AI Sends Global Crime Syndicates into Fraud Nirvana

By Tara Seals, Dark Reading
Click here to read the entire article

In bad news for financial institutions, online retailers, cryptocurrency exchanges, and people in the dating pool who rely on identity verification to make sure they’re not getting taken for a ride, global fraud gangs are aggressively industrializing their scam efforts.

That’s according to Eric Huber, senior manager for adversary intelligence and disruption at TD Bank, who said that major centers for organized crime specializing in financial fraud (notably in Southeast Asia and West Africa) are bypassing “know your customer (KYC)” rules and other identity-verification methods with an updated AI tool set that offers the ability to build completely believable synthetic identities capable of fooling even advanced AI-enabled behavioral defenses.

His research into fraud cartels dovetails with recent numbers from Interpol, which in March said that, since 2024, the number of fraud-related campaigns it tracks has increased by 54%, fueled by AI. Over the same period, Interpol-supported member countries in more than 1,500 transnational fraud cases lost assets valued at $1.1 billion; it also deduced that AI-enhanced fraud is 4.5 times more profitable than traditional methods.

Speaking from the stage of the AI Summit at Black Hat USA 2026, Huber pointed to a real-world example of the threat landscape: recent updates to three-year-old tradecraft used by Nigerian scam rings called ProKYC, which is a turnkey KYC-bypass kit that defeats document-plus-selfie customer onboarding with convincing forged IDs and deepfaked “liveness” videos.

ProKYC: West African KYC-Bypass Supercharges Its Chances
To show how ProKYC is iterating in concerning ways, Huber first demoed a legacy version of the tool, which takes any photograph and generates a non-existent person using stolen personally identifiable information (PII). It first creates a convincing facsimile of a passport (in the demo, it’s an Australian document), as well as a video showing a person moving their head around, which should satisfy liveness detection. If asked, it can also emulate a mobile camera feed, so the verifier “sees” a live session with the fake person.

“It’s very convincing, and yeah, I’m sure you’re going to see a successful attack at the end,” Huber said. “Are bad guys very pleased? Yes.”

That’s impressive enough, but in the age of deepfake detection and other AI fraud-rooting defenses, this baseline deepfaking isn’t as successful as it once was. So, newer versions sold via Telegram channels offer specifically tailored workflows for a broad target list across crypto-exchanges and fintechs, with new AI-enabled features that can match the verifier’s request flow automatically.

One of the more notable features is auto-generation of “selfie-with-ID” uploads (essentially, a person holding a “real” ID that was just purportedly uploaded for verification, featuring a desk, keyboard, or table in the background for verisimilitude).

“The thing is, if you were defending yourself, how are you going to defend yourself against a perfectly convincing [fake picture supposedly taken in real time]? One of the things you do is you’re going to look at the ID, and [ask for backup verification],” said Huber. “So ProKYC will go ahead and create that selfie, or even emulate the supposed customer taking a picture of the picture on a keyboard or a table.”

Other recent AI-enabled features include automatic geo-tailored EXIF metadata insertion on the fake images to evade origin checks. Thus, a selfie-with-ID picture “taken” in Nigeria can be made to say it was taken in Sydney, in the Australian example.

Click here to continue reading.