AI-Based Attacks
,
Finance & Banking
,
Fraud Management & Cybercrime
Point Predictive’s Matt Vega on Detecting Identity Fraud and $30 Liveness Kits
Facial liveness checks are the foundation for mobile device verification. But now injection kits selling for about $30 enable fraud rings hot-wire a mobile device’s camera feed or inject a deepfake stream into the verification process, bypassing checks many institutions still rely on, said Matt Vega, chief fraud strategist at Point Predictive.
See Also: How to Defend Against AI-Powered Identity Fraud
Once an injection kit clears that first gate, the fraud doesn’t stop at onboarding and the identity keeps building, Vega said. Synthetic profiles typically take six to 18 months to mature, using agentic artificial intelligence to automate payments on secured cards and micro trade lines to build a healthy repayment history that pushes the profile into prime or super-prime territory.
“A sudden jump from a dormant credit file to strong repayment is itself a warning sign, and that patience makes the fraud hard to catch on the credit side,” Vega said.
No single technology stops these attacks. Multi-layered verification, income checks and continuous monitoring catch most synthetic identities before they reach major credit lines. Data sharing helps too, but herd immunity comes into play, he said.
“It’s hard because in data consortium models, you get herd immunity,” Vega said. “If there’s an attack on one, the immune system responds and builds up the defenses for everyone else within the consortium. But it usually comes down to good old-fashioned rule engines. Old-school rule engines can knock out a lot of the high-risk fraud that’s out there. The more advanced the attack vector, usually the more basic the control is to mitigate it.”
In this video interview with ISMG, Vega also discussed:
- How physiological signals such as heartbeat and pupil dilation help detect deepfake liveness attempts;
- Why deferred first-payment loan programs give synthetic identity rings a wider window to operate;
- The limits of fraud data-sharing for financial institutions that can’t join a consortium.
Vega supports Point Predictive’s banking, fintech and digital asset fraud strategy. He has spent nearly 20 years in fraud prevention, moving from e-commerce fraud roles into military cyber and signals intelligence work with U.S. federal agencies. He also was chief fraud strategist at Sardine AI.

