National digital identity programs and biometric platforms now anchor banking, government services, and cross-border commerce across Southeast Asia. As enrollment volumes climb, criminal groups have moved from stealing identities to manufacturing them, using genuine data with fabricated details to build synthetic profiles that clear conventional checks with ease. Platforms that still rely on outdated verification face real exposure, since attackers no longer need to steal a password when they can fabricate an entire identity.
The financial and reputational stakes grow heavier each year as these platforms scale to serve millions of citizens and customers. Closing this gap starts with layered verification and multi factor authentication engineered to withstand AI-generated impersonation, not just password theft.
Fraudsters typically pair a stolen or purchased identification number with a fabricated name, address, and date of birth. The resulting profile has no single living victim, so standard fraud alerts rarely trigger. Once the synthetic identity clears onboarding, it can open accounts, build a credit history, and quietly gain trust before being exploited at scale.
Biometric systems face two dominant threats:
Both techniques rely on the false assumption that an on-screen face proves a person is genuinely present.
Businesses worldwide lose an estimated $20 to $40 billion annually to synthetic identity fraud, with the United States carrying more than $3.3 billion in exposure tied to fabricated new accounts alone.
Deepfake technology has become increasingly accessible through deepfake-as-a-service platforms, with ready-made synthetic identities reportedly available for as little as US$15. What was once a highly specialised capability is now an inexpensive tool that enables even low-level criminal networks to launch sophisticated fraud campaigns.
At the same time, the volume of deepfake-generated content has surged dramatically, rising from approximately 500,000 files in 2023 to nearly 8 million in 2025, underscoring the rapid scale and accessibility of synthetic media.
Fintech losses tied to deepfake cases in Indonesia now exceed $138.5 million, driven by a 1,550% surge in AI-driven fraud between 2022 and 2024, much of it routed through biometric spoofing during loan applications.
Many onboarding systems still rely on one check, typically a static photo matched against a government identification card. Once that initial barrier is bypassed, fraudsters can gain broad access to accounts and services. Combining document verification with identity verification, liveness detection, and additional authentication factors helps close this gap by requiring multiple, independent signals to validate a user’s identity before access or high-risk transactions are approved.
Basic facial recognition was never built to catch unnatural blinking, inconsistent lighting reflections, or subtle motion artifacts that reveal a deepfake. Institutions lacking robust liveness detection risk accepting a fabricated face as a genuine, present applicant, particularly during remote account opening. Many legacy deployments still rely on static image comparison, which offers little resistance to a well-produced synthetic video feed.
National identity schemes across Southeast Asia sit under differing rules for:
This fragmentation slows a coordinated response when a synthetic identity ring operates across several jurisdictions at once, allowing fraud rings to reuse compromised identities across borders before enforcement catches up.
Modern platforms increasingly combine document authentication with facial matching, device integrity signals, and liveness detection into one decision layer, often through ping identity verification style checks. Working with an advanced authentication leader provides institutions with continuously updated fraud detection models that recognize new deepfake generation techniques as they emerge.
Typing rhythm, device handling patterns, and navigation behavior form a second layer of assurance that is difficult for a synthetic identity to replicate consistently. Risk scoring engines that combine these behavioral signals with multi factor authentication flag suspicious sessions before an account is even opened.
Regulators, banks, and technology vendors need shared threat intelligence and consistent biometric standards to prevent fraudsters from exploiting the weakest link in the ecosystem. Joint task forces and cross-industry data sharing agreements make it harder for a single compromised identity to circulate unnoticed across multiple institutions.
Technology alone is not enough to counter AI-enabled fraud. Fraud teams require continuous training to recognize emerging attack techniques, while governance frameworks must evolve in step with generative AI capabilities that are making sophisticated attacks faster, cheaper, and more scalable.
Investing in analyst upskilling, well-defined escalation procedures, and cross-functional incident response ensures that high-risk cases are identified early, investigated effectively, and resolved before they result in significant financial or reputational damage.
Synthetic identity fraud is no longer a future concern; it is an active, industrialised threat that is reshaping how national digital identity and biometric platforms must be secured.
The IndoSec summit, taking place on 15–16 September 2026 at The Ritz-Carlton Jakarta, Pacific Place, will bring together regulators, financial institutions, cybersecurity leaders, and technology providers to exchange verified threat intelligence, practical defence strategies, and lessons learned from organisations that have responded to large-scale identity fraud.
Attendees will also gain insights from leading authentication experts on designing resilient identity verification systems capable of withstanding the next generation of AI-enabled threats.
Join the conversation and contribute to building a more secure and trusted digital identity ecosystem across the region!
What is a synthetic identity attack?
It blends real and fabricated data to create a fictitious identity that passes verification checks undetected.
How common is deepfake fraud in Southeast Asia?
Deepfake fraud is escalating across Southeast Asia. In Indonesia, reported fintech fraud involving deepfake technology surged by more than 1,500% between 2022 and 2024.
Can biometric systems fully stop synthetic identities?
No single control suffices; layered verification, liveness detection, and behavioral scoring together reduce exposure meaningfully across the account lifecycle.
Why do legacy systems fail against these attacks?
Single-factor checks lack the corroborating signals needed to detect fabricated documents or injected video streams.
What role does regulation play?
Consistent cross-border standards help close the enforcement gaps that fraud rings currently exploit.