A collaborative initiative hosted by the World Economic Forum (WEF) hopes to disrupt cyber-crime at scale, as new research highlights the growing risks posed by deepfake technologies.
The Cybercrime Atlas, hosted at the WEF, was established to address what they describe as a “fragmented cyber defence landscape, where experts and organisations often work in isolation.”
By providing a shared platform for collaboration, the initiative aims to multiply the impact of individual efforts and support disruption of cyber-criminal activity. Since the publication of its first Cybercrime Atlas Impact Report in 2024, the community has moved beyond research delivery towards applying its findings directly to the disruption of cyber-crime networks.
INTERPOL has emphasised the value of this collaborative approach in navigating the complexity of the global cybercrime ecosystem. Neal Jetton, Cybercrime Director at INTERPOL, said: “Disrupting organised cybercrime requires a global effort, with strong, trusted relationships between private-sector participants and between the private- and public-sector partners.
“The World Economic Forum provides the Cybercrime Atlas community with an impartial platform to support international public-private collaboration.” He added that working collaboratively enables connections and insights into cyberthreats that might otherwise be missed, contributing to improved global safety.”
Deepfake technology and KYC vulnerabilities
The latest Cybercrime Atlas research – titled Unmasking Cybercrime: Strengthening Digital Identity Verification against Deepfakes has focused on the growing use of deepfake-generating technologies, particularly face-swapping tools by bad actors.
According to a new report published on January 8 for the WEF’s Cybercrime Atlas, these technologies are enabling attackers to bypass know-your-customer (KYC) and remote verification processes, creating financial, operational and systemic risks for institutions that rely on digital trust.
The research notes that this development coincides with other concerning trends, including increased targeting of financial services and cryptocurrency platforms, which are considered particularly vulnerable to KYC bypass attacks.
KYC protections are widely used across industries to authenticate new customers and assess associated risks, typically combining document verification of government-issued identity documents with biometric checks such as facial images or short videos – formally secure means that are now at risk.
Can face-swapping and camera injection tools be fooled?
The study analysed 17 face-swapping tools and eight camera injection tools to assess whether they could enable KYC bypass and to characterise the current deepfake landscape. The research team included Natalia Umansky and Seán Doyle, respectively project specialist and lead of the Cybercrime Atlas, alongside research leads from Banco Santander and Group-IB.
While specific tool identities, vendors and step-by-step exploitation techniques were redacted to prevent misuse, the report states that most of the tools examined were intended for creative or entertainment purposes.
None explicitly advertised anti-KYC functionality in publicly available documentation or websites. Despite this, the researchers concluded that some tools possess capabilities that can defeat traditional digital KYC protections.
The analysis further found that even moderate-quality face-swapping models, when combined with camera injection techniques, can deceive certain biometric systems under specific environmental or technical conditions.
What can be done?
Looking ahead, the researchers forecast several trends likely to shape the threat landscape over the next year.
These include the continued democratisation of AI tools, lowering entry barriers while increasing attack complexity, and the persistence of finance and cryptocurrency as primary targets, with potential expansion into other KYC-dependent sectors.
The report also anticipates rising fidelity in face-swap technology, which could further undermine verification processes, alongside the persistence of presentation attacks in the near term and an escalation of injection attacks as active liveness detection becomes more widespread.
Beyond this, regulatory fragmentation is expected to constrain defences in the short term, although the researchers suggest that regulatory convergence could improve resilience over the medium term.
Strengthening defences against deepfake-enabled fraud
The report sets out a broad framework of recommendations and countermeasures, warning that the rapid evolution of deepfake technology is intensifying the contest between generative AI systems capable of producing synthetic identities and the fraud detection mechanisms designed to stop them.
According to the report, maintaining trust in digital identity verification will require defences that are adaptive, multi-layered and continuously improved.
The recommendations are structured around three core stakeholder groups within the digital KYC ecosystem: KYC solution providers, fraud teams, and financial institutions. Across all three, the report stresses the need to combine technical rigour with risk-based monitoring and strong governance, while balancing privacy, regulatory compliance and operational efficiency.
For KYC solution providers – particularly those offering liveness detection and anti-spoofing technologies – the report emphasises the importance of detecting manipulated visual streams before identity verification is completed. It highlights the need for stronger validation of camera sources, more dynamic and unpredictable liveness checks, and greater scrutiny of the video stream actually received by verification systems, rather than local previews.
Monitoring consistency over time, surfacing explainable detection outcomes, and designing models calibrated for real-world conditions such as low light or limited bandwidth are also identified as key measures.
The report further calls for closer integration between detection systems and customer risk policies, alongside safe testing environments that allow providers and customers to fine-tune defences before deployment.
Fraud teams are positioned as central to operational monitoring and analytics-driven risk assessment. The report recommends tighter controls over trusted camera sources, deeper analysis of response timing and latency, and more systematic correlation of contextual signals such as device, browser and encoding data.
It also highlights the importance of clearly defined escalation pathways when risk thresholds are breached, ensuring that additional verification or human review is applied in a controlled and proportionate way. Standardised case labelling, combined analysis of multiple attack signals, and structured feedback loops with KYC vendors are presented as essential to improving detection accuracy over time.
At an institutional level, the report focuses on governance and programme oversight. It advises organisations to prioritise defensive controls for high-risk scenarios such as onboarding, account recovery and high-value transactions, while maintaining strict privacy, data retention and audit controls around biometric information. Transparency with customers around verification processes is also highlighted as a means of reducing friction and confusion.
The report further recommends embedding advanced detection capabilities into procurement standards, maintaining clear operational documentation and appeal mechanisms, and ensuring staff are trained to respond consistently to suspected fraud cases. Regular simulation exercises are encouraged to test resilience against emerging face-swapping techniques, alongside the adoption of layered verification models that combine multiple identity signals.
Finally, the report points to the role of wider institutional and regulatory support, stating that intelligence sharing between companies, government agencies and peer organisations can strengthen collective resilience when conducted lawfully and proportionately, and suggests that broader legislative protections around an individual’s “right to identity” could help counter the misuse of face, voice and body likenesses by deepfake technologies.





