All posts
4 August 2026· 3 min read

How a $20 Deepfake Toolkit Beats Bank-Grade Liveness Checks

Deepfakes now account for roughly 11% of global fraud, up from 7% two years ago. Here's exactly how a cheap, off-the-shelf toolkit bypasses the KYC liveness checks banks and crypto exchanges rely on.

Deepfakes bypass KYC verification by feeding an AI-generated video into the exact camera stream a verification system expects a live selfie from, using virtual camera software rather than presenting a printed photo to a real camera. The system asks the user to blink, turn their head, or read a code aloud; the deepfake does all three on command, because that's precisely what commodity toolkits are built to automate. The check passes, because it was designed to confirm a face is moving, not to confirm the video feed is real.

The toolkit is cheap and already for sale

This isn't a nation-state capability anymore. Researchers monitoring fraud channels on Telegram identified 22 public groups, operating in Chinese, Vietnamese, and English, openly advertising virtual-camera software, stolen biometric templates, and deepfake video generators built specifically to target named institutions including Binance, BBVA, and Revolut. Reporting on the broader toolkit market puts the entry price for a working deepfake-and-injection kit at roughly $20, low enough that KYC bypass has moved from a specialist fraud operation to a commodity service.

How the bypass actually works, step by step

  1. Identity sourcing. The fraudster obtains a stolen or synthetic identity document, often through the same Telegram channels selling the injection tools.
  2. Face generation. A deepfake video is generated from a photo of the stolen identity, or a real-time face-swap filter is applied over a live camera feed.
  3. Camera injection. Virtual camera software presents the generated video to the verification system as if it were a live webcam feed, bypassing the physical camera entirely.
  4. Liveness prompt evasion. The injected video responds to blink, turn, and smile prompts on command, because generation tools are built to automate exactly those checks.
  5. Verification passes. The system logs a successful liveness check and proceeds to open the account, approve the loan, or clear the transaction.

Why this has gotten worse, not better

Deepfakes now account for roughly 11 percent of global fraud activity, up from 7 percent two years earlier. Group-IB separately tracked 8,065 distinct biometric injection attempts against loan-application liveness checks alone. The trend has been recognized at the regulatory level: FATF's December 2025 Horizon Scan explicitly names deepfakes as a tool capable of bypassing anti-money-laundering controls, customer due diligence systems, and digital ID verification at onboarding, a formal acknowledgment that the previous generation of liveness checks no longer proves what it was built to prove.

What actually stops it

Blocking the specific virtual-camera driver in use today buys weeks, not years, because the next toolkit update routes around the block. The systems catching this reliably combine two things: presentation-attack detection tuned to the injection method itself (depth inconsistency, frame-rate artifacts, compression signatures a virtual camera introduces), and continuous retraining against synthetic identities running the same evasion techniques the real toolkits use, so the detector isn't learning only from fraud attempts that already succeeded once.

FAQ

How much does it cost to buy a deepfake KYC bypass toolkit?
Reporting on the underground market puts entry-level virtual-camera injection kits at roughly $20, sold openly through Telegram channels alongside stolen biometric templates and deepfake generators targeting specific banks and exchanges by name.

What percentage of fraud today involves deepfakes?
Roughly 11 percent of global fraud activity in 2026, up from 7 percent two years earlier, according to industry fraud tracking. Group-IB separately documented 8,065 distinct deepfake injection attempts against loan-application liveness checks in isolation.

Do regulators recognize deepfakes as a KYC bypass risk?
Yes. FATF's Horizon Scan, published December 2025, explicitly identifies deepfakes as capable of defeating anti-money-laundering controls, customer due diligence, and digital identity verification, formally elevating it from an emerging concern to a named compliance risk.

Read the white paper to see how detection is hardened against injection attacks, or place your order.

Sources: Telegram KYC-bypass marketplace via tech-insider.org; deepfake fraud percentage and toolkit pricing via Socure and duckduckgoose.ai; Group-IB injection-attack figure via Adaptive Security; FATF Horizon Scan reference via Facia.

Measuring this on your own model

The first step is a sample built to your specification, which you score on your own detectors and benchmarks. No cost and no commitment.