Mazda CX5
Як зробити цифрову копію себе. Ось відео —>

AI instead of a face: how fraudsters bypass bank biometrics and what they fall for

The last few years have been a watershed for the Ukrainian fintech market. While cyber fraud was previously associated with banal phishing or telephone «scams» ​​on behalf of the «bank security service,» now the industry is facing a technological nightmare.

Leave a comment
AI instead of a face: how fraudsters bypass bank biometrics and what they fall for

The last few years have been a watershed for the Ukrainian fintech market. While cyber fraud was previously associated with banal phishing or telephone «scams» ​​on behalf of the «bank security service,» now the industry is facing a technological nightmare.

According to experts from the Ukrainian Interbank Association of Payment Systems Members (EMA), the transformation of fraudulent scenarios has reached the level of high-tech AI attacks. Fraudsters have learned to create digital clones of real people to bypass Liveness Detection systems (checking the user’s «liveness» in front of the camera), which banks and government services use to remotely open accounts, confirm large transactions, or restore access to accounts.

What vulnerabilities are exploited by attackers, why the development of digital services has unexpectedly deceived migrants abroad — we will understand without unnecessary pathos and clericalism in the material of dev.ua.

Anatomy of a scheme: from an «inherited» number to a loan in «Diya»

The scheme, which has been widely documented recently, works like a well-tuned pipeline and consists of several steps:

1. Hunting for ghost numbers

It all starts with purchasing a SIM card with a number that previously belonged to a citizen of Ukraine, but due to lack of top-ups within a year, was deactivated by the operator and put up for sale again.

How do scammers understand which numbers are «promising»? There are two main versions:

Bruteforce: Attackers launch bots on financial services registration pages. If the system does not offer to create a new account, but recognizes the number as an existing client — okay, there is a real person behind this number, let’s continue searching.

Analysis via GetContact: If a number has a rich history of tags in phone books, tied to names or positions, this is a green light for scammers — the owner may have a credit history.

2. Capture «Actions» via BankID

With the financial number, the attackers log in to the donor bank where the victim has an account. The bank recognizes the «native» number and requires a minimum of checks. The next step is to log in to the «Diya» account via BankID. The fraudsters end up with digital documents, as well as the Diya.Sharing and Diya.Signature tools.

3. Attack on Liveness Detection and Onboarding

With someone else’s digital identity, fraudsters are flocking to new banks and MFIs where the victim has never been served, but where fast remote onboarding is available. At the biometric facial verification stage, artificial intelligence comes into play.

The Evolution of Technology: From Masks to Fraud-as-a-Feature

High-profile arrests of fraudulent groups demonstrate how quickly the tools of criminals are developing.

Stage 1: Face Morphing (Local Replacements)

Until recently, scammers actively used face morphing attacks. The attacker took his own face as a basis and, using neural networks, superimposed anthropometric features (the shape of the eyes, nose, proportions) of the victim on it.

Stage 2: Full Generation and Presentation Attacks

Over time, the approach has transformed into full-fledged image and video generation by artificial intelligence. Moreover, cases of banal Presentation Attacks have been recorded — when a pre-prepared high-quality animated video is simply played in front of the smartphone camera on another screen. Fraudsters act openly and experiment, sometimes even leaving watermarks of commercial AI platforms on the video.

Trend: Shift to «Fraud-as-a-Feature»

Today, there is a dangerous tectonic shift: from the Crime-as-a-Feature model (creation of specialized hacking software) to Fraud-as-a-Feature.

Attackers no longer need deep technical knowledge. They use legal commercial AI services designed for entertainment, video enhancement, or anonymization. Basic user skills are enough to adapt cheap civilian AI tools to bypass banking Liveness checks.

Do you understand now why Anthropic is so slow to release (or not at all) new big language models like Mythos or Fable 5 to the open market? Because they are able to not only find a vulnerability in your software, but also easily write an exploit for the criminal. And he doesn’t even have to be a hacker to do this now. Fraud-as-a-Feature in action.

Adaptation for underwriting

Previously, scammers focused exclusively on robots (automatic approval without human intervention). But as banks tightened controls, attackers began to confidently engage in direct communication with live underwriters. With a «live» phone number, full data from «Diya» and a detailed credit history, they convincingly impersonate a client during video calls.

Real case: UAH 56,000 loan in Poland

According to the materials of the court case of the Novobuzky District Court of Mykolaiv Region, the criminal managed to spend a fairly large amount from the victim’s account by re-registering the financial number to himself. Migrants are a delicacy for scammers, because their rights while abroad are, in a sense, limited. Now we will explain why.

The «number release» scheme: how a displaced person was robbed

The victim of the crime has been permanently residing in Poland since April 2022. In March 2026, she unexpectedly discovered that her financial phone number of the Kyivstar operator stopped working.

As it turned out later, the card was «released» from the operator and re-registered to another person. Having gained control of the number, the attackers gained full access to the woman’s banking and began intercepting OTP confirmation codes.

In just one day, March 25, 2026, the scammers managed to:

  1. Write off the entire credit limit at the bank (which was previously unused and was fully repaid) in the amount of UAH 36,421.35.
  2. Go to the Kasta+ marketplace and open a credit limit there for another 20,000 UAH.
  3. Submit applications and try to obtain microloans on the ShvydkoGroshy and Moneyveo websites.

The woman immediately contacted the bank with a demand to block the accounts, declare the transactions fraudulent, and initiate the procedure for returning the funds. The bank set a fair condition: the debt could be canceled only after providing an official extract from the Unified Register of Pre-Trial Investigations (URDR). Without an extract from the register, he could not return the money.

And here there is a nuance. The fact is that the victim, in addition to the online application, must personally contact the district police department at the place of residence and personally sign a statement about the commission of the offense. According to the law, only a personally signed statement has legal force for the initiation of criminal proceedings.

In the future, it is planned to introduce the possibility of signing a statement about committing an offense through the Action.Signature and submission of an application through the bank using EDS/CEP. So far, this has not been implemented, and neither the banks nor the Police are to blame for this.

Therefore, the victim had to contact a lawyer who represented her interests in the Ukrainian court, which ruled in her favor in the first instance — obliging law enforcement officers to register a statement with the ERDR.

Common scheme

The situation that the victim from Poland found herself in is quite common. And there are many victims. For example, at the end of last year, police investigators exposed an organized group that used artificial intelligence to issue loans to Ukrainians.

The deal was organized by a 33-year-old woman who also traveled to Poland during the full-scale invasion (such an unfortunate coincidence).

The woman received personal data of online banking users from unidentified sources — financial mobile phone numbers, passwords, and authorization codes. She passed them on to other members of the group, who made unauthorized logins to the mobile applications of Ukrainian banks, and then to Diy via the BankID authorization system.

Ultimately, the attackers concluded contracts and opened accounts in the name of at least 286 citizens, and some of them received loans totaling over 4,000,000 hryvnias.

Case study from the arrest: The most interesting thing about this scheme is how exactly the scammers deceived the system. The neural network changed only the face itself to make it look like the victim (Face Matching technology). However, the scammer got it wrong on a small detail: the characteristic tattoo on her neck remained unchanged, which was noticed by the Cyber ​​Police.

Moreover, during other attempts, the scammers used the face of their male accomplice — artificial intelligence «morphed» (reshaped) his appearance to fit the women they needed.

NFC as the new defense line (and why it’s not perfect)

In response to the threat of deepfakes, Diya has introduced a mandatory authorization step from a new or untrusted device — an updated Diya.Signature activation process using NFC technology. To activate, you need to read a biometric document (ID card or passport) via NFC, pass a photo verification, and set a code.

This made it significantly more difficult for scammers to do their job, but they quickly adapted through social engineering:

Attack on a person, not on hardware: Instead of technically bypassing NFC, attackers use the phone to convince the victim to attach a document to the phone and pass a photo verification under their dictation. The protection works correctly, but in favor of the fraudster.

Conceptual rollback: The requirement to attach a plastic passport contradicts the idea of ​​purely digital identification as a full replacement for physical documents. The system is forced to return to a physical medium.

Complicating the customer experience: The presence of a document «here and now» creates an additional barrier, reduces conversion for banks, and reading the chip via NFC often causes technical difficulties for users.

Who is to blame: changing the paradigm of responsibility

This type of fraud (Stolen Identity) is fundamentally different from classic schemes. In cases of ordinary social engineering, the client is to blame for his own carelessness: he succumbed to pressure or voluntarily transferred money.

In cases with DeepFake and attacks on Liveness Detection, the client does not participate in the process at all (until the implementation of NFC authorization). He does not perform transactions and does not even suspect that his digital copy is just now taking out a loan. He does not take direct part in the process, but still creates the prerequisites for fraud by not untying bank accounts from his financial number.

A person becomes a victim of rapid digital development, not his own stupidity. By creating convenient digital ecosystems, the state and the financial sector have formed a comfortable space for servicing customers. However, in the absence of absolute security safeguards, this space becomes equally convenient for both citizens and fraudsters, allowing the latter to scale attacks without any contact with the victim. The main cluster of victims in this scheme are Ukrainians abroad who simply stopped using their Ukrainian SIM cards.

EMA safety checklist: how to protect yourself?

1. Stop using your number? Untie it from everything!

Be sure to change your financial number in banks and government registries if you:

  1. you have moved abroad and do not keep your Ukrainian SIM card active;
  2. you plan to change operator or number;
  3. You have lost your SIM card and are not going to restore it.

Once your old number is resold, it will become a master key to your past digital life.

2. Never pass identification «under dictation»

If during a telephone conversation (even if the caller introduces himself as the police, bank, or technical support) you are asked:

  1. open the Action application, turn on the demonstration;
  2. scan a passport or ID card via NFC;
  3. activate «Action.Signature» or sign a document;
  4. Hang up immediately. No real institution will instruct you on biometric verification over the phone.

3. No third-party applications

Banks never ask customers to install third-party apps for «account protection» or «virus scanning.» Any such request is an attempt to gain remote access (like AnyDesk) to your smartphone.

Preventive life hacks

To protect yourself from unpleasant surprises, enable notifications in the «Action» application about events in your credit history: Menu → Notifications → Enable notifications.

If you suddenly receive a notification in «Actions» about a request for your credit history from an organization to which you did not apply for a loan, call them immediately and report a possible attempt to fraudulently obtain a loan in your name.

Protect yourself from scammers with the FREEZE feature on the UBKI website. It temporarily «freezes» your credit history, so banks and microloans (MFIs) will not be able to check it and will simply refuse any loan in your name.

This is a paid service that you should enable if you:

  • lost your passport or ID card (so that no one takes out an online loan on you);
  • you are going abroad for a long time and definitely do not plan to buy anything in installments;
  • noticed that they had already started collecting fraudulent loans — to stop the next ones.

You can enable it here.

Have important news to share? Message our Telegram bot

Key events and useful links in our Telegram channel

Discussion
No comments yet.