Hello Fraud Fighters!
This week the whole "biometric liveness check" premise took a beating. In Spain, a fraudster's real face flickered through his own deepfake for less than a second — enough for police to catch him mid-heist. Interpol says AI touched over half of Africa's reported cybercrime last year. Elsewhere: registration forms are the new frontline (and fraudsters are winning), Wall Street's hedge funds are getting worked over the phone, and Walmart's own fraud-prevention tech has landed it in a lawsuit that could cost $5,000 a voiceprint.
Let's get into it.
Nick
Big Story: When the Mask Slips
Somewhere in the Murcia region of Spain, a man was running a live video identification session, presenting himself as someone else, when the video feed lagged for a fraction of a second. In that gap, his real face showed through the deepfake he was “wearing”. Spanish police say he'd allegedly posed as 30 different people across 38 attempts to obtain fraudulent digital certificates, using a real-time face-swap feed combined with a lighting rig built to mimic the security features on legitimate ID documents.
The Register's reporting on the case highlights the problem; liveness detection built around blinks and head-turns was designed to catch printed photos, not a hijacked camera feed being rewritten in real time.
Interpol's new African Cyberthreat Assessment Report 2026 further catalogs this growth in AI fraud: AI was a component in 55% of reported cybercrime across Africa in 2025, and deepfake incidents spiked sevenfold between Q2 and Q4 of 2024 alone, continuing to climb since. Interpol frames last year as the moment identity theft shifted from credential theft toward synthetic identities and AI built specifically to beat biometric checks — and notes that countries like Tanzania and Rwanda, which introduced biometric SIM registration precisely to fight this, are struggling to keep the technology ahead of the attackers.
The uncomfortable truth comes from KnowBe4's internal testing of humans versus bots at social engineering: humans won in 2023, barely held on in 2024, and lost outright last year. Chief Deception Strategist Perry Carpenter told Black Hat attendees this month that hyper-personalized, near-zero-human-involvement attacks at scale are one to two years out, not five.
So what: if your identity stack's strongest defense is still "does this look like a live human," you're one lag spike away from finding out it isn't.
Quick Hit #1: The Account That Should Never Have Existed
Every fraud scheme starts with a signup, and that signup is getting harder to catch, according to a handful of recent reports.
Akamai's 2026 State of the Internet research found AI-powered bot traffic up 300% in a single year, much of it purpose-built to pass as human at signup. Sumsub's Identity Fraud Report 2025-2026 puts the overall fraud rate across verified accounts at 2.2%, rising to 6.3% on dating and media platforms, and finds multi-step identity fraud — chaining several tactics together instead of relying on one — jumped from 10% of attacks in 2024 to 28% in 2025. And the FBI's Internet Crime Complaint Center 2026 annual report counted roughly 453,000 cyber-enabled fraud complaints, with reported losses exceeding $17.7 billion.

The supply chain behind a fake account is now genuinely industrial: synthetic identities blending stolen and fabricated data, disposable VoIP numbers, device farms spinning up thousands of "unique" sessions, residential proxy networks, generative AI selfies matched to forged documents, and CAPTCHA-solving services staffed by low-wage workers. None of these tactics is invisible on its own — device fingerprinting, network reputation, behavioral signals like typing cadence, and velocity analysis across shared devices or payment instruments each catch a piece of it — but teams still relying on any single check at the registration gate are bringing a knife to a gunfight.
BioCatch's new 2026 Digital Banking Fraud Trends in the U.S. report, drawn from 292 institutions serving more than 280 million customers, found impersonation scam attempts more than doubled between 2025 and 2026. Investment scams remain the costliest category despite being less frequent — the FBI estimates investment fraud losses topped $8.6 billion in 2025, and BioCatch's own bank customers logged $46 million in attempted investment losses alone. Phishing attempts climbed 50%, remote-access-tool sessions rose 45%, and more than 83% of fraud attempts originated from U.S.-based devices — a signature of scams that manipulate victims into authorizing their own transactions rather than hacking in.
The same week, Malwarebytes uncovered a $500 turnkey scam kit, complete with fake dashboards, countdown timers, and an admin panel for harvesting crypto recovery phrases, being sold on a cybercrime forum by a vendor tracked since March. From retail banking to hedge fund back offices to crypto forums, the common denominator is the same: attackers are buying persuasion infrastructure off the shelf rather than building technical exploits, which means the defense has to be behavioral and cross-institutional too.
Quick Hit #3: 94 Cards, One Email, No Alarm
Sift's Q2 2026 Digital Trust Index walked through the anatomy of two real fraud rings pulled from its network. In one case, a single email address cycled through 94 different stolen cards, running $4 transactions purely to validate which cards were still live before reselling or escalating them. The ring hit five separate food and delivery businesses, none of which saw more than their own slice of the pattern; only a network-wide view exposed the full 94-card scale.

The second ring, tied to account takeover, told a messier story: more than 90 businesses, nearly 13,000 attempted transactions, and none of the uniform ugliness of card testing, because the accounts themselves were genuine. A loyalty-account email change surfaced as the clearest early signal of takeover in progress. A Sift spokesperson stated that card testing can be blocked aggressively with little downside, but ATO calls for friction because the same session data belongs to a real customer with a real history, and a hard block just moves the damage from fraud loss to churn.
Quick Hit #4: The Speed Trap
PYMNTS Intelligence, working with Plaid, surveyed 150 senior payments executives across seven payment-heavy industries and found a familiar gap between the tools firms have and the coverage they actually deliver. Ninety percent said secure bank connectivity improved onboarding and 89% said it lowered operating costs, but real-time account ownership checks are where the real split shows up: firms that verify ownership in real time catch fraud before funds move or within minutes 60% of the time, versus just 23% for firms without those checks.
Only 17% of firms describe their own payment experience as "excellent", seventy percent plan to expand automated payment matching in the next 12 months, 65% plan to strengthen identity verification, and 59% plan to widen bank connectivity and AI-based fraud detection; upgrades aimed squarely at the gap between having fraud tools and having fraud tools that actually cover the whole payment, not just the parts that were easy to instrument first.
Quick Hit #5: The $5,000 Voiceprint
Two Illinois plaintiffs have filed a proposed class action against Walmart, alleging the retailer's AI silently converts customer service calls into biometric voiceprints without the written consent Illinois's Biometric Information Privacy Act requires. The complaint says callers only hear a generic warning that calls "may be recorded for business purposes, including fraud prevention" — with no disclosure that a mathematical voice template gets created, how long it's kept, or who might receive it. Walmart's own June 18 privacy notice already lists voiceprints among the biometric data it may collect, which the plaintiffs will likely use against the company as evidence the practice exists, even as it stops short of proving every call is converted.
BIPA damages run $1,000 per negligent violation and $5,000 per intentional one, and while a 2024 amendment now treats repeated collection through the same method as a single violation rather than one per call, the plaintiffs still peg the amount in controversy above $5 million for a class they estimate in the hundreds. The irony shouldn't be lost on fraud teams: voice biometrics are exactly the kind of continuous-verification signal this week's Big Story argues the industry needs more of, and the same infrastructure built to stop fraud is now Exhibit A in a lawsuit; a reminder that the consent and disclosure layer has to ship alongside the model, not get bolted on after a plaintiff's attorney finds the privacy notice first.
This Week in Fraud is a publication for fintech operators, fraud teams, and risk professionals. Have a tip or story? Reply to this email or drop Nick Holland [email protected] a note directly.


