental phase, but of a category already profitable for criminals and costly for institutions.

Key Facts Table

Date Fact Source Confidence
2026-07-10 El Economista reports that AI synthetic identity fraud reaches 48.3% of cases in Latin America, the highest global share for this modality. El Economista Confirmed
2026-07-12 El Tiempo MX reproduces the same figure for Latin America and the attribution to the Unico and Liminal report. El Tiempo MX Confirmed
2026-07-10 LexisNexis Risk Solutions, cited by the report, estimates synthetic identity represents 11% of global fraud and grows by about eight times a year. El Economista Confirmed
2026-07-12 El Tiempo MX reproduces the 11% global figure and the approximate eight-times-per-year growth rate. El Tiempo MX Confirmed
2026-06-30 Neurona Magazine includes synthetic identity fraud and real-time payments fraud among 2026 financial fraud trends. Neurona Magazine Confirmed
2026-07-07 DuckDuckGoose.ai documents that a convincing synthetic face can be generated for less than $20 and about 30 minutes of work. DuckDuckGoose.ai Confirmed
2026-07-07 DuckDuckGoose.ai describes presentation attacks and video injection attacks against remote KYC. DuckDuckGoose.ai Confirmed
2026-07-09 Veriff warns that attackers are hitting the API junctions of legacy verification systems with elaborate synthetic profiles. Veriff Confirmed
2026-07-07 India’s Ministry of Home Affairs, via I4C, warns about synthetic identities and deepfakes used to evade video-KYC, facial authentication, and account recovery. Vijay Malhotra on LinkedIn Confirmed
2026-07-06 Fintech Global reports losses above $1 million at more than 10% of surveyed banks in deepfake incidents. Fintech Global Confirmed
2026-06-28 Exame reports that deepfake use in Brazil grew 830% between 2024 and 2025. Exame Confirmed
2026-06-28 Exame reports that AI tools were present in 42.5% of financial frauds recorded in Brazil between 2024 and 2025. Exame Confirmed
2025-07 Colombia approved a reform of Article 296 of the Criminal Code to punish identity impersonation with AI and explicitly recognize deepfake, image, and digital identity. Abogados.com.ar Confirmed
2026-06-18 The legal analysis says Colombia has explicitly linked AI and criminal protection of identity, ahead of other countries in the region. Abogados.com.ar Confirmed
2026-07-11 MarketsandMarkets highlights biometrics with liveness and deepfake detection for KYC in high-risk regions such as Latin America. MarketsandMarkets Confirmed
2026-07-09 iDenfy says identity fraud has become the main vector for companies with KYC obligations. iDenfy Confirmed

Operation Timeline

Date Event Actor/vector Verified source
2025-07 Colombia reforms Article 296 of the Criminal Code and increases penalties for identity impersonation when AI is involved. Regulatory framework, deepfakes, and digital identity Abogados.com.ar
2025 Javelin, cited by FRPA, records $27.3 billion in losses from traditional identity fraud in the U.S. Large-scale identity fraud losses FRPA Fraud Viewer
2026-06-18 The legal analysis positions Colombia as a regional reference in regulating deepfakes and identity impersonation. Criminal law comparison Abogados.com.ar
2026-06-22 Unico, on LinkedIn, points to the gap in traditional KYC against fabricated identities. Verification gap, KYC Unico on LinkedIn
2026-06-22 El Deber reports on Instagram scams with deepfakes and cloned voices in calls to banks. Voice cloning, phishing El Deber
2026-06-23 fintechexpert.mx reports that Unico grew 84% in identity verification transactions in Q1 2026. Identity verification, onboarding fintechexpert.mx
2026-06-24 Jack Fitzpatrick describes the typical synthetic identity lifecycle, from stolen data to high-value credit. Fraud maturation chain LinkedIn
2026-06-28 Exame reports 830% growth in deepfakes in Brazil and 42.5% of financial frauds involving AI. Deepfakes, financial fraud Exame
2026-06-30 Neurona Magazine adds synthetic fraud as a 2026 trend. Risk trend Neurona Magazine
2026-07-06 Fintech Global reports losses from deepfakes and the FBI's $893 million in AI-related scam losses. Economic impact, losses Fintech Global
2026-07-07 DuckDuckGoose.ai details three vectors against remote KYC and the low cost of a synthetic face. Technical attack on onboarding DuckDuckGoose.ai
2026-07-07 India warns about fake video-KYC and Jamtara 2.0-style patterns. Facial authentication, video-KYC Vijay Malhotra on LinkedIn
2026-07-09 Veriff warns about abuse of legacy APIs and initial scoring by synthetic profiles. API integrations, scoring Veriff
2026-07-09 iDenfy places identity fraud as the main vector for KYC companies. Document verification, biometrics iDenfy
2026-07-10 El Economista publishes that Latin America concentrates 48.3% of global AI synthetic identity fraud cases. Regional exposure El Economista
2026-07-10 La FM Nativa repeats the regional 48.3% figure. Media replication La FM Nativa
2026-07-11 MarketsandMarkets stresses biometrics with liveness and deepfake detection as the direct response. KYC defense MarketsandMarkets
2026-07-12 El Tiempo MX confirms the regional figure and the global 11% share and eight-times-per-year growth. Media consolidation El Tiempo MX
Flujo de ataque de identidad sintéticaFlujo técnico desde obtención de datos hasta monetización y evasión de controles.1. InputsBreaches, OSINTreal datafake data2. SynthesisFace, voicedocumentsfake profile3. BypassSelfie, livenessdeepfake videolegacy API4. Maturationlow accounthistoryalgorithmic trust5. MonetizationCredit, paymentstransfershigh-value fraud
Synthetic identity attack chain — Inputs, synthesis, verification bypass, aging, and monetization.

Attack Chain and TTPs

The chain described in the consolidated material follows a recognizable, though not linear, pattern. First comes the collection of inputs. Fitzpatrick points to identity fragments taken from data breaches and illicit markets. The same analysis adds that attackers can combine that information with AI generation of faces, documents, and fake work histories. Vijay Malhotra, citing the I4C alert in India, adds another source of training, social engineering, fake job interviews, video calls, and online public content reused to clone faces and voices. In other words, the input no longer depends only on a large-scale leak. It is also fed by everyday exposure and publicly available material.

The second step is building the synthetic identity. Revista Selecciones explains it in simple terms, criminals do not impersonate a specific person, but manufacture a new identity from legitimate fragments and false data. The Instagram reel on financial fraud reinforces the idea, the fraudster does not steal an existing identity, but creates a new combination to deceive verification systems. At this stage, the profile has to look coherent. That coherence is what allows it to pass initial filters and sustain the deception during maturation periods.

The third step is bypassing remote controls. DuckDuckGoose.ai identifies three technical routes, using AI-generated faces on forged documents, presentation attacks with deepfake video shown to the camera, and video injection attacks through virtual cameras. Veriff completes the picture by warning that attackers deliberately target the API junctions of legacy verification systems. The operational conclusion is straightforward, systems designed as discrete checkpoints can be bypassed if the attacker controls the visual input, the video stream, or the integration between services.

The fourth step is building history. Fitzpatrick explains that attackers often open low-risk accounts to create a behavioral footprint before applying for credit or higher-value products. That movement resembles identity grooming. Synthetic identity does not aim to exploit everything immediately. It appears as just another customer, builds reputation, earns algorithmic trust, and only then enters the monetizable phase. That behavior explains why losses can appear long after the initial onboarding event.

The fifth step is monetization. The material mentions high-value loans, financial products, online purchases, instant transfers, loans to third parties, fraudulent investment schemes, and payment fraud. In Brazil, Exame documents calls to family members using cloned voices to trigger urgent transfers and investment campaigns with deepfake celebrities tied to Pix. In Colombia, Blu Radio and El Tiempo describe fake audio or video used to request money in the name of relatives or employees. In Bolivia, several official alerts focus on messages requesting credentials, while educational content warns about extortion using AI-generated video. The vector changes, but the monetization pattern remains the same, extracting money or enabling fraudulent access to financial products.

Matriz de TTPs del fraude sintéticoTabla visual de técnicas, descripción y referencias del material consolidado.TTPDescriptionSourceStolen dataBreaches, illicit markets, OSINTFitzpatrick, Vijay MalhotraFacial deepfakeSynthetic faces over documents or selfiesDuckDuckGoose.ai, ExameVideo injectionVirtual camera or synthetic stream in the appDuckDuckGoose.aiAPI abuseAttack on legacy integrations and scoringVeriffMaturityLow account age, history, high monetizationFitzpatrick
Synthetic fraud TTPs — Recurring techniques observed in remote KYC and customer service channels.
TTP Description Source
Collection of identity fragments Use of stolen data from breaches, illicit markets, social engineering, and public content to assemble inputs. Jack Fitzpatrick, Vijay Malhotra, DuckDuckGoose.ai
Face and voice synthesis Generation of facial deepfakes and voice cloning for remote verification and calls. Exame, DuckDuckGoose.ai, El Deber, Blu Radio
Document fabrication Creation or alteration of documents and photos to support the fake profile. DuckDuckGoose.ai, iDenfy, Revista Selecciones
Liveness bypass Use of deepfake video, spoofing, or virtual cameras to defeat liveness checks. DuckDuckGoose.ai, Veriff, Vijay Malhotra
Abuse of verification APIs Attacks on legacy integrations and automated checkpoints. Veriff
Identity maturation Opening low-risk accounts to build history before higher-value fraud. Jack Fitzpatrick
Financial monetization Credit, transfers, payment fraud, purchases, and investment schemes. Exame, El Tiempo, Blu Radio, Fintech Global

The full sequence shows a mix of automation and patience. This is not always a "fast" fraud. In several examples, the attacker accumulates signals, tests the response of the victim or the system, builds profiles, and only then launches the monetizable event. That is why defenses that only look at the moment of account creation are insufficient. The problem extends to the continuity of identity, not just a single point of entry.

Regional Impact

Regional Overview

The cross-cutting reading of the corpus is that the region is no longer debating whether AI-driven synthetic fraud exists, but how quickly it is industrializing. The 48.3% attributed to Latin America by Unico and Liminal is disproportionate relative to the rest of the world and places the region as an exposure laboratory. That position has an operational counterpart. Remote onboarding environments, the expansion of fintechs, payment digitization, and the mass adoption of app- or messaging-based service channels create surfaces that attackers exploit with fabricated identities and human signals mimicked by AI.

The evidence also suggests that fraud is shifting from the documentary plane to the representation plane. It is no longer enough to fake a document. Attackers clone voices, generate faces, fabricate work histories, simulate family emergencies, produce extortion videos, or manipulate passport-style photos. This directly affects banks, fintechs, digital merchants, and lending platforms, because traditional control tends to validate separate pieces of evidence, not the full genealogy of the presented subject. The result is an operational risk, but also a compliance risk, a reputational risk, and losses from first-party fraud or third-party induced fraud.

Mapa regional de impacto del fraude sintéticoMapa visual de casos y señales por país con base en el material consolidado.Signals by country0mediumhighvery highBoliviaAlerts andanti-fraud educationBrazil+830% deepfakes42.5% AI fraudColombiaCriminal lawon deepfakesMexicoSophisticationand debateU.S.Losseshigh base
Regional impact map — Brazil leads the growth; Colombia is moving ahead on regulation; Bolivia and Mexico show operational pressure.

Bolivia

Bolivia shows a highly visible layer of public awareness and alerts. El Deber shared an Instagram video linking artificial intelligence, deepfakes, and phishing to bank calls using cloned voices. Bolivisión, in turn, published a segment with specialists explaining how to prevent extortion through AI-generated videos and warning about the risks of identity theft. Bolivia's Central Bank warned about emails and social media posts designed to manipulate victims psychologically by making them believe their accounts are at risk.

At the institutional level, the Ministry of Economy and Public Finance denied a supposed advertisement for "ASFI Renta" and direct transfers to banks, while ASFI warned about fake investment offers with fabricated profit screenshots, websites without legal information, and payments only in cryptocurrencies or unregulated wallets. Banco Nacional de Bolivia reinforced on Facebook and Instagram that messages asking for usernames, passwords, or personal data are digital scams, and Banco Bisa asked users to pause and verify before answering calls or sharing credentials. Banco Unión highlighted the growth of digital payments as part of Bolivia's economy, which adds context, the more digitized the environment becomes, the greater the exposure to remote fraud if controls do not grow at the same pace.

The Bolivian case does not, by itself, prove a measurable wave of synthetic identity on the scale of Brazil or Colombia, but it does show an environment where phishing, smishing, fake investments, digital extortion, voice cloning, and profile impersonation are already part of the public and regulatory conversation. The presence of a reported alleged scam involving BancoSol loans, cited by ADICH Radio and marked as an uncertain source, fits that broader picture, although it does not support additional technical attribution.

Colombia

Colombia is the country with the most advanced regulatory movement in the available material. According to the legal analysis by Abogados.com.ar, in July 2025 Article 296 of the Criminal Code was reformed to penalize identity impersonation when carried out with artificial intelligence, and concepts such as deepfake, image, and digital identity were explicitly recognized. The same analysis says that, compared with Brazil, Argentina, Mexico, and Chile, Colombia has already linked AI directly to criminal protection of identity.

On the operational side, Blu Radio reported cases in which AI is used to impersonate relatives or acquaintances with fake audio or video to request money. El Tiempo described frauds in which criminals duplicate the voices of known people or employees and present them as part of the most common digital scams. The combination of criminal law, public circulation of cases, and citizen training suggests that the problem is already visible enough to have entered the legal and media agenda, although the corpus does not provide local prevalence statistics.

Brazil

Brazil is the clearest case of quantitative acceleration. Exame, citing Federal Police data, reported that deepfake use grew 830% between 2024 and 2025. The same report said AI tools were present in 42.5% of financial frauds recorded during that period. The story is not limited to volume. Exame described two concrete patterns, voice cloning from just a few seconds of audio pulled from social media or WhatsApp to simulate emergencies and obtain immediate transfers, and the use of face and voice deepfakes of celebrities in social media ads to promote fraudulent investments, products, or raffles, often tied to Pix.

The Unico information reinforces the defensive angle. The Brazil-based company increased its identity verification transaction volume by 84% in the first quarter of 2026 compared with the same period a year earlier. Its expansion outside Brazil is happening just as identity verification becomes a critical layer for banks, fintechs, and merchants exposed to AI-driven fraud. Its platform combines facial biometrics, liveness, and identity authentication, with offerings such as Unico IDCloud One and Unico IDPay. The company data confirms that the defense market is growing alongside the threat.

Mexico

Mexico appears less often in quantitative terms, but it does show operational and educational pressure. Asociación La Nacional warned that criminals are already building full identities by mixing real information with artificial data and urged the Congress of the Union to focus on the impact of synthetic identity fraud. An educational social media post said fraud in the country not only grew, but became more sophisticated, incorporating synthetic identities, deepfakes, and altered documents. That angle matches the regional trend away from simple scams and toward AI-supported schemes aimed at credit and payments.

On the corporate side, fintechexpert.mx said identity verification is becoming a critical layer for banks, fintechs, digital merchants, and platforms exposed to AI-generated fraud. In addition, the note on Unico suggests that part of regional demand is shifting toward biometrics, liveness, and enhanced identity validation tools. Mexico, according to the material, does not lead the regulatory narrative, but it is clearly a market where the discussion has moved beyond theory.

United States

The corpus provides only an economic and scale reference point. FRPA, citing Javelin Strategy & Research, reports that U.S. consumers lost $27.3 billion to traditional identity fraud in 2025. Although the figure is not specific to synthetic identity or Latin America, it helps frame the size of the identity fraud economy in which this modality operates. In the same source ecosystem, Fintech Global adds that the FBI reported $893 million in losses tied to AI-related scams during 2025, a figure the bureau itself considers conservative.

Brazil, Colombia, and Mexico, the most visible triad

Taken together, the material shows Brazil providing the evidence of growth and volume, Colombia the most advanced legal response, and Mexico the signal of problem sophistication and pressure on the financial ecosystem. Bolivia, by contrast, shows a very active public and banking alert layer. The result is a regional map where AI-driven synthetic identity is no longer a homogeneous or marginal threat. In some markets volume dominates, in others regulation, and in others antifraud education. But the underlying pattern is the same, the replacement of verifiable identity with fabricated identity.

The countries with no additional verified facts in the material are Argentina, Chile, Paraguay, and Peru.

Technical Indicators

No classic IOCs such as hashes, domains, IPs, or specific accounts were published in the consolidated material. There are, however, operational technical indicators that are useful for detection and prioritization, even if they do not amount to traditional threat intelligence.

Type Value Source
Estimated generation cost Less than $20 for a convincing synthetic face DuckDuckGoose.ai
Estimated generation time About 30 minutes to produce a convincing synthetic face DuckDuckGoose.ai
Regional growth 48.3% of AI synthetic identity fraud cases in Latin America El Economista, El Tiempo MX
Global growth rate for the modality About eight times a year LexisNexis Risk Solutions, cited by El Economista and El Tiempo MX
Global weight of the modality 11% of fraud cases worldwide LexisNexis Risk Solutions, cited by El Economista and El Tiempo MX
Deepfake growth in Brazil 830% between 2024 and 2025 Exame
AI presence in financial fraud in Brazil 42.5% Exame
Average loss per deepfake incident in banks $600,000 per incident Fintech Global
Banks with losses above $1 million More than 10% of those surveyed Fintech Global
Average loss in fake video-KYC in India 34,500 rupees per case Vijay Malhotra on LinkedIn

Analysis for Security Teams

The first operational implication is that identity control can no longer be treated as a one-time event. The material shows a shift from initial validation toward continuous and contextual verification. A system that only checks whether the document and the face match risks accepting a fabricated identity that is internally consistent. That is why the defenses most often cited in the corpus are not limited to OCR or facial matching, but include stronger biometrics, active and passive liveness detection, real-time analytics, and cross-checking against broader sources.

The second implication is that teams need to treat onboarding as a multi-channel attack surface. DuckDuckGoose.ai describes the use of AI-generated faces, deepfake video, and virtual cameras. Veriff adds abuse of legacy APIs. That means reviewing not only the front-end layer, but also the integration between the verification provider, risk engine, video orchestration, and manual fallback processes. An attacker does not need to break the entire system, only to find the least resistant point between layers.

The third implication is that identity maturation matters as much as creation. Fitzpatrick describes a sequence that begins with stolen data and ends with low-risk accounts and high-value products. If an organization only monitors account opening, it can miss the window where the profile looks legitimate but has not yet monetized. Risk models need to account for behavioral signals, changes in transaction patterns, repeated devices, abnormal maturation times, and consistency between declared attributes and actual activity.

The fourth implication is managing the support and recovery channel. The Indian Ministry of Home Affairs alert, via I4C, shows that attackers do not only target onboarding, they also use synthetic identities and deepfakes to evade account recovery, facial authentication, and video-KYC. That means review of credential reset procedures, phone number change validation, access restoration, and call center handling. Cloned voices and fake videos are convincing enough to affect human operators if procedures do not include additional brakes.

The fifth implication is internal training. The regional material from Bolivia, Colombia, and Brazil suggests that many frauds now take the form of calls, messages, or videos that appear familiar. Antifraud, risk, and customer service teams should share signals, escalation scripts, and rejection criteria. A call with a cloned voice, a video of a supposed relative, a passport photo requested over chat, or a new account trying to move too quickly toward high-value products should not be treated as isolated incidents.

In terms of prioritization, the material suggests focusing on three areas. First, harden remote onboarding with robust liveness detection and non-reusable verification mechanisms. Second, strengthen post-onboarding monitoring, because synthetic identity often matures before it monetizes. Third, audit API integrations and fallback flows, since Veriff warns that attackers are exploiting precisely those legacy and point-in-time junctions. Added to that is the need to correlate voice fraud, phishing, extortion, and document impersonation events as part of the same ecosystem, not as separate incidents.

Material Limitations

The corpus is strong on trend, technique, and sector examples, but it has clear limits. It does not include classic verifiable IOCs, nor campaigns with domains, hashes, IP addresses, malware names, or attributable infrastructure. It also does not provide a country-by-country statistical breakdown for Latin America that would allow a rigorous comparison of synthetic identity incidence across markets, beyond the cases of Brazil, Colombia, Bolivia, and indirect references to Mexico.

Several sources appear as attributed by the material itself rather than verified first-hand, including Sputnik Mundo on X, FRPA's summary of Mitek and Datos Insights, AdaptiveSecurity in a trend analysis, Unico on LinkedIn regarding the limits of traditional KYC, some Instagram content, and context references on LinkedIn. These pieces are useful for technical and narrative reading, but should be treated with the appropriate caution.

There are also no longitudinal series for Latin America that would allow quarterly or annual evolution to be measured with the same precision that Exame documents for Brazil. The consolidated research does allow one to say that the problem has already reached critical regional scale, that 48.3% is the highest global value reported in the cited report, and that remote identity controls face a structural gap against fabricated identities. What it does not yet allow is a uniform curve of spread by country, sector, or financial product type.

Finally, the material does not provide forensic evidence of a specific campaign against a named entity in Latin America. For that reason, this research should be read as a technical analysis of trend, TTPs, and operational exposure, not as attribution of a single operation.

Sources

View all