Maryland and District of Columbia Credit Union Association Inc.

19/11/2024 | News release | Distributed by Public on 19/11/2024 13:06

FinCEN Alert on Deepfake Fraud Schemes Targeting Financial Institutions

The U.S. Department of the Treasury's Financial Crimes Enforcement Network (FinCEN) has issued an alert to help financial institutions identify and address fraud schemes involving deepfake media created with generative artificial intelligence (GenAI) tools. This alert highlights the increasing use of GenAI to produce fraudulent identity documents, such as driver's licenses and passports, which are then used by criminals to circumvent verification processes. These fraudulent documents are often combined with stolen or entirely fake personal identifiable information (PII) to create synthetic identities. These identities have been linked to various fraudulent activities, including check fraud, credit card fraud, loan fraud, and unemployment fraud, among others.

FinCEN emphasizes that criminals use these techniques to open accounts, launder money, and execute other illicit schemes. Financial institutions have detected these activities by employing methods such as metadata analysis, reverse image searches, and specialized software designed to identify deepfakes. Enhanced due diligence, including live verification checks and the use of multifactor authentication (MFA), has also proven effective in uncovering inconsistencies in fraudulent identities.

Several red flags indicate potential GenAI-related fraud, such as inconsistencies in identity documents or customer profiles, rapid and unusual transaction patterns, and payments to high-risk entities like offshore exchanges or gambling websites. Unusual behavior during verification processes, including claims of technical difficulties or the use of third-party tools to manipulate webcam video, may also warrant further scrutiny.

FinCEN notes that the advancements in GenAI have significantly reduced the resources required to produce realistic synthetic content, posing significant challenges to financial institutions. However, the use of robust safeguards, including phishing-resistant MFA and vigilant monitoring of suspicious account activities, can help mitigate these risks. This alert aims to support financial institutions in complying with Bank Secrecy Act (BSA) requirements and addressing the emerging fraud risks associated with GenAI technologies.