The rise of deepfakes: why they are a growing threat for businesses

The rise of deepfakes: why they are a growing threat for businesses

Deepfakes in business: how synthetic identity fraud is growing, what risks it creates, and what controls to apply in onboarding and authentication.

August 30, 2026·8 min read·Guide
Share:
Sebastián Stranieri
Sebastián StranieriCEO & Founder, VU Security

CONTENTS
In summary
  • Deepfakes are no longer viral content: they are a practical tool for identity fraud, social engineering, and account takeover.
  • The most exposed companies are those that depend on visual or audio signals without liveness detection, risk analysis, and traceability.
  • In financial services, gaming, retail, and background screening, the risk appears in onboarding, authentication, support, and account recovery.
  • The defense is not a single control: it combines identity verification, liveness detection, adaptive authentication, and real-time fraud detection.

Deloitte estimates that losses from generative AI-enabled fraud in financial services in the United States could reach USD 40 billion by 2027. Gartner projected that, by 2026, 30% of enterprises will no longer consider identity verification and biometric authentication reliable in isolation because of the rise of deepfakes.

Behind those two numbers is an assumption that no longer holds. For years, many companies assumed that a document, a selfie, and a video call were enough to know who was on the other side. That assumption no longer works when a face, a voice, or an entire meeting can be synthesized with publicly available tools.

The problem is not only technological. It is operational. A deepfake can enter through onboarding, customer support, an internal approval call, a vendor registration process, or account recovery. If your company makes critical decisions based on visual or audio signals without additional controls, that is the weak point.

In LATAM, the risk has an additional layer: accelerated digital adoption, pressure for conversion, and regulatory frameworks that are starting to demand more traceability. The debate is no longer whether deepfakes will affect businesses. The debate is which controls survive when the attacker can fabricate presence.

Deepfakes turn identity into an attack surface

A deepfake is synthetic content generated or manipulated with artificial intelligence to simulate a person’s appearance, voice, or behavior. It can be an image, an audio file, a recorded video, or a live stream. In business fraud, cinematic quality is not what matters: what matters is whether the content can pass a control.

Technical progress has lowered the barrier to entry. In the past, producing a convincing impersonation required specialized knowledge, time, and equipment. Now, an attacker can generate cloned voices, animated faces, and manipulated videos at low cost and with fast testing cycles.

This changes the risk model. The company no longer faces only forged documents or stolen credentials. It faces full identities, fabricated to fit into digital processes designed for real users.

USD 40 billion
Generative AI-enabled fraud in financial services. Estimated potential losses in the United States by 2027, according to Deloitte.

In digital banking, the impact is direct: fraudulent registrations, mule account opening — accounts opened under third-party names to move money from illicit sources — account recovery with manipulated biometrics, attacks on support channels, and remote validations. In gaming and gambling, it appears in mass account creation, bonus abuse, and evasion of KYC controls, meaning the required verification of who the customer is before they can operate. In retail, it affects returns, credit, wallets, and loyalty programs.

Deepfakes do not replace traditional fraud. They make it cheaper, more scalable, and harder to review manually.

Business risk appears in everyday processes

The most obvious image of a deepfake is a fake video call with an executive. That case exists: in 2024, a multinational company reported a multimillion-dollar transfer after a meeting in which the participants had been simulated with deepfake technology. But focusing only on that example limits the problem.

Inside a company, identity is validated all the time. Every weak validation is a possible door.

Exposed processes: areas where a deepfake can be inserted without looking like a sophisticated attack.

  • Digital onboarding: the attacker combines an altered document, a synthetic face, and manipulated liveness detection to open an account.
  • Account recovery: fraud starts when the user “loses” access and forces a new authentication factor.
  • Customer support: a cloned voice can pressure an agent to change data, reset credentials, or elevate privileges.
  • Vendor registration: a synthetic identity can enter through administrative processes that do not have the same controls as the customer channel.
  • Internal approvals: a fake video call or audio file can accelerate payments, bank account changes, or process exceptions.

The constant is the same: the attacker looks for the point where the company trusts a human signal without enough technical corroboration.

In financial services, this becomes more delicate because teams need to balance fraud, compliance, and conversion. If the control is too weak, fraud gets in. If the control is too heavy, the legitimate user drops off. That is why defense against deepfakes is not solved with indiscriminate friction.

If you operate digital channels in banking, fintech, or credit, the discussion connects directly with identity verification and with the ability to detect signs of manipulation before approving a registration.

Visual verification in isolation is no longer enough

Many companies still treat the selfie as if it were a strong proof on its own. That approach is outdated. An image can appear alive and still be false in origin. A face can move, blink, and respond to an instruction without belonging to a person present in front of the camera.

Liveness detection exists to address part of that problem: distinguishing between a present person and a presentation attack instrument, meaning a printed photo, a mask, or a screen placed in front of the camera. But even there, there are nuances. Detecting a printed photo is not the same as detecting video injection, a mask, a high-resolution screen, or a generated face.

The ISO/IEC 30107-3 standard defines methodologies and metrics to evaluate biometric presentation attacks. Testing by laboratories such as iBeta is relevant because it requires an external test against real artifacts and documented methodologies, and results in a confirmation letter of conformity. It does not eliminate risk on its own, but it raises the technical floor of the conversation.

The central point is this: biometrics should not be evaluated as an isolated signal. It needs context.

Signals that matter: controls that strengthen an identity decision.

  • Liveness detection: validates presence in front of the camera and resistance to presentation attacks.
  • Device integrity: detects manipulated environments, emulators, virtual cameras, or anomalous signals.
  • Document consistency: cross-checks document data, visual reading, validity, alteration signals, and the MRZ — the two- or three-line band at the bottom of the document that the machine reads.
  • Transactional risk: observes amount, frequency, geography, time, behavior, and historical pattern.
  • Identity history: connects prior attempts, associated accounts, devices, and fraud events.

A company that only looks at the face sees part of the event. A company that combines signals understands intent.

Defense requires combined signals and real-time decisions

Deepfake fraud does not wait for later analysis: if the system approves a fake account, the control needed to act before approval, not in the following month’s audit. The same applies to account recovery or to an internal exception approved by phone.

That is why the control needs to operate during the event. In digital identity, real time does not only mean low latency. It means making a decision with enough evidence before exposing the asset.

At VU, we work on this problem through three connected capabilities: Verify for onboarding and biometric identity, Authenticate for access and passwordless MFA — meaning validation with more than one factor and without the user needing to remember anything — and Protect for real-time fraud detection and blocking. Consolidating them in VU ONE responds to a concrete reality: separating verification, authentication, and fraud prevention into isolated systems leaves gaps. Today we process more than 350 million identities in LATAM, and that volume shows us where gaps appear before they become fraud.

Effective defense needs to distinguish between low risk and high risk. Not every user needs the same validation level in every event, and that is where security without friction lives: the legitimate user should not pay the attacker’s cost. But when anomalous signals appear, the platform must raise the control: request additional proof, block the operation, route to review, or end the session. That is adaptive authentication: a control that changes its requirements according to the risk of the moment instead of always applying the same step.

That is the practical criterion. Fewer blind controls. More risk-based decisions.

Teams need to evaluate providers with stricter criteria

The rise of deepfakes forces a change in the questions used to evaluate providers. It is no longer enough to ask whether they have facial biometrics or liveness detection. Those answers say little if they are not backed by evidence, technical coverage, and production behavior.

The right question is not “whether it detects deepfakes.” The right question is under what conditions, against which types of attacks, with what legitimate rejection rate, with what external audit, and with what update capacity.

If you are building that RFP, look at at least five criteria.

Evaluation criteria: signs that a platform is prepared for current risk.

  • Current external audit: recent testing and evaluations, not old seals used as commercial arguments.
  • Injection coverage: detection of virtual cameras, manipulated streams, and real feed bypass — meaning when the attacker replaces what the camera sends without ever standing in front of it.
  • Risk orchestration: ability to combine biometrics, device, behavior, document, and transaction.
  • Traceability: enough technical evidence for audit, internal review, and regulatory compliance.
  • Regional experience: knowledge of documents, regulation, fraud, and operational patterns in LATAM.

In regulated industries, this last point carries more weight than it may seem. A model trained or adjusted far from the region can fail on local documents, lighting, devices, connectivity, and fraud patterns. Digital identity in LATAM is not solved with a global checklist.

For financial services, the topic also touches compliance. Identity validation affects KYC, fraud prevention, personal data protection, and evidence for audit. In Argentina, Brazil, and Chile, regulations such as Law 25.326, Brazil’s LGPD personal data protection law, and Law 21.719 increase the pressure for traceable controls and proportionality in data processing.

The standard is the floor. What decides is daily operation, and that is where the trust of the user who is who they claim to be is earned.

shield
Restore trust in every digital interaction. If you are reviewing your identity controls in onboarding, authentication, or account recovery,
let’s talk and we will review it with your team.

Frequently asked questions

They are synthetic images, audio files, or videos used to impersonate people in business processes. They can affect onboarding, support, authentication, internal approvals, account recovery, and vendor registration.
Because banks, fintechs, and digital wallets make high-impact decisions based on remote identity. A deepfake can be used to open fake accounts, recover legitimate accounts, or deceive internal teams into approving operations.
Not all controls have the same level of resistance. Well-evaluated liveness detection should cover presentation attacks, video injection, and manipulation of the capture channel. It should also be combined with device, document, and transactional risk signals.
The priority is to combine identity verification, adaptive authentication, and real-time fraud detection. The control should adjust to the risk of the event, not apply the same friction to every user.
Synthetic identity combines real and false data to create an apparently valid person. Deepfakes add a visual or audio layer that makes that identity more credible during remote processes.

Want to stay up to date with the latest in digital identity?Want to stay up to date with the latest in digital identity?Want to stay up to date with the latest in digital identity?

Subscribe to VU's newsletter and receive use cases, industry news and articles on verification, authentication and fraud prevention.

Subscribe to VU's newsletter and receive use cases, industry news and articles on verification, authentication and fraud prevention.