TartanHQ Logo – Powering Seamless Enterprise Workflows with APIs and AI

Enterprise & Industry Insights

Enterprise & Industry Insights

Your deepfake fraud problem starts before the document check - and CPV is where it ends

Your deepfake fraud problem starts before the document check - and CPV is where it ends

Your deepfake fraud problem starts before the document check - and CPV is where it ends

Rohan Mahajan

Rohan Mahajan

10 Min

10 Min

Build Connected Systems with Tartan

Automate workflows with integrated data across your customer applications at scale

For fraud heads, identity verification leads, and risk teams at digital-first financial institutions - and anyone who has watched deepfake fraud volumes rise and wondered where the reliable detection point actually is.

The deepfake fraud numbers for 2026 are alarming. Deepfake fraud is projected to surge 495% this year. Injection attack attempts - where fraudsters bypass the camera entirely and inject pre-recorded or AI-generated video directly into the verification stream - rose 700% year over year according to Jumio's 2026 Online Identity Study.

The sophistication of AI-generated fraud has reached the point where modern fraudsters can produce identity documents, facial biometrics, and voice authentication samples that defeat many verification checks in isolation.

The industry response has been to invest heavily in deeper liveness detection, more sophisticated document forensics, and increasingly complex biometric checks. These investments are necessary and valuable. 

But there is a structural problem with the defensive posture they create: deepfake fraud is specifically designed to defeat identity checks. Every advance in document liveness detection is met with a corresponding advance in document generation. Every improvement in biometric matching is met with an improvement in face synthesis. The arms race runs at the speed of AI development - and in 2026, that is very fast.

The question worth asking is not just how to make identity checks better at catching deepfakes. It is whether there is a verification layer that deepfake fraud is harder to defeat - one that the AI-generated fraud stack finds more difficult to fabricate convincingly. There is. It is contact point verification. And it is the check that most verification stacks are running last, or not at all, when it should be running first.

What synthetic identity and deepfake fraud require

To understand why CPV is the hardest layer for deepfake fraud to defeat, it helps to understand what a successful synthetic identity or deepfake fraud attempt actually requires from the attacker.

A synthetic identity is constructed from a combination of real and fabricated personal information. 

The fraudster may use a real PAN number or Aadhaar number combined with a fabricated name, date of birth, and address. They create a credit history by piggybacking on legitimate accounts or by opening low-value accounts and building a payment history before graduating to high-value fraud. The identity is designed to pass automated verification checks - to produce a bureau score, to match on KYC databases, to present documents that OCR systems will accept.

A deepfake fraud attempt goes further - the fraudster uses AI-generated facial imagery or video to defeat biometric liveness checks, producing a face that matches the identity document they have constructed or stolen and that passes the facial matching check the verification system requires.

What both of these fraud types require, but rarely fabricate convincingly, is a contact point that is simultaneously:

  • Active in a live telco database with a real subscriber record

  • Associated with usage patterns consistent with a genuine individual's phone behaviour

  • Not flagged in fraud intelligence databases as associated with high-velocity account creation

  • Not associated with known fraud rings, SIM swap patterns, or synthetic identity clusters

  • Matched to a deliverable physical address that is consistent with the claimed identity

Fabricating a deepfake face is, in 2026, within the capability of reasonably sophisticated fraudsters. 

Fabricating a phone number that passes all five of these contact point checks simultaneously is significantly harder - and at scale, across thousands of synthetic identities, it is a resource constraint that limits the fraud operation even when the document and biometric layers have been defeated.

495%

projected surge in deepfake fraud in 2026

700%

YoY rise in injection attacks on biometric verification - Jumio 2026

$3.5B

consumer losses to imposter scams - FTC 2025

Why the contact point is where synthetic identity fraud is most vulnerable

The deep structural reason that CPV catches synthetic identity fraud that document and biometric checks miss is the network intelligence dimension.

A phone number does not exist in isolation. It has a history - how long it has been active, how many accounts it has been used to open, whether it has appeared in fraud reports, whether the subscriber account it belongs to was recently activated, whether the SIM associated with it has been swapped recently. This history is available in telco databases and fraud intelligence networks. It is not available from the number itself. And it is the history that reveals synthetic identity fraud at a level of reliability that document fabrication cannot evade.

A synthetic identity constructed with a newly activated SIM - which is what most synthetic identity operations use, because they need a clean phone number for each fabricated identity - will present a phone number that is active but has no history. No prior accounts. A very recent activation date. 

No usage pattern consistent with a genuine individual's phone. These signals are detectable at the contact point layer before any document is examined. The fraud operation needs to produce hundreds or thousands of synthetic identities. It cannot produce hundreds or thousands of phone numbers that all have the kind of history that genuine individuals accumulate over years of normal use.

This is the asymmetry that makes CPV the most cost-effective deepfake fraud detection layer available. The fraudster can generate a convincing face. They cannot generate a convincing phone history. The contact point check catches what the face check cannot.

The optimal position for CPV in the verification stack

Most verification stacks currently run CPV at the end - after identity document verification, after biometric matching, and often only as part of the fraud review process when an application has already been flagged as suspicious. This ordering is counterproductive for two reasons.

First, it means that expensive document and biometric verification checks are running on applications that CPV would have rejected in milliseconds at the beginning. The cost of a biometric liveness check is orders of magnitude higher than the cost of a phone number verification. Running the expensive checks before the cheap ones inverts the cost-efficiency logic of a well-designed fraud prevention stack.

Second, it means that the fraud detection sequence is optimised for the fraud types that CPV is least suited to catching - document fraud - rather than for the fraud types that CPV is most suited to catching - synthetic identity and organised ring fraud at scale. If the document check is first in the stack, the fraudster who defeats it is already deep in the verification journey before CPV gets a chance to surface the network signals that would have caught them at the front door.

The optimal position for CPV in the verification stack is first, not last. Before the identity document is examined. Before the biometric liveness check is run. Before any expensive verification infrastructure is engaged. The contact point check is the lowest-cost, highest-signal fraud detection step available - and running it first means that the applications which fail it never consume the more expensive checks that follow.

The specific signals CPV provides for deepfake fraud detection

Beyond the basic active/inactive check, a well-implemented digital CPV layer provides a set of signals that are specifically relevant to deepfake and synthetic identity fraud detection.

SIM age and activation patterns. A SIM that was activated in the last 30 days and is being used to open a financial account is a materially higher-risk signal than a SIM associated with a subscriber who has been active for three years. At the population level, the proportion of genuine applicants with very recently activated SIMs is low. The proportion of synthetic identity applicants with recently activated SIMs is high - because fraud operations need fresh SIMs for each synthetic identity they construct.

SIM swap recency. A SIM swap in the last 72 hours before an onboarding attempt is one of the strongest fraud signals in the verification stack. It indicates that the phone number has recently changed hands - either as part of an account takeover operation targeting the legitimate holder, or as part of a synthetic identity construction where the fraudster has acquired a phone number with an existing history by engineering a swap. RBI guidelines on SIM swap detection for digital banking transactions make this check not just a fraud best practice but an emerging regulatory expectation.

Phone number to identity coherence. The geographic registration of the phone number, the network operator, and the subscriber account type should be coherent with the identity being presented. A phone number registered in a different state than the declared address, on a prepaid SIM with no subscriber name associated, presenting an identity document with a third state of residence is a coherence failure that suggests synthetic construction. No single signal is definitive; the combination is.

Address deliverability and fraud history. An address verification check that goes beyond postal validity to include deliverability status - is this address currently receiving mail? - and fraud database history - has this address appeared in fraud reports, been associated with known fraud operations, or flagged as a freight forwarder or virtual mailbox - provides a second layer of network intelligence that deepfake fraud cannot easily fabricate around.

The arms race problem - and why CPV holds up better than document checks

The deepfake fraud arms race is a genuine concern for the industry. As liveness detection improves, face generation improves. As document forensics advance, document generation advances. The trajectory of AI development suggests this race will continue for the foreseeable future, with periods of detection advantage giving way to periods of fraudster advantage as new generation techniques emerge.

CPV does not face the same arms race dynamic - and this is the structural argument for its long-term value in the fraud prevention stack.

Document and biometric fraud is a software problem. The fraudster needs better generative AI to defeat better detection AI. Software development is fast. Advantage cycles are short.

Contact point fraud is an infrastructure problem. The fraudster needs real phone numbers with genuine usage histories, real addresses with genuine occupancy histories, and real email addresses with genuine digital footprints. Building this infrastructure at scale - maintaining thousands of phone numbers with sufficient history to pass contact point verification for each synthetic identity - is expensive, slow, and limited by real-world constraints that software alone cannot solve. A fraudster who needs one thousand synthetic identities needs one thousand phone numbers with plausible histories. Those histories take years to build, not weeks. That is a constraint the fraud operation cannot code its way around.

This is why CPV holds up better against the fraud escalation trajectory of 2026 than document and biometric checks alone. It is not immune to fraud - nothing is. But the resource cost to defeat it at scale is fundamentally higher than the resource cost to defeat a document check, because the contact point signals are grounded in real-world infrastructure constraints that AI cannot fabricate.

The implementation argument

For fraud and identity teams evaluating where to invest their next fraud prevention budget, the CPV case is straightforward on the economics.

A digital CPV check - phone number verification against live telco database plus address verification against deliverability and fraud intelligence databases - is among the lowest-cost verification checks available per unit. It runs in milliseconds. It requires no customer interaction. It can be integrated at the very first step of the onboarding journey through a simple API call.

The fraud it catches at that step - synthetic identities with network signals that reveal their construction, SIM swaps that indicate account takeover attempts, addresses associated with known fraud patterns - is fraud that would otherwise progress through the entire verification journey and in many cases succeed. The catch rate at the contact point layer for organised, ring-based synthetic identity fraud is higher than the catch rate at the document layer, because organised fraud has the resources to fabricate convincing documents but cannot easily fabricate convincing contact infrastructure at scale.

The deepfake fraud surge of 2026 is real and the investment in defeating it at the document and biometric layer is necessary. But the fastest, cheapest, and in many cases most reliable detection point is the one that comes before the document is ever examined. Check the contact point first. The deepfake fraud problem does not start there - but for a significant proportion of the fraud attempts that reach the document layer, it ends there.

One platform. Across workflows.

One platform. Across workflows.

Tartan helps teams integrate, enrich, and validate critical customer data across workflows, not as a one-off step but as an infrastructure layer.

Tartan helps teams integrate, enrich, and validate critical customer data across workflows, not as a one-off step but as an infrastructure layer.

Tartan helps teams integrate, enrich, and validate critical customer data across workflows, not as a one-off step but as an infrastructure layer.