Why Brazil Is a Front Line for Deepfake Fraud
Three conditions converge in Brazil at a scale that creates a particularly strong incentive for identity fraud.
Instant payments create an immediate payoff
Pix makes payments instant and available around the clock. Brazil recorded R$6.5 billion in fraudulent Pix transactions in 2025, and Pix now features in roughly 85% of financial frauds.
The Special Return Mechanism (MED) gives victims a route to contest a transfer, but recovery is not guaranteed. By the time fraud is reported, funds may already have been split across multiple accounts and withdrawn.
For fraudsters, the equation is straightforward: defeating identity verification can create access to an account that can immediately move money.
Mule accounts turn fake identities into financial infrastructure
Contas laranja, or mule accounts, are used to receive and move stolen funds. Demand for these accounts drives fraudulent account opening in the first place.
A fraudster does not attack eKYC simply to defeat a verification check. They attack it because a verified account is the asset the wider fraud operation depends on.
Digital onboarding moves identity verification online
Account opening in Brazil is overwhelmingly digital, bringing tens of millions of people into the financial system without requiring an in-person branch visit.
That also means the barrier between a fraudster and a verified account can be reduced to a camera, a document, and an identity verification flow.
Together, these conditions create a strong incentive to attack eKYC. A successful deepfake can produce a verified account on an instant payment rail, making identity verification a high-value target.
Two Types of Deepfake Attacks on eKYC: Presentation and Injection
Deepfake fraud is often treated as a single problem. In practice, there are two major attack categories, and the distinction matters because they require different defensive controls.
Both presentation and injection attacks are covered by ISO/IEC 30107-3, the international standard for testing presentation attack detection.
What is a presentation attack?
A presentation attack puts something fake in front of a genuine camera.
This could include:
- A photo displayed on a screen
- A printed image
- A 2D or 3D mask
- A video playing on another monitor
The camera itself is real and the capture path remains intact. The problem is that what the camera is capturing is fake.
What is an injection attack?
An injection attack bypasses the camera altogether.
Instead of presenting a fake face to a physical camera, the attacker feeds synthetic video directly into the identity verification stream using techniques such as:
- Virtual camera software
- Hooked applications
- Manipulated APIs
- Instrumented runtimes
Nothing necessarily appears in front of a physical camera.
Injection attacks are particularly dangerous because they can scale. A presentation attack generally requires a physical setup and an operator. An injection attack can be software-driven and repeated across hundreds of sessions.
How Fraudsters Bypass Identity Verification in Brazil
Synthetic video injection: The attacker builds a synthetic video of the target's face performing the required liveness actions, then feeds it into the session through virtual camera software. The platform receives what appears to be a camera stream. Source material for the face is usually public: social media, video calls, professional profiles.
Real-time face swap: Rather than pre-recording, the attacker sits in front of a real camera and uses a model to replace their face frame by frame. Because the underlying performance is a real person responding in real time, the motion, timing and reaction to prompts are naturally human. This is the variant that defeats behaviour-based liveness reasoning, because the behaviour is genuine.
Synthetic identities built on leaked data: Here there is no single victim to impersonate. The attacker generates a face that belongs to nobody and pairs it with real or partially real personal data, often a CPF number taken from one of the large data leaks Brazil has experienced. The result is submitted as a new customer. These identities are hard to catch. There is no real person to report the abuse and no fraud history attached to the identity. In Brazil, this is one of the main supply routes for mule accounts.
Defeating challenge-response liveness: Many platforms use prompted liveness: turn your head, blink, open your mouth. That design works well against static photo attacks. It does not work against a model that generates the requested action on a synthetic face in real time, because the prompt is answered correctly every time.
Voice cloning: For flows that include voice verification, a few seconds of recorded audio is now enough to produce a convincing clone. The source is frequently a phone call the target doesn't remember making.
Why Liveness Detection Alone Can't Stop Deepfakes
Most eKYC deployments rest on the assumption that a face is difficult to fake convincingly. That assumption is becoming less reliable. A systematic review and meta-analysis published in Computers in Human Behavior Reports (Diel et al., 2024), aggregating 56 studies across 86,155 participants, found that average human accuracy at distinguishing real from synthetic media was 55.54%, statistically indistinguishable from chance. Human review as a backstop does not work, and neither does asking an agent to eyeball a suspicious capture.
There are three more specific problems:
- Verification is a moment. A biometric check runs once, at onboarding or at a step-up, and returns a pass or fail. It sees nothing before or after that moment, and fraud operations know exactly when the check runs.
- The check evaluates the image, not the path. A liveness algorithm assesses whether the face in the frame appears to belong to a living person. It cannot tell whether that frame came from a physical camera sensor or from a virtual device pretending to be one.
- Generation improves faster than detection. Every advance in synthetic media is immediately available to attackers. Every advance in detection has to be built, tested and deployed first. That gap is structural.
None of this means biometrics are no longer useful.
It means they are being asked to answer a question they were not designed to answer.
A liveness check can help determine whether a face appears real. It cannot establish whether the device and session delivering that face are genuine.
That requires another layer of intelligence.
Where Device Intelligence Fits in the eKYC Stack
A modern eKYC stack has four layers, and each answers a question the others can't.
Document verification asks whether the document is authentic. It checks security features, fonts, data consistency, and where available reads the chip. It is the oldest layer and still necessary, but it evaluates an artefact rather than a person.
Biometric verification and PAD ask whether the face is real and whether it matches the document. This is where liveness detection and presentation attack detection live, tested against ISO/IEC 30107-3. Against someone holding a screen up to a camera, this layer is the right answer.
Device intelligence evaluates the device and its environment rather than relying solely on the identity presented. For injection attacks, this can include signals associated with virtual cameras, hooking frameworks, remote access tools, emulators, or cloned applications. For presentation attacks, device intelligence can identify patterns around the operation behind the attack. A device repeatedly associated with identity submissions, replay attempts, or other suspicious activity can reveal a pattern that a single biometric check cannot.
Behavioral and transaction monitoring asks what the account does after it exists. Onboarding is a single decision, and some fraud only becomes visible in the pattern of activity that follows.
The reason device intelligence has become the layer most stacks are missing is that it was the last one to become necessary. When deepfakes were rare and unconvincing, the biometric layer was sufficient on its own. Once synthetic media became cheap enough to industrialise, the question shifted from whether the face is real to whether the face arrived the way a face is supposed to arrive - and no amount of improvement at the biometric layer answers that.
Device Signals That Can Expose Deepfake Fraud
Four categories of device signals are particularly relevant when detecting deepfake-enabled identity fraud.
1. Capture Path Integrity
Injection attacks require something between the camera and the application.
That could be a virtual camera driver, hooking framework, instrumented runtime, or modified application build.
Presentation attacks leave the camera in place, but may involve screen sharing or remote access tools, particularly when an operator is controlling the capture remotely.
These tools can leave traces on the device.
The advantage of detecting the delivery mechanism is that it can remain relevant even as the appearance of the deepfake changes.
2. Device History Across Identities
A single device submitting multiple identities over time can be a strong indicator of identity farming.
This pattern is invisible when each application is evaluated independently.
A persistent device identifier allows the organisation to ask a different question: Has this device been associated with multiple identities before?
In a market where mule accounts are a critical part of fraud operations, that historical context can add a significant signal to the identity verification process.
3. Cross-Platform Device Reputation
A device associated with fraud at another institution can be relevant when it appears at a new organisation.
This is particularly important in Brazil, where fraud operations can move between banks, fintechs, betting platforms, and marketplaces.
An intelligence layer that can identify connections beyond a single institution can reveal patterns that an organisation's internal data cannot.
4. Environment Consistency
Emulators, virtualised environments, remote access tools, and cloned applications can behave differently from genuine consumer devices.
At scale, these signals can help distinguish an individual customer from an automated identity-farming operation.
How SHIELD Helps Brazilian Platforms Detect Deepfake Fraud at Onboarding
SHIELD adds device intelligence to the identity verification flow, giving platforms visibility into the device and session alongside the face and document.
SHIELD Device ID maintains a persistent identifier for each physical device that survives factory resets, app reinstalls, and SIM swaps. That persistence is what makes identity-farming visible. A device that submitted three identities last month is recognisable when it submits a fourth, regardless of how convincing each individual face and document appears.
SHIELD Fraud Intelligence, powered by SHIELD Sentinel, provides continuous session monitoring rather than a single assessment. Injection tooling is frequently activated at the moment of capture rather than at session start, precisely because a check at the beginning of the flow is a predictable event. Sentinel is built to identify the point during a session at which a malicious tool becomes active: a virtual camera engaging, a hooking framework loading, an environment characteristic changing.
SHIELD’s Global Intelligence Network provides a broader device-level view beyond the data available to a single organisation. This is particularly relevant in Brazil, where the same devices, fraud operations, and attack infrastructure can move across financial services, iGaming, marketplaces, and other digital platforms.
SHIELD’s device intelligence operates without collecting personally identifiable information (PII), enabling privacy-focused identity verification while supporting enterprises in meeting requirements such as Brazil’s LGPD.
This is how the layers fit together in practice. An identity verification network establishes whether the face and document presented are genuine. A device intelligence layer establishes whether the session delivering them is genuine, and whether the device behind it has a history the identity itself would never reveal. Neither question substitutes for the other, and deepfake fraud lives in the space between them - a convincing face, delivered through a channel and from a device that no biometric algorithm was designed to inspect.
FAQs
What is deepfake fraud in eKYC?
Deepfake fraud in eKYC is the use of AI-generated video, images or audio to pass a digital identity check, either by impersonating a real person or by presenting an identity that belongs to nobody at all. The target is the biometric step: the selfie, the liveness check, the voice prompt. In Brazil the scale of this is no longer marginal. Deepfakes went from one tenth of one percent of detected fraud in March 2025 to 6.5% in 2026, and Unico, the largest identity verification network in Latin America, recorded a rise of more than 1,000% in sophisticated AI-powered fraud attempts across 2025.
How do deepfakes bypass eKYC verification?
Through two routes. A presentation attack holds something in front of a genuine camera - a screen, a printout, a 2D or 3D mask, a video playing on a second monitor. An injection attack skips the camera entirely, feeding synthetic video straight into the verification stream through a virtual camera, a hooked application or a manipulated API call. Both defeat challenge-response liveness, because a model can generate the requested blink, head turn or smile on a synthetic face in real time. The prompt gets answered correctly every time, which is why a passed liveness check is no longer strong evidence on its own.
How can businesses detect deepfake identity fraud?
By treating it as a stack problem rather than a biometric one. Document verification checks whether the document is authentic. Biometric verification and presentation attack detection, tested against ISO/IEC 30107-3, check whether the face in the frame is real and matches the document. Device intelligence checks whether the session delivering both is genuine and what the device behind it has done before. Behavioural monitoring checks what the account does once it exists.
How does device intelligence help detect deepfakes?
It answers a different question from the biometric layer. Rather than asking whether the face is real, it asks who is submitting it, what they're submitting it from, and how often they've done it before. Four signals carry most of that. Capture path integrity exposes virtual cameras, hooking frameworks and remote access tooling. Device history across identities surfaces the single device that has submitted five applications under five names. Cross-platform reputation flags devices already linked to fraud at another institution. Environment consistency identifies emulators, virtualised environments and cloned applications. All four are available during the session itself, early enough to change the decision rather than explain it afterwards.
Can device intelligence prevent eKYC fraud?
Device intelligence creates a persistent identifier for each physical device, allowing platforms to detect when the same device is used across multiple identities or has a history of fraudulent activity, even after factory resets or app reinstalls. Combined with real-time session monitoring, it closes the gap that biometric verification alone cannot cover.