# Fraud rings now operate like a business—and one-time onboarding checks aren’t enough

By MarketScale Newsroom · Published 2026-09-22 · Updated 2026-09-23 · Business Services on MarketScale
Canonical: https://www.marketscale.com/industries/business-services/fraud-rings-now-run-as-a-business-that-one-time-onboarding-checks-cannot-catch

> M&T Bank's Karen Boyer and Mitek's Adam Basia say fraud rings now recruit on Telegram, season synthetic accounts early and repeat any gap they find.

## Key points

- Synthetic sleeper accounts opened before the pandemic were later used to funnel EIDL relief funds, so a clean opening period no longer proves an account is legitimate.
- Check fraud has moved from washing one paper check to digitizing a genuine check and depositing the template at multiple banks; the check is real, so the activity around it is the only tell.
- A face-morphed video call can now match a fake ID, which pushes banks from verifying data to authenticating the person typing it and monitoring transactions for the life of the account.

Karen Boyer spends part of her week in industry groups, IFCI, BPI and the ABA among them, and she was careful to say on Mitek Systems' Fraud and Focus podcast that she was describing what those groups see across the industry, not what any one bank sees. What they see is a criminal trade with no entry requirements. A fraudster once had to find a dark net forum and get another criminal to vouch for them, Boyer, senior vice president of financial crimes at M&T Bank, told host Adam Basia, who leads product marketing at Mitek.

> But now it's just at scale, I just have to download Telegram, and I'm part of it now. — Karen Boyer, Senior Vice President, Financial Crimes, M&T Bank

That change ties together what Basia calls the four horsemen: deepfakes, data breaches, template attacks and injection attacks. Each is a separate problem. Together, Boyer and Basia argue, they turn fraud into a business that is tested, refined and resold, and that a one-time onboarding check was never built to stop.

## Check cooking shows how a single hit becomes a run

Basia points to check fraud, which he said has occupied Mitek for a large share of its history, as the clearest example. Check washing meant stealing one paper check, lifting the ink and getting one attempt. Now, he said, a criminal photographs the check, builds a template and deposits the same image at multiple institutions, altering it slightly after each success.

Boyer corrected him on one point: the deposits do not just get attempted, they clear. The check itself is genuine, taken from stolen mail, so the counterfeit-detection work banks spent years building around check stock has nothing to flag. What gives the scheme away is the activity around the check, she said, and regulations written for paper originals have not caught up with the technology.

For a payments or operations leader the lesson is uncomfortable. A control that goes quiet is not a control that is finished. Basia compared fraudsters to water that always finds the path of least resistance, and said the industry never gets to drop a defense, only add to it.

## A fake ID and a face morph beat the front door

Deepfakes get the headlines because they are visual, Basia said. Boyer said the threat is neither overstated nor fearmongering, and it predates the generative AI news cycle. In her investigator days, one question to a scam victim, whether they had ever met the person, was often enough to break the spell. Today victims answer that they FaceTime the person every day, and some of those faces are morphed to match a fake profile.

The same tools hit onboarding, where the bank has no history on the applicant at all.

> But I can generate a fake ID online for $3.95. I can use a quick tool like Magic Cam or something else to face morph myself to look like whatever person is on that ID. — Adam Basia, Product Marketing Lead, Mitek Systems

Adaptive Security, a security awareness training vendor, describes on its own site a January 2024 case in which a finance worker at an engineering firm authorized $25.6 million in wire transfers to accounts controlled by AI-generated impersonators, on a video call where every other participant was a deepfake. The same material lists identity verification and know-your-customer systems as under pressure from AI-generated documents, synthetic identities and digital injection attacks. It is marketing for a training product and carries the vendor's interest, but the case it cites is dated and specific.

Boyer said the onboarding problem is spreading past banks into underwriting, title companies and real estate, and into hiring, where employers are discovering that applicants can pretend to be other people. Basia added that the branch deserves attention. A teller in Austin, Texas has no way to know what a Minnesota driver's license should look like, he said, and the digital defenses banks built in 2020 did not follow customers into the branch, which can make it easier to open a mule account in person.

## Sleeper accounts waited for a pandemic that had not started yet

Every synthetic identity starts with something real, Basia said: stolen personal data from breaches, of which there is now no shortage. He asked whether that reality has changed how Boyer views trust at onboarding. Her answer was that it has not, because her career has run on guilty until proven innocent, but the bar for proof has moved.

A decade ago, matching an application's data to identity verification records counted for something, because the applicant had to know all of it. Now, Boyer said, that step proves little on its own. The work shifts to what she calls identity authentication, proving that the person typing Adam's information is Adam, with other digital signals doing the same job.

The long game is where the damage hides. At a bank where she worked previously, Boyer said, her team spotted synthetic sleeper accounts in 2020 and watched them in what she described as a honeypot. When EIDL pandemic relief arrived, the accounts began funneling government funds, even though they had been opened before the pandemic existed, farmed and seasoned for a bust-out whose target the fraudsters had not yet chosen.

Basia said he sees the same pattern: accounts built quietly to accumulate credit, then busted out, sold on Telegram or turned to money laundering. Boyer said the seasoning and the bust-out are often done by different people, with the account changing hands in between. Credit monitoring catches little of this, she said, and identity theft with no credit component at all, such as a stolen identity carrying a heroin-trafficking warrant, stays under the radar.

## One gap at one bank becomes a flood everywhere

Template attacks give the model its scale. Once a ring finds a document type or application pattern that passes at one institution, Basia said, it repeats it thousands of times and moves to the next. He asked whether the past two years feel like a shift from isolated attacks to something industrialized.

> And it's almost like the new phishing where it's okay. Well, I'm gonna send a thousand emails out. And if I get 10 people to answer, that's still a good day. — Karen Boyer, Senior Vice President, Financial Crimes, M&T Bank

Boyer offered a hypothetical, with her usual disclaimer that she has no inside knowledge of any bank's controls: a ring learns that one bank accepts passport cards its document check handles poorly, floods it, then scouts for other banks using the same vendor. The consequence for a fraud or risk executive is that onboarding cannot be treated as a gate, she said. It has to be one input into monitoring that runs for the life of the account.

> That's why you also can't just trust the onboarding and you have to have the continuous monitoring of the transactions. And that's how you're going to find the root cause of what might be the broken control of the onboarding. — Karen Boyer, Senior Vice President, Financial Crimes, M&T Bank

The old rule of thumb that a bad account reveals itself within a few months of opening no longer holds for sophisticated schemes, she said. Losses have to be reviewed at scale, not one by one, to find the shared feature that traces back to a broken control at application time. Basia said fraud defense is by nature a little reactive: the first sighting of a new tactic is usually a loss, and the job then is to search the book for everything that resembles it before it breaks out.

## Injection attacks arrive looking like normal traffic

The fourth horseman used to seem technical even to him, Basia said. Free virtual cameras and online tutorial libraries now let someone with a decent laptop push content straight into a verification system in minutes. Boyer's response was blunt: a well-executed injection attack does not look like an attack, it looks like ordinary activity, so the industry is less sure how much it is seeing than how much it is missing.

That is the practical question for a bank or fintech buying identity tooling, and for the CFO signing off on it. Basia's warning is that nothing gets retired, since check fraud returned once the industry assumed it was solved. Boyer's signal is more specific: when losses examined together share a document type, a channel or a vendor path that dates to onboarding, that commonality is the broken control, and a ring is already testing it at the next bank.

## Sources

- [Deepfake Attack Examples: 11 Real-World Cases of AI Voice Cloning, Video Impersonation, and Synthetic Media Fraud](https://www.adaptivesecurity.com/blog/11-deepfake-attack-examples-2026) (Adaptive Security)

Tags: Mitek Systems, M&T Bank, fraud prevention, identity verification, financial services, risk and compliance

---
Source: MarketScale, https://www.marketscale.com/industries/business-services/fraud-rings-now-run-as-a-business-that-one-time-onboarding-checks-cannot-catch. Published for AI indexing and citation; cite the canonical URL. Site guide for agents: https://www.marketscale.com/llms.txt
