Woman using a smartphone for facial identity verification with deepfake fraud detection graphics on screen
Sep
14

Deepfake KYC Fraud in 2026: Why KYC Needs More Than a Selfie Check

Entrust found that deepfakes were linked to approximately one in five biometric fraud attempts. That does not mean one in five KYC applicants, identity verifications, or fraud attempts involved a deepfake. It refers only to biometric fraud attempts measured in Entrust’s data.

The finding comes from Entrust’s 2026 Identity Fraud Report, released November 18, 2025, which draws on more than one billion identity verifications across 195 countries and more than 30 industries. Another finding deserves attention: fraud attempts peaked between 2 and 4 AM UTC, when Entrust says defenses in many regions are offline.

That timing finding does not prove attackers wait for empty review queues or periods with fewer human reviewers. Entrust does not make that claim. It does show why KYC teams should review both the biometric check and the other controls around it.

Deepfakes Now Account for 1 in 5 Biometric Fraud Attempts  

The one-in-five figure needs precise wording.

Entrust specifically describes the figure as approximately one in every five biometric fraud attempts. The denominator matters because the statistic should not be applied to all identity verifications or fraud activity.

Among the biometric fraud attempts measured by Entrust, deepfakes represented a significant share of the activity.

Deepfaked Selfies Attempts Increased 58% in 2025  

Entrust reported that instances of deepfaked selfies increased 58% in 2025. It does not provide a narrower month-to-month period for this statistic.

A successful selfie check does not confirm that the applicant’s other submitted identity information is accurate or consistent.

Injection Attacks Can Bypass Live-Capture Step  

Deepfakes are not the only issue affecting biometric verification.

Entrust reported that the cadence of injection attacks increased roughly 40% year over year. The report compares the 2024 to 2025 period with the prior year.

Instead of relying on a normal live camera capture, manipulated imagery or video can be fed directly into the verification process.

What Entrust Means by an Injection Attack  

An injection attack sends manipulated or untrusted information directly into a verification system. Entrust identifies virtual-camera injection and device emulation as examples.

With virtual-camera injection, a fraudulent video stream can be presented to the verification system as if it were coming from a live camera. That stream may contain a deepfake or other fraudulent content.

Fraud Attempts Peak Between 2 and 4 AM UTC  

Entrust’s timing data also raises questions about how verification controls operate outside normal business hours.

The report found that fraud attempts peak between 2 and 4 AM UTC. Entrust presents the finding within its global report, which draws on identity-verification activity across 195 countries.

Entrust says the peak occurs when defenses in many regions are offline and discusses fraud activity taking advantage of coverage gaps.

That does not mean every company has weaker controls during those hours. It also does not mean every country experiences the same pattern at its own local time.

What the Timing Data Does and Does Not Prove  

The 2 to 4 AM UTC finding should not be stretched beyond what Entrust reported.

The report does not say verification queues are empty during that period. It does not show that fewer human reviewers are working. Entrust also does not prove that individual attackers deliberately schedule submissions around staffing levels.

The supported finding is narrower: fraud attempts peaked between 2 and 4 AM UTC, and Entrust says defenses in many regions are offline during that period.

KYC teams should determine whether verification, monitoring, data checks, and escalation procedures operate consistently at all hours.

Why KYC Teams May Need More Than a Liveness Check  

A biometric result is one part of the identity-verification process. Other checks can provide separate information about the same applicant.

“Did the Selfie Pass?” and “Does the Identity Match?” Are Different Questions  

A biometric system evaluates the facial input presented during verification, while identity-data checks examine information associated with the applicant.

Does submitted identity and contact information align with the available records? Do separate compliance screening results require further review?

Those checks do not prove identity ownership. They provide additional information that can be evaluated alongside other KYC signals.

For example, an applicant may pass a selfie check while other submitted identity information conflicts with available records. The organization can then request another verification step or route the application for further review.

How Independent Identity Checks Can Support Layered KYC  

Searchbug can support the identity-data portion of a layered KYC workflow.

Our tools provide identity and compliance data for use within an organization’s existing verification process. They do not detect synthetic media, replace biometric verification, or make final onboarding decisions.

SSN and Name Match Can Check Submitted Identity Data  

SSN and Name Match can help answer a separate question: does the submitted name align with the SSN information being checked?

It supports checks using a full SSN with a last name or, for supported API requests, the last four SSN digits with a full name.

A mismatch can provide a reason for closer review, but it does not prove fraud. A successful match also does not prove that the person submitting the information is the identity owner.

AML Screening Adds a Separate Compliance Check  

AML Screening addresses a different question: does the submitted identity appear in the supported government or watchlist data included in the service?

Biometric verification and AML screening serve different purposes. A passed selfie check does not replace AML screening when it is required under an organization’s process. An AML result also does not authenticate a selfie or detect synthetic media.

People Search API Can Provide Additional Identity and Contact Data 

People Search API provides identity and contact data that teams can compare with information submitted during onboarding.

Subject to permitted use and access requirements, teams can compare the returned data with information collected during onboarding. A matching or conflicting record may support further review, but it does not determine the final decision.

What a Layered Identity Verification Workflow Could Look Like  

A layered KYC workflow could include several separate checks:

  1. The applicant submits identity information.
  2. The organization’s biometric or liveness system runs its checks.
  3. Name and SSN information is checked where appropriate.
  4. Additional identity or contact data is compared when more corroboration is needed.
  5. AML screening runs when required.
  6. Conflicting signals are handled under the organization’s review rules.
  7. Cases that meet defined criteria move to additional review.

Searchbug can support the identity-data and screening steps. The organization remains responsible for interpreting the results and making the final decision.

How Should KYC Teams Handle Conflicting Results?  

A passed selfie check should not automatically override conflicting identity data, and one mismatch should not automatically result in a fraud determination. Organizations should define when conflicting results require additional verification or human review.

What KYC Teams Should Review in Their Current Process  

Entrust’s findings give onboarding and compliance teams several areas to review.

1. Coverage Outside Normal Review Hours

Entrust found that fraud attempts peaked between 2 and 4 AM UTC and says defenses in many regions may be offline during that period.

Teams can review whether automated verification, additional identity checks, escalation rules, alerts, and follow-up processes remain consistent across operating hours.

The goal is not to assume overnight activity is fraudulent. It is to understand how the workflow responds at different times.

Teams can ask:

  • Do automated identity checks run the same way outside normal staffing hours?
  • Are mismatches still routed for follow-up?
  • Are higher-risk cases held for review instead of moving forward automatically?
  • Are escalation rules applied consistently across time zones?

2. Independent Signals After a Passed Selfie

A KYC process should define what happens when a biometric result passes but another part of the identity record does not align.

Searchbug’s SSN Verification tools and People Search API can provide separate data signals for that review where access and use are appropriate.

Neither should be treated as a replacement for the biometric system.

3. When Mismatches Should Trigger Additional Review

Teams should also decide which inconsistencies require another step.

That could involve differences between submitted identity data and independent data sources or results that require review under the company’s KYC and AML procedures.

Searchbug can provide supporting data for that review, but the final decision remains with the organization.

TL;DR  

  • Deepfakes were linked to approximately one in five biometric fraud attempts measured by Entrust.
  • Instances of deepfaked selfies increased 58% in 2025.
  • The cadence of injection attacks increased roughly 40% year over year.
  • Fraud attempts peaked between 2 and 4 AM UTC, but the data does not prove this was caused by staffing levels.
  • Biometric checks and independent identity-data checks serve different purposes in a KYC workflow.

Entrust’s findings point to a broader issue for KYC teams: no single verification result should be expected to answer every identity question.

Biometric checks and independent identity-data checks address different parts of the verification process. When signals conflict, organizations can apply their own review rules rather than relying on one passed or failed check alone.

Searchbug’s SSN and Name Match, AML Screening, and People Search API can add separate identity and compliance data to that review. These tools do not replace biometric verification or make the final decision.

Create a free Searchbug API Test Account and get $10 in credits to test identity and contact data searches within your verification workflow. Teams working with larger datasets can also use Searchbug Bulk Processing for high-volume verification and data enrichment.

Editorial note: This article is for informational purposes only and is not legal or compliance advice. Organizations should review their own KYC, AML, identity-verification, and data-use requirements with qualified legal or compliance professionals.