Identity Verification for Telcos: Are Selfies Still Enough in the Age of Deepfakes?
GenAI has made deepfakes and synthetic identities cheap to produce. See what telcos need beyond selfies to verify identity and stop fraud.
Generative AI has quietly rewritten the economics of identity fraud. What once required real skill and time now takes little more than a laptop and access to widely available tools that can produce a synthetic driver’s license, a lifelike deepfake video, or a cloned voice in minutes.
For telcos, sitting at the intersection of digital onboarding and always-on network access, that shift lands directly on them. Deloitte’s Center for Financial Services projects that generative-AI-enabled fraud could push U.S. fraud losses to $40 billion by 2027, up from $12.3 billion in 2023 — a trajectory driven largely by how cheaply criminals can now manufacture convincing fake identities at scale.
The question telcos have been asking since biometric onboarding went mainstream — “are selfies enough?” — hasn’t gone away. It has just gotten a lot harder to answer yes, and the cost of getting it wrong has moved well beyond a bad onboarding experience.
Key Takeaways
- Selfie-only identity verification for telcos no longer holds. Generative AI has made synthetic identities, deepfake video, and voice cloning cheap and accessible, pushing projected U.S. fraud losses to $40 billion by 2027, up from $12.3 billion in 2023 (Deloitte).
- "Enough" verification now means layered evidence, not a single check. Passive liveness detection, forensic document analysis, device and network intelligence, and cross-application pattern matching each catch what the others miss. No single signal is deepfake-proof alone.
- Identity verification can't stop at onboarding. SIM swap fraud (up 1,055% year-over-year in the UK per Cifas) shows telco accounts stay exposed long after account opening, making continuous identity signals across the customer lifecycle essential.
- Liability is shifting toward telcos. Regulatory moves like the UK's APP fraud reimbursement rules and the EU's Payment Services Regulation are extending fraud accountability to telcos, not just banks, raising the compliance stakes for identity assurance.
The Two Identity Verification Questions Haven’t Changed — But the Answers Have
Strip away the technology and identity verification still comes down to two questions:
Both are harder to answer honestly than they were even three years ago.
Generative AI has weakened question one by enabling synthetic identities — fabricated profiles that blend a real identifier, like a social security number or address, with fabricated details, built specifically to pass document and database checks. Answering it now depends on resolving identity data across sources rather than trusting a single record at face value; FICO’s Identity Resolution Engine (IRE) does exactly that, linking and reconciling fragmented or shared identity signals to determine whether an identity is genuine or a synthetic composite.
Generative AI has also weakened question two by putting deepfake video and voice-cloning tools within reach of ordinary fraud rings, not just well-funded ones. A liveness check built to catch a photo held up to a webcam was never designed to catch a synthetic face generated frame by frame in real time.
What Does “Enough” Identity Verification Look Like in 2026?
For years, identity verification via “liveness” meant an active challenge: look left, look right, blink, smile. That bar is no longer high enough — off-the-shelf deepfake generation tools can now respond to active prompts convincingly, so a check designed to prove a human is present no longer reliably proves it.
What “enough” looks like today is layered, not single signal. Passive, ML-based liveness detection — analyzing skin texture, micro-movement, and light reflection without asking the user to perform a scripted action — is harder for generative tools to spoof than active challenges.
No individual signal is deepfake-proof on its own. Raising the bar requires combining evidence across multiple signals into a single body of proof:
- Cross-signal enrichment: pairs the biometric and document result with device intelligence, network signals, and behavioral patterns to build a fuller picture of the applicant.
- Network analytics: flags when the same face or document fragments reappear across multiple applications, exposing coordinated fraud attempts that a single check would miss.
Together, these signals turn a single pass or fail check into a body of evidence that is far harder to fake than any one check alone.
Why Doesn't Identity Verification End at Onboarding?
Even a perfect onboarding check only proves who opened the account. It says nothing about what happens after — and for telcos, after is where much of the risk lives. Telco accounts are a favored target for SIM swap fraud, because control of a phone number is often the last authentication factor standing between a criminal and someone else’s bank account, email, or crypto wallet.
In the UK, Cifas recorded a 1,055% year-over-year surge in unauthorized SIM swaps reported to its National Fraud Database in 2024 — nearly 3,000 cases, in a mobile and telco sector that fraudsters increasingly treat as a soft entry point.
That’s an authentication and account-management problem as much as an onboarding one, and it argues for identity signals that persist across the customer lifecycle rather than resetting to zero after day one. Closing the gap between “verified once” and “verified continuously” is where telcos have the most ground to make up.
SIM swaps are only one side of the exposure. Device, financing, and subscription fraud using synthetic or stolen identities to obtain subsidized devices is a significant onboarding-stage gap that has worsened alongside the surge in AI-generated identities, and it hits telcos directly as revenue loss rather than as a pass-through to someone else’s account. That leaves telcos absorbing fraud on two fronts: direct losses on their own accounts, and, as the next section covers, growing liability for fraud committed through their networks against someone else’s.
A Compliance Bar That’s Rising, not Relaxing
The regulatory signal is consistent even where the specifics vary by market: the bar for identity assurance is going up, not down, and liability for fraud losses is moving upstream toward whoever was best positioned to catch it.
The UK’s move toward mandatory reimbursement for authorized push payment (APP) fraud is one visible example of liability shifting toward institutions across the transaction chain including, the telcos whose networks and accounts scammers rely on to execute the fraud.
Regulators and industry bodies in multiple markets are converging on the same expectation: verification at onboarding is necessary but not sufficient, and organizations need to demonstrate ongoing vigilance across the life of the customer relationship.
How Should Telcos Adapt Their Identity Verification Strategy?
The right response isn’t a better standalone biometric check — it’s connecting identity verification at onboarding to the fraud detection, authentication, and customer intelligence systems that operate for the life of the account. Treating identity as a single point-in-time decision leaves telcos blind the moment a fraudster clears that first gate. Treating it as one input into an orchestrated decisioning layer — where onboarding signals, ongoing authentication events, network analytics, and fraud detection share context in real time — closes that gap.
FICO Platform’s API-first, modular architecture streamlines operational complexities while delivering the speed, performance, and resilience that high-volume, mission-critical workflows demand. This architecture lets telcos plug identity and authentication capabilities into the fraud and customer management systems they already run, rather than bolting on another disconnected point solution.
Bolt-on approaches leave each system operating from isolated data repositories, creating silos and expensive integrations. FICO Platform consolidates identity signals, authentication events, transaction history, and customer behavior into one unified data layer, so every decision draws from the same authoritative context — eliminating silos and the latency of repeated reconciliation.
Equally critical is how the platform maintains dynamic, real-time customer profiles. Rather than static snapshots, profiles evolve as behaviors change — capturing shifts in usage patterns, location access, and authentication methods instantly. This real-time visibility transforms fraud detection, enabling telcos to spot emerging anomalies as they develop rather than after batch processes complete, driving faster response and better lifecycle protection.
Selfies Were Never the Whole Answer
They’re an even smaller part of it now that a convincing fake face costs a criminal almost nothing to produce. The telcos that get ahead of this treat identity as a continuous signal, not a one-time gate — see how FICO helps telcos close the identity and authentication gap.
How FICO Is Helping Telcos
- Read our current posts on synthetic identity fraud and how to protect mobile wallets from prepaid card fraud for telcos
- Download the IT Leadership Reimagined: A Telco Playbook for the Age of AI, featuring a telco giant's journey to processing over 1 million monthly credit applications with zero downtime, to learn how IT leaders can become intelligence architects, not just infrastructure managers
- Read our executive brief on the Telco CIO as Architect of AI-Driven Digital Transformation to understand the role of decision intelligence in the next era of telecommunications
- Download our Practical Guide for Telco IT Leaders to learn how composable decisioning infrastructure helps telco IT leaders deliver faster, governed, and scalable AI across the subscriber lifecycle.
Note: This is an update of a post from 2020.
Frequently Asked Questions
Effective subscription fraud prevention combines advanced analytics with full customer lifecycle monitoring rather than a single credit check at signup. Machine learning models built specifically for first-party and synthetic identity fraud, network analytics that expose fraud rings sharing recycled personal information, and fuzzy matching that catches manipulated income or address details all outperform static rules-based screening.
Reducing friction starts with replacing active liveness challenges (look left, look right, blink) with passive, ML-based liveness detection that runs in the background without asking the applicant to perform an action. Auto-populating application fields by extracting data directly from a scanned identity document removes manual re-entry and cuts abandonment. Risk-based, adaptive workflows apply the heaviest verification steps only to applications carrying elevated risk signals, letting low-risk customers move through with a single check rather than several. Orchestrating these signals in real time, rather than running each check as a separate gate, lets telcos approve legitimate customers in seconds while still building the layered evidence needed to catch synthetic identities and deepfakes.
Regulatory pressure is building well beyond the UK. The European Union's incoming Payment Services Regulation extends its impersonation fraud liability regime to electronic communications service providers, the category that includes telecom carriers, alongside payment service providers, meaning telcos can share liability when strong customer authentication is bypassed through channels like SIM swapping. In Australia, the updated 2026 Telecommunications Consumer Protections Code adds stronger identity protections and SIM-swap safeguards directly targeting scam risk. The pattern across markets is the same: regulators are no longer treating telecom identity controls as separate from financial fraud liability; they are folding them into the same accountability framework banks already operate under.
Identity verification confirms that the person presenting an application is who they claim to be, typically by matching a government-issued document to a live selfie at a single point in time. Identity resolution goes further: it links and reconciles identity signals, names, addresses, phone numbers, device identifiers, across multiple internal and third-party data sources to determine whether those signals describe one genuine person or a fabricated composite. FICO® Identity Resolution Engine performs this reconciliation, which is why it can catch synthetic identities that pass a standard verification check because every individual data point looks legitimate on its own.
Popular Posts
Has the Reporting of Rental Data to the Credit Reporting Agencies (CRAs) Increased?
FICO Score 10T includes rental data, but consumers can only experience the benefit of this to the extent that their rental data is reported to the CRAs
Read more
Average U.S. FICO® Score at 716, Indicating Improvement in Consumer Credit Behaviors Despite Pandemic
The FICO Score is a broad-based, independent standard measure of credit risk
Read more
Average U.S. FICO Score at 711, But Uncertainty Abounds
It generally takes some time for the effects of a major macroeconomic event to start to show up in consumers’ credit reports.
Read moreTake the next step
Connect with FICO for answers to all your product and solution questions. Interested in becoming a business partner? Contact us to learn more. We look forward to hearing from you.