TL;DR: Deepfake fraud in Indonesia increased by 1,550% in just one year. VIDA's study found that 100% of businesses are concerned about AI-driven fraud, yet 46% do not understand how deepfakes work. The real threat is not the deepfake content itself, but how deepfakes can be weaponized to commit fraud.
Deepfake technology is opening new possibilities for creativity while creating new risks for digital identity and security.
Deepfake fraud in Indonesia increased by 1,550% between 2022 and 2023. The same trend was seen across Asia Pacific, where deepfake fraud increased by 1,540% during the same period.
According to a VIDA study, 100% of Indonesian businesses surveyed, spanning industries from banking to e-commerce, are concerned about the growing threat of AI-driven fraud. However, 46% admit they do not fully understand how deepfakes work. More concerning, 61% of companies surveyed believe their existing systems can prevent deepfake attacks, even though there is still no single type of attack that can fully test or validate the effectiveness of their security systems.
What Is Deepfake and Why Is It a Threat to Identity Verification?
Deepfakes are fake content, including videos, images, or audio, created using AI to imitate a person's identity. They can be convincing enough to fool not only the human eye, but also identity verification systems.
Consider what happens when a deepfake is used during digital onboarding or identity verification. A system that only checks whether a face matches the claimed identity can be deceived if the input is a highly convincing digital representation of another person.
This allows fraudsters to attempt to pass identity verification using someone else's identity without ever legitimately possessing or controlling that identity.
For businesses that rely on identity verification to open accounts, provide access to services, or authorize transactions, the rise of deepfake threats points to an important conclusion: simply verifying that a face looks real is no longer enough.
The system must also determine whether the person behind the verification is the legitimate user and whether the input received actually comes from a trusted source.
Why Liveness Checks Fail Against Deepfakes
Liveness detection plays an important role in biometric verification by determining whether the biometric input comes from a live person rather than a static image or prerecorded video.
But why do liveness checks fail against deepfakes?
The answer lies in how the attack reaches the verification system. Traditional liveness checks are designed to detect presentation attacks, where a fraudster presents a fake biometric, such as a photo, video, or mask, in front of the device's camera. However, increasingly sophisticated attacks can bypass the physical camera altogether through injection attacks.
This means that the problem is not always whether the deepfake can fool the liveness algorithm. The bigger question is whether the deepfake can enter the system without being detected in the first place.
Deepfake as a Weapon: The Rise of Injection Attacks
The public often focuses on how realistic a deepfake video looks. But in digital security, an even more important question is how that deepfake enters the system.
"Deepfakes often get the spotlight, but in digital security, the real entry point is the injection attack," said Niki Luhur, Founder and Group CEO of VIDA.
An injection attack occurs when a fraudster injects manipulated biometric content directly into the data stream of an identity verification system, bypassing the physical camera on the user's device.
We often imagine deepfake fraud as someone holding a deepfake video in front of a camera during verification. In reality, attackers can take a more sophisticated approach by injecting a deepfake video directly into the data pipeline during the verification process.
The user and the application may not even know that the attack is happening. Everything can appear normal, as if the verification is being performed by the legitimate user.
This is particularly dangerous because not all systems are designed to detect manipulated media that has been injected directly into the verification data stream.
That is why protection against injection attacks needs to secure the integrity of the entire input pathway, from the camera to the verification system. The goal is not simply to detect a deepfake after it enters the system, but to prevent manipulated media from entering the verification process in the first place.
How to Prevent Deepfakes in Digital Identity Verification
Effective protection cannot rely on a single security measure. It requires multiple layers of verification working together.
1. Verify That the User Is Real
The first layer is determining whether the person undergoing verification is actually present, rather than a photo, prerecorded video, or deepfake.
Liveness detection helps determine whether biometric input comes from a live person. At the same time, protection against injection attacks helps ensure that manipulated images or videos cannot be injected directly into the verification process.
2. Verify That the User Is the Legitimate Identity Owner
The next layer is ensuring that the person accessing an account is the legitimate owner of the identity.
User identities can be bound to trusted devices using cryptographic technology, making it significantly harder for fraudsters to access an account from an unknown device using only a stolen password or OTP.
Biometric authentication can provide another layer of assurance by matching the user's face against their registered identity.
3. Keep Verifying After Login
Security should not end once a user successfully logs in. Account activity should be continuously monitored to identify unusual patterns, including transactions or behaviors that may indicate fraud.
This is particularly important as deepfake fraud trends in banking continue to evolve. Deepfakes are no longer limited to identity verification. They can be combined with social engineering, account takeover, and other attack techniques throughout the customer journey.
Why Layered Verification Matters
Layered verification and authentication are important because different security layers address different types of threats. These are the layered verification
First, verify that the person undergoing the verification process is a real human, not a photo, video, or deepfake. Liveness detection can help ensure that the biometric input comes from a live face, while protection against injection attacks helps prevent fake videos or images from being injected directly into the system.
Second, make sure that the person accessing the account is the legitimate owner of the identity. The user's identity can be bound to a specific device through device binding, so the account can only be accessed from the device originally registered by the user. Biometric verification can also be used to confirm that the face belongs to the legitimate user.
Third, verification should not stop once the user has successfully logged in. Account activity should be continuously monitored to identify unusual patterns, including transactions or behaviors that may indicate fraud.
By verifying all three throughout the digital journey, businesses can build stronger defenses against increasingly sophisticated forms of fraud.
For financial institutions, healthcare providers, government agencies, and other organizations that rely on digital identity verification, the question is no longer whether they will face deepfake attacks.
The more important question is:
How well do they understand the role of deepfakes in modern fraud, and how prepared are their systems to stop them?