The report
A deepfake does not have to defeat every layer of a banking system to matter. Sometimes it only has to reach the step that lets an attacker replace the next trusted factor.
KZ-CERT documented that pattern in a May 2024 fraud advisory. According to the advisory, an attacker first recorded a bank customer's face during a messenger video call. The previously recorded material was then used with DeepFake face substitution while the customer's identity was confirmed through bank video verification.
The sequence did not end at the camera check. KZ-CERT reported that the trusted phone number was then changed to the attacker's number, authentication continued through that changed number, and funds were transferred to accounts controlled through third parties.
The important part is the trust transition
The most consequential step is not simply that synthetic or replayed facial material appeared during video verification. It is what successful verification was allowed to authorize next.
In the sequence described by KZ-CERT, video verification preceded replacement of the trusted phone number. That makes the biometric step a recovery pivot: if defeating one verification stage can establish a new trusted possession factor, the attacker may no longer need to keep defeating the biometric system afterward.
This is why account recovery deserves to be treated as part of the authentication boundary rather than as a separate convenience flow. A control that appears narrow in isolation can become high-impact when it is allowed to rewrite another trusted factor.
What the evidence does and does not show
The advisory supports a specific documented sequence: facial-video capture, DeepFake-assisted bank video verification, trusted-number replacement, subsequent authentication and transfer of funds. KZ-CERT also explicitly stated that DeepFake technology was used in the fraud type it described.
It does not identify the affected bank. It also does not establish that every bank, every present-day recovery implementation or a modern deepfake-aware verification system remains susceptible to the same technique.
The defensible lesson is narrower and more useful: when identity verification can authorize replacement of another authentication factor, the security of the recovery path depends on the whole chain, not only on the quality of the camera check.