Verihubs Logo
Home Blog Deepfake Fraud in the Philippines: How to Detect and Stop It
12 min read Deepfake Detection Published on June 30, 2026

Deepfake Fraud in the Philippines: How to Detect and Stop It

Deepfake Fraud in the Philippines: How to Detect and Stop It

Deepfake fraud in the Philippines is accelerating: according to Sumsub internal statistics cited in BusinessWorld (January 2026), synthetic identity document fraud surged 291% in the first half of 2025 compared to the same period in 2024, making the Philippines the second-fastest growing deepfake fraud environment in Asia-Pacific. Deepfakes are now used to bypass eKYC liveness detection, forge identity documents, and create synthetic accounts at scale. The Philippine government launched a formal inter-agency crackdown in April 2026 through a DOJ-PCO-DICT Memorandum of Agreement. Financial institutions need AI-powered deepfake detection, not just passive liveness, to stop this threat at onboarding.

What Is Deepfake Fraud?

Deepfake fraud refers to the use of AI-generated or AI-manipulated images, video, or audio to deceive identity verification systems, impersonate individuals, or create entirely fabricated identities. In the context of financial services, the primary target is eKYC onboarding: fraudsters use deepfake technology to pass selfie verification, fool liveness detection tests, and open accounts in identities that do not correspond to the real person holding the device.

Unlike traditional identity fraud, which relies on stolen physical documents, deepfake fraud can operate entirely in the digital layer. A fraudster does not need to steal your wallet. They need an AI tool, a stolen ID photo, and a fake camera feed that injects fabricated biometric data into the verification system.

Deepfake Fraud in the Philippines: Scale and Acceleration

Three data points define the current scale of the problem.

According to Sumsub internal statistics cited in BusinessWorld reporting (January 2026), synthetic identity document fraud in the Philippines increased 291% in the first half of 2025 compared to the same period in 2024. That is the second-highest jump in Asia-Pacific. This figure covers synthetic identity documents created using AI, not just traditional document forgery.

But the synthetic ID surge is only one piece of a wider pattern. According to TransUnion Philippines data cited in BusinessWorld (April 2025), the Philippines has consistently exceeded the global digital fraud rate of 5.4% since 2020, with identity-related fraud surging 121% in 2024. According to Asian Banking and Finance reporting (February 2025), 8.3% of all digital transactions in 2023 were flagged as fraudulent.

Once the scale became impossible to ignore, the government moved. In April 2026, the Department of Justice, the Presidential Communications Office, and the Department of Information and Communications Technology signed a Memorandum of Agreement to formalize inter-agency coordination on deepfake crackdowns, recognizing deepfake fraud as a national-level threat to digital financial infrastructure. According to Biometric Update reporting (April 2026), DOJ Secretary Frederick Vida, PCO Secretary Dave Gomez, and DICT Secretary Henry Aguda signed the MOA at DOJ headquarters in Manila.

How Deepfakes Attack eKYC Systems: Two Attack Types

Deepfake attacks on eKYC systems fall into two distinct categories that require different detection approaches.

Attack TypeMethodDetection DifficultyPhilippine Exposure
Presentation attackFake face shown to physical camera via screen, mask, or deepfake toolMedium; defeated by active liveness with unpredictable promptsHigh: targets digital bank and e-wallet onboarding
Injection attackSynthetic video inserted directly into data stream, bypassing cameraHigh; requires camera metadata and signal consistency checksGrowing: increasingly used by organized fraud groups
Document forgeryAI-generated government ID documents with pixel-level manipulationHigh; requires AI forensics beyond template matchingHigh: 291% synthetic document fraud surge in H1 2025

Presentation Attacks

A presentation attack involves presenting a fabricated image or video to the camera of a real device. Early presentation attacks used printed photos. Modern attacks use screens displaying high-resolution videos of the target face, 3D masks, or generative AI tools like DeepFaceLive and Magicam that manipulate a live camera feed in real time. According to Veriff identity verification research (November 2025), AI-powered scam tools can now alter a fraudster’s face, voice, gender, and race during live video calls, meaning a fraudster can simultaneously match the stolen ID photo and appear live on camera with a deepfake persona.

Traditional passive liveness detection, which checks for blinking, head movement, or depth cues, is increasingly ineffective against modern presentation attacks. According to Signicat research, 42.5% of fraud attempts now use AI, with 29% of such attacks successfully breaching company defenses. Active liveness prompts requiring specific movements can be defeated by AI tools trained on adversarial samples.

Injection Attacks

An injection attack bypasses the camera entirely. Instead of presenting a fake face to the physical camera, the attacker injects fabricated video data directly into the data stream between the camera hardware and the verification application. The verification system receives what looks like camera input, but it is actually a synthetic video stream generated by the attacker’s tools. Injection attacks are considerably harder to detect because they do not require the fake face to survive real-world camera optics.

According to Respicio and Co. legal analysis (July 2025), Philippine fintechs are increasingly adopting face-movement challenge-response and NFC e-passport verification specifically to counter deepfake KYC video attacks, indicating that the threat is already shaping product decisions in the Philippine market.

Deepfake injection attack vs presentation attack on eKYC systems Philippines fintech

Why Philippine Financial Institutions Are Particularly Exposed

Three features of the Philippine digital finance environment amplify deepfake fraud risk.

Digital-first onboarding at scale. The six licensed Philippine digital banks grew their depositor base from 3.6 million to 8.7 million between June 2023 and June 2024 entirely through eKYC onboarding. BSP licenses 42 EMI-NBFIs and 28 EMI-banks as of July 2025. Every one of these institutions relies on remote biometric verification without a branch alternative. At this volume, even a small percentage of deepfake-enabled synthetic accounts represents a substantial fraud exposure.

High value of synthetic account networks for laundering. Synthetic accounts created through deepfake-bypassed eKYC are not just used for direct fraud. They are the infrastructure of smurfing and money laundering networks. A network of 100 synthetic accounts with PHP 400,000 per account per day can structure PHP 40 million in deposits daily without triggering a single CTR. The deepfake problem is inseparable from the AML problem.

Weak detection in older eKYC implementations. Many Philippine fintech platforms implemented eKYC before deepfake attacks became commercially scalable. Those implementations relied on passive liveness, basic photo-to-selfie matching, and OCR without AI-level document forensics. That generation of eKYC is no longer sufficient. According to iProov CTO Dominic Forrest in BusinessWorld (January 2026), synthetic fraud is vastly underestimated, with 2026 expected to be the year the true scale begins to be understood.

What Effective Deepfake Detection Requires

Stopping deepfake fraud at eKYC onboarding requires layered controls that go beyond basic liveness detection.

Active liveness with unpredictable, randomized challenges is the first upgrade. Passive liveness is no longer sufficient. Active liveness requiring specific, randomized movements creates a higher bar for AI manipulation tools, which need to predict and replicate the challenge in real time.

Deepfake-specific AI detection runs as a second layer, independent of liveness. Dedicated deepfake detection models trained on synthetic media signatures can identify the artifacts left by generative AI tools, including unnatural texture gradients, compression artifacts from re-encoded video, and micro-expression inconsistencies that human reviewers miss. This layer operates independently of liveness and catches attacks that pass basic movement checks.

Injection attack detection requires a different approach entirely. Camera metadata analysis, device environment checks, and signal consistency verification can identify when the video stream being received does not match the expected behavior of a real camera on a real device.

Document forensics is the fourth layer, and the most underdeployed. AI-generated identity documents have improved dramatically. Document verification that only checks formatting and font is insufficient. AI-powered document forensics analyzes pixel-level consistency, printing artifact patterns, and security feature integrity to identify documents generated by AI rather than printed by a government authority.

Verihubs Deepfake Detection for Philippine eKYC

Verihubs eKYC API is built with deepfake detection as a core layer, not an add-on. The system combines biometric verification with AI-powered liveness detection trained specifically to identify modern deepfake attack patterns, including face-swap attacks, injection attacks, and AI-generated document fraud. For Philippine financial institutions operating at scale under BSP Circular 1170 eKYC requirements, this provides a detection capability that keeps pace with the accelerating sophistication of deepfake tools.

Frequently Asked Questions About Deepfake Fraud in the Philippines

How bad is deepfake fraud in the Philippines?

According to Sumsub internal statistics cited in BusinessWorld (January 2026), synthetic identity document fraud in the Philippines surged 291% in the first half of 2025 compared to the same period in 2024, the second-highest increase in Asia-Pacific. The Philippines government launched a formal inter-agency crackdown through a DOJ-PCO-DICT MOA in April 2026.

How do deepfakes bypass liveness detection?

Modern deepfake tools use presentation attacks (displaying AI-manipulated video to the camera) and injection attacks (inserting synthetic video directly into the data stream bypassing the camera). Advanced tools like DeepFaceLive can replicate active liveness prompts including blinking, head turns, and facial expressions in real time.

What is the difference between a presentation attack and an injection attack?

A presentation attack involves showing a fake face to the physical camera of a device. An injection attack bypasses the camera entirely by inserting fabricated video data directly into the verification system’s data stream. Injection attacks are generally harder to detect because they do not need to survive real camera optics.

Is deepfake fraud illegal in the Philippines?

Yes. Using deepfakes to fraudulently pass identity verification constitutes identity fraud under Republic Act No. 10175 (Cybercrime Prevention Act) and potentially estafa under the Revised Penal Code. The Philippine government formalized inter-agency deepfake enforcement coordination through a DOJ-PCO-DICT MOA signed in April 2026.

How does Verihubs stop deepfake fraud?

Verihubs eKYC API combines AI-powered liveness detection with dedicated deepfake detection models that identify synthetic face manipulation, injection attack signatures, and AI-generated document forgeries. The system is designed for the Philippine regulatory environment under BSP Circular 1170 eKYC requirements.

Liveness Detection Alone Is No Longer Enough

The gap between what most Philippine fintechs have deployed and what 2025-era deepfake tools can defeat is wider than most compliance teams realize. The 291% surge in synthetic identity fraud in the Philippines in 2025 is not an anomaly. It is the visible outcome of AI tools becoming commercially accessible to criminal networks at scale. Every Philippine financial institution that relies solely on passive liveness detection for eKYC is operating with a defense that was designed for a threat environment that no longer exists.

Deepfake detection requires a dedicated AI layer, trained on adversarial synthetic media, that works alongside liveness to catch what liveness alone misses. Verihubs provides that layer, built for the Philippine market and compliant with BSP Circular 1170 eKYC requirements.

Talk to the Verihubs team about deepfake-resistant eKYC for your Philippine onboarding workflow.

Client Verihubs
Detect Face Swap with Verihubs Deepfake Detection
Get FREE Trial
View Blog