Written by a human

FinCEN's Deepfake Fraud Alert (FIN-2024-DEEPFAKEFRAUD): What financial institutions must do

Generative AI deepfakes are putting firms' security systems to the test, with fraudsters using them to slip past identity and verification controls. Learn more about FinCEN's Deepfake Fraud Alert, including what it is, who it binds, and how bad actors are using deepfake media against BSA-covered institutions.

Global Relay Compliant business communications archiving, messaging, supervision, and eDiscovery
13 mins read 11 September 2026

On November 13, 2024, the U.S. Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN) issued Alert FIN-2024-Alert004, warning financial institutions that fraudsters are using generative-AI deepfakes — fake IDs, cloned voices, and synthetic video — to slip past identity and verification controls. The alert reminds firms of their Bank Secrecy Act (BSA) reporting duties and tells them to flag suspected deepfake fraud in suspicious activity reports (SARs) using the key term “FIN-2024-DEEPFAKEFRAUD.”

That single instruction of tagging the SAR is the operational core of the alert. But the reason it landed with such force is the scale of the problem that triggered it. Deepfake-enabled social engineering has already been used to steal tens of millions of dollars from a single company in one video call, and law enforcement and international bodies keep confirming the trend is accelerating, not slowing down.

This guide covers what the FinCEN deepfake fraud alert (FIN-2024-DEEPFAKEFRAUD) is, who it binds, and exactly how fraudsters are using deepfake media against the Bank Secrecy Act (BSA)-covered institutions. It also clarifies the red flags that FinCEN lists, and the concrete steps compliance and financial-crime teams need to take to tackle deepfake fraud detection for banks and other financial institutions.

Key takeaways

  • FIN-2024-DEEPFAKEFRAUD is the suspicious activity report (SAR) key term tied to FinCEN Alert FIN-2024-Alert004, and requires institutions (banks, credit unions, and money services businesses among others) to identify suspected deepfake-enabled fraud and file a SAR referencing the key term in field 2 and the narrative.
  • FinCEN lists nine red-flag indicators spanning identity documents, live verification, and account activity.
  • The alert is guidance on an existing Bank Secrecy Act duty; it doesn’t create a new legal requirement.

What the alert is and why FinCEN issued it

FinCEN deepfake fraud alert (FIN-2024-DEEPFAKEFRAUD) does three things:

  1. Explains how criminals are using generative AI (GenAI) to build and deploy deepfake media against financial institutions including deepfake identity verification fraud.
  2. Lists red flag indicators to help institutions spot that activity.
  3. Reminds institutions of their existing reporting duties under the BSA.

FinCEN’s trigger for issuing the alert was a pattern in its own data. Starting in 2023 and continuing into 2024, the agency saw a rise in SARs describing the suspected use of deepfake media in fraud schemes aimed at financial institutions and their customers. Most of that activity involved criminals altering or fabricating identity documents to get past identity verification and customer due diligence controls.

The deepfake SAR reporting alert sits inside the BSA’s broader reporting framework, which requires covered institutions to identify and report suspicious activity, and it’s part of a wider Treasury effort to keep institutions current on AI-related fraud risk. Separately, the Anti-Money Laundering Act of 2020 directs FinCEN to periodically publish threat pattern and trend information drawn from BSA filings — part of the same feedback-loop mandate behind FinCEN’s broader library of alerts and advisories. The abuse of deepfakes and GenAI tools touches two of FinCEN’s standing AML/CFT National Priorities: fraud and cybercrime. That’s a large part of why this particular threat resulted in a dedicated alert and its own SAR key term, rather than being folded into general guidance.

What deepfake media is, and how fraudsters use it

Definition: Synthetic content — realistic but inauthentic video, images, audio, or text — created with AI/machine learning tools to make it look like a real person did or said something they didn’t, or to fabricate a person or document that doesn’t exist at all. This is how FinCEN defines the term in FIN-2024-Alert004.

What makes this alert different from a generic AI-fraud warning is how specifically it maps the abuse to financial institution workflows. FinCEN’s own analysis of BSA data points to four recurring patterns:

How fraudsters use deepfakesExample
Fake or altered identity documentsSynthetic or manipulated driver’s licenses and passports, often combined with stolen or fabricated personally identifiable information (PII) to build a synthetic identity.
Fraudulent account openingDeepfake photos, videos, and identity documents used to pass onboarding and identity verification, with the resulting account later used to move funds.
Downstream fraudCheck fraud, credit card fraud, authorized push payment (APP) fraud, loan fraud, and unemployment fraud routed through accounts opened this way.
GenAI-enabled social engineeringDeepfake audio, video, and AI-written messages used in business email compromise (BEC), spear phishing, romance scams, elder financial exploitation, and virtual currency investment scams.

The account-opening typology and the social-engineering typology are related but distinct problems. Deepfake account opening fraud is about a financial institution being deceived directly during onboarding. Social engineering fraud is about a financial institution’s customers or employees being deceived by a deepfake voice or video impersonating someone they trust — a family member, a colleague, or an executive, to induce them into making transactions.

The red-flag indicators FinCEN lists

Regulatory expectations for surveillance model governance now map onto a recognizable lifecycle, running from before a model is deployed through to its retirement. Each stage, from surveillance model testing to ongoing calibration, produces evidence that a firm can point to when asked to prove the system works.

So how are fraudsters using deepfakes against financial institutions? While GenAI fraud typologies are numerous, FinCEN has identified several core red flags.

FinCEN, however, is explicit that no single indicator on its own proves illicit activity. Institutions need to weigh the surrounding facts and circumstances. But taken together, the alert’s red flags give compliance teams a concrete checklist for both account opening and ongoing monitoring:

  • Synthetic identity red flags include a customer’s photo that’s internally inconsistent (shows visible signs of alteration) or doesn’t match other identifying information on file. For example, a stated date of birth that doesn’t match how old the person in the photo appears.
  • A customer submits multiple identity documents that are inconsistent with each other.
  • A customer uses a third-party webcam plugin during a live verification check, or tries to switch communication methods, citing repeated technical glitches, during that check.
  • A customer declines to use multifactor authentication (MFA) to verify their identity.
  • A reverse-image search or open-source lookup matches a customer’s identity photo to an image in an online gallery of AI-generated faces.
  • A customer’s photo or video is flagged by commercial or open-source deepfake-detection software.
  • GenAI-detection software flags likely AI-generated text in a customer’s profile or responses.
  • A customer’s geographic location or device data is inconsistent with their identity documents.
  • A newly opened account, or one with little transaction history, shows rapid transaction activity, high payment volumes to higher-risk payees such as gambling sites or digital-asset exchanges, or a high volume of chargebacks or rejected payments.

What financial institutions must do

So, what does FIN-2024-DEEPFAKEFRAUD require?

1. File a SAR and use the key term

Here’s how to report deepfake fraud on a SAR: When an institution suspects deepfake media is involved in fraudulent activity, it should file a SAR and reference this alert by including the key term “FIN-2024-DEEPFAKEFRAUD” in SAR field 2 (“Filing Institution Note to FinCEN”) and again in the narrative. FinCEN also asks institutions to include any additional key terms that describe the underlying fraud typology, for instance, terms associated with account takeover, business email compromise, or elder financial exploitation, where applicable. Standard BSA filing timelines apply.

2. Strengthen identity verification controls, without treating them as a safe harbor

FinCEN points to MFA — including phishing-resistant MFA — and live verification checks that require a customer to confirm their identity through audio or video as practices that can reduce exposure to deepfake identity fraud. It also notes the limits: illicit actors may respond to live-verification prompts using synthetic audio or video, so live checks can still be circumvented and shouldn’t be treated as conclusive proof of identity on their own.

3. Recognize this as an existing duty, not a new one

The FinCEN deepfake fraud alert (FIN-2024-DEEPFAKEFRAUD) doesn’t create a new regulatory requirement. It’s guidance that clarifies how an existing BSA reporting obligation applies to a new fraud vector. Institutions that already have mature SAR processes mainly need to update their red-flag training, detection tooling, and narrative templates, rather than build a new compliance program from scratch.

Why now: The threat behind the alert

Recent, current events explain why deepfake fraud for financial institutions has remained incredibly relevant rather than fading with the news cycle.

FinCEN’s own alert cites the shocking case that put deepfake fraud on every compliance team’s radar. In January 2024, a finance employee at the Hong Kong office of engineering firm Arup was convinced, over a video call with what appeared to be the company’s CFO and several colleagues, to authorize 15 transfers totaling roughly $25.6 million. Every participant on that call, except the victim, was an AI-generated deepfake built from publicly available footage of real executives.

Law enforcement and international bodies have kept the warnings coming since the FinCEN deepfake fraud alert (FIN-2024-DEEPFAKEFRAUD). The FBI’s Internet Crime Complaint Center (IC3) issued a public service announcement in December 2024 warning that criminals are exploiting generative AI to scale fraud and make their schemes more convincing, including through synthetic voice and video (known as synthetic identity fraud). In the IC3 2025 annual report, the organization tracked a dedicated AI-fraud category for the first time, logging over 22,000 complaints and roughly $893 million in reported losses.

INTERPOL’s 2026 Global Financial Fraud Threat Assessment estimated that financial fraud of all kinds (including but not only deepfakes) cost the global economy more than $442 billion in 2025, and rated the overall risk for 2026 as high. The same assessment found that AI-enhanced fraud schemes are roughly 4.5 times more profitable for criminals than traditional methods, and flagged a growing criminal market for “deepfake-as-a-service” kits, voice-cloning tools, and synthetic identity packages.

Inside financial institutions themselves, the numbers are just as stark. A Medius 2024 survey of more than 1,500 U.S. and U.K. finance professionals found that 53% had been targeted with a deepfake fraud attempt, and 43% had fallen for one.

How firms respond across the communications surface

Identity and document verification is a distinct control area, generally owned by KYC, onboarding, and identity-verification vendors. Global Relay, in contrast, specializes in the communications and evidence side.

This includes surveilling monitored communications for deepfake-enabled social engineering (like executive impersonation, business email compromise, and coercion) and capturing and preserving the communications record so suspected incidents can be investigated and evidenced to support SAR decisions and follow-ups. Where cloned-voice authorizations are a risk on recorded lines, Global Relay’s voice surveillance extends that same detection and evidence capability to audio.

At the core of both of these disciplines is effectively monitoring eComms, and it’s important to understand the challenges of eComms surveillance and how organizations can overcome these.

Direction of travel

FinCEN is likely to keep refining its guidance as SAR data reveals how deepfake typologies evolve, potentially through follow-on alerts or Financial Trend Analyses similar to those it has published on other threats.

Other regulators are moving in parallel: New York’s Department of Financial Services has told institutions regulated under 23 NYCRR Part 500 that its existing cybersecurity rule already covers AI-related risk, including deepfake-enabled social engineering, and has pointed institutions toward authentication methods that AI-generated deepfakes can’t easily impersonate.

The EU AI Act, meanwhile, introduces transparency obligations requiring certain AI-generated or manipulated content to be disclosed as synthetic. None of this replaces FinCEN deepfake fraud alert (FIN-2024-DEEPFAKEFRAUD) as the primary U.S. reference point for financial institutions, but it signals that deepfake-specific obligations are becoming a permanent, cross-jurisdictional fixture of financial crime compliance rather than a one-off warning.

FAQs

What is the FinCEN deepfake fraud alert (FIN-2024-DEEPFAKEFRAUD)?

FIN-2024-DEEPFAKEFRAUD is the SAR key term tied to FinCEN Alert FIN-2024-Alert004, which financial institutions use to flag suspicious activity reports connected to suspected deepfake fraud. The alert itself explains how criminals use generative-AI deepfakes to defraud financial institutions and their customers, lists red flag indicators, and reminds institutions of their BSA reporting duties.

When did FinCEN issue the deepfake alert?

FinCEN issued the alert on November 13, 2024. It followed an increase in suspicious activity reports, beginning in 2023 and continuing into 2024, describing the suspected use of deepfake media in fraud schemes.

Who does the alert apply to?

The alert applies to financial institutions subject to the Bank Secrecy Act (BSA), a category that includes banks, credit unions, money services businesses, securities and futures firms, and other BSA-covered entities. These are the same institutions already required to maintain AML programs and file SARs.

How do banks report deepfake fraud?

Banks and other financial institutions bound by the BSA should file a SAR and include the key term “FIN-2024-DEEPFAKEFRAUD” in SAR field 2 (“Filing Institution Note to FinCEN”) and in the narrative. FinCEN also asks institutions to add any other key terms that identify the underlying fraud typology, such as account takeover or business email compromise (BEC), as part of the BSA deepfake reporting process.

What are the red flags for deepfake fraud?

GenAI fraud red flags include inconsistent or altered identity photos, mismatched identity documents, use of webcam plugins or excuses to avoid live verification, declining MFA, image matches to known AI-generated face galleries, detection-software flags on photos, video, or text, mismatched geographic or device data, and rapid transaction activity on new or thin-history accounts. FinCEN stresses that no single red flag alone proves suspicious activity.

Is the alert a new legal requirement?

No, the alert is guidance, not a new rule. It reinforces financial institutions’ existing BSA obligation to identify and report suspicious activity, and is applied specifically to deepfake-enabled fraud schemes.

How can firms detect deepfake-enabled social engineering in communications?

Firms can extend communications monitoring and surveillance to the channels where executive impersonation, BEC, and voice-cloning attempts typically arrive, and preserve those communications as evidence to support investigations and SAR decisions. This complements (but doesn’t replace) identity verification controls at account opening, which remain a separate discipline.

Final thoughts

FinCEN deepfake fraud alert (FIN-2024-DEEPFAKEFRAUD) tells financial institutions to identify deepfake-enabled fraud and report it via SARs using a specific key term, in line with existing BSA duties. What’s urgent is the fact that this issue is escalating faster than most institutions’ controls.  

Getting the reporting right is table stakes; building the detection and evidence trail to back it up, particularly across AI-powered AML compliance programs and real-time compliance monitoring, is the harder ongoing work.

Learn more about how Global Relay’s communications surveillance solution fits into your deepfake SAR reporting, or get in touch with the Global Relay team.

Global Relay Compliant business communications archiving, messaging, supervision, and eDiscovery
13 mins read 11 September 2026