INQUEST INSIGHTS
SYNTHETIC IDENTITIES – EVOLUTION OF AI AS A THREAT
404 Media, 7 February 2024
Source: 404 Media
Risk Category: Cybersecurity/ Technological Risk
Emerging technology has disrupted the existing fabric of technological advancement, particularly with the advent of artificial intelligence. As machines become capable of thinking, humans struggle to keep systems in check. One such disruptive model emerged with an underground website called OnlyFake, claiming to generate realistic fake IDs and enabling a sleuth of unethical and illegal activities. They claim to use ‘neural networks’ to generate hundreds of documents using Excel data. Neural networks mimic biological neurons to emulate the human brain and lie at the intersection of machine learning, deep learning and artificial intelligence.
The platform generates IDs that appear realistic and are capable of fooling online verification systems, resulting in identity theft and streamlining fraudulent activities. While the owner of OnlyFake claims that he intends to use this service ethically and legally, he hides behind the pseudonym John Wick. The platform uses telegram to demonstrate the efficacy of its services by uploading several fabricated IDs, including passports and driver’s licenses. The 404 media tested this technology by using a fake British passport generated by OnlyFake for identity verification on a cryptocurrency exchange. The ID was authenticated following the requirement of a selfie. The site claims that its
products can bypass verification at a large number of sites, including Biance, Revolut, Wise, Kraken, Airbnb, OKX and the like. The deceitful functionality of the services provided by emerging technology is a matter of grave ethical and security concern.
ISSUE & ANALYSIS
The use of generative AI to surpass necessary identity verification systems is extremely problematic in the face of traditional countermeasures still in practice. So far, OnlyFake faces a challenge in verifications, which require holding up the ID next to one’s face for verification. According to 404 Media, there is another market which profits from offering a solution to this loophole. There are sets of photos on sale wherein people are holding a piece of paper/passport- sized document to the camera, on which fake documents can be superimposed for the purpose of verification. A glaring issue here is the generation of more fraudulent markets for tying up loose ends in emerging technologies, putting established systems in a state of disarray. To complement
such disruption, OnlyFake plans to introduce a face and selfie generator soon.
Facial deepfakes and fake ID generation are a part of evolving generative AI, which also includes synthetic voice phishing. These identity verification enablers dilute existing security tests like two-factor authentications and KYC (know your customer) and, in a matter of time, are likely to surpass them with ease. This poses a serious threat to all financial systems across the globe, especially banks, stock exchanges, and currency/cryptocurrency exchanges. The ease of breaking through identification security will facilitate money laundering and big financial frauds, threatening economic security for both consumers and investors.
Another matter of concern is the ethical use of such technology and its impact on cybersecurity and data privacy. While laws have been enforced globally to protect public data, the unethical use of such technology challenges the very concept of security in the cyber realm.
Governments have consistently tried to counter novel methods of security breaches, but innovators have managed to find ways around such safety walls. The very nature of technological innovation is solution-oriented; hence, every time authorities find ways to counter disruption, it leads to the modification and evolution of the previous technological model. As governments worldwide are struggling with linear growth in cyber security with the introduction of a wider
array of biometric identification, the need of the hour is to create tools to detect digital tampering of data. Disruptive technology is especially intriguing in its potential to be the solution for most of the problems it creates.
DISCLAIMER
This report is structured on the basis of the information available in the public
domain. Any statements, projections, or advisories issued are only circumstantial and declared with the purpose of creating awareness and providing guidance among the readers and the general public. InQuest assumes no responsibility or liability for any discretion or action taken or concluded by the subject reader, and the general audience.
India Office:
InQuest Advisories Pvt. Ltd.
1114/G, Sector 57,
Gurugram,
Haryana – 122018
Contact: +91 9899692549
Email: info@inquest.global
UAE Office:
InQuest Advisories FZCO,
Dubai Silicon Oasis,
DDP, Building A2,
Dubai, UAE
Contact: +971 581992549
Email: info@inquest.global

