AI Face-Swapping Cross-Border KYC Fraud: Using Forged Videos to Steal Identity Information for Cross-Border Transfers
The main victims include finance heads at cross-border e-commerce companies, CEOs of startups expanding overseas, individuals studying or working abroad, and compliance staff at some small and medium-sized financial institutions. They are generally eager to complete cross-border fund flows, lack awareness of AI face-swapping technology, are easily tempted by promises of low-cost and fast KYC approval, and are insufficiently aware of protecting sensitive personal information.
Key Fields
FIELD STAMPSWho Gets Targeted
The main victims include finance heads at cross-border e-commerce companies, CEOs of startups expanding overseas, individuals studying or working abroad, and compliance staff at some small and medium-sized financial institutions. They are generally eager to complete cross-border fund flows, lack awareness of AI face-swapping technology, are easily tempted by promises of low-cost and fast KYC approval, and are insufficiently aware of protecting sensitive personal information.
骗局怎么运作
- Step 1: Scammers post advertisements in industry WeChat groups, on LinkedIn, or in professional forums for 'AI deep face-swapping + one-click KYC approval' services, claiming they can use the latest large models to generate realistic facial videos and ID documents. The fee is only a few thousand yuan, and they promise to complete identity verification on cross-border financial platforms within 48 hours.
- Step 2: Victims enter their real identity information on phishing login pages provided by the platform, including name, passport number, photo, and bank account information. The scammers use a back-end AI model to synthesize the victim's real photo with a fake background video prepared in advance by the fraudster, generating a 'trustworthy' identity video and uploading it to the KYC system specified by the victim.
- Step 3: After the AI-generated forged video passes automated checks such as facial recognition and liveness detection, the platform mistakenly determines it to be a real identity and then opens a cross-border account or payment channel for the scammer. The victim's personal information and bank account are then bound for subsequent fund transfers.
- Step 4: After the fraudulent KYC is approved, the scammers use the victim's cross-border account for large-scale money laundering or disguised legitimate trade payments. Common methods include fake invoices and cross-border e-commerce receipts and payments, forming chain transfers that are extremely difficult to trace.
- Step 5: After completing the transfer, the scammers immediately cancel or change the victim's login credentials in the KYC system and use the acquired identity information to continue opening new accounts on other platforms, creating multi-point harm and making it difficult for victims to trace the underlying chain of victimization after the fact.
红旗信号(看到这些快跑)
- 🚩 Advertising the use of AI face-swapping or deepfake videos for KYC
- 🚩 Fees significantly lower than the industry average
- 🚩 Requesting complete passports, bank statements, and selfie videos
- 🚩 Completing identity verification only through an online form
- 🚩 Providing KYC platform links that are not official domains or do not use HTTPS encryption
- 🚩 Immediately requiring linking a payment account or transferring funds after login
- 🚩 Customer service contact information using unfamiliar email addresses or temporary domains
真实案例
- On March 17, 2026, Fuzhou police busted a case involving the use of AI face-swapping to forge ID documents for KYC on a cross-border e-commerce platform. Two suspects successfully passed platform review with forged videos and then transferred nearly RMB 1.5 million from the victim company. The court sentenced them to fixed-term imprisonment and fines in accordance with the law. Source: https://news.fznews.com.cn/fzyw/20260317/69b8a05c53e24.shtml
- On April 12, 2026, a university student used generative AI to synthesize a classmate's facial photo into a fake bank facial video and, over four consecutive months, fraudulently obtained RMB 50,000 through the online face-scanning system of a small or medium-sized domestic bank. After the case was exposed by the media, police opened an investigation. Source: https://ezone.hk/article/20106670/%E5%88%B7%E8%87%89-%E8%AA%8D%E8%AF%86%E4%B8%8D%E5%86%8D%E5%AE%89%E5%85%A8-%E5%86%85%E5%9C%B0%E5%A4%A7%E5%AD%A6%E7%94%9F%E5%88%A9%E7%94%A8ai%E5%85%89%E7%89%87%E7%A7%92%E7%A0%B4%E9%8A%80%E8%A1%8C%E4%BA%BA%E8%87%89%E6%AA%A2%E9%A9%97
- On September 20, 2025, Tianquan News reported that cyber police busted a case of illegally intruding into computer information systems through AI face-swapping technology. The suspect used forged KYC videos to successfully log into multiple cross-border payment platforms and illegally transferred about RMB 3 million in total. Several suspects involved have been criminally detained. Source: https://news.tqhzx.com/plus/view-29736-1.html
Official Stance
- On February 15, 2026, the Cybersecurity Protection Bureau of the Ministry of Public Security issued the 'Security Risk Advisory on Online Identity Verification', warning of the high risk of using AI-generated videos for KYC and listing seven key preventive points.
- On March 1, 2026, the Financial Regulatory Bureau of the Central Bank issued the 'Administrative Measures for Identity Verification on Cross-Border Payment Platforms (Trial)', explicitly prohibiting the use of uncertified AI face-swapping technology for identity verification.
- On April 20, 2026, the provincial departments of the Ministry of Industry and Information Technology jointly issued the 'Guidelines for the Prevention and Control of AI Deepfake Technology', proposing special detection requirements for the financial industry.
How to Protect Yourself
- ✅ When conducting cross-border KYC, be sure to use the HTTPS-encrypted login portal officially provided by the platform, verify whether the URL is the official domain, and avoid submitting personal information through third-party links.
- ✅ Use multi-factor authentication, such as SMS verification codes plus hardware tokens, rather than only video liveness detection, to improve the credibility of identity verification.
- ✅ Use an official SDK with anti-spoofing algorithms for liveness detection, or conduct cross-verification through biometric services from a trusted third-party institution, to prevent AI face-swap videos from deceiving the system.
- ✅ Regularly audit and monitor account login records. If abnormal IPs, devices, or multiple identity verification attempts in a short period are found, freeze the account promptly and report to the regulator.
- https://cn.t00ls.com/articles-75498.html
- https://gxt.fujian.gov.cn/zwgk/ztjj/wxdgl/djzldxwlxxwffzzxxd/202606/t20260623_7166764.htm
- https://stock.10jqka.com.cn/20260817/c679017619.shtml
- https://www.unite.ai/zh-cn/ai-agents-machine-identity-fraud/
- https://news.tqhzx.com/plus/view-29736-1.html
- http://www.cq.xinhuanet.com/20260817/af4d516639f2401a848010236b9fa67b/c.html
- https://www.hk01.com/%E6%95%B8%E7%A2%BC%E7%94%9F%E6%B4%BB/60380756/%E7%94%A8ai%E7%A0%B4%E8%A7%A3%E9%8A%80%E8%A1%8C%E4%BA%BA%E8%87%89%E8%AD%98%E5%88%A5-%E5%85%A7%E5%9C%B0%E5%A4%A7%E5%AD%B8%E7%94%9F4%E5%80%8B%E6%9C%88%E7%9B%9C%E5%88%B75%E8%90%AC-%E5%B0%88%E5%AE%B6%E6%95%991%E6%8B%9B%E9%98%B2%E7%AF%84
- https://finance.sina.com.cn/money/fund/jjzl/2026-08-20/doc-ininyfvr8744000.shtml