Even the people who study fake faces for a living are no longer comfortable trusting what they see on screen.
Dominic Forrest, Chief Technology Officer at iProov, said that he has spent more than a decade studying manipulated faces and the ways attackers try to fool identity systems.
But right now, the problem he’s facing is that the old visual clues are disappearing.

“I have spent the last 13 years looking at fake faces, and I can no longer tell the difference,” Dominic told the webinar hosted by Fintech News Network.
Coming from someone with that much experience in the field, the admission is difficult to brush aside.
It says a lot about how far deepfake tools have advanced, and how little ordinary users can rely on what looks real during a live digital interaction.
His point also lands at a time when deepfake fraud in the Asia Pacific (APAC) is becoming harder for banks to treat as a future concern.
Reports of GenAI-enabled scams rose 456% between May 2024 and April 2025, adding urgency to a discussion that centred on how banks can keep trust intact when impersonation looks increasingly convincing.
Generative AI is putting more pressure on banks to prove who is behind a screen without turning every digital interaction into a frustrating checkpoint.
The webinar brought together executives from Tonik, GXBank, Ryt Bank and iProov to discuss how financial institutions are responding as AI-driven fraud becomes more convincing.
Existing eKYC, biometric authentication and liveness checks have helped digital finance scale within APAC, but deepfake fraud attacks are now testing its limits, whether those controls can keep learning as quickly as fraudsters change their tactics.
Deepfakes Are Becoming Easier to Launch
Dominic pointed out that the most striking change in the fraud landscape is how quickly convincing attacks can now be created, with believable fakes no longer requiring a professional or expensive setup.
According to him, iProov tracks more than 130 face-swapping tools, many of which are available at a surprisingly very low cost. Some are even free.
With a single still image from LinkedIn or a company website, someone can now appear as another person on a live video call, which has led to the barrier to entry dropping significantly, turning deepfake scams into something far more easily accessible than they were just a few years ago.
Gan Kee Lim, Head of CyberSecurity and Tech Risk at GXBank, noted that digital banks in Malaysia are seeing the same change in the threat landscape.

“Fraud is no longer just poorly worded phishing emails. It now involves hyper-realistic deepfakes, voice cloning and AI-enabled chatbots,” Gan said.
Attackers are also treating fraud more like a scalable business. Gan described the rise of cybercrime-as-a-service models, where criminal tools and attack methods can be shared quickly across groups and markets.
The pace of those attacks puts pressure on banks that still depend heavily on manual review.
“Manual fraud reviews are no longer sufficient,” Gan noted.
GXBank has responded by using internally developed AI tools to support fraud detection and transaction monitoring.
Gan added that the bank has reduced case assessment time from around 15 minutes to close to five minutes, while keeping human review in the decision-making process.
Southeast Asia’s Digital Growth Has Created a Larger Attack Surface
GXBank’s use of AI in fraud detection reflects a wider pressure across the region, as more banking activity moves onto digital channels.
Within the APAC picture, Southeast Asia has become a particularly important market to watch. Dominic noted that the region stands out because many countries have moved quickly into digital-first financial services, bringing more first-time users into online banking.
The wider access has been positive for customers, especially in markets where digital banks are trying to reach underserved segments. The same growth also gives criminals more chances to test new tactics at scale.
During the webinar, the discussion referenced iProov’s finding that attacks in Southeast Asia rose sharply in 2025, including a 719.55% increase in Q3.
Gan noted that better detection may have contributed to the higher number of recorded cases. Even with that caveat, he added that the underlying threat is still growing as generative AI helps fraudsters move faster.
Catherine Paleracio, Chief Information Security Officer of Tonik, gave digital banks a warning.

“It is not the time for us to be lax,” Catherine said.
Tonik is responding by strengthening its cyber resilience programme and using AI-driven analysis to support fraud prevention.
Catherine also said an attack on one financial institution should be treated as a warning to the wider financial industry.
Fraud tactics can travel quickly across Southeast Asia once criminals find an approach that works, and these groups have been seen to be learning from each other while often reusing successful playbooks that have worked in other markets.
Banks Need to Authenticate Presence, Not Just Faces
When fraud tactics can move quickly across markets, banks have less room to wait until something looks suspicious after the fact. Banks need enough confidence during the interaction itself to know whether the person behind the screen is real.
All this while financial institutions have already built many of their digital journeys around identity verification.
eKYC and biometric checks have made remote onboarding possible, while liveness checks have helped institutions confirm that a customer is not simply presenting a static image or recording.
Julius Rajeswaran, Chief Operating Officer of Ryt Bank, took that point further, arguing that banks need to think more carefully about what they are actually proving.

“Authenticating faces is important, but authenticating presence is what we need to concentrate on,” Julius stated.
A face match may only show that an image resembles the customer.
Deepfake fraud prevention now requires banks to assess whether a real person is present and whether the interaction fits the customer’s usual behaviour. Higher-risk moments may also need another layer of checks.
Julius added that fraud controls cannot create too much friction for customers.
Ryt Bank has onboarded 1.2 million customers in seven months, and that scale makes customer experience a central part of the security conversation.
“Whatever we do in the fight against fraud has to be invisible to the customer,” Julius noted.
Deepfake fraud in APAC is forcing banks to work within a narrow space. Controls have to become stronger without making the digital banking journey feel harder than customers are willing to accept.
Stronger Security Still Has to Work for Everyone
Keeping the digital banking journey from feeling too difficult becomes even more complicated when customers do not all come to the service with the same devices or digital confidence.
Julius pointed to older customers and vulnerable segments as part of that challenge.
Lower-end devices add another layer of difficulty because a biometric system that works well on a flagship smartphone may perform differently on a low-cost Android phone with a weaker camera.
Dominic made a similar point from the technology side, stressing that inclusivity cannot be treated as a nice-to-have.
Identity verification systems need to work reliably for customers with different skin tones and across a wide range of age groups. The same standard also has to hold when device quality or network conditions are less than ideal.
He noted that iProov has operated across more than 27,000 makes and models of devices globally.
Some users may be trying to complete onboarding or authentication on very low-cost devices, with unstable internet connections making the process even harder.
Digital banking security cannot be built only for customers with the latest phones and strong connectivity.
Banks risk excluding users, or giving them a weaker experience, if identity checks fail to work reliably for the people who most need digital financial services to be accessible.
Catherine explained that onboarding remains one of the most vulnerable customer touchpoints because it is where a bank establishes identity.
At Tonik, the bank combines multiple data points in the background, including eKYC and liveness checks.
Document checks and device behaviour also help the bank strengthen fraud detection without overwhelming customers.
One-Time Verification Is No Longer Enough
At the end of the discussion, Dominic brought the issue back to whether banks can keep identity checks effective after the first moment of verification.
He urged financial institutions to look closely at whether their existing biometric liveness systems can stand up to today’s AI-generated attacks.
eKYC and broader identity verification controls also need the same level of scrutiny.
External testing matters here too, and so do recognised certifications and standards, because banks in APAC cannot rely only on vendor claims when tools that are being used for deepfake fraud keep evolving.
A customer may pass authentication at the start of a session, only for the risk picture to change minutes later as their behaviour or device signals begin to look different.
“Verification can no longer be a one-time gate,” Dominic highlighted.
Across APAC, the next stage of deepfake fraud prevention will depend on controls that can adapt throughout the customer journey, especially during account recovery and higher-risk transactions.
The full discussion goes deeper into how Tonik, GXBank, Ryt Bank and iProov are thinking about deepfake fraud and the future of identity checks in APAC.
Watch the full webinar here:
Featured image: Edited by Fintech News Singapore based on an image by user850788 via Magnific.



