Analysis · DiggingBeagle record

When a deepfake can become an account-recovery pivot

A KZ-CERT advisory documented a fraud sequence in which facial video captured during a messenger call was reused with DeepFake technology during bank video verification, followed by replacement of the trusted phone number and subsequent account access. The important security boundary is the transition from proving identity to establishing a new trusted authentication factor.

Analysis synthesizing underlying research. Follow the linked dossiers for Claim-level evidence.

The report

A deepfake does not have to defeat every layer of a banking system to matter. Sometimes it only has to reach the step that lets an attacker replace the next trusted factor.

KZ-CERT documented that pattern in a May 2024 fraud advisory. According to the advisory, an attacker first recorded a bank customer's face during a messenger video call. The previously recorded material was then used with DeepFake face substitution while the customer's identity was confirmed through bank video verification.

The sequence did not end at the camera check. KZ-CERT reported that the trusted phone number was then changed to the attacker's number, authentication continued through that changed number, and funds were transferred to accounts controlled through third parties.

The important part is the trust transition

The most consequential step is not simply that synthetic or replayed facial material appeared during video verification. It is what successful verification was allowed to authorize next.

In the sequence described by KZ-CERT, video verification preceded replacement of the trusted phone number. That makes the biometric step a recovery pivot: if defeating one verification stage can establish a new trusted possession factor, the attacker may no longer need to keep defeating the biometric system afterward.

This is why account recovery deserves to be treated as part of the authentication boundary rather than as a separate convenience flow. A control that appears narrow in isolation can become high-impact when it is allowed to rewrite another trusted factor.

What the evidence does and does not show

The advisory supports a specific documented sequence: facial-video capture, DeepFake-assisted bank video verification, trusted-number replacement, subsequent authentication and transfer of funds. KZ-CERT also explicitly stated that DeepFake technology was used in the fraud type it described.

It does not identify the affected bank. It also does not establish that every bank, every present-day recovery implementation or a modern deepfake-aware verification system remains susceptible to the same technique.

The defensible lesson is narrower and more useful: when identity verification can authorize replacement of another authentication factor, the security of the recovery path depends on the whole chain, not only on the quality of the camera check.

Research behind this

Cite this record

DiggingBeagle. “When a deepfake can become an account-recovery pivot.” https://diggingbeagle.com/articles/when-a-deepfake-can-become-an-account-recovery-pivot/

Citation guidance

Independent research

The source stays with the story.

Claims, evidence and corrections remain inspectable. About the project · Our methodology