Synthetic and AI-Generated Onboarding DocumentsRarely covered in training
In the assessment
Statements, identity documents and supporting evidence are generated rather than obtained, and are internally consistent in ways genuine documents are not.
What the analyst seesStatements with no fees or charges across months, running balances consistent to the penny, logos at incorrect aspect ratio, institution codes in the wrong format, identity photographs internally inconsistent or inconsistent with stated age, third-party webcam plugins during liveness checks.
Biometric Injection and Liveness BypassRarely covered in training
In the assessment
Rather than holding a fake face up to the camera, the attacker bypasses the camera entirely: virtual-camera software injects a pre-rendered or real-time face-swapped video stream directly into the onboarding app, so the liveness check is validating a video file rather than a person.
What the analyst seesEmulator and virtual-camera artefacts in the capture stream, device and app-integrity signals that contradict a genuine handset, repeated onboarding attempts from the same device fingerprint under different identities, and capture metadata inconsistent with the phone the customer claims to hold.
Synthetic Identities at ScaleRarely covered in training
In the assessment
A person who does not exist is assembled from a mixture of real and fabricated data, passed through onboarding, allowed to build a credit and transaction history, and then used as durable laundering infrastructure rather than for a single fraud.
What the analyst seesThin-file customers who behave impeccably for months, clusters sharing partial attributes such as address, device or contact details, credit files that begin abruptly in adulthood, and accounts whose only real purpose emerges long after onboarding.