Video KYC deepfake risk shown through a professional video call onboarding session

Your Video KYC Can Be Deepfaked — and Private Banks Know It

Video KYC deepfake fraud is not a hypothetical risk for private banks. It already worked. In January 2024, an employee at the Hong Kong office of British engineering firm Arup joined a video call. The people on it looked and sounded exactly like the company’s CFO and several colleagues. None of them were real. Over the next hour, fifteen wire transfers moved HK$200 million, roughly US$25.6 million, into accounts controlled by fraudsters running a synthetic video feed in real time.

That call was not KYC. But the technology behind it is the same technology now sitting on the other side of every remote private-banking application into Singapore. That includes the ones we help clients prepare at Easy Global Banking. Our own Singapore onboarding page tells applicants they can complete the process remotely, from digital identity verification to electronic signatures. Video verification replaces the flight to Changi. That claim is accurate. It is also, as of 2025, the exact claim regulators and fraud researchers are watching most closely.

The Monetary Authority of Singapore spent much of last September documenting how deepfakes are already defeating biometric checks at real financial institutions. Not in a lab. Real accounts, real money. The uncomfortable part is not that video KYC can be beaten. It is that the reason it can be beaten has almost nothing to do with weak banks. It has almost everything to do with which layer of Singapore’s identity system a foreign applicant never touches in the first place.

What Actually Happened in Hong Kong, Jakarta, and Singapore

Arup’s HK$200 million call was the headline case. But MAS’s September 2025 information paper on cyber risks associated with deepfakes lists it alongside quieter incidents. These matter more for KYC specifically.

Video KYC deepfake risk shown through a video call screen in a dark room
Injection attacks replace the camera feed itself, which is why the glitch, if there is one, never reaches the person reviewing the call.

In August 2024, an Indonesian financial institution caught fraudsters running virtual-camera software during a digital loan application. The software fed AI-generated deepfake photos straight into the verification pipeline. The system read a fabricated face as a live one. That same year, malware operators in Vietnam and Thailand harvested victims’ own photos, videos, and banking credentials straight off their phones. They used that stolen material to build deepfakes convincing enough to pass facial biometric authentication at multiple banks.

Singapore had its own moment in March 2025. A finance director at a local company joined what looked like a routine Zoom call with the firm’s CEO and colleagues. He transferred more than US$499,000. A second request, for US$1.4 million, made him pause and check. Authorities in Singapore and Hong Kong recovered the first transfer. That is the rare case with a happy ending, and it happened because a human got suspicious, not because a system flagged the video as synthetic.

None of these are edge cases anymore. They are the reason Singapore’s identity-verification vendors are now racing to patch the exact gap fraudsters keep finding. Here is the sequence, in order:

Deepfake fraud timeline: from a $25,000 loan scam to a $25.6 million video call
August 2023 — Hong Kong
GenAI-doctored images used in loan scams against moneylenders; roughly US$25,000 in fraudulent loans approved.
January 2024 — Hong Kong
Arup employee loses US$25.6 million across 15 wire transfers after a deepfake video call impersonating the CFO and colleagues.
August 2024 — Indonesia
Virtual-camera software injects AI-generated deepfake photos into a digital loan KYC process, defeating facial recognition.
2024 — Vietnam & Thailand
Malware harvests victims’ own photos and banking credentials, used to build deepfakes that pass facial biometric bank logins.
March 2025 — Singapore
A finance director transfers over US$499,000 on a fake Zoom call with a deepfake CEO before a second request raises suspicion.
September 2025 — MAS
MAS publishes its Cyber Risks Associated with Deepfakes information paper, formalising liveness and verification guidance for banks.
November 2025 — Sumsub
Identity Fraud Report 2025-2026 finds Singapore deepfake incidents up 158% year-on-year even as overall fraud fell 12%.

Timeline: Aug 2023 Hong Kong $25k loan scam; Jan 2024 Hong Kong Arup $25.6M deepfake call; Aug 2024 Indonesia injection attack; 2024 Vietnam and Thailand malware-built deepfakes; Mar 2025 Singapore $499k Zoom deepfake; Sep 2025 MAS deepfake paper; Nov 2025 Sumsub report showing 158% Singapore deepfake growth.

Why Video KYC Deepfake Attempts Are Now Singapore’s Fastest-Growing Fraud Type

Singapore’s overall fraud rate actually fell in 2025. That is the twist most coverage skips. According to Sumsub’s Identity Fraud Report 2025-2026, released in November 2025 from more than four million analysed fraud attempts, Singapore’s total fraud growth dropped 12% year-on-year. That is one of the better trends in the region.

Deepfake incidents inside that same market rose 158% year-on-year over the same period. That is the sixth-fastest deepfake growth rate anywhere in Asia-Pacific. Impersonation scams and fraudulent e-wallet registrations drove most of it.

+158%
Singapore deepfake incidents, YoY 2025
↑ 6th-highest in APAC
−12%
Singapore overall fraud growth, YoY 2025
↓ falling even as deepfakes rise
+142%
APAC synthetic-identity attacks, YoY
15.7% of all APAC fraud
$25.6M
Arup deepfake video-call loss, Jan 2024
15 wire transfers, one day

Key statistics: Singapore deepfake incidents up 158% year-on-year in 2025, the sixth-highest growth rate in APAC. Singapore’s overall fraud growth fell 12% year-on-year in the same period. APAC-wide synthetic-identity attacks rose 142% year-on-year, now 15.7% of all fraud attempts. The Arup deepfake video call fraud cost US$25.6 million across 15 wire transfers in a single day, January 2024.

Read those two Singapore numbers side by side and the story changes. Basic scams, the kind static fraud filters already catch, are getting rarer. What is growing is the narrow category built to beat video KYC directly: injected video, synthetic faces, cloned voices. Across APAC as a whole, Sumsub found synthetic personal data attacks up 142% year-on-year. That is now 15.7% of all fraud attempts in the region, its third-largest fraud category.

Penny Chai, Sumsub’s Vice President for APAC, put it plainly. Enforcement worked well enough against basic scams that attackers adapted. Deepfakes are now rising faster in this region than anywhere else in the world.

Presentation Attacks vs. Injection Attacks: The Distinction That Actually Matters

Fraud researchers split camera-based attacks into two families. The difference decides which defence actually stops them.

A presentation attack holds something up to a real camera. A printed photo. A phone screen replaying a video. Occasionally a 3D mask. These are the attacks liveness checks were originally built to catch, and they mostly still work against them.

An injection attack skips the camera altogether. Software intercepts the video feed at the device or driver level and substitutes a pre-built file: a deepfake, a synthesised face, a looped recording. The verification system never sees a real lens pointed at a real person. That is exactly what the Indonesian lender caught fraudsters doing in August 2024. Virtual-camera software stood in for the phone’s actual camera.

MAS’s September 2025 paper treats these as the first of three threat categories facing financial institutions. The second is deepfake-enhanced social engineering, the Arup and Singapore Zoom cases. The third is deepfake-driven misinformation aimed at market confidence. Singapore’s own Prime Minister Lawrence Wong had to publicly warn about crypto scams using his likeness in March 2025. A similar deepfake of Senior Minister Lee Hsien Loong circulated in December 2023.

For KYC specifically, the injection attack is the one that matters. It targets the one moment private banks have started treating as sufficient on its own: the live video call.

The Layer Singapore’s Digital ID System Never Reaches

Singapore built one of the more credible answers to this problem years before deepfakes made headlines. Singpass, the national digital identity system, lets residents authenticate with a QR scan and a biometric or passcode check on their own phone. Its MyInfo layer then lets them consent to share verified information pulled directly from government registries.

Close-up of biometric passports representing Singapore's two-layer identity verification stack behind video KYC deepfake defenses
Layer one confirms a government record. Layer two has to confirm a live human, and it is the layer non-residents rely on alone.

Where MyInfo is used, MAS does not require banks to collect separate identification documents at all. The data is not self-submitted. It is fetched straight from the source. DBS adopted the MyInfo API back in 2017. By Sumsub’s count, the system is now familiar to five million citizens and residents across more than 2,700 government and private-sector services.

Here is the part most coverage of this issue misses. Singpass verifies who someone claims to be against a government database. It does not, and was never built to, verify that the person on today’s video call is that same someone, live, right now. That second question, liveness, is a separate technical problem. It is solved by different technology entirely, and it is the layer every injection attack targets. A system can nail identity verification perfectly and still get fooled the moment it has to trust a camera feed.

For Singaporean citizens and residents opening a retail account, this mostly does not matter. Singpass covers layer one, so liveness checks only have to cover layer two. For a non-resident applying to a private bank from overseas, the exact client Easy Global Banking works with, Singpass is not available at all. There is no national digital ID to lean on.

The entire identity claim rests on whatever the video call, the passport photo, and the notarised documents can establish. Foreign private-banking applicants get the weakest version of Singapore’s video KYC stack, not the strongest. That happens at precisely the account size where a successful fraud does the most damage.

Singapore’s two-layer verification stack: what each layer actually checks, and who is covered
LayerWhat it verifiesWho gets full coverageDeepfake resistance
Layer 1 — Singpass / MyInfoClaimed identity matches a government recordCitizens, PRs, long-term pass holdersHigh — data never touches a camera feed
Layer 2 — Video liveness / KYCThe person on camera today is a live human, not synthetic mediaEveryone, including non-residentsDepends entirely on the liveness technology deployed — this is where injection attacks land

What MAS Actually Told Banks to Do About It

MAS’s response to video KYC deepfake risk was not a ban on video onboarding. Remote KYC remains explicitly permitted. It was a specific technical and procedural checklist instead.

Liveness checks should analyse motion, texture, and 3D depth rather than accept a static or looping image. They should prompt an applicant to perform an action in real time: turn their head, read a random number aloud. Not simply confirm a face is present. Where non-facial biometrics like fingerprint or palm vein are used, MAS wants detection tuned to that specific modality, not repurposed face-detection logic.

For high-privilege accounts and high-risk activity such as wire transfers, MAS pushes multi-factor authentication. Where video or audio drives a sensitive decision, it wants a second channel entirely: a code word, a one-time password, a callback to a number the bank already has on file rather than one supplied on the call. Separation of duties for large transfers, plus active monitoring for deepfake-based brand impersonation, round out the list.

None of this is exotic. It is close to what a careful compliance officer would have insisted on before deepfakes existed: verify twice, through two different channels, before moving money or approving a new relationship. What changed is that skipping it now has a specific, well-documented failure mode with a dollar figure attached.

How Private Banks Compensate When the Video Call Isn’t Enough

This is also why the private banks we work with at Easy Global Banking never treat a video KYC call as the entire compliance file. A liveness check earns an applicant limited trust, nothing more.

The notarised documentation standard almost every top-tier institution demands is doing a different job than the camera. Precisely sequenced source-of-wealth evidence. Certified passport copies. A named compliance contact reviewing the file rather than an automated queue. Together, these build a paper trail that a synthetic face on a screen cannot fabricate on the spot. It depends on documents that took years to accumulate, and a named relationship manager can cross-check it against what the bank already expects from that client profile.

Video-only onboarding vs. video KYC backed by a full compliance file

Video call only

Identity confidence
4/10
Injection-attack resistance
3/10
Approval speed
9/10

Video KYC + paper trail

Identity confidence
9/10
Injection-attack resistance
8/10
Approval speed
6/10

Illustrative comparison: a video call alone scores low on identity confidence and injection-attack resistance but is fast to complete. Video KYC combined with a notarised, source-of-wealth-backed compliance file scores high on identity confidence and injection-attack resistance, with a moderate trade-off in approval speed. Scores are directional, based on the compliance factors described in this article, not a formal industry benchmark.

That is the honest trade-off behind a US$2 million-plus private banking minimum in Singapore. The compliance overhead is real. Increasingly, it exists because the video-only path has a documented failure rate that institutions can no longer treat as theoretical. A well-prepared file, one where the source-of-wealth narrative, the identity documents, and the video session all tell the same consistent story, moves through that scrutiny quickly. A thin file gets exactly the scrutiny thin files have always deserved, just with a sharper reason behind it now.

Before Your Own Video KYC Call: What to Actually Check

  • Use your device’s native camera app for the call. Never a virtual camera, screen-share, or emulator; that is precisely the vector behind the August 2024 Indonesia case.
  • Expect a challenge, not just a stare. A compliance officer or system may ask you to turn your head, hold up a specific finger count, or read a number aloud in real time. Static footage cannot do that convincingly yet.
  • Confirm your relationship manager’s identity through a channel the bank already has on file, a callback number from the original application, not one given to you mid-call, before discussing account changes or transfers.
  • Keep your notarisation and source-of-wealth documents consistent with what you say on camera. Mismatches between the paper file and the video story are exactly what a human reviewer is trained to catch.
  • Treat any request for a secret or unusually urgent transfer during or after a video call as a red flag first and a bank instruction second. Arup’s fifteen wire transfers all happened inside one working day.

Video KYC deepfake risk will not disappear because a bank adds one more checkbox. It shrinks when a live camera feed is only ever one part of a larger, harder-to-fake story about who you are and where your money came from. Our free AML risk score calculator is a reasonable place to start building that story before a bank asks for it.

Frequently Asked Questions

Yes, documented cases exist, though not by defeating a single check. Fraudsters exploit the gap between identity verification and liveness verification, often with injection attacks that replace a live camera feed with synthetic video. MAS’s September 2025 paper on cyber risks associated with deepfakes documents several such cases across the region since 2023.
Indirectly, and only for applicants who have it. Singpass and MyInfo verify that submitted identity data matches a government record; they do not verify that the person on a live video call is that same individual in real time. Non-resident applicants, who make up most private banking clients, do not have Singpass access at all.
MAS has not restricted remote onboarding. It has told institutions to run better liveness checks, including motion, texture, and depth analysis plus active challenge prompts, and to add independent verification for high-risk transactions. Video KYC combined with a thorough paper-based compliance file remains standard practice among Singapore’s private banks.
A presentation attack shows a real camera something fake, such as a printed photo or a replayed video. An injection attack bypasses the camera entirely, feeding a synthetic video file directly into the verification software. Injection attacks are the harder problem, and the one behind most 2024-2025 KYC-bypass cases in the region.
Individual cases range from the low thousands to tens of millions. Arup lost roughly US$25.6 million to a single deepfake video call in Hong Kong in January 2024; a Singapore finance director transferred over US$499,000 in March 2025 before recovering it through cross-border cooperation. Sumsub’s 2025-2026 fraud report found deepfake incidents in Singapore alone grew 158% year-on-year.
No institution or intermediary can promise that, and we would not claim otherwise. What we can do is prepare a KYC dossier and source-of-wealth narrative consistent enough that a human compliance reviewer has no reason to escalate, which is the actual defence private banks are leaning on as video-only verification comes under more scrutiny.

Composite illustrations: the two-layer verification stack table and the video-only-vs-paper-trail comparison are original Easy Global Banking educational frameworks built from the sources cited below. They illustrate a structural pattern; they are not a formal industry benchmark and do not represent any single bank’s internal scoring.

Disclaimer: The information provided in this article is for general informational and educational purposes only. It does not constitute financial, legal, immigration, or compliance advice, and nothing here should be relied on as a substitute for guidance from a licensed advisor, your bank’s compliance team, or the relevant regulator. Easy Global Banking operates as a registered trading name of BMA Business Solutions GmbH (UID CHE-422.832.034), a Swiss business consultancy; we are not a regulated financial institution and offer no financial services. Fraud statistics and incident details are drawn from the primary and third-party sources cited below, current as of publication, and may be updated or revised by those sources over time. Always verify current requirements directly with MAS, your bank, or a qualified adviser before acting on anything in this article.

Methodology and Sources

Every incident, dollar figure, and growth statistic in this article was checked directly against the primary publication, not a secondhand summary: MAS’s own information paper, Sumsub’s original press release for its Identity Fraud Report 2025-2026, and contemporaneous news reporting on the Arup case. The two-layer verification stack and the video-only-vs-paper-trail comparison are original Easy Global Banking analysis built on top of those sources, not a claim attributed to MAS, Sumsub, or any bank. Content current as of publication; regulatory guidance and fraud statistics can change, so verify anything time-sensitive against the primary source before relying on it.

References

  1. MAS, Cyber Risks Associated with Deepfakes (Information Paper, September 2025) (opens in new tab)
  2. Sumsub, Identity Fraud Report 2025-2026 (opens in new tab)
  3. CNN, “Finance worker pays out $25 million after video call with deepfake ‘chief financial officer'” (opens in new tab)
  4. Singapore Government Developer Portal, MyInfo — How It Works (opens in new tab)
  5. Sumsub / PR Newswire, “Annual Sumsub Report Reveals Synthetic Personal Data in APAC Soars 142% YoY” (November 25, 2025) (opens in new tab)