← Back to list

How One Man Fooled a Bank 46 Times: The Reality of Synthetic Identity Fraud

In March 2026, a courtroom in the Netherlands became the setting for a story that feels like it belongs in a movie. A man stood accused of…

Malaika Sohail · 2026-04-22 13:08 · 0 claps · 5.0 min read
#deepfake-fraud-2026 #amld6 #synthetic-identities
Open on Medium ↗
Wiki topics: GEN · Genomics & Sequencing 🎬 · Film & Television ⚖️ · Law & Justice

How One Man Fooled a Bank 46 Times: The Reality of Synthetic Identity Fraud

In March 2026, a courtroom in the Netherlands became the setting for a story that feels like it belongs in a movie. A man stood accused of something incredible: he successfully opened 46 different bank accounts at one of the country’s biggest financial institutions, ABN AMRO. He didn’t use a gang of professional hackers, he didn’t break into a vault, and he didn’t bribe anyone.

He did it all from his living room with a laptop and a clever piece of software.

According to reports from **DutchNews.nl**, this case has sent a massive shockwave through the business world. It wasn’t just a simple crime; it was proof that the “digital mirrors” we’ve trusted for a decade — those quick face scans we do on our phones — can now be shattered.

The Scam: How it Started with a Fake Apartment

The man’s strategy was surprisingly simple. He started by posting fake apartment rental ads in Amsterdam on a popular local website, Marktplaats. Because the housing market is so crowded, people are desperate. When they messaged him, he asked them to send a photo of their ID card “to verify their identity” before they could see the place.

Most people, wanting the apartment, sent the photos without a second thought. Once the man had these IDs, he had everything he needed. He took the victims’ photos and used deepfake technology to create a moving, 3D digital “mask” of their faces that perfectly mimicked his own expressions.

He then went to the bank’s website to open an account. When the bank’s security check asked him to take a live selfie, he “put on” his digital mask. He blinked, he smiled, and he turned his head exactly when the app told him to. The bank’s security system “saw” the person on the ID and let him in.

He did this 46 times. He was only caught on his 47th attempt because of a clumsy human error: he accidentally tried to use a woman’s ID while using his own male deepfake face.

The “Working”: How the Magic Trick Fooled the Tech

To understand how he pulled this off, you have to understand a trick called a “camera hijack” (or an “injection attack”).

Normally, when you take a selfie for an app, you think the app is looking through your phone’s physical camera lens. But this man used a “virtual camera.” Think of it like a high-tech “filter” on social media, but instead of adding dog ears, it replaces your entire face with a digital version of someone else.

Here is the simple breakdown of how it works:

  • The Hijack: The fraudster uses software to sit between the computer’s camera hardware and the banking app.
  • The Switch: He tells the app, “Don’t look at my real face. Look at this video file instead.”
  • The Performance: As the security check asks him to “Blink now” or “Turn your head,” the fraudster complies. His software instantly maps his movements onto the stolen face in the video.

Research from the **Sensity 2024 “Face Off” study using the Deepfake Offensive Toolkit (DOT) found that 9 out of 10 identity check systems** were completely unprepared for this kind of “virtual camera” trick. They were so focused on analyzing the face that they didn’t check where the video stream was actually coming from.

The Huge Rise in Digital “Ghosts”

The Amsterdam story is just the tip of the iceberg. We are now living in a world where “seeing is no longer believing,” and the numbers are honestly quite scary.

  • Industry-Wide Surge: Globally, deepfake-related fraud attempts have exploded. Recent industry data shows that these attacks have increased by over 2,000% in the last few years as AI tools have become cheaper and easier to use.
  • Waning Trust: In the report **“Predicts 2024: AI & Cybersecurity — Turning Disruption into an Opportunity,” Gartner predicts that by the end of 2026, 30% of large enterprises** will no longer consider standalone facial biometrics to be a reliable way to verify identity on their own.
  • The Price of Failure: For a business, the risk is massive. According to **Shufti Pro’s internal 2025 impact analysis, the average cost to a large company for missing just one of these sophisticated deepfakes is nearly $680,000** once you factor in legal fees, lost money, and regulatory fines.

The Law is Getting Tougher (AMLD6)

Because of cases like the one in Amsterdam, the law is changing fast. A new rule called AMLD6 (the Sixth Anti-Money Laundering Directive) has changed the game for business owners.

In the past, if a fraudster used a fake ID to open an account, only the fraudster got in trouble. But under the new rules, the company can be held responsible too. If your business doesn’t have strong enough security to stop these deepfakes, you could face massive fines or even legal action for “failing to prevent” financial crime. The government’s message is clear: “It’s your job to make sure the person is real.”

The Solution: Moving from “Looking Real” to “Being Real”

So, if an AI can look exactly like a human, how do we stop it? The answer is to stop looking at the face and start looking at the source. We are moving into a new era called “Official Source Verification.” Here are the two ways modern businesses stay safe:

1. The “Digital Heartbeat” Check. Instead of just looking at the video, the system checks the “digital signature” of the phone itself. It ensures the video is coming from the actual physical lens and not a “virtual camera” file. If the system detects a hijack, it blocks the attempt instantly.

2. Direct Government Pings. This is the most secure way to work. Instead of asking a user like “Sarah” to take a photo of her passport (which could be a deepfake), we ask her to log in through a government-backed digital identity framework.

  • In the European Union, this means using eIDAS-compliant systems like DigiD in the Netherlands.
  • In the Middle East, the gold standard is **UAE Pass**.

We aren’t “guessing” if her photo matches her ID card. We are asking the official database, “Is this person who they say they are?” When the system says “Yes,” you know for a fact that the person exists and is real. No more guessing, no more blurry photos, and no more deepfakes.

The Future of Digital Trust

The 46 bank accounts opened in Amsterdam prove that the “identity crisis” of 2026 is real. But it also shows us the path forward. The businesses that will win in this new era are the ones that stop trying to “win” a visual battle with AI and start building security around hardware and government-backed data.

Speed is a way to show respect to your customers, but security is how you protect your business. You want to make it as easy as possible for a real person to join you, but impossible for a “ghost” to get through the door.

Think about your own business for a second. If a professional deepfake tried to sign up for your service tonight, would your system catch them on the first try — or would you only find out when account #46 has already moved the money?

Stop the “Ghosts” before they enter. Shufti’s Deepfake Detector and eIDV integration (supporting systems like UAE Pass and eIDAS/DigiD) are designed to catch fake videos and “Virtual Camera” tricks in under 3 seconds. We give you 100% verified truth with zero document uploads. Don’t wait to become the next headline. **Secure your business with Shufti today.**


메타데이터
post_id
7ea00a44382f
slug
how-one-man-fooled-a-bank-46-times-the-reality-of-synthetic-identity-fraud-7ea00a44382f
url
https://medium.com/@Compliance_Journal_By_Shufti/how-one-man-fooled-a-bank-46-times-the-reality-of-synthetic-identity-fraud-7ea00a44382f
canonical_url
https://medium.com/@Compliance_Journal_By_Shufti/how-one-man-fooled-a-bank-46-times-the-reality-of-synthetic-identity-fraud-7ea00a44382f
author_url
https://medium.com/@Compliance_Journal_By_Shufti
status
ok
fetched_at
2026-08-01 02:08:18