Tuesday, August 4, 2026
Green Sheet interviews LexisNexis Risk Solutions' Kimberly Sutherland
Deepfake-enabled identity fraud has surged over the past year, forcing organizations to rethink how they verify identities while maintaining a low-friction customer experience. To better understand the threat and how the industry can respond, Green Sheet touched base with Kimberly Sutherland, global head of Fraud and Identity at LexisNexis Risk Solutions, about the rapid rise of deepfakes, the limitations of traditional fraud defenses and the practical steps organizations can take to prepare for the next generation of AI-powered attacks.
Green Sheet: Deepfake attacks increased 180 percent year over year. What's driving that surge, and why has the problem accelerated so quickly over the past 12 months?
Kimberly Sutherland: The increasing availability of tools fraudsters can use to automate and improve their fraud attempts is the largest driver. Deepfake attacks have become more convincing, less detectable and easier to commit. Recent studies have shown that as high as 60 percent of attempted fraud involves digitally generated or manipulated identity data, documents or images.
Fraudsters are leveraging AI-powered “deepfake-as-a-service" style websites where tools are available that make it faster and cheaper to execute these types of attacks with less experience and more precision.
In addition, AI agents are fundamentally changing the scale, speed and operational consistency of fraud attacks. Rarely can humans identify these types of attacks and they are increasingly able to deceive traditional verification methods.
GS: What are the biggest mistakes financial institutions, payment providers and merchants are making when trying to detect deepfake-based identity fraud?
KS: The biggest mistake is assuming or misunderstanding that deepfake-based identity fraud can be detected by all document authentication and liveness detection tools. The second mistake is assuming that deepfakes are not happening to them, which is highly unlikely given the prevalence of this type of attack. Synthetic identity and deepfake media generation capabilities are not just increasing in volume, they are also evolving rapidly.
The majority of document authentication and liveness detection methods historically implemented have been static detection models, and these can become operationally stale within months. To protect against these attacks, enterprise integrations should support continuous model deployment, rapid policy updates, fraud feedback loops and dynamic workflows without requiring major application or infrastructure redesign.
GS You've said deepfakes typically fail on multiple subtle flaws rather than one obvious one. What technologies or capabilities are now essential for organizations that want to detect these attacks effectively?
KS: With the sophistication of tools that fraudsters use to create deepfakes, solutions to detect deepfake attacks must be equally advanced. Organization now need to deploy solutions that can detect the use of AI while also detecting in real time whether facial movement, behavioral patterns and environmental context have changed. Feedback loops, velocity and other defensive countermeasures encountered during a session are minimum requirements, not an option.
Since there is no silver bullet or single method to solve for the challenges of deepfakes attacks, organizations will be required to deploy layered, explainable AI powered models and policy-driven risk decisioning processes to improve their ability to keep pace with the rate of advancement in deepfake-based identity fraud.
GS: How should payment providers balance stronger identity verification with the need to minimize friction for legitimate customers during onboarding and account access
KS: Organizations have the challenge of protecting against evolving fraud attacks while providing their best customer experience for legitimate customers who are typically the majority of users that they encounter. In addition, they must prioritize accessibility, usability and inclusiveness as they deliver a low-friction and equitable user experience.
The industry is increasingly recognizing that modern deepfake defenses must require validating the integrity of the full capture and transmission pipeline – assessing risks associated with the device used and the entire session of the interaction.
Modern deepfake defense solutions are generally expected to return calibrated risk scores, confidence values or policy signals capable of supporting internal threshold tuning, adaptive authentication, workflow orchestration, and downstream fraud decisioning. Increasingly, the differentiator is not the standalone detection event itself, but the ability to integrate those signals into broader fraud, identity, and trust orchestration ecosystems.
GS: Many ISOs and merchant acquirers serve small and midsize businesses with limited fraud budgets. What practical steps can they take today to reduce their exposure to deepfake-related fraud?
KS: In the current environment, most organization will experience a deepfake attack. Human or manual intervention is not sufficient. Organizations with limited budgets should at minimum leverage as many risk signals as possible to detect anomalous behavior or inconsistencies and remain vigilant in their fight against fraud by incorporating non-technical processes to aid overall fraud detection.
Fraudsters maximize their impact with organizations that are less prepared. This means risk managers should increase focus on documenting an operational playbook and consistent response approach to synthetic identity fraud, onboarding attacks, account takeover scenarios, disputed identity claims, and coordinated fraud campaigns.
GS: Looking ahead, how do you expect AI-generated identity fraud to evolve over the next two to three years, and what should the payments industry be doing now to prepare?
KS: We expect deepfake and synthetic identity defense to evolve beyond isolated session-level analysis toward persistent trust and network-level fraud intelligence capable of identifying repeat fraud actors, coordinated attack infrastructure, synthetic identity reuse, cross-session behavioral anomalies, and broader ecosystem-level attack patterns.
Organizations should assess how rapidly vendors can adapt to emerging attack techniques, deploy updated detection models, retrain neural architectures, and operationalize new threat intelligence. The most important indicator is not static benchmark performance, but the vendor’s ability to sustain detection efficacy as generative AI systems, synthetic identity tooling and adversarial attack workflows evolve over time.
Notice to readers: These are archived articles. Contact information, links and other details may be out of date. We regret any inconvenience.
