The 9 typologies
Synthetic and AI-Generated Onboarding DocumentsRarely covered in training
AI-enabled
Statements, identity documents and supporting evidence are generated rather than obtained, and are internally consistent in ways genuine documents are not.
What the analyst seesStatements with no fees or charges across months, running balances consistent to the penny, logos at incorrect aspect ratio, institution codes in the wrong format, identity photographs internally inconsistent or inconsistent with stated age, third-party webcam plugins during liveness checks.
Evidenced byFinCEN Alert FIN-2024-Alert004 (13 November 2024) on fraud schemes using generative AI to circumvent identity verification, authentication and due diligence controls, including its red-flag indicators and the SAR key term FIN-2024-DEEPFAKEFRAUD.
Biometric Injection and Liveness BypassRarely covered in training
AI-enabled
Rather than holding a fake face up to the camera, the attacker bypasses the camera entirely: virtual-camera software injects a pre-rendered or real-time face-swapped video stream directly into the onboarding app, so the liveness check is validating a video file rather than a person.
What the analyst seesEmulator and virtual-camera artefacts in the capture stream, device and app-integrity signals that contradict a genuine handset, repeated onboarding attempts from the same device fingerprint under different identities, and capture metadata inconsistent with the phone the customer claims to hold.
Evidenced byGroup-IB, Weaponized AI (January 2026), documenting 8,065 biometric injection attempts against the digital loan onboarding of a single financial institution between January and August 2025; iProov threat intelligence recording a sharp year-on-year rise in iOS injection attacks across 2025 and dating the point at which injection attacks overtook presentation attacks to 2024; World Economic Forum testing of virtual-camera injection against live selfie flows. Vendor-published figures: treat the direction as reliable and the precise numbers as indicative.
Synthetic Identities at ScaleRarely covered in training
AI-enabled
A person who does not exist is assembled from a mixture of real and fabricated data, passed through onboarding, allowed to build a credit and transaction history, and then used as durable laundering infrastructure rather than for a single fraud.
What the analyst seesThin-file customers who behave impeccably for months, clusters sharing partial attributes such as address, device or contact details, credit files that begin abruptly in adulthood, and accounts whose only real purpose emerges long after onboarding.
Evidenced byUS Federal Reserve payments-improvement material on the transformation of synthetic identity fraud by generative AI; industry fraud reporting describing synthetic identity as the fastest-growing fraud type globally in 2025 and present in roughly a fifth of detected first-party fraud. The quantitative claims are vendor-published: direction reliable, precise figures indicative.
AI-Fabricated Corporate PresenceRarely covered in training
AI-enabled
An entity that does not trade is given everything a due diligence check looks for: a website, product imagery, a founder with a biography and video presence, filed documentation and a digital footprint, all generated rather than earned.
What the analyst seesA corporate customer or merchant whose entire evidenced existence post-dates its application, imagery and copy that cannot be traced to any real premises or product, a domain registered shortly before onboarding, and referees who exist only online.
Evidenced byDue diligence industry reporting on generative AI lowering the cost of fabricating a corporate identity — website, product imagery, founder biography and video — to the point where it clears checks designed for a different threat model; security research identifying over 18,000 newly registered domains with seasonal keywords ahead of the 2025 retail season, of which at least 750 were confirmed malicious. Emerging typology: vendor and security-research sourced, with no concluded enforcement case yet.
Agentic Laundering and Automated SmurfingRarely covered in training
AI-enabled
An autonomous agent executes the layering stage without a human in the loop: fragmenting funds into micro-transactions, selecting bridge and exchange routes on live liquidity, sizing transfers to stay inside observed thresholds, and adapting when a route stops working.
What the analyst seesTransaction sequences with machine timing and sizing characteristics, activity that reshapes itself shortly after a control is changed, and volumes of small movements that exceed what any manual operation could sustain.
Evidenced byTRM Labs, Autonomous AI Agents and Financial Crime (2026), identifying layering as the stage most susceptible to automation because route selection, transaction sizing and swap execution can all be optimised without human input; GNET (Global Network on Extremism and Technology), 'Agentic Smurfing: How AI-Autonomous Micro-Laundering is Outpacing Traditional Terrorist Financing Detection' (28 January 2026), on automated high-frequency micro-transaction laundering by extremist fundraising networks; reporting on state actors applying agents to sanctions evasion and automated shell company creation. Emerging typology: the mechanism is documented by analysts and vendor research, and there is not yet a concluded enforcement case to cite.
Synthetic Voice Against Telephone and Callback ControlsRarely covered in training
AI-enabled
Cloned voice defeats the control the firm added to catch impersonation: the callback. Voice biometrics and telephone banking authentication are attacked with audio generated from publicly available recordings.
What the analyst seesVoice authentication passing on a call whose channel or device signals are inconsistent with the customer, callbacks answered on newly registered numbers, and instructions confirmed by voice that the customer later disputes entirely.
Evidenced byFinCEN Alert FIN-2024-Alert004 (13 November 2024), whose red flags cover GenAI-assisted impersonation used to circumvent identity verification and authentication controls; FATF horizon-scanning material on deepfake impersonation of senior staff and customers to pressure payment authorisation. The video-call variant is evidenced by the Arup case; the voice-only attack on callback and telephone-banking controls is documented by supervisors and vendors rather than by a concluded case.
Laundering and Fraud as a ServiceRarely covered in training
AI-enabled
Capability is rented rather than built. Subscription platforms supply mule account provisioning, KYC-bypass tooling, synthetic identity generation, deepfake kits and end-to-end laundering, so an operator needs money rather than skill.
What the analyst seesThe same tooling signature across customers with no other connection: identical document templates, shared device or capture characteristics, and mule accounts appearing in coordinated batches rather than individually.
Evidenced byFATF, Professional Money Laundering (26 July 2018), describing professional launderers, organisations and networks that launder for a fee and setting out their characteristics and tools; FATF material identifying money-laundering-as-a-service with tiered service levels; threat-intelligence reporting on mule-as-a-service providers and messaging-platform channels advertising virtual-camera software, deepfake generators and KYC-bypass services.
Control Probing and Detection-Threshold Discovery
AI-enabled
Small test transactions are run to establish where a firm's rules and thresholds sit, and activity is then shaped to stay just inside them. Automation makes the probing cheap and the adaptation continuous.
What the analyst seesSequences of small value-varying transactions preceding a step change in volume, activity that settles just below alerting thresholds across several distinct rules at once, and customers whose behaviour changes within days of a rule being retuned.
Evidenced byAnalytic pattern rather than a single reported case. Threshold structuring is a recognised offence in its own right in several jurisdictions, and the adaptation of behaviour once detection rules become known is documented across supervisory and academic literature on rule-based transaction monitoring. Automation lowers the cost of the probing rather than changing its logic.
Deepfake-Enabled Payment Instruction FraudRarely covered in training
AI-enabled
Synthetic video and voice impersonate executives on a live call to authorise urgent transfers, defeating the callback and video-verification controls firms adopted precisely to stop email-based impersonation.
What the analyst seesMultiple urgent same-day transfers to new beneficiaries authorised by one employee, outside normal approval patterns, following a confidential instruction the payer cannot corroborate internally.
Evidenced byArup, Hong Kong (January 2024): 15 transfers totalling approximately HK$200m (about US$25.6m) executed in a single day after a finance employee joined a video call on which every other participant was an AI-generated impersonation of a colleague.