AI Sends Global Crime Syndicates Into Fraud Nirvana
Criminal groups are using an AI toolkit called ProKYC to fake the photo ID and selfie video checks that banks, exchanges, and apps use to verify new customers. It builds a fake passport and a video of a fake person moving their head, good enough to slip past identity checks and open fraudulent accounts.
- Report priority
- Critical
- Targets
- ProKYC+2 more
How it works
An operator feeds ProKYC a photograph and stolen personal details, and the tool generates a convincing fake passport along with a video of that fake person turning their head, which is enough to fool the liveness checks meant to prove a real human is present.
What to do
Organizations that rely on photo-ID-plus-selfie checks should treat basic liveness detection as no longer sufficient and watch for updated guidance from identity-verification vendors and groups like Interpol on AI-enabled KYC fraud.
Technical details
Affected software: ProKYC, Cryptocurrency exchanges, Online retailers
A security researcher from TD Bank demos a version of ProKYC on stage at Black Hat USA 2026. He feeds it stolen personal information and a photo, and it generates a fake Australian passport along with a video of the fake person moving their head around. The tool can also fake a live phone camera feed, so an identity checker believes it is watching a real live video call with that person.
ProKYC is described as three-year-old tradecraft from Nigerian scam rings that has been updated with newer AI capability. It generates forged identity documents and deepfake liveness videos from a supplied photo and stolen PII, and can reportedly emulate a live mobile camera feed to defeat remote identity-verification sessions in real time. Interpol reported a 54% rise in tracked fraud campaigns since 2024 and estimated AI-enhanced fraud is 4.5 times more profitable than traditional methods, with over $1.1 billion in assets lost across more than 1,500 tracked transnational fraud cases.