Video KYC deepfake fraud is not a hypothetical risk for private banks. It already worked. In January 2024, an employee at the Hong Kong office of British engineering firm Arup joined a video call. The people on it looked and sounded exactly like the company’s CFO and several colleagues. None of them were real. Over the next hour, fifteen wire transfers moved HK$200 million, roughly US$25.6 million, into accounts controlled by fraudsters running a synthetic video feed in real time.
That call was not KYC. But the technology behind it is the same technology now sitting on the other side of every remote private-banking application into Singapore. That includes the ones we help clients prepare at Easy Global Banking. Our own Singapore onboarding page tells applicants they can complete the process remotely, from digital identity verification to electronic signatures. Video verification replaces the flight to Changi. That claim is accurate. It is also, as of 2025, the exact claim regulators and fraud researchers are watching most closely.
The Monetary Authority of Singapore spent much of last September documenting how deepfakes are already defeating biometric checks at real financial institutions. Not in a lab. Real accounts, real money. The uncomfortable part is not that video KYC can be beaten. It is that the reason it can be beaten has almost nothing to do with weak banks. It has almost everything to do with which layer of Singapore’s identity system a foreign applicant never touches in the first place.
What Actually Happened in Hong Kong, Jakarta, and Singapore
Arup’s HK$200 million call was the headline case. But MAS’s September 2025 information paper on cyber risks associated with deepfakes lists it alongside quieter incidents. These matter more for KYC specifically.

In August 2024, an Indonesian financial institution caught fraudsters running virtual-camera software during a digital loan application. The software fed AI-generated deepfake photos straight into the verification pipeline. The system read a fabricated face as a live one. That same year, malware operators in Vietnam and Thailand harvested victims’ own photos, videos, and banking credentials straight off their phones. They used that stolen material to build deepfakes convincing enough to pass facial biometric authentication at multiple banks.
Singapore had its own moment in March 2025. A finance director at a local company joined what looked like a routine Zoom call with the firm’s CEO and colleagues. He transferred more than US$499,000. A second request, for US$1.4 million, made him pause and check. Authorities in Singapore and Hong Kong recovered the first transfer. That is the rare case with a happy ending, and it happened because a human got suspicious, not because a system flagged the video as synthetic.
None of these are edge cases anymore. They are the reason Singapore’s identity-verification vendors are now racing to patch the exact gap fraudsters keep finding. Here is the sequence, in order:
Timeline: Aug 2023 Hong Kong $25k loan scam; Jan 2024 Hong Kong Arup $25.6M deepfake call; Aug 2024 Indonesia injection attack; 2024 Vietnam and Thailand malware-built deepfakes; Mar 2025 Singapore $499k Zoom deepfake; Sep 2025 MAS deepfake paper; Nov 2025 Sumsub report showing 158% Singapore deepfake growth.
Why Video KYC Deepfake Attempts Are Now Singapore’s Fastest-Growing Fraud Type
Singapore’s overall fraud rate actually fell in 2025. That is the twist most coverage skips. According to Sumsub’s Identity Fraud Report 2025-2026, released in November 2025 from more than four million analysed fraud attempts, Singapore’s total fraud growth dropped 12% year-on-year. That is one of the better trends in the region.
Deepfake incidents inside that same market rose 158% year-on-year over the same period. That is the sixth-fastest deepfake growth rate anywhere in Asia-Pacific. Impersonation scams and fraudulent e-wallet registrations drove most of it.
Key statistics: Singapore deepfake incidents up 158% year-on-year in 2025, the sixth-highest growth rate in APAC. Singapore’s overall fraud growth fell 12% year-on-year in the same period. APAC-wide synthetic-identity attacks rose 142% year-on-year, now 15.7% of all fraud attempts. The Arup deepfake video call fraud cost US$25.6 million across 15 wire transfers in a single day, January 2024.
Read those two Singapore numbers side by side and the story changes. Basic scams, the kind static fraud filters already catch, are getting rarer. What is growing is the narrow category built to beat video KYC directly: injected video, synthetic faces, cloned voices. Across APAC as a whole, Sumsub found synthetic personal data attacks up 142% year-on-year. That is now 15.7% of all fraud attempts in the region, its third-largest fraud category.
Penny Chai, Sumsub’s Vice President for APAC, put it plainly. Enforcement worked well enough against basic scams that attackers adapted. Deepfakes are now rising faster in this region than anywhere else in the world.
Presentation Attacks vs. Injection Attacks: The Distinction That Actually Matters
Fraud researchers split camera-based attacks into two families. The difference decides which defence actually stops them.
A presentation attack holds something up to a real camera. A printed photo. A phone screen replaying a video. Occasionally a 3D mask. These are the attacks liveness checks were originally built to catch, and they mostly still work against them.
An injection attack skips the camera altogether. Software intercepts the video feed at the device or driver level and substitutes a pre-built file: a deepfake, a synthesised face, a looped recording. The verification system never sees a real lens pointed at a real person. That is exactly what the Indonesian lender caught fraudsters doing in August 2024. Virtual-camera software stood in for the phone’s actual camera.
MAS’s September 2025 paper treats these as the first of three threat categories facing financial institutions. The second is deepfake-enhanced social engineering, the Arup and Singapore Zoom cases. The third is deepfake-driven misinformation aimed at market confidence. Singapore’s own Prime Minister Lawrence Wong had to publicly warn about crypto scams using his likeness in March 2025. A similar deepfake of Senior Minister Lee Hsien Loong circulated in December 2023.
For KYC specifically, the injection attack is the one that matters. It targets the one moment private banks have started treating as sufficient on its own: the live video call.
The Layer Singapore’s Digital ID System Never Reaches
Singapore built one of the more credible answers to this problem years before deepfakes made headlines. Singpass, the national digital identity system, lets residents authenticate with a QR scan and a biometric or passcode check on their own phone. Its MyInfo layer then lets them consent to share verified information pulled directly from government registries.

Where MyInfo is used, MAS does not require banks to collect separate identification documents at all. The data is not self-submitted. It is fetched straight from the source. DBS adopted the MyInfo API back in 2017. By Sumsub’s count, the system is now familiar to five million citizens and residents across more than 2,700 government and private-sector services.
Here is the part most coverage of this issue misses. Singpass verifies who someone claims to be against a government database. It does not, and was never built to, verify that the person on today’s video call is that same someone, live, right now. That second question, liveness, is a separate technical problem. It is solved by different technology entirely, and it is the layer every injection attack targets. A system can nail identity verification perfectly and still get fooled the moment it has to trust a camera feed.
For Singaporean citizens and residents opening a retail account, this mostly does not matter. Singpass covers layer one, so liveness checks only have to cover layer two. For a non-resident applying to a private bank from overseas, the exact client Easy Global Banking works with, Singpass is not available at all. There is no national digital ID to lean on.
The entire identity claim rests on whatever the video call, the passport photo, and the notarised documents can establish. Foreign private-banking applicants get the weakest version of Singapore’s video KYC stack, not the strongest. That happens at precisely the account size where a successful fraud does the most damage.
| Layer | What it verifies | Who gets full coverage | Deepfake resistance |
|---|---|---|---|
| Layer 1 — Singpass / MyInfo | Claimed identity matches a government record | Citizens, PRs, long-term pass holders | High — data never touches a camera feed |
| Layer 2 — Video liveness / KYC | The person on camera today is a live human, not synthetic media | Everyone, including non-residents | Depends entirely on the liveness technology deployed — this is where injection attacks land |
What MAS Actually Told Banks to Do About It
MAS’s response to video KYC deepfake risk was not a ban on video onboarding. Remote KYC remains explicitly permitted. It was a specific technical and procedural checklist instead.
Liveness checks should analyse motion, texture, and 3D depth rather than accept a static or looping image. They should prompt an applicant to perform an action in real time: turn their head, read a random number aloud. Not simply confirm a face is present. Where non-facial biometrics like fingerprint or palm vein are used, MAS wants detection tuned to that specific modality, not repurposed face-detection logic.
For high-privilege accounts and high-risk activity such as wire transfers, MAS pushes multi-factor authentication. Where video or audio drives a sensitive decision, it wants a second channel entirely: a code word, a one-time password, a callback to a number the bank already has on file rather than one supplied on the call. Separation of duties for large transfers, plus active monitoring for deepfake-based brand impersonation, round out the list.
None of this is exotic. It is close to what a careful compliance officer would have insisted on before deepfakes existed: verify twice, through two different channels, before moving money or approving a new relationship. What changed is that skipping it now has a specific, well-documented failure mode with a dollar figure attached.
How Private Banks Compensate When the Video Call Isn’t Enough
This is also why the private banks we work with at Easy Global Banking never treat a video KYC call as the entire compliance file. A liveness check earns an applicant limited trust, nothing more.
The notarised documentation standard almost every top-tier institution demands is doing a different job than the camera. Precisely sequenced source-of-wealth evidence. Certified passport copies. A named compliance contact reviewing the file rather than an automated queue. Together, these build a paper trail that a synthetic face on a screen cannot fabricate on the spot. It depends on documents that took years to accumulate, and a named relationship manager can cross-check it against what the bank already expects from that client profile.
Video call only
Video KYC + paper trail
Illustrative comparison: a video call alone scores low on identity confidence and injection-attack resistance but is fast to complete. Video KYC combined with a notarised, source-of-wealth-backed compliance file scores high on identity confidence and injection-attack resistance, with a moderate trade-off in approval speed. Scores are directional, based on the compliance factors described in this article, not a formal industry benchmark.
That is the honest trade-off behind a US$2 million-plus private banking minimum in Singapore. The compliance overhead is real. Increasingly, it exists because the video-only path has a documented failure rate that institutions can no longer treat as theoretical. A well-prepared file, one where the source-of-wealth narrative, the identity documents, and the video session all tell the same consistent story, moves through that scrutiny quickly. A thin file gets exactly the scrutiny thin files have always deserved, just with a sharper reason behind it now.
Before Your Own Video KYC Call: What to Actually Check
- Use your device’s native camera app for the call. Never a virtual camera, screen-share, or emulator; that is precisely the vector behind the August 2024 Indonesia case.
- Expect a challenge, not just a stare. A compliance officer or system may ask you to turn your head, hold up a specific finger count, or read a number aloud in real time. Static footage cannot do that convincingly yet.
- Confirm your relationship manager’s identity through a channel the bank already has on file, a callback number from the original application, not one given to you mid-call, before discussing account changes or transfers.
- Keep your notarisation and source-of-wealth documents consistent with what you say on camera. Mismatches between the paper file and the video story are exactly what a human reviewer is trained to catch.
- Treat any request for a secret or unusually urgent transfer during or after a video call as a red flag first and a bank instruction second. Arup’s fifteen wire transfers all happened inside one working day.
Video KYC deepfake risk will not disappear because a bank adds one more checkbox. It shrinks when a live camera feed is only ever one part of a larger, harder-to-fake story about who you are and where your money came from. Our free AML risk score calculator is a reasonable place to start building that story before a bank asks for it.
Related reading:
Frequently Asked Questions
Can deepfakes actually bypass Singapore bank video KYC?
Does Singpass or MyInfo stop deepfake fraud?
Is video KYC still safe to use for private banking?
What is the difference between a presentation attack and an injection attack?
How much money has deepfake fraud actually cost financial institutions?
Can Easy Global Banking guarantee my video KYC session won’t be flagged?
Composite illustrations: the two-layer verification stack table and the video-only-vs-paper-trail comparison are original Easy Global Banking educational frameworks built from the sources cited below. They illustrate a structural pattern; they are not a formal industry benchmark and do not represent any single bank’s internal scoring.
Methodology and Sources
Every incident, dollar figure, and growth statistic in this article was checked directly against the primary publication, not a secondhand summary: MAS’s own information paper, Sumsub’s original press release for its Identity Fraud Report 2025-2026, and contemporaneous news reporting on the Arup case. The two-layer verification stack and the video-only-vs-paper-trail comparison are original Easy Global Banking analysis built on top of those sources, not a claim attributed to MAS, Sumsub, or any bank. Content current as of publication; regulatory guidance and fraud statistics can change, so verify anything time-sensitive against the primary source before relying on it.
References
- MAS, Cyber Risks Associated with Deepfakes (Information Paper, September 2025) (opens in new tab)
- Sumsub, Identity Fraud Report 2025-2026 (opens in new tab)
- CNN, “Finance worker pays out $25 million after video call with deepfake ‘chief financial officer'” (opens in new tab)
- Singapore Government Developer Portal, MyInfo — How It Works (opens in new tab)
- Sumsub / PR Newswire, “Annual Sumsub Report Reveals Synthetic Personal Data in APAC Soars 142% YoY” (November 25, 2025) (opens in new tab)




