All posts
4 August 2026· 2 min read

46 Accounts, One Face: The Digital Identity Problem

One fraudster used stolen IDs and deepfake video to open 46 bank accounts. Governments building national identity systems at population scale are now the ones asking how to stop the next 46.

Researchers monitoring fraud channels on Telegram found 22 public groups, operating in Chinese, Vietnamese, and English, openly advertising virtual-camera software, stolen biometric templates, and deepfake video generators built specifically to bypass identity verification at named institutions, including Binance, BBVA, and Revolut. This isn't underground anymore. It's a marketplace with reviews and pricing, and the ABN Amro case, 46 fraudulent bank accounts opened with stolen IDs and deepfake video before the pattern was caught, is what that marketplace produces at scale.

Governments are watching this unfold at the exact moment they're building national identity systems that will carry far more weight than a single bank account. The eIDAS 2.0 mandate requires every EU member state to offer a European Digital Identity Wallet by the end of 2026. India's Aadhaar program already operates at population scale. Independent estimates place the digital-identity market at $80 to 133 billion by 2030, with sovereign and national programs forming a substantial share of that figure. These systems will handle document verification, biometric matching, and liveness detection for entire populations, and they're being built during the exact window in which deepfake tooling to defeat all three has become a $20 commodity, not a nation-state capability.

The obvious response, test the system against real citizen data before launch, runs into the problem that generated it in the first place: exposing more real biometric data to build a system meant to protect biometric data is a contradiction most privacy frameworks won't allow, and shouldn't. A national identity program can't harden its liveness detection by feeding it more citizens' faces without creating the exact honeypot it's trying to prevent.

That's the gap synthetic testing data is built to close. A synthetic-data foundry can supply matching, passive liveness, and anti-spoofing training material calibrated to a specific population's demographics, without a single real citizen's biometric information ever entering the training set. The system gets hardened against the ABN Amro-style attack pattern, the Telegram-marketplace tooling, and whatever comes after both, without the privacy trade-off that real data would require.

TessLabs was built inside a live identity-verification business handling roughly 15 million real onboardings over eight years, calibrated for the populations most existing detectors are weakest on. That production base, not a synthetic-data side project, is what an acquirer or a national program enriches to deliver an existing capability rather than build one from first principles.

Read the white paper or book a call to see the calibration data.

Case studies: ABN Amro fraud via Biometric Update; Telegram KYC-bypass marketplace via tech-insider.org.

Measuring this on your own model

The first step is a sample built to your specification, which you score on your own detectors and benchmarks. No cost and no commitment.