Technology

Synthetic identity, deepfake and generative-fraud technology

Synthetic identity, deepfake and generative-fraud technology covers tools and methods used to fabricate or manipulate identity evidence, personas and media in order to obtain funds, employment, credentials or system access. Most observed activity is private fraud or organised crime. It becomes economic statecraft only where evidence establishes state direction, control or strategic revenue use. The generic technology therefore belongs in context, while documented state-directed campaigns require separate cases.

Definitions and control layers

Synthetic identity fraud predates generative artificial intelligence. The Federal Reserve describes identities built from fabricated information and, in some cases, real information. A real government identifier is not required by every authoritative definition. The National Institute of Standards and Technology's 2025 guidance separately addresses fabricated evidence for a person who does not exist.

Synthetic identity, stolen identity, borrowed identity, account takeover, false documents, impersonation, deepfake media and social engineering are different methods. Identity proofing resolves a claimed identity, validates evidence and verifies that the applicant is associated with it. Authentication tests control of an enrolled authenticator. It does not re-prove the underlying real-world identity on every use. Transaction monitoring examines later behaviour and payments.

Generative systems can create or alter documents, images, voices, video and text. They can lower production cost and increase variation, but they are not necessary for large-scale fraud. Existing document forgery, money mules, compromised accounts, scripted social engineering and corrupt facilitators remain material. A sound assessment identifies what generative technology contributed and which non-AI control failed.

Fraud evidence and process failure

The Financial Crimes Enforcement Network warned institutions in November 2024 about deepfake media used to circumvent identity verification and authentication. The alert provides observed indicators and reporting guidance, not a population-wide incidence estimate.

Hong Kong's Legislative Council recorded a case in which an employee of a company transferred approximately HKD 200 million after a fraudulent video conference that impersonated senior managers. The authoritative record supports the amount and general method but does not justify naming the victim company here. The loss involved both fabricated media and failures in meeting trust, payment authorisation and independent verification. It should not be represented as a purely technical defeat.

Defence is layered. Authoritative-source checks, evidence validation, presentation-attack detection, liveness tests, independent call-backs, multi-person approval and behavioural monitoring address different failure points. Generative media can degrade identity confidence and increase investigative cost. It does not destroy financial intelligence or establish that offence universally outpaces defence.

Documented state nexus

North Korean remote-worker operations establish a bounded statecraft pathway. United States Treasury sanctions findings connect named networks to revenue for North Korean weapons programmes. Federal Bureau of Investigation alerts describe methods and facilitators. Department of Justice records cover searches, seizures, charges and proved facilitator cases. These evidence classes must not be merged. A charge remains an allegation; a conviction or sentence establishes the disposition stated in that record.

The strategic mechanism is not generic identity fraud. It is the use of false, stolen or borrowed identities to obtain employment, earn revenue, evade sanctions and, in some cases, gain network access under documented state direction or control. Each case still requires proof of the actor, facilitator, proceeds and public objective.

Southeast Asian scam operations belong to a different category unless state direction is proved. United Nations human-rights reporting documents transnational organised crime, trafficking and forced criminality, with varying corruption or protection by officials. Perpetrators, trafficked workers, facilitators, complicit officials and victims must remain distinct. Cross-border scale and official corruption do not by themselves convert every compound into state economic warfare.

Evaluation boundary

Scale should distinguish reports, victims, identities, workers, transfers, losses and proceeds. Statecraft classification requires evidence of state financing, tasking, control or strategic revenue purpose. Profit-motivated crime is not statecraft by default, and strategic benefit is not proof of sponsorship. Case records should preserve sanctions findings, alerts, charges, pleas, convictions and sentences under their exact procedural status.

See also

Fraud as statecraft · North Korean remote IT-worker revenue schemes (2022-present) · Deepfakes and synthetic media in financial disinformation · Large language models for influence and market manipulation · Financial intelligence (FININT)

Sources

  1. Board of Governors of the Federal Reserve System, Synthetic Identity Fraud in the U.S. Payment System (2019).
  2. National Institute of Standards and Technology, Digital Identity Guidelines: Identity Proofing and Enrollment, SP 800-63A-4 (2025).
  3. Financial Crimes Enforcement Network, Alert on Fraud Schemes Involving Deepfake Media Targeting Financial Institutions, 13 November 2024.
  4. Financial Action Task Force, Cyber-Enabled Fraud: Digitalisation and Money Laundering, Terrorist Financing and Proliferation Financing Risks, 24 February 2026.
  5. Hong Kong Legislative Council, Official Record, 21 November 2024.
  6. Hong Kong Legislative Council, Official Record, 26 February 2025.
  7. United States Department of the Treasury, "Treasury Targets IT Worker Network Generating Revenue for DPRK Weapons Programs", 16 January 2025.
  8. Federal Bureau of Investigation, "North Korean IT Worker Threats to U.S. Businesses", 23 July 2025.
  9. United States Department of Justice, "Justice Department Announces Coordinated Nationwide Actions to Combat North Korean Remote IT Worker Schemes", 30 June 2025.
  10. United States Department of Justice, "Arizona Woman Sentenced in Information Technology Worker Fraud Scheme", 24 July 2025.
  11. Office of the United Nations High Commissioner for Human Rights, Online Scam Operations and Trafficking into Forced Criminality in Southeast Asia: Recommendations for a Human Rights Response (2023).
  12. United States Government Accountability Office, Science and Technology Spotlight: Malicious Use of Generative AI, GAO-26-108695 (2025).

Recommended citation

Cite this entry

Tennant, James J., ed. 'Synthetic identity, deepfake and generative-fraud technology.' The Encyclopedia of Economic Statecraft, version 2.0, last reviewed 29 July 2026. https://jamesjtennant.com/entries/synthetic-identity-and-generative-fraud-technology/.

Suggest an edit