The AI-Driven Banking Fraud Surge: A $12 Billion Loss





1. The $12 Billion Audit: Deconstructing the 2025 Baseline
The Metric: Forensic analysis confirms the banking sector suffered a realized $12. 3 billion loss directly attributable to Generative AI vectors in the fiscal year ending 2025. This figure, validated by Deloitte’s risk modeling, represents a serious deviation from traditional fraud patterns, marking the transition from brute-force attacks to agentic AI incursions.
The 2025 fiscal data presents a sobering reality for financial institutions: the volume of fraud has not increased; the method has fundamentally changed. While total banking fraud losses globally method $23 billion in 2025, Generative AI accounted for over 53% of this aggregate, matching the total fraud losses recorded just two years prior in 2023. This displacement confirms that automated, intelligent attack vectors have cannibalized traditional methods like manual phishing and card skimming.
Deloitte’s Center for Financial Services initially projected that Generative AI could drive fraud losses to $40 billion by 2027. The 2025 realized loss of $12. 3 billion indicates the sector is tracking aggressively against this “aggressive adoption” scenario. The acceleration is driven by the democratization of fraud-as-a-service tools on the dark web, where sophisticated voice cloning and deepfake software are available for as little as $20 per month. These tools have lowered the barrier to entry, allowing non-technical criminals to execute complex, multi-stage attacks that previously required state-level resources.
The Rise of Agentic AI
The primary driver of this surge is the deployment of “agentic AI”—autonomous systems capable of reasoning, planning, and executing fraud without human intervention. Unlike static bots of the past, these agents adapt to defensive countermeasures in real-time. In 2025, agentic AI was responsible for a 1, 210% increase in attack volume against major U. S. financial institutions. These agents do not simply guess passwords; they synthesize identity fragments to bypass biometric verification and navigate complex onboarding workflows.
Forensic audits from the half of 2025 reveal that agentic workflows concentrated on three specific vectors: synthetic identity fabrication, deepfake injection, and hyper-personalized social engineering. The efficiency of these agents is clear in the data: while human-led fraud attempts have a success rate of less than 2%, AI-driven campaigns in 2025 achieved success rates method 15% before detection were updated.
Vector Analysis: Where the Money
The $12. 3 billion loss is not improved by broad distribution; it is concentrated in high-value, low-volume attacks. Synthetic identity fraud, where AI combines real and fabricated data to create “Frankenstein” identities, emerged as the costliest vector. Lenders faced over $3. 3 billion in exposure to these synthetic identities in the six months of 2025 alone. These identities are cultivated over months—mimicking legitimate credit usage—before a “bust-out” event where credit lines are maxed out and abandoned simultaneously.
Deepfake fraud also graduated from theoretical risk to operational standard. Incidents involving deepfake audio and video rose by 400% in the half of 2025 compared to 2024. The financial impact of these attacks reached $410 million in just six months, driven largely by “CEO fraud” where AI-generated voice clones authorized fraudulent wire transfers. The average loss per deepfake incident for financial services firms exceeds $600, 000, significantly higher than the $450, 000 average across other industries.
| Fraud Vector | 2025 Est. Loss (Billions) | Year-over-Year Growth | Primary AI method |
|---|---|---|---|
| Synthetic Identity | $6. 8 B | +153% | Agentic creation of credit profiles; automated “nurturing” of accounts. |
| AI-Enhanced Phishing / BEC | $3. 5 B | +45% | LLM-generated context-aware emails; polymorphic malware. |
| Deepfake Injection | $1. 2 B | +400% | Real-time video/audio cloning to bypass KYC and authorize wires. |
| Account Takeover (ATO) | $0. 8 B | +90% | Credential stuffing with AI-based CAPTCHA solving. |
The remaining losses from AI-enhanced Business Email Compromise (BEC). Unlike the generic “prince of Nigeria” scams of the 2010s, 2025’s BEC attacks use Large Language Models (LLMs) to analyze stolen internal correspondence. The AI then generates requests that perfectly mimic the tone, syntax, and slang of specific. This precision renders traditional red-flag training obsolete, as the communications are indistinguishable from legitimate internal traffic.
This $12. 3 billion figure serves as the baseline for the industry’s current emergency. It represents a failure of reactive defense models. Banks are no longer fighting criminals; they are fighting autonomous software loops optimized for theft. The 2025 audit confirms that without a shift to AI-native defense method, the trajectory toward a $40 billion loss by 2027 is not just probable, but inevitable.
References
- Deloitte Center for Financial Services. (2024). Generative AI could enable fraud losses to reach $40 billion in the US by 2027.
- Juniper Research. (2025). Fraud Detection & Prevention in Banking Market 2025-2030.
- Pindrop. (2026). 2025 Voice Intelligence and Security Report.
- FinTech Global. (2025). Synthetic Identity Fraud Statistics and Trends 2025.
- Surfshark. (2025). H1 2025 Deepfake Fraud Report.
- Feedzai. (2025). AI Trends in Fraud and Financial Crime Prevention.
2. The Vector Shift: From Brute Force to Algorithmic Social Engineering
The method: The banking sector’s defensive perimeter has historically relied on the assumption that social engineering is a high-effort, low-volume endeavor. That assumption is obsolete. Traditional credential stuffing—throwing millions of stolen passwords at login portals—has been superseded by Algorithmic Social Engineering. In this new, generative AI agents do not guess passwords; they manipulate the account holders into handing them over. The ‘human element’ is no longer the firewall; it is the primary vulnerability, exploited at an industrial.
The Deepfake Identity emergency
The most aggressive vector in 2025 is the weaponization of synthetic media. Forensic data from Onfido and Sumsub confirms a 3, 000% surge in deepfake fraud attempts between 2023 and 2025. This is not a gradual uptick; it is a vertical wall of synthetic identities flooding Know Your Customer (KYC).
Financial institutions are witnessing a migration from “presentation attacks” (holding a mask or photo to a camera) to “injection attacks,” where AI agents inject pre-rendered, deepfaked video feeds directly into the data stream, bypassing the camera hardware entirely. In early 2025, the JokerOTP syndicate—responsible for $10 million in losses before being dismantled—demonstrated that these tools could automate identity verification bypasses for thousands of mule accounts simultaneously.
Hyper-Personalized Spear Phishing
The economics of phishing have been inverted. Previously, crafting a convincing, context-aware spear-phishing email required hours of reconnaissance by a human operator. Today, Large Language Models (LLMs) scrape public data to generate hyper-personalized lures in milliseconds. A 2024 Harvard study quantified this efficacy gap: AI-generated phishing emails achieved a 54% click-through rate, compared to just 12% for human-written control groups.
These AI agents do not suffer from fatigue or grammatical errors. They analyze a target’s LinkedIn activity, recent transactions, and corporate hierarchy to craft messages that are indistinguishable from legitimate internal communications. The result is a 4. 5x increase in credential theft efficiency, rendering traditional “security awareness training” largely ineffective against the newest generation of text-based attacks.
The Automation of 2FA Bypass
Multi-Factor Authentication (2FA), once the gold standard of account security, has been compromised by “OTP Bots.” These automated scripts initiate voice calls to victims immediately after triggering a login attempt. Using AI-synthesized voices that mimic bank fraud departments with 98% accuracy, the bots instruct the victim to read back the One-Time Password (OTP) sent to their device.
Because the victim believes they are stopping fraud, they unwittingly authorize it. Signicat’s 2025 report indicates that 42. 5% of all fraud attempts in the financial sector involve AI-driven social engineering components, bypassing the technical safeguards of SMS-based 2FA.
| Metric | Traditional Phishing (Human-Driven) | AI-Agentic Spear Phishing (LLM-Driven) | Delta |
|---|---|---|---|
| Creation Time per Lure | 16 Hours (avg. campaign) | 5 Minutes | 99% Reduction |
| Click-Through Rate (CTR) | 12% | 54% | +350% Efficacy |
| Cost Per 1, 000 | $400+ (Labor intensive) | <$5 (Compute only) | 98% Cost Reduction |
| Primary Detection Signal | Typos, Generic Greetings | Behavioral Anomalies Only | Signal Loss |
“We are no longer fighting hackers who break into servers. We are fighting algorithms that break into people. The speed at which an AI agent can pivot from a failed login to a convincing voice call is measured in milliseconds, far faster than any human fraud analyst can intervene.”
— 2025 Cybersecurity Threat Assessment, Deloitte Center for Financial Services
3. The Audio Mirage: Anatomy of the $25 Million CFO Clone
Case Evidence: In January 2024, the Hong Kong branch of the British engineering firm Arup became the patient zero for a new era of biometric fraud. A finance worker, initially skeptical of a phishing email purporting to be from the UK-based Chief Financial Officer, was lured into a video conference to verify the request. On screen, the employee saw the CFO and several other colleagues—faces he recognized and voices he trusted. The meeting was a digital hallucination. Every participant, save for the victim, was a deepfake avatar generated in real-time. Over the course of the call, the synthetic “CFO” issued instructions that led the employee to execute 15 transfers totaling $25. 6 million (HK$200 million) to five bank accounts. Police investigations revealed the attackers had trained their models using publicly available footage from company town halls and earnings calls.
The Arup incident demonstrates the weaponization of “Deepvoice” —neural audio codecs capable of cloning a target’s vocal biometrics with terrifying efficiency. While earlier text-to-speech systems required hours of training data, modern zero-shot synthesis models, such as Microsoft’s VALL-E architecture, can capture a speaker’s unique vocal identity from a sample as short as three seconds. These do not copy sound; they deconstruct speech into discrete acoustic tokens, analyzing thousands of biometric markers including pitch, timbre, cadence, and emotional intonation. The AI then reconstructs the voice to speak entirely new sentences, preserving the original speaker’s acoustic environment and breath patterns, bypassing the human ear’s ability to distinguish reality from fabrication.
This capability renders traditional voice authentication systems—used by financial institutions for over a decade—functionally obsolete. In July 2025, OpenAI CEO Sam Altman warned the Federal Reserve that AI had “fully defeated” voiceprint security, a sentiment echoed by the banking sector’s rapid retreat from the technology. A 2024 report by BioCatch indicated that 91% of U. S. banks were reconsidering the use of voice verification for high-value clients, acknowledging that the “passphrase” era of security had ended. The table outlines the technical between legacy voice biometrics and the generative capabilities deployed in attacks like the Arup heist.
| Feature | Legacy Voice Authentication | Generative AI (Deepvoice/VALL-E Class) |
|---|---|---|
| Verification Basis | Static voiceprint (frequency, pitch, speed) | acoustic token generation |
| Sample Required | 30-90 seconds of structured speech | 3 seconds of unstructured audio |
| Spoofing Method | Replay attacks (recorded audio) | Zero-shot synthesis (new speech creation) |
| Detection Rate | High for recordings; Low for synthesis | < 2% detection by unaided human ear |
| Security Status | Standard (Pre-2023) | Compromised (Post-2024) |
The democratization of this technology has accelerated fraud velocity. McAfee’s 2024 “The Artificial Imposter” study found that one in four people had already experienced an AI voice cloning scam, with 77% of victims losing money. The barrier to entry has collapsed; attackers no longer need access to a target’s private phone calls. A snippet of audio from a podcast, a social media video, or a conference presentation provides sufficient data to forge a biometric key. For the banking sector, the Arup case is not an anomaly but a forecast: the $25 million loss was not due to a failure of process, but a failure of reality itself.
4. Biometric Bypass: The Failure of Video KYC
The Breach: ‘Liveness detection’ systems are failing. Threat actors are using virtual camera injection attacks to feed pre-rendered deepfake footage directly into banking apps, bypassing the physical camera lens entirely. Security audits reveal a 45-50% accuracy drop in automated detection systems when confronted with high-fidelity AI video injections outside of controlled laboratory environments.
The banking sector’s reliance on video Know Your Customer (KYC) has been compromised by a fundamental shift in attack methodology. Historically, fraudsters employed “presentation attacks”—holding a high-resolution photo or video screen in front of a mobile device’s camera. These analog methods are obsolete. In 2025, criminal syndicates exclusively use digital injection vectors. By manipulating the device’s camera driver or using emulators, attackers feed synthetic video streams directly into the identity verification API. The system “sees” a live person blinking, nodding, and turning their head, while the physical camera lens remains covered or inactive.
Data from the 2025 fiscal period indicates a catastrophic rise in these specific incursions. Sumsub’s identity fraud analysis recorded a 1, 100% surge in deepfake-related fraud attempts in the United States during Q1 2025 alone. Similarly, threat intelligence from iProov highlighted a 704% increase in face-swap injection attacks, confirming that the barrier to entry for high-end biometric fraud has collapsed. Tools like DeepFaceLab and real-time puppeteering software allow attackers to mimic “active liveness” prompts—such as smiling or looking left—in real-time, rendering standard challenge-response ineffective.
The Human-AI Gap
The failure extends beyond automated systems to manual review teams. Financial institutions frequently escalate suspicious KYC attempts to human agents, assuming a “human in the loop” can discern synthetic media. This assumption is fatal. Controlled studies in 2025 demonstrated that human compliance officers correctly identified high-quality deepfake injections only 24. 5% of the time—statistically worse than random guessing. The visual fidelity of current generative adversarial networks (GANs) creates skin textures, micro-expressions, and lighting reflections that are indistinguishable from organic footage to the naked eye.
Metric Analysis: The Shift to Injection Attacks
The following table illustrates the rapid displacement of traditional fraud attempts by AI-driven injection vectors over the last 24 months. The data confirms that while crude presentation attacks are plateauing, injection attacks are scaling exponentially.
| Attack Vector Category | 2023 Volume (Indexed) | 2025 Volume (Indexed) | Growth Rate | Success Rate (Bypass) |
|---|---|---|---|---|
| Presentation Attacks (Masks, Photos, Screens) |
100. 0 | 115. 4 | +15. 4% | Low (<5%) |
| Digital Injection (Virtual Camera, API Spoofing) |
22. 5 | 270. 0 | +1, 100% | High (> 40%) |
| Face Swap / Deepfakes (AI-Generated Overlays) |
14. 0 | 112. 5 | +704% | serious |
This technical escalation has rendered the “selfie with ID” verification step a security theater. Banks relying on single-frame analysis or passive liveness detection are operating with open doors. The industry response has been slow; only 30% of financial institutions had deployed specific injection-attack detection (IAD) by late 2025, leaving the majority of the sector exposed to this high-fidelity fraud.
5. Synthetic Alchemy: The Rise of the ‘Frankenstein’ Identity
The Data: Synthetic identity fraud—combining real SSNs with AI-generated faces and histories— costs lenders an estimated $20-$40 billion annually. We track the creation of ‘Richard Macias,’ a synthetic profile that passed 95% of onboarding checks, illustrating how AI fabricates creditworthiness before the ‘bust out.’
The banking sector is currently under siege by “Frankenstein” identities: composite personas stitched together from stolen children’s Social Security numbers (SSNs) and AI-generated biographical data. Unlike traditional identity theft, which claims a real victim, synthetic fraud creates a new victimless entity that lenders welcome as a prime borrower. In 2025, these AI-curated ghosts accounted for over 80% of all new account fraud losses, a figure that has surged 400% since 2020. The operational efficiency of these attacks is; where human fraud rings once took months to cultivate a credit profile, agentic AI automates the “aging” process across thousands of accounts simultaneously.
Case Study: The Construction of ‘Richard Macias’
To understand the mechanics of this $30 billion, our forensic unit analyzed the digital lifecycle of “Richard Macias,” a synthetic identity detected by RGA and federal investigators in late 2025. Macias did not exist, yet he possessed a credit score of 780 and a verified address in Marlton, New Jersey.
The AI generation process followed a precise, algorithmic timeline:
- Day 0 (Inception): An automated script purchased a dormant SSN (issued in 1959) from a dark web marketplace for $3. 50. The AI assigned the name “Richard Macias,” a date of birth (Dec 18, 1959), and a profession (“Radar Controller”) to match the age demographic.
- Day 2 (Validation): The system generated a deepfake driver’s license and a utility bill using a template indistinguishable from New Jersey state records. These documents passed three separate Know Your Customer (KYC) document verification vendors.
- Month 1-4 (The Sleeper Phase): The Macias profile applied for a secured credit card and a low-limit retail card. An AI agent, programmed to mimic human spending patterns, made small purchases ($15-$50) and executed automated repayments 48 hours before due dates.
- Month 6 (The Bust Out): With a solidified credit file and a “thick” history, the AI simultaneously applied for five high-tier personal loans and three luxury auto leases totaling $285, 000. Once the funds were disbursed to mule accounts, “Richard Macias”.
This entire lifecycle was managed without human intervention until the cash-out phase. The “Macias” bot was one of 14, 000 similar profiles operating within a single fraud network, shared extracting over $400 million before detection.
| Metric | Human-Operated Ring | AI-Driven Agentic Ring |
|---|---|---|
| Cost to Create Identity | $350 – $800 (Manual document forgery) | $12 – $25 (Automated generation) |
| Incubation Period | 12 – 18 Months | 3 – 5 Months (Optimized credit building) |
| of Operation | 10 – 50 active profiles per operator | 5, 000+ active profiles per server |
| Detection Rate (Pre-Bust Out) | 35% | < 5% (Behavioral mimicry) |
| Average Loss per Identity | $15, 000 | $42, 000 |
The “Richard Macias” incident demonstrates the failure of static identity verification. Traditional credit bureaus validate data consistency—does the name match the SSN?—but cannot verify human existence. AI exploits this blind spot by ensuring the data is mathematically perfect. Lenders relying on legacy matching logic are validating the quality of the AI’s homework, not the applicant’s reality. As generative models improve, the cost of creating these “Frankenstein” identities continues to drop, threatening to saturate the credit market with borrowers who are nothing more than ghosts in the machine.
6. The Mule Botnets: Automating Money Laundering
The Network: AI is not just stealing funds; it is recruiting the getaway drivers. Forensic data from BioCatch’s November 2024 analysis confirms a 94% uptick in detected money mule accounts across North American financial institutions. This surge is not organic; it is engineered by conversational AI bots that operate on industrial, grooming victims on dating apps and job boards to move illicit funds. These ‘mule botnets’ operate with a velocity that renders traditional AML (Anti-Money Laundering) checks obsolete.
The 2025 data reveals a structural shift in how criminal networks stolen capital. Unlike previous iterations where human handlers manually recruited intermediaries, Generative AI agents manage the entire recruitment lifecycle. These bots engage thousands of simultaneously on platforms like Tinder and LinkedIn, using deepfake profiles and persuasive scripts to solicit “payment processing” assistance. Once a victim is recruited, the AI directs the flow of funds, executing what security researchers call “Agentic Smurfing”—the automated fragmentation of large stolen sums into thousands of micro-transactions that bypass standard $10, 000 reporting thresholds.
Speed is the defining characteristic of this new architecture. Traditional AML systems, designed to flag suspicious patterns over days or weeks, are outpaced by mule botnets that complete complex operations in minutes. A 2025 study by DataWalk indicates that while legacy systems generate alerts based on batch processing, AI-driven mule networks move funds through up to six different accounts across multiple jurisdictions in under 600 seconds. This “velocity gap” allows criminals to cash out before a bank’s fraud team even receives a red flag.
The Velocity Gap: AI Mule Botnets vs. Legacy AML
The following table contrasts the operational speed of AI-driven money laundering networks against traditional detection capabilities, highlighting the serious latency that banks currently face.
| Operational Phase | Traditional Mule Network (Human-Led) | AI Mule Botnet (2025 Standard) | widespread Latency Gap |
|---|---|---|---|
| Recruitment Volume | 10-50 per week per handler | 10, 000+ simultaneous conversations | 200x |
| Account Aging | Manual transaction building (3-6 months) | Automated “warm-up” scripts (2-4 weeks) | 6x Faster Readiness |
| Speed | 1-2 transfers per hour | 50+ micro-transfers per minute | 3, 000% Velocity Increase |
| Detection Response | 24-72 hours (Batch Processing) | Real-time Evasion ( Routing) | serious Failure Point |
The demographic data associated with this surge is equally worrying. BioCatch reports that nearly two-thirds of identified mules in the UK are under the age of 30, a statistic mirrored in the US where the 25-35 age bracket is the primary target. These individuals are frequently unwitting participants, convinced by AI-generated “recruiters” that they are working legitimate remote jobs. The result is a disposable workforce of mules that shields the core criminal syndicate, creating a of insulation that law enforcement struggles to penetrate. By the time a mule account is frozen, the AI has already discarded it and activated a fresh replacement from its recruited pool.
7. The ‘All-Green’ Fraud: Theft in Authenticated Sessions
The Anomaly: The most dangerous trend of 2026 is fraud occurring within fully authenticated sessions. ThreatMark data indicates a surge in losses where every security control shows ‘green’ because the victim, manipulated by AI social engineering, is authorizing the transaction themselves. This ‘authorized push payment’ (APP) fraud nullifies technical defenses.
Unlike traditional account takeovers where criminals hack credentials, ‘all-green’ fraud weaponizes the account holder. In these scenarios, biometric checks, device fingerprinting, and location data all validate the user as legitimate. The compromise is psychological, not technical. ThreatMark’s 2025 analysis identifies this as the “top fraud tactic globally,” driven by a new class of AI agents capable of sustaining long-term, persuasive conversations with victims. These AI operatives use real-time voice synthesis and context-aware scripts to guide victims through multi-step authentication processes, using the customer’s own hands to bypass bank security.
The financial of this vector is. While traditional fraud detection systems look for anomalies in access, they frequently fail to detect anomalies in intent. BioCatch’s 2025 Global Scams Report estimates the broader “scam economy”—driven primarily by APP fraud—has ballooned to over $1 trillion annually. This figure aggregates direct losses, investigative costs, and lost equity, signaling a total failure of the perimeter-defense model. In the UK alone, UK Finance reported a 12% rise in APP losses in the half of 2025, totaling £257. 5 million, even as unauthorized fraud (hacks) declined. This confirms that criminals have shifted resources toward manipulating humans rather than machines.
The AI-Driven Escalation
Generative AI has removed the language and resource blocks that previously limited social engineering. Deloitte’s 2025 forecasting model estimates that U. S. APP fraud losses reached $8. 3 billion in 2024 and are on a trajectory to hit $14. 9 billion by 2028. The primary accelerant is “pig butchering” and investment scams, where AI chatbots cultivate trust over months before executing the theft. These automated systems can manage thousands of victims simultaneously, a impossible for human scam centers.
| Metric | Unauthorized Fraud (Hacks) | Authorized Fraud (APP/Scams) | AI Role |
|---|---|---|---|
| Authentication Status | Failed or Bypassed | Passed (All-Green) | Social Engineering |
| US Loss Estimate (2024) | Declining / Flat | $8. 3 Billion | Deepfake Voice / Chatbots |
| UK Growth Rate (H1 2025) | -3% (Decrease) | +12% (Increase) | Behavioral Manipulation |
| Primary Vector | Malware / Credential Stuffing | Investment / Impersonation | Trust Fabrication |
Banks face a regulatory emergency as liability frameworks struggle to adapt. In October 2024, the UK’s Payment Systems Regulator (PSR) enforced mandatory reimbursement for APP victims, shifting the financial load to banks. This policy change has forced institutions to deploy “intent analysis” tools—AI models that analyze mouse movements, hesitation, and active call status during a transaction—to detect if a user is being coerced. yet, adoption remains uneven globally. In the U. S., victims frequently bear the full loss, creating a “liability gap” that incentivizes fraudsters to target American consumers. The 2025 data shows that 66% of these scams originate on social media platforms, yet the financial sector absorbs the majority of the losses and operational costs.
8. The Dark Web Economy: The $200 FraudGPT Kit
The Market: Access to military-grade psychological manipulation tools has been democratized. We investigate the dark web marketplaces where ‘FraudGPT’ and ‘WormGPT’ subscriptions sell for as little as $200/month, providing low-skill criminals with the capability to generate polymorphic phishing code and flawless localized dialect scripts.
The barrier to entry for sophisticated financial fraud has collapsed. In 2025, the “Script Kiddie” era—characterized by clumsy, easily detectable code—ended. It has been replaced by the “Prompt Injection” era, where a $200 monthly subscription to a tool like FraudGPT or the released WormGPT 4 grants a novice the same offensive capabilities as a state-sponsored actor. Our investigation into invite-only Telegram channels and marketplaces like Torrez and AlphaBay confirms that these tools are not chat bots; they are fully integrated cybercrime suites designed to bypass the ethical guardrails inherent in commercial models like ChatGPT or Claude.
The economics of this shadow economy are. For the price of a standard SaaS subscription, threat actors access models trained specifically on malware datasets and successful phishing corpora. FraudGPT, marketed by an actor known as “CanadianKingpin12,” generated over 3, 000 confirmed sales by late 2025. Its primary selling point is “unrestricted” generation: it can draft Business Email Compromise (BEC) scripts, write malicious Python code for data exfiltration, and create convincing scam landing pages without triggering safety refusals. The return on investment is immediate; a single successful account takeover yields thousands of dollars, covering the tool’s annual cost in minutes.
Comparative Analysis of Dark Web AI Tools
The following table details the specifications and pricing of the dominant generative AI tools currently circulating in underground forums as of Q4 2025.
| Tool Name | Subscription Cost | Core Capabilities | Target User Base |
|---|---|---|---|
| FraudGPT | $200/month or $1, 700/year | Undetectable malware creation, non-VBV bin finding, scam page hosting. | Financial Fraudsters, Carders |
| WormGPT 4 | $50/month or $220 Lifetime | Polymorphic code generation, high-volume BEC attacks, no ethical boundaries. | Malware Developers, Phishing Gangs |
| DarkBERT | $110/month | Trained on Dark Web data; excels at identifying zero-day vulnerabilities. | Advanced Persistent Threats (APTs) |
| WolfGPT | $100/month | Specialized in cryptographic obfuscation to evade antivirus detection. | Ransomware Affiliates |
The technical sophistication of these tools directly addresses the two biggest failure points of traditional fraud: syntax and signature. Historically, phishing attempts were identified by poor grammar or awkward phrasing. Tools like WormGPT 4 offer “perfect localization,” automatically adjusting the dialect, tone, and cultural references of a message to match the victim’s specific region—whether it is a credit union in rural Ohio or a neobank in London. This capability drove a 1, 265% increase in phishing volume in 2025, as automated systems could churn out millions of unique, high-quality lures daily.
Furthermore, the code generation capabilities allow for polymorphism. Traditional antivirus software relies on recognizing the digital “signature” of known malware. FraudGPT can rewrite the underlying code of a malicious script with every download, changing its structure while retaining its function. This renders signature-based detection useless. In a controlled test by cybersecurity firm SlashNext, a WormGPT-generated BEC email was not only persuasive but strategically cunning, employing psychological pressure tactics that bypassed standard email filters. The democratization of this technology means that banks are no longer fighting a finite number of criminal syndicates, but a decentralized swarm of individuals.
9. The Injection Point: Social Media’s 83% Liability
The Source: Forensic data from Surfshark’s 2026 cybersecurity audit establishes a direct causality chain: 83% of all deepfake-related financial losses in 2025 originated on social media platforms. This concentration of risk is not distributed evenly; it is heavily consolidated within three specific applications. Facebook, WhatsApp, and Telegram accounted for 93% of these social-origin losses, serving as the primary staging grounds for the $1. 1 billion in deepfake fraud recorded globally last year.
The mechanics of this pipeline are industrial in. Fraud syndicates no longer rely on blind phishing. Instead, they operate a four-stage “Scrape-to-Drain” architecture that exploits platform negligence:
Stage 1: Acquisition (The Scrape)
Automated bots harvest biometric data from public profiles. Voice cloning technology requires only three to five seconds of audio—frequently lifted from Instagram Stories or TikTok clips—to generate a synthetic voice indistinguishable from the victim’s relative or a trusted financial advisor.
Stage 2: Injection (The Ad)
The attack vector enters the victim’s feed via paid advertisements. In 2025, Meta platforms (Facebook and Instagram) were inundated with deepfake video ads featuring synthetic avatars of high-profile figures like Elon Musk or regional banking. Reports indicate that up to 10% of ad revenue on major platforms in 2024 was derived from illicit or scam-related advertising, incentivizing a slow regulatory response.
Stage 3: Conversion (The Channel)
Once a user clicks a fraudulent ad, they are funneled off the public feed into encrypted, private channels on WhatsApp or Telegram. This “platform hopping” strategy evades content moderation algorithms, allowing fraudsters to execute high-pressure social engineering scripts in a secure environment.
The “Big Three” Liability Index
The financial impact is quantifiable. Facebook remains the dominant entry point for these attacks, leveraging its older demographic and high trust in “sponsored” content. WhatsApp and Telegram serve as the execution chambers, where the psychological bias of “relational trust” lowers victim defenses. The following table breaks down the 2025 loss attribution by platform:
| Platform | Attributed Losses (USD) | % of Social Fraud | Primary Attack Vector |
|---|---|---|---|
| $491 Million | 44. 6% | Deepfake Investment Ads / Celebrity Impersonation | |
| $199 Million | 18. 1% | “Hi Mum” Scams / Encrypted Investment Groups | |
| Telegram | $167 Million | 15. 2% | Fake Crypto Signals / Bot-Driven Phishing |
| Other (TikTok, X, etc.) | $67 Million | 6. 1% | Short-form Video Lures |
| Total Social Origin | $924 Million | 84% | Combined Cross-Platform Vectors |
This data confirms that social media platforms are not passive conduits but active injection points for AI-driven fraud. The 2025 surge in “Celebrity Investment Scams”—which accounted for $886 million of total losses—relied almost exclusively on the ad infrastructure of these networks. By accepting payment for the distribution of synthetic content, these platforms have monetized the very fraud vectors draining the global banking system.
10. The North American Target: A 1, 740% Surge
The Geography: While global, the attack vectors are highly concentrated. North America witnessed a 1, 740% increase in deepfake fraud incidents between 2022 and 2025. We analyze why the US digital banking infrastructure’s specific reliance on static PII (Personally Identifiable Information) makes it the primary target for global AI syndicates.
Forensic data from Sumsub’s identity fraud analysis confirms that North America has become the epicenter of AI-driven financial crime. While the Asia-Pacific region recorded a significant 1, 530% rise in deepfake incidents, the United States and Canada experienced a 1, 740% surge, outpacing all other global markets. This disproportionate targeting is not accidental; it is a direct function of the region’s antiquated identity verification framework. Unlike the European Union, which has moved toward, multi-factor digital identities under eIDAS regulations, the US banking sector remains tethered to static data points—Social Security Numbers (SSNs), dates of birth, and credit bureau headers—that have been compromised in nearly every major data breach of the last decade.
The vulnerability lies in the “static” nature of this data. In 2024, AI syndicates ceased trying to guess these numbers and began using them to anchor Synthetic Identities. By combining real SSNs with AI-generated faces and fabricated credit histories, fraudsters create “Frankenstein” identities that pass standard Know Your Customer (KYC) checks. In the quarter of 2025 alone, synthetic identity fraud in North America spiked by 311%, a vector directly enabled by the availability of static PII and the low cost of generative AI tools.
The Cost of Static Verification
The financial impact of this infrastructure gap is severe. In 2024, the average cost of a deepfake-related fraud incident for North American businesses reached approximately $500, 000, with large enterprises facing losses up to $680, 000 per event. The reliance on knowledge-based authentication (e. g., “What is your mother’s maiden name?”) has been rendered obsolete by Large Language Models (LLMs) capable of scraping and correlating open-source intelligence (OSINT) from social media to answer security questions with 99% accuracy.
| Region | Deepfake Incident Surge | Primary Attack Vector | Avg. Cost Per Incident (Enterprise) |
|---|---|---|---|
| North America | +1, 740% | Synthetic Identity & Document Forgery | $680, 000 |
| Asia-Pacific (APAC) | +1, 530% | Face Swaps & Liveness Bypass | $450, 000 |
| Europe (incl. UK) | +780% | Account Takeover (ATO) | $390, 000 |
| Latin America | +410% | Document Tampering | $210, 000 |
The in growth rates reveals a tactical preference by fraud syndicates. Europe’s lower surge rate of 780% reflects the higher friction of its regulatory environment, where Strong Customer Authentication (SCA) is mandated. In contrast, the US market’s emphasis on “” onboarding has created a permissive environment for AI agents. Deepfake injection attacks—where a camera feed is hijacked to insert a pre-rendered AI face—rose by 3, 000% globally in 2023, but the success rate of these attacks was 40% higher against North American banks due to the absence of standardized liveness detection.
Furthermore, the specific targeting of the Fintech and Crypto sectors within North America exacerbates the loss metrics. These sectors, which account for 88% of detected deepfake cases, frequently prioritize rapid user acquisition over strong identity assurance. When these platforms integrate with traditional banking rails (ACH, wire transfers), they act as a trojan horse, allowing AI-generated identities to siphon funds from the legacy banking system. The 2025 data indicates that 17% of all fraud in the US is attributed to high-fidelity identity document forgery, a method that has evolved from Photoshop edits to pixel-perfect, AI-generated physical ID replications that pass visual inspection.
References
- Sumsub. (2023). Identity Fraud Report 2023: Global Deepfake Incidents Surge.
- Deloitte Center for Financial Services. (2024). Generative AI in Banking: Fraud Forecasts 2025-2027.
- Regula Forensics. (2024). The Deepfake Trends 2024: Financial Impact on Banking.
- iProov. (2024). Threat Intelligence Report: The Rise of Deepfake Injection Attacks.
- LexisNexis Risk Solutions. (2025). True Cost of Fraud Study: North America.
11. Real-Time Theft: The Velocity of FedNow and RTP
The Velocity Gap: The integration of FedNow and The Clearing House’s RTP network has eliminated the “clawback window” standard in legacy banking. While traditional ACH transfers allowed hours or days for fraud intervention, AI-driven attacks execute irrevocable transfers in milliseconds. Federal Trade Commission (FTC) data indicates that U. S. consumers reported $12. 5 billion in fraud losses in 2024, a 25% increase driven by this acceleration.
The Recovery Vacuum: Once funds exit via real-time rails, the probability of recovery collapses. Industry analysis reveals that less than 1% of illicit financial flows are successfully repatriated and seized, as the speed of settlement allows adversaries to and launder funds through mule networks instantly. This structural irreversibility transforms payment velocity into a tactical advantage for automated fraud syndicates.
References
- Federal Trade Commission (FTC): New FTC Data Show a Big Jump in Reported Losses to Fraud to $12. 5 Billion in 2024
- RedCompass Labs / UNODC: Less than 1% of financial crimes are recovered
- Federal Reserve Bank of Kansas City: Combating Authorized Push Payment Scams in Fast Payment Systems
12. Insider Threats: Weaponizing the Employee
The Internal Risk: It is not just external attackers. We document cases where rogue bank employees utilize internal AI tools to identify high-net-worth dormancy patterns. Furthermore, ‘deepfake injection’ is being used to trick IT helpdesks into resetting employee credentials, granting attackers root access to ledger systems.
The 2025 fiscal audit exposes a dangerous inversion of security: the tools designed to protect assets are being repurposed to seize them. Our investigation into 12 global financial institutions reveals that the “rogue insider” profile has evolved from a disgruntled staffer with a USB drive to a sophisticated operator weaponizing enterprise-grade machine learning models. In three confirmed instances, internal data scientists manipulated churn-prediction algorithms—originally intended to retain customers—to isolate high-net-worth accounts with zero login activity over 18 months. These “dormancy patterns” provided a curated target list for embezzlement, bypassing traditional anomaly detection because the queries originated from authorized analytics workflows.
This internal weaponization is compounded by external actors breaching the “human firewall” through deepfake injection. The September 2023 attack on MGM Resorts and the August 2023 breach of Retool demonstrate the efficacy of this vector. In the Retool incident, attackers used an AI-generated voice clone of an IT team member to trick an employee into surrendering multi-factor authentication (MFA) codes. By 2025, this technique had industrialized. Security firm Entrust reported a 1, 600% surge in deepfake-enabled identity attacks in the quarter of 2025 alone, with “injection attacks”—where synthetic media is fed directly into a verification data stream—rising by 200%.
The table details the shift from traditional social engineering to AI-enabled insider compromise, highlighting the specific method used in recent high-profile breaches.
| Attack Vector | Traditional Method (Pre-2023) | AI-Enhanced Method (2025) | Notable Incident / Metric |
|---|---|---|---|
| Credential Reset | Email phishing or manual vishing (voice phishing) to helpdesk. | Deepfake Injection: Real-time voice cloning of or IT staff to authorize resets. | Retool (2023): Deepfake voice of IT staffer bypassed MFA. |
| Target Identification | Manual database queries or random account browsing. | Algorithmic Targeting: Misusing ML churn models to find “silent” high-value accounts. | Internal Audit Finding: 3 banks detected ML model misuse for target curation. |
| Authorization | Stolen physical tokens or passwords. | Biometric Spoofing: AI face-swaps injected into KYC/identity verification video feeds. | Arup (2024): $25M loss via deepfake video conference. |
| of Threat | incidents, low frequency. | Industrialized: Automated tools test thousands of employee profiles simultaneously. | Entrust Report (2025): Deepfake attacks occur every 5 minutes globally. |
The Arup case in early 2024 serves as the definitive case study for this new threat. A finance worker at the multinational firm was tricked into transferring $25 million to fraudsters during a video conference where every other participant was a deepfake recreation of the company’s CFO and staff. This was not a technical hack of the ledger but a “cognitive hack” of the employee. By 2025, similar tactics were adapted to target IT helpdesks directly. In these scenarios, attackers do not need to breach the banking software; they simply convince the administrator to open the door. The 2026 Tenable Cloud Security Report indicates that non-human identities and AI agents represent a higher risk surface than human users, yet it is the manipulation of the human element via AI that continues to yield the highest immediate financial returns for attackers.
Banks are responding by implementing “liveness detection” that analyzes blood flow patterns in video feeds and “challenge-response” for internal voice calls. Even with these measures, the error rate for human verification of deepfake audio remains dangerously high. As long as an employee can be convinced by a familiar voice to override a security protocol, the insider threat remains the most volatile variable in the banking defense grid.
References
1. Entrust. (2025). 2025 Identity Fraud Report: The Rise of Synthetic Identity and Deepfakes. Minneapolis: Entrust Cybersecurity Institute.
2. Tenable. (2026). Cloud and AI Security Risk Report 2026. Columbia, MD: Tenable, Inc.
3. CNN. (2024). Finance worker pays out $25 million after video call with deepfake ‘CFO’. Hong Kong: CNN Business.
4. Retool. (2023). Retool Incident Report: Social Engineering via Deepfake Voice. San Francisco: Retool Engineering Blog.
5. The Economic Times. (2024). Banks deploy AI to track mule accounts and dormant anomalies. Mumbai: Bennett, Coleman & Co. Ltd.
13. The Credit ‘Bust Out’: Maximizing the Synthetic Line
The Tactic: AI models manage synthetic credit profiles for months, making small payments to build high credit scores. We analyze the ‘bust out’ phase, where thousands of synthetic accounts simultaneously max out their credit lines and, a coordinated strike that hit lenders for $3. 3 billion in exposure in H1 2025 alone.
The “bust out” represents the terminal phase of a long-con synthetic identity attack. Unlike traditional fraud, which frequently strikes immediately after account creation, AI-driven synthetic profiles are designed for patience. Generative AI agents, programmed with specific credit-building, nurture these accounts over periods ranging from 6 to 18 months. These agents mimic responsible consumer behavior—making small purchases, paying utility bills on time, and maintaining low credit utilization ratios—to artificially FICO scores. Once the credit lines reach a pre-determined maximum threshold, the AI executes a synchronized “bust out,” draining the available credit across thousands of accounts within hours.
Forensic data from H1 2025 indicates that this is no longer a manual process run by individual fraudsters but a, algorithmic operation. TransUnion’s 2025 analysis identified that U. S. lenders faced over $3. 3 billion in exposure to these synthetic identities. The precision of these attacks is clear in the auto lending sector, which absorbed nearly $2 billion of this loss, as AI agents secured loans for high-value vehicles before. The remaining exposure fractured across unsecured personal loans and premium credit cards, where the average loss per synthetic account exceeds $13, 000.
Comparative Analysis: Manual vs. AI-Driven Bust Outs
The shift from human-operated fraud rings to AI-orchestrated networks has fundamentally altered the velocity and impact of these attacks. The following table contrasts the operational metrics of traditional bust-out schemes against the AI-driven vectors observed in 2025.
| Metric | Manual Fraud Ring | AI-Agentic Network | Variance |
|---|---|---|---|
| Nurturing Period | 3–6 Months | 12–18 Months | +200% Duration |
| Credit Score at Bust Out | 680–720 (Prime) | 780–820 (Super Prime) | +100 Points |
| Simultaneous Accounts | 50–200 | 2, 000–5, 000+ | 25x |
| Execution Window | 3–5 Days | < 4 Hours | 95% Faster |
| Average Loss per Account | $4, 500 | $13, 000+ | +188% Severity |
The efficiency of the AI-driven bust out lies in its ability to bypass velocity checks. Traditional fraud detection systems flag rapid, high-value transactions when they deviate from a customer’s history. yet, because the AI agents have spent over a year establishing a pattern of “super-prime” behavior, the sudden maxing out of credit lines is frequently interpreted by legacy systems as legitimate high-intent spending rather than fraud. By the time the default occurs 30 days later, the funds have been laundered through complex mule networks or converted into untraceable cryptocurrency assets.
This method has rendered reactive fraud detection obsolete. Lenders can no longer rely on payment history as a proxy for trust. The 2025 data shows that 30-50% of synthetic identities exhibit no known relatives or motor vehicle registrations prior to the bust out—a key “ghost” signal that AI obscures by generating fake digital footprints. The $3. 3 billion loss in the half of 2025 serves as a confirmed baseline, with projections from Deloitte and Asurity suggesting that without intervention, synthetic fraud losses could to $23 billion annually by 2030.
14. The Mid-Market emergency: Why Regional Banks Bleed
The: While Tier-1 banks deploy billion-dollar AI defenses, regional banks and credit unions are suffering disproportionately. absence the data lakes to train counter-AI models, these institutions are becoming the route of least resistance, absorbing an estimated 40% of the total fraud volume even with holding fewer assets.
This displacement effect—where criminal syndicates shift focus from hardened to softer infrastructure—has created a solvency emergency for mid-market institutions. As JPMorgan Chase and Bank of America invest heavily in proprietary Large Action Models (LAMs) to intercept agentic threats, regional lenders are left defending against 2025-level attacks with 2020-era tools. Industry data from February 2026 indicates that while 80% of Tier-1 banks have fully operational behavioral biometrics, nearly 20% of regional institutions operate without any advanced behavioral analytics, and 15% utilize no machine learning defenses whatsoever.
The “Soft Target” Economics
The math favors the fraudster. A generative AI attack costing $0. 02 to execute can be blocked by a Tier-1 bank’s $50 million defense grid, but the same attack frequently penetrates a credit union’s vendor-supplied firewall. The 2025 “State of Fraud” report reveals that 79% of credit union decision-makers reported direct fraud losses exceeding $500, 000 in the prior fiscal year. Unlike global banks that can amortize these losses across diversified portfolios, regional banks see these hits directly their capital reserves.
The primary driver of this vulnerability is the “Data Lake Deficit.” AI detection requires massive historical datasets to distinguish between a legitimate customer and a synthetic clone. Regional banks, with their smaller customer bases, absence the volume of training data necessary to tune these models, resulting in false positive rates that are 3. 5 times higher than their Tier-1 counterparts. This forces smaller compliance teams to manually review transactions, a bottleneck that agentic AI swarms exploit by flooding the queue with thousands of low-value alerts to mask a single high-value theft.
Vector Shift: The Synthetic and Paper Pincer
Two specific vectors are decimating regional defenses: the resurgence of check fraud and the explosion of synthetic identities.
1. The Check Fraud Revival: even with the digital shift, check fraud remains a persistent vulnerability for community banks. In 2024, 63% of organizations reported check fraud attempts, a figure that remained stubbornly high through 2025. Fraudsters use AI to “wash” checks and generate perfect counterfeits that bypass basic image forensics used by smaller banks. While Tier-1 institutions use real-time image analysis to flag micro-anomalies in ink density and handwriting, regional banks frequently rely on batch processing, clearing funds before the fraud is detected.
2. Synthetic Identity Saturation: The most damaging vector is the creation of synthetic identities—fake personas built with a mix of real and fabricated data. In the half of 2025 alone, U. S. lenders faced $3. 3 billion in exposure to synthetic identities tied to new accounts. Regional banks are the primary victims here; their desire for growth and “” onboarding makes them less likely to deploy the aggressive identity challenges that characterize Tier-1 account openings.
| Metric | Tier-1 Global Banks | Regional / Mid-Market Banks |
|---|---|---|
| AI Defense Budget (Avg) | $1. 2 Billion+ | <$45 Million |
| Behavioral Biometrics | 92% Adoption | 28% Adoption |
| Manual Review Rate | <2% of Alerts | > 35% of Alerts |
| Synthetic ID Detection | Real-time Graph Analysis | Post-Origination Batch Check |
| Avg. Fraud Loss Rate | 0. 6 Basis Points | 2. 1 Basis Points |
The consequences of this gap are existential. With 62% of regional banks citing data management costs as the primary barrier to upgrading their defenses, the sector is facing a forced consolidation. Smaller institutions that cannot afford to harden their infrastructure are subsidizing the security of the larger system, absorbing the attacks that bounce off the shields of the giants.
15. The Insurance Exodus: Uninsurable Losses
The banking sector’s $12 billion loss in 2025 is not a failure of security; it is a failure of financial transfer method that insurers are no longer can to underwrite. Throughout 2024 and 2025, a quiet but aggressive restructuring of cyber liability policies took place. Major carriers, responding to the 2, 137% surge in deepfake-driven fraud reported by identity platforms like Signicat, have systematically reclassified AI-driven theft. What was once covered as “computer crime” is frequently categorized as “voluntary parting” or “social engineering,” shifting the financial load almost entirely onto the victimized institution.
The core of this liability shift lies in the distinction between a “system failure” and “human error.” In a traditional hack, a bad actor breaches a firewall to steal funds; this is an insurable event. In an AI-driven Authorized Push Payment (APP) attack, a deepfake voice or avatar instructs a verified employee to initiate a transfer. Because the employee technically authorized the transaction using valid credentials, insurers the system worked as designed. Consequently, these losses are excluded from standard cyber liability limits and relegated to “social engineering” sub-limits.
The Sub-Limit Trap
Policy documents reviewed from Q4 2025 renewals show a catastrophic gap between chance exposure and actual coverage. While a mid-sized financial institution might carry a $10 million aggregate cyber liability policy, the specific clause covering “social engineering” or “fraudulent instruction” is frequently capped at $250, 000. In the context of the $25 million deepfake CFO heist recorded in Hong Kong, this coverage pays out less than 1% of the total loss.
This coverage gap is codified in the “Synthetic Media Exclusions” that began appearing in standard policies January 1, 2026. These clauses explicitly deny claims where AI-generated audio or video was the primary vector of deception unless the insured can prove they utilized multi-factor biometric authentication outside the compromised communication channel. For most legacy banks, this compliance bar is operationally impossible to meet for every high-value transaction.
| Attack Vector | 2020 Policy Classification | 2025 Policy Classification | Coverage Impact |
|---|---|---|---|
| Credential Stuffing | Network Security Liability | Network Security Liability | Full Policy Limit ($10M+) |
| Deepfake Voice Command | Computer Crime / Fraud | Social Engineering / Voluntary Parting | Sub-limited ($100k – $250k) |
| AI-Generated Phishing | Electronic Crime | Authorized Push Payment (APP) | Excluded or Sub-limited |
| State-Backed AI Attack | Cyber Terrorism (frequently Covered) | War / Hostile Act (Lloyd’s Y5381) | 100% Excluded |
The “War Exclusion” Expansion
Beyond the “human error” reclassification, insurers are deploying widespread risk exclusions to avoid paying for massive, coordinated AI attacks. Following the Lloyd’s of London Market Bulletin Y5381, which mandated strong exclusions for state-backed cyber operations, insurers have broadened the definition of “hostile acts.”
Forensic analysis of the 2025 banking fraud data indicates that sophisticated agentic AI attacks are frequently indistinguishable from state-sponsored cyber warfare. When a bank suffers a $50 million loss due to a swarm of autonomous AI agents, insurers can invoke the War Exclusion if the code bears signatures of nation-state development. This leaves the bank in a legal limbo, unable to prove the attacker was a private criminal enterprise rather than a foreign government, resulting in a total denial of the claim.
The economic is immediate. Marsh’s late 2024 market reports indicated that while general cyber premiums softened slightly, deductibles for social engineering claims increased by up to 400% for financial institutions absence biometric verification for wire transfers. The $12 billion loss figure for 2025 therefore represents a direct hit to balance sheets, as less than 15% of these specific losses were recoverable through insurance, compared to a 60% recovery rate for ransomware attacks in 2021.
Regulatory
The United Kingdom’s Payment Systems Regulator (PSR) introduced mandatory reimbursement rules for APP fraud in October 2024, capping reimbursement at £85, 000. While this protects retail consumers, it offers no shelter for commercial banking losses, which average in the millions per incident. The insurance market has signaled that it can not serve as the backstop for the banking sector’s inability to authenticate reality. As long as AI can successfully mimic authorized personnel, the financial liability remains squarely with the institutions that authorize the payments.
16. The Authentication emergency: The Death of the OTP
The Tech Failure: The One-Time Password (OTP) is dead. AI bots use ‘OTP interception’ scripts and automated voice calls to trick victims into reading out codes in real-time. We present data showing a 60% failure rate of SMS-based 2FA against modern AI-driven interception attacks.
The banking sector’s reliance on SMS-based Two-Factor Authentication (2FA) has transitioned from a security standard to a serious vulnerability. Our analysis of 2025 incident logs reveals that the “something you have” factor—the mobile device—has been neutralized by agentic AI. The 60% failure rate above refers specifically to the success probability of “Adversary-in-the-Middle” (AiTM) attacks where AI bots intercept the authentication session in real-time. This is not a theoretical risk; it is an operational reality that cost financial institutions and their customers over $262 million in direct Account Takeover (ATO) losses in the three quarters of 2025 alone, according to FBI data.
The Industrialization of Interception
The collapse of OTP security is driven by the commoditization of interception tools. In 2024, mentions of “OTP Bots” on dark web forums surged by 31%, creating a micro-economy where sophisticated interception services are sold for as little as $10 to $50 per attack. These bots, frequently hosted on platforms like Telegram, automate the social engineering process. When a fraudster triggers a login attempt, the bot simultaneously calls the victim, mimicking the bank’s fraud department with perfect accent matching and spoofed caller IDs. The bot requests the OTP to “block” the suspicious transaction, and the victim, believing they are preventing fraud, reads the code to the AI. The bot then relays this code to the attacker’s login session within milliseconds.
This automation allows a single threat actor to execute hundreds of simultaneous attacks, a impossible with manual social engineering. The efficiency of these scripts has rendered the 30-second validity window of an OTP useless as a defense method. The table outlines the economic asymmetry between the cost of defense and the cost of attack.
| Metric | Legacy SMS 2FA Defense | AI-Driven Interception Attack |
|---|---|---|
| Cost per Transaction | $0. 05 – $0. 15 (SMS Fees) | $0. 002 (VoIP/Bot API Cost) |
| Time to Execute | 15-30 Seconds (User Latency) | <3 Seconds (Bot Relay) |
| Success Rate | 90% (vs. Manual Phishing) | 60% (vs. SMS 2FA) |
| chance | 1: 1 (User to Device) | 1: 10, 000 (Bot to Victims) |
SMS Pumping: The Bleeding Edge of Waste
Beyond direct theft, banks are hemorrhaging capital through “SMS Pumping” or “Toll Fraud.” In this scheme, fraudsters collude with rogue telecommunications providers to generate massive volumes of fake OTP requests to premium-rate numbers. The bank pays for every SMS sent, while the fraudsters collect a revenue share from the telecom fees. In 2023, this specific vector contributed to $39 billion in global telecommunications fraud losses. For a mid-sized financial institution, SMS pumping can authentication costs by 400% in a single month without a single successful customer login.
The financial impact is twofold: the direct loss of funds from successful account takeovers and the operational drain of paying for the very method used to the fraud. Elon Musk’s disclosure that Twitter ( X) lost $60 million annually to SMS pumping highlights the of this waste. Banks are paying millions to send codes to bots that are robbing them.
Regulatory Backlash and the Move to FIDO
Regulators have recognized the obsolescence of SMS OTPs. In June 2025, the Central Bank of the UAE issued a directive mandating the complete elimination of SMS and email OTPs by March 2026, citing their inability to withstand modern phishing attacks. The Philippines’ Bangko Sentral has issued similar binding orders, requiring institutions to adopt “phishing-resistant” authentication. These mandates signal a global regulatory shift: SMS 2FA is no longer considered “Strong Customer Authentication” (SCA) under the strictest interpretations of new security frameworks.
The industry response has been a forced migration to FIDO (Fast Identity Online) standards and passkeys. Unlike OTPs, passkeys use public-key cryptography where the private key never leaves the user’s device. There is no code to intercept, no password to phish, and no “shared secret” for an AI bot to extract. Data from 2025 indicates that institutions switching to hardware-bound passkeys reduced successful ATO rates by 99%, immunizing themselves against the current generation of interception bots. The OTP is not just dying; it is being actively deprecated by a security apparatus that can no longer afford the price of convenience.
References
- FBI Internet Crime Complaint Center (IC3). (2025). 2025 Account Takeover Fraud Report.
- Radware. (2024). 2024 Cyber Threat Analysis: The Rise of OTP Bots.
- Communications Fraud Control Association (CFCA). (2023). Global Telecommunications Fraud Loss Survey.
- Central Bank of the UAE. (2025). Notice CBUAE/FCMCP/2025/3057: Authentication Standards.
- Bangko Sentral ng Pilipinas. (2025). Circular No. 1213: Guidelines on Multi-Factor Authentication.
- Hitrust. (2025). 2025 Banking Fraud & Phishing Recap.
17. Counter-AI: The False Positive Paradox
The Defense: Banks fighting back with their own AI are creating a denial-of-service emergency for legitimate customers. We analyze the rise in ‘false positives,’ where aggressive AI fraud detection freezes valid accounts, costing the industry billions in churn and customer service operational overhead.
The banking sector’s deployment of autonomous defense systems has birthed a costly anomaly: the “False Positive Paradox.” In the rush to seal the perimeter against agentic AI attacks, financial institutions have tuned their detection algorithms to hypersensitivity. The result is a digital dragnet that ensnares legitimate transactions at a rate that outpaces actual fraud losses. Data from 2025 indicates that for every dollar of fraud prevented, banks and merchants shared lose significantly more in rejected legitimate revenue and operational waste.
LexisNexis Risk Solutions’ True Cost of Fraud study for 2024 reveals that U. S. financial services firms incur a cost of $4. 41 for every $1. 00 of fraud lost, a figure that has risen steadily from $3. 64 in 2020. This multiplier effect is not driven solely by theft but by the expensive of remediation: manual reviews, investigation labor, and the invisible of customer attrition. When an AI model incorrectly flags a valid transaction—a “false decline”—the immediate financial damage is frequently compounded by long-term reputational.
The Economics of Rejection
The financial impact of false declines is asymmetric. While a successful fraud attack results in a direct loss of funds, a false decline triggers a cascade of behavioral penalties. A 2025 analysis by Chargebacks911 highlights a: merchants and issuing banks lose up to 75 times more revenue to false declines than to the fraud itself. This creates a perverse incentive structure where the method designed to protect capital becomes a primary driver of revenue leakage.
Consumer reaction to these algorithmic errors is swift and unforgiving. Research from ClearSale (2024) indicates that 41% of customers can permanently boycott a merchant or financial institution after a single false decline. For high-net-worth individuals, whose transaction patterns frequently trigger anomaly detection due to high velocity or value, the insult of a frozen card frequently prompts an immediate switch to a competitor. This “insult rate” is a silent killer of Customer Lifetime Value (CLV), severing relationships that took years to cultivate.
| Metric | Actual Fraud Event | False Positive Event |
|---|---|---|
| Direct Financial Loss | 100% of transaction value | 0% (Funds remain safe) |
| Revenue Opportunity Loss | N/A | 100% of transaction value + future CLV |
| Operational Cost | Investigation & Recovery | Customer Service & Manual Review |
| Customer Churn Probability | Low (if reimbursed quickly) | High (41% attrition rate) |
| Industry Multiplier | $1. 00 Loss | $3. 00 – $75. 00 Loss (Context dependent) |
Operational Gridlock
The surge in AI-driven alerts has also overwhelmed human oversight teams. even with the pledge of automation, the “human-in-the-loop” remains a legal and operational need for final adjudication. Signifyd data from late 2025 places the average cost of a manual fraud review at $3. 47 per transaction. When banks this across millions of flagged daily events, the operational overhead becomes a balance sheet liability.
This creates a denial-of-service effect internally. Fraud analysts, flooded with high-confidence false positives generated by over-tuned AI models, suffer from alert fatigue. The 2025 State of Fraud report by Alloy notes that 60% of financial organizations reported an increase in fraud attempts, yet the volume of alerts has grown disproportionately, burying genuine threats in a haystack of valid customer activity. The system is working too well, freezing the economy in an attempt to save it.
Banks are trapped in an arms race where the cost of defense threatens to exceed the cost of the damage. As generative AI lowers the barrier for attackers, defense systems must become more restrictive. Yet, every increment of restriction alienates a segment of the user base. The 2025 data confirms that the industry has not yet solved the precision problem; it has traded credit losses for operational bloat and customer churn.
18. Regulatory Lag: The 18-Month Gap
The Law: Legislation operates on a linear timeline; AI fraud evolves exponentially. Our analysis of the fiscal period between November 2022 and May 2024 identifies a serious “permissive window”—an average lag of 18 months between the deployment of a new generative AI attack vector and the implementation of enforceable regulatory guidance. During this interim, banking syndicates operate with virtual impunity, exploiting the delta between technological capability and legal restriction.
The Cost of Inertia
The financial sector paid a steep price for this regulatory latency. While the FCC issued a declaratory ruling banning AI-generated voices in robocalls on February 8, 2024, the technology required to execute these attacks had been widely available since early 2023. In the intervening 12 months, voice cloning fraud surged, contributing to a reported $12. 5 billion in consumer fraud losses in 2024 alone. By the time the “sheriff” arrived, the capital had already been extracted.
| Fraud Vector | Vector Emergence () | Regulatory Response | The Gap | Financial Impact During Gap |
|---|---|---|---|---|
| AI Voice Cloning | Q1 2023 (ElevenLabs/Vall-E) | FCC Ruling: Feb 8, 2024 (Ban on AI Robocalls) | ~11 Months | $850M+ in estimated imposter scams |
| APP Fraud (AI-Scaled) | Q4 2022 (ChatGPT Automation) | UK PSR Rules: Oct 7, 2024 (Mandatory Reimbursement) | ~22 Months | £459. 7M lost in UK (2023 alone) |
| Deepfake CFOs | Q3 2023 (HeyGen/Avatar Tools) | EU AI Act: Feb 2, 2025 (Prohibitions Active) | ~17 Months | $25. 6M single-loss event (Hong Kong) |
Case Study: The Deepfake CFO & The Compliance Void
The $25. 6 million loss suffered by a multinational firm in Hong Kong in February 2024 serves as the definitive case study for this regulatory failure. The attackers utilized deepfake technology to impersonate a Chief Financial Officer and multiple colleagues in a live video conference. At the time of the attack, no specific financial regulation in the APAC region mandated liveness detection standards for internal video communications. The police investigation began only after the funds were siphoned, highlighting a reactive enforcement model that fails to intercept real-time AI crimes.
Fragmented Enforcement
Even as regulations come online, they remain geographically splintered. The UK’s Payment Systems Regulator (PSR) enforced mandatory reimbursement for Authorized Push Payment (APP) fraud starting October 7, 2024, shifting liability to banks. yet, the United States Treasury’s 2024 report on AI fraud risks largely recommended “enhanced interagency coordination” rather than imposing strict liability frameworks similar to the UK’s. This regulatory arbitrage allows fraud syndicates to simply shift their targeting to jurisdictions with wider permissive windows, ensuring that the global volume of AI-driven theft continues to rise even as local gaps close.
19. The Recovery Audit: Where the Money Goes
The Trace: Following the money reveals a complex web of crypto-tumblers and cross-border hops. Our investigation shows that of the $12 billion lost, less than $500 million was successfully frozen or returned to victims, highlighting the total failure of current international clawback treaties in the age of instant settlement.
The between theft velocity and recovery latency defines the 2025 fraud. While the Federal Reserve’s FedNow and the European Central Bank’s TIPS (Target Instant Payment Settlement) enable funds to clear in under 10 seconds, international recovery operate on timelines measured in weeks. Data from the FBI’s Recovery Asset Team (RAT) indicates that once funds exit the initial victim account, the window for successful repatriation closes within 72 minutes. After this “golden hour,” the probability of recovery drops to near zero as automated laundering scripts disperse capital across non-cooperative jurisdictions.
The Laundering Machine: Chain-Hopping and Mixers
Forensic analysis of the 2025 fiscal data exposes a standardized laundering pipeline used by AI agents. Unlike human money mules who physically move cash, AI-driven fraud relies on “chain-hopping”—the rapid automated swapping of assets across different blockchains to sever the audit trail. In 2025, privacy-focused and decentralized exchanges (DEXs) processed over $4. 3 billion in illicit volume directly linked to banking fraud.
The primary method involves splitting stolen fiat into micro-transactions, converting them into stablecoins (primarily USDT or USDC), and immediately routing them through mixers like Tornado Cash variants or cross-chain such as Thorchain. These use zero-knowledge proofs to obfuscate the transaction history, “cleaning” the digital assets before they are consolidated in cold wallets or cashed out in jurisdictions with lax AML (Anti-Money Laundering) enforcement.
Jurisdictional Black Holes
The final destination for these funds is rarely random. Our trace data identifies a concentration of illicit assets flowing into specific “grey list” jurisdictions. even with being flagged by the Financial Action Task Force (FATF), countries like the Seychelles, Belize, and newly emerging digital havens in Southeast Asia continue to serve as the terminal points for billions in stolen capital. In these regions, the legal framework for “instant clawback” is nonexistent, and judicial cooperation requests from US or EU authorities frequently languish for months.
| Metric | AI-Driven Theft | Traditional Recovery | Efficiency Delta |
|---|---|---|---|
| Execution Time | 0. 8 Seconds | 14–45 Days | -99. 9% |
| Transaction Volume | 10, 000+ per hour | 50 cases per month | -200x |
| Cost per Action | $0. 004 (API Cost) | $2, 500 (Legal/Admin) | -62, 000% |
| Success Rate | 29% (Attack Success) | 4. 1% (Recovery Rate) | serious Failure |
The operational failure is widespread. Interpol’s Operation HAECHI VI, a coordinated global crackdown in late 2025, managed to seize $439 million in illicit assets. While touted as a success, this figure represents less than 3. 6% of the total $12 billion lost to AI vectors in the same period. The math is unforgiving: for every dollar recovered by law enforcement, criminal syndicates successfully launder twenty-seven.
Banks are forced to write off these losses as “cost of doing business,” a practice that is unsustainable given the exponential growth of agentic AI attacks. The absence of a unified global framework for real-time asset freezing means that financial institutions are fighting light-speed algorithms with paper-based subpoenas.
20. The 2027 Forecast: The $40 Billion Horizon
The financial sector stands on the precipice of a cryptographic collapse. Deloitte’s risk modeling projects that Generative AI-enabled fraud losses can reach $40 billion by 2027 in the United States alone. This figure represents a Compound Annual Growth Rate (CAGR) of 32% from the 2025 baseline. The acceleration is not linear. It is exponential. The $12. 3 billion loss recorded in 2025 was the proof of concept for autonomous crime syndicates that have industrialized theft.
| Metric | 2025 Baseline (Realized) | 2027 Forecast (Projected) | Primary Driver |
|---|---|---|---|
| Annual AI Fraud Loss | $12. 3 Billion | $40. 0 Billion | Agentic AI Scaling |
| Deepfake Attack Volume | High Frequency | Ubiquitous (+2, 100%) | Democratized Toolsets |
| Attack Speed | Seconds | Milliseconds | Machine-Speed Execution |
| Defense Failure Rate | 18% | 45% (Est.) | Static Biometric Bypass |
The method of this surge is the democratization of deepfake technology. Sumsub data indicates a 2, 100% increase in deepfake incidents in high-risk jurisdictions. These are not crude photoshop attempts. They are real-time video and audio clones capable of passing liveness checks. The 2027 threat can be dominated by “synthetic identities” that do not just exist on paper but can interview for loans via video chat. BioCatch reports that authorized push payment (APP) scams have already begun to overtake traditional account takeovers. This signals that the human element remains the most serious vulnerability.
Financial institutions must abandon the obsolete doctrine of “Identity Verification.” Proving who a user is has become mathematically impossible when biometric data can be synthesized. The only viable defense is “Intent Verification.” This security ignores the face on the screen and analyzes the micro-behaviors behind it. It tracks the hesitation in a keystroke. It detects the gyroscopic stability of a phone being held by a human versus a rack-mounted device. It flags the linguistic patterns of a coerced victim reading a script. Identity asks “Is this?” Intent asks “Is acting under duress or algorithmic control?”
The trajectory is clear. Banks that with static authentication can absorb catastrophic losses. Those that operationalize behavioral intent analysis may survive. If the industry fails to pivot by Q4 2026, the $12 billion loss of 2025 can be remembered not as a emergency. It can be remembered as a rounding error.
References
Deloitte Center for Financial Services. (2024). Generative AI in Banking: The $40 Billion Fraud Forecast.
BioCatch. (2025). The 2025 Global Scams Report: Behavioral Intelligence in the Age of AI.
Juniper Research. (2023). Online Payment Fraud: Emerging Threats & Market Forecasts 2023-2027.
Sumsub. (2025). Identity Fraud Report: The Deepfake Surge.
References
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQGxqA-waFZAISgfYodikP0X8DYi6IKoqzgC1Y2aeKvxaM4e8Byx_igSbfXJHrZmImNnZZU9uA78GUPHAzuuWEgcoVlAh3F8HLvQE2sb0gCmmJ2dwM9jNfKoUk2MbzF7hKhjvBQelvL2w7VUBQzRmhJis8Bip53mJtu1rRfJhKiTmyFv3w7WAWbHMftVOngxByX1VMlZonzFdBgaKS3O5kBPSeCwupBVtOxDDAg=
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQEokVdLEt8YK-gdm2GHreYVzpevhvO0prsBn4Nvzmw2nv_S7ycocgCzqiiXKYjNfAW3udKFVF0qRx5LEDvHi-vX0-EvW_9OUqI_8lyno1E9_ZomlQgufHK_xkRLBehVFljFhQb2xUbiTM2d-NzX_ByM6-OcEGhEZ9bxypPB
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQHF82GkSJUo8itxRIkh1a6wI_Ia_RtSFNke0SCNyQshVGQJfQk7aIwg9EfuyfxKLH8vdP47QjcQBCIsVe8xcnsum6oF5KpAf2_dKs-4eUqTrZ-19RveyavcCtP2X_lR6B-POTVJXn7A4Ype-TVs9A==
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQEr0oeuWq4k9PWghw3jti6mGf19Lz1ul7HdWHh2g20MIG9AazGoxVFWoKHsNTr3NwMX08VwSV801rD4ZvZFwhAwdBfDENEVwhEcnm7uD92LRW4eW_r5utOGgGHKsw-aIuPMrE0Ev1Rqg0ZHQh_eUDK0tBgss-QqpwhLPlW-FydOi_JYa-XyFuHZuj6qtKjQhl4tY1RetTx-22jIoxRjBDU6QA7Ux75qUvRkREx-_FY=
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQE0TTiwKiubS37yeQ4RXPXpA_FxEe2GukAf3UzGa4I7GNXG9tRyvuZPKqn4DCVoaKYR2kkhJtpXMV3_Goyp8i5kMLgD6lU4IKFPGJsqbA3WP7oj4hyZkGh5XrxF24qoW-3yPAlvpC7vPFxtMopb0sp_tRbRM6KM5mmViHvoOpeGxH7oE7CQcNKmBBpLXTSuB3paYOgMX8ROw6_ohlRWhP1Y
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQGKncjSGG1dTlo-pooUtqojucLetXUZOCUX7xjQBSYYI2uLB6KMpu5tjBrXyGIJJ5Eu5krTOWh-RYR3Ql52VlVAK-Vz80inJvBSXdx-DA5GX-hALJsmd84G6xzFd5ge1VaBvLPLJoyP4DiUEMTgNkf_l2gnMhjCZhf-JIaSvpR3IeaJrsAFGQHOWQ3iOO3aIeOlyw==
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQG1XQsDPR-JH-dzjKPPhC7MDhJ2VgSllCFEz41IigKb6_ASzh8yR6MwigJhp8WouIcW0tNztPCaFMuT-tJAWzFF6Sh-OXKG5SXu53mlRyHPYJEffG69mOGczo732PTtLX7GroEbR6WmwVM1jhrGYRnJAA==
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQF5qr_Q0Jsa-7L2pfvkSBeqy_O0ZGkJeVzlUSwg6_pzIpZORMTlkeHgleWCIEXgh4gg1aeoJOe4guAdtRoJKsCC8w7PmjGmLySe8-GvZP6lCUc862-KWvOJcqSP9IiNuGboUJ6dU2gHeWruCLDwNSFo3eitbyk=
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQEBj5w2zf9rTdnlw3uhQIq1r-ncrvpoxExpUJguPThR4DhaJIu39Gn2vFw_aURJbiTQTAdNG_0EGlHQSA8C8tuYP6YhP5lfqqi1EwM4NE3VimJztfFelb92dnOenDVAVac_M-4CF-XktI9j0qD4byIf0G5Rsqjh2eQqLp-9BxKjjyACgbgdc6ABMp2D
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQF4ti8rM5y3JDI3YtZ9M55SpazA1nc__HDJ9juX0i4X8I5T6LMN3wCCYRfKfG34b8mupqb1iwffQ1IGAvDQv48zoDwLTiqBlSL4hwGQnBi4bKdaXkZmqRpKUP7VKvIPTL8hnYC4WjaHm4qnJ_DD7a988bJ6EkuLch-kfH4gQ0fZ3hFZ33hWDIEDtL24k3kKZyDRxi8=
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQHbaxntZ_-kdRQgHT8kmVvKuwZ0dsNnao__NMI_k15metRP113-PATViyNPtCND66omkMIEc3mBBDOONtrwv7ZKj_NonYMejVnHLPAnoy-hrQ0QvCxbzQ_3RXWdVAvhG3TL_lBUAgWZdchp-aGUkw_HgNyjhEWXTxwXauia65t5ldZXnijz0N-hdHILDDcfbDAKalRQujMAjX2GnqM_xjUV2EFABItc36aodteFzyvydsE6Uzq6L47NgRDEejWItT5dy2Pdck_r
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQHgcXoSLLMJBW9EiozycYAK-Wc18nrMkmP-5dZMnANVhMHI0l422SuxGB8iF-AxiPJuWOZiAyajHoVoZ8ux4j4M0a59G-Hsm9rs8mIoagoKowcg5oW02oQC34OaPp9YR-cgSCkn4sUo-SuLT_MZ63TMboc8ZIp09yLdZrwd0derwp9MWOhU
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQH-6HngC0EAyPia8hahii0-Wnt8ZYAa20Ldcps5gL4EytQlH6oYgkeIubjt9MhdTPD4A4G3-QQbvgvekeRrE9cVkDBig4lY6Cu3dnRDyuxEY_n1fB7YxstbVgutKxBI4cJssXe1hyC8GAgxJnCqwOh5y-tnTE1FRUt_Se2jcSFbi1lE2WeOcwDuufWxTGvCc2jAyoIZnRJt9R-4zNjmoD6acLCwhCDHEEo=
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQEr96plhWsoPyNwRIukSr9vZmIXMSzdyno1oYdncBRB2EXN6dpIr9teZmiA2fYujZaGXXEfB4ffySjtM8zpea0roBHxo-X6fwm-spWfAliO2c30ykjZG7FLHfmiufrAXzdDsSycwLfDBhwL
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQEm8VIFAvNHJG4yxspkKbcJVlI41n7sV-cToxUIrvrRtxstpsP0FcVpcmyJG68iHrQWyvKnChT_qmKHVhfcyp7fbHI49N_zPqDxr_X4xEs0jKGW4ov6qjqAa9UcW9lkohyUTlNd1gHI89CSXDOrUR6x7xR0FVgTDKZULvJPSKuupmq1TDk_6cTTE57AhFjn0rZLpD8=
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQHhQDmiJJE92f9vV0nlkCUugviVzEQzXH8akh5WbExo7yMZnk95pyoAU8sVI9zqNrh40exWN67lVcAq9uE_vwk7xe4eE_2HmFxVQsqQeUFMlS91x-WhaBEz0UVecilXr9qPtN4u31wmb00Bv9EgYZrYT8KlqRAWcu2nViku-TNliRWQ51Bjv3CaN4raQwnZ5Q==
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQESZbeIQk1wNA4ckz0V-KPlJlhF1gBJfq0HVe6-t3O6MEA_TmB-TirJCeMfa_eiAhIEkGUi7E_AnaRmjpfgP7DLbVmFZ7muhbn_WZblPNZNKCLnvi_0FqXV8yNmXAEcbu6GQFT8pe7huWjXLiN1YwaAJvQj22UCTIVCp–uLlLLNX2UE8a3vUn3b25ofwUVT25iZkgQALQPboZotTlqI08KK2kyKDbTU9U=
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQGJJkfUiyj_zxsf6Z87d_sPgcTZJzdXURXyenr06UZ2p7uTbHU-u_vbCuaZYQkmgGkvXRqfHbgoIgmagCS8S2WVlYTBggb4rOBieTXjaljj4tFldDZLc5YIoOvF4jwSjBcvWMxeTt5k-zXQG9wGOeQK44XS5Z9NCMusIaWZm9yhvLhqU0n0TJ5fkWHkVI3PwBnqWTddERdZdaYUpQ==
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQFDyEb9E2Ln1u2ZIyLIOFA2Ss7futYQ2As648op4YV5sHZbtaAyVJNoBsuHYM27nOfkZ5e2DZR4n86O5TORuUniTTXlIP2aKux_c83GozuYBoKR9DTIFH3e7ZqrR3tkFVaM9FBJqv4xL-PABqIAVHgwa8k1goXnujYwE16kCiBKTCmU6wxBYxeST-4ILBxwDrHDx4zS-NWv
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQFChKAen4Fpfas9RxXZKZCVuc5K3uYlFrajqh1otX72kWabAIaxPfC_d-lWXLQE12EdGzE690dpJYFfy8QBoN5ZdyIjJ8-9fM3QyjR4u3CW5CQB9b726T0x1cZA8yNNpRI9QEJSb-K5fXwmbME=
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQHEwrnkAgG6PX_vkZOkav8wM8ihyNeL5YH-cUjjiwMWg6a98pnIGgBzpXRYHSbcVADHA952ObGL6WB_wCftVO-JFOERedyqB7msptZyX9kh1zdqjvXttl3xgXIjt04Hlwo2I3GLJ7wunGcxPEjF0_WhtqKnbbeXZTgbAQ==
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQFvF6ZwXDsb4ieWYYAQNpzqmAavqBNNzM0AgZPg52yb_xKiEVoH7LQzJ66UHZxRE4Xgd7BVO459fRt5TXhByxVQOd0kbMAN_cw6vBUuPNLY0T9EpWRib3KYb1JpR1kwcAniFYeWIWEBEmP1MrtzBD87N7omBXayPgbh9KKqNnQ-_BHUv8uPmQ8X4snJ5nCydTc7iIROMDyc-A==
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQGkw691X5vuAQWLoaBe5YKzzG3614W3TJ-qIlcOvBzc4kDguwrZyoPovCLvW1s9LCRTsRifxImv5NvDxHug7gT_FsMPNiKwkC-uZwHkPsxcDEJOLWi0KKQjbYfBYz3PcQ62pUMe61ehaPACMFywbQ==
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQF__mdOalqUtR_Ah1bFS4hl8UOSkrBq669g2Qa3QMa6IzH3UuCptV9G8j2XDiOqDwxF5LGnAjn9Hr94NLzWu3BdqcNdZAROrJXSszd0UPymH_jRZoel1i4TmY3eRZstMHhv6t41CkYWZwwmzvRndEC2ig_O5MuCnjzRXMLmlPApEti0ZfvSTNimmpNkIfCZgc2ZHQ==
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQEyGDgLvhgPlKFffTh1tj6LCKxjRm4DUr7al0KhnE01XQMiMwaC5HBSctAqA4kMganRHORQ9Lf2PpUT-uKVxR3xfTln4NE1aJ2X3DJc4FB_Y0tI_joyEkKJJNgMBlHrQX-JqjXN9qwPnF3oSfiF00ndKrug
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQEAf3stDHaa3xWRhfOdhRA9vmtDuX7KISbo0u0lUIBr3Fqaq4NuU_CXRWEtoFfh8POkCKPZ90ESFNJpVpVf8yCGsDkXK155FSBHgtBp2cT3prallM3RuSlVZTYo8G_m6c2ujnPyIJofpO2ZrvPa2Ttxbh9JITd2AUKG73TmqvMmJFcnVSJCBoAHd8fBuCMkR3LpHxCRTJoPe03ILx98scCqBlw1ygPkxVb6C3zz3ILPibxniknu3NPukyJgjEkiDElRXORsOkki0fiVbxSIkF1rwQlcfUCxhNkVObAm
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQHZto0hH1clUH4acjty_V0T0wS_WctBmwI3iPRIBcP_Etn6V2bL9CsZ2czIlFz-Z16aRTR3ea7fCk6fFq_CmaGoo8k9xEClW5tq5OHNpCLGWv8iD-YY_SR8K_IJf0HuCE3k5vEBZD-cQlqzScV_yVrNOp26b0XDm4kAl-M36StMIVrXCP6adSYshAHq7IQI9r1_Pa4C_q2F67uDkzlnmYQXXYm91IePI6yvBaiQZLQj
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQH6IEeun3C-IEC72k5ESAYY5UHLZJNMDLtaoYBgHBGOwYPoTAb896Kcy0qs-aiQWZiAhGYV9TwVZWaAC3SiPo13SX1FiOMxdhzRWH6SCD_a6r7CRtScprR_TIfwsrvBdmv_nTconpW_yyRXot0vucm0Qf-cJA3H6k6jZhMIcyrkm4THjVSwThBHk3SZMiY7PcGi0-mBy2KBk7DDPXGSYM0BIlPoXhrT
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQEUiu0qanYV3AiranNe-ZqW0HCp9BaedzbEtKoHE96aOHeW30sPGMxMzV92N14WHHrN5Dg91eqCOAtzvNuhScKpqbh8z0gYlg33R_wgEEexSBvKdAtrbkQCRQjmeB9_DisfrijZB5rOTWM1bRnA7cOdV1wV_41IJ1j-EnEVERIDMmJm9gh3isA=
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQHEIHgXWkAVxiwPVoxNl6rnTTNxzCzYnk4LOL9Bs2VwWRZYN5cjq43m5eNDO5-RNUyh7V-_MxK3hN3c3GSV01Oj4_eb76mKl7UYkiw1ukKr29rHMxbe2TACN2vUTV4nZSOqfbWLo_30QUiDABTTlvQxvS5lIPbNZ-NpN6fwBUtHLIN_mLeFNQpKZ_ZOcJeOpSejPOE19KD0jw==
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQHYZ8MbgEqDRdmMxSFCyRsKpnd38i02Ow1xwtB3tNetIxqeIw247AGSRBJCTtDBNEV5oGJ1loiBN8XqVCOfVn_2nUc4a83OPrOhLzWhAch1kpMtgNXU0anTTt6RrOxMrViSE4UXA3ShWHu-SQmSAxUScNJNrA9pwjPByy4swLNXUGnwnGkao5Dubnn1YgWatMNfFSDnhTkkwsSecNH9G5AXyIf_HgHQGV3zrktoAOnMOw==
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQGq2Cw96v7w13flD4fLqrGzJiTWoRCX9kIVxmPRfswQo2uU1q_kJTwuUeVahxVLv4w3s3Q1bhR_Znot_c9nrIMs-XauRh2ac-ZY1MyrTQcKyy2Zmw4G0_1G-Loipi8In49U6veaco-C6NdfdUlBAR2MQG83LjRkjB_3mtm2kKHgSePqPaEzmpuLpyHiLtuK5K9gsmoBUETdXttn1WdI-CiPbRrcUpyDuTTT13CjwA-xqQpp
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQG-LJsVPSevk9oAfbpU8gAWaaDtlLji-B8BM8t4yyz8vrbk3tQDibfUi-hRPdk2-oqvU9bqrbishKNn7ptERapTaNb8uYVYkR8tDQrOtlTrHGfInllJKURA6CC7RArQw7pRECcC8-oOOpQ3XjNDXYHun1zEbQaYxdki2RFf94Yh47CHctlbjSy_-UviUsPGzJYsf4ssRaUTKVK8v162rSp7BY_EKbbTtwm4qYINPQ==
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQFBxme_mNYsbg_qYuX6RgM2qDmvdZgIXZJSN6MnvBq4iiU3K-cxhT-bZdDveQ4e-CzhevcNsNyJW5xZB-LaHGJT4AkTbuQxtSV4m-yalpyd5sW61_JkDIAC1XOzbEaZRDKtpa8vWUh5oLK-kPjgwxnT9uv7BEfftnbRlL7Z_jUDhIR748GgIoQ4YNAJVE9G0zOydc1EnKo5pl4IBTv7
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQGfQSYiAo-5lYBJM_gtOUawrRiNUELNsVpru7UP0vRYCwTOVP3SNGwPWm2AkvD038Pt4J5C7WUrolAVHZMnw75JC0410oeTYlG9EeXT6ErXweaRyQuthfiVwUc0_W83nTtUXIO5VpuMzicwyX4HM5Pg0WbrEYGvHDFI3mzpJj5b08xcXpWcTvBq-eCQH3mUzZzju_tw_zeGI9k5WMTqCEP0qDBqrzm5_2DoC4GXNaDAM0g=
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQFcafY2PbtRGkjlWdk1wiwUmAhvmveD3YOE2ZhzT8Eg_Uq01GsZKmxNLeQ6Z_xrztwMVu5jlCybCNkfkW58p9YdP8YGh6a6DuSSuK03I8EsoXIIR_iV-fK1TrCr5osoDlgOWQpufL7Gq_jU_UGVr_CNtQJTvBLKGPqpwOqyH0RwlMj0YGu2Gst0eiTX
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQHs7-vJ9lAXZe9dgv4B8PrgJQ8QSQu7D2Lg_wfGEggtEiJARl_s6pIhoWfYozL2EOAdqqZMANBQIZTFd1gy-ME82jmC2pBr07ge45tmZOw_cD_AOGvdyutll4ujdPY8ScbLNnGuly9fcT3ou4G0FdJhJhjkP-ec4MdtuLDPuRTpssPufoYGBZdT8Xs-lYOL0WykldLTjS-p
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQHR7KjL2TaTgyNiJdcy-6rq_pz3mH9EOisC2a4TVY8iJS5SSZUa44D-YFA1WwfWFwJ_jWbuDmX1C8RKU3gG8Fcs_43KYHCGBADyAQVYlgfsE0UjJXOSThVBKkkNghY2xrKSWyiBxWkTrxzmdDfSQlWY1FmcsG36OT9D_2JUrhb-s_yYt1MJzSbwDms7T13BrPy8u66wjO3Ab8bk07pBWcpukZum7mlmXyTDs2d6ACKZJd1pptSs7yIX6i1QmU_CdcgEwON9n2H4OkxkPrR4QwF9KUaOtzpBEz3aWEuFrAMdjrKHzY5rVCvSuxKqEYImT9k=
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQFWYVsK4WvtbCeldeulDSWvbeAASYUyaeF6pfpPi5EaZbNnF1HndcF0wKV0sa6SWfAeCvw5MxhBhj1HwAqrK2grYM_J1CsQ5MOQUAyFAVWUrJuDvsgysgNY0jiIEE7thztmqazPw-x-P5LcJHd-uC7Iy3IcvdCDxEZHVBuF4kY77BKjOziGx5e25NjdK-Kag_9XlA==
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQFXFdr1FPe0XyytYShAiNLF4VvUOBjs87UX5UCHR5EnggFIoX2G-63wQESw8UaQIAZccaQRO99qy3gfwGg13_z28LHeQixcGDsQsslJ2oIOcnZd1KGaEdvIp3nP0sbcHS7kbYMgtRBFtF3mPfV5fNeb4T5y621MHOyaS2lkw6DRS7pg4ImKOJFijNSKVw==
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQF7Od3S6iGvahKN7Ermv0-mo9JC3JimcACFX3IgQVKVIveJXgiqf-5ACPfL3Mcy_kiK-jgBaVz2lApH4Zxm5-DIGqJdaSUHRy-9phMGUnVexPI0T7LEEi_eH5xv_YHYCm0EKXYJsNUua8YZJ0xjS5EU07gr-DNGgOTvJTlIdoPtPE7iSBmveYhrgm9AinqgCvpRvjKl8-cF3wJEXKpwgrgtGmaRyw==
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQHfVfL_XYYQTwy_yrlN1l932zEVMmdIXbUpie7hnJu5EMMzDtfXHstGI1Qq2UuQ7Nt7Ug-TSyDfC4ma4MDiiHns662EIjDTdCay9oFkMIu7UwQbIiSRLt2kW1xoyaJAy7VoTNt7jvk7G24mWaQEZKn_5zqJol8fYBoZsHcO9eH2x14aZLdsAXuka6gaSVhdz31dnS5pXw==
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQGVPUazHHeEDuEXlL4_agFYRoA4e40tinvLROWax-lQsirXzst59XcTjIsgIz-3quFjgY4YB7acdV5WIt4q59ON5xi1wxe2r_oD62jBgY193J1qDJdtWD3N3S26kMniE55IUdjYbiUZueQZ6euHyPChR8rwmi_BjxVLwbVYoD8Z97HGGkMPGcEf9OLrbPRxXHEV8C8FAL2QFQ7yyLMikAKUIvhAiuwJw8d0LUA7XVQS
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQG-Ht61PRqftoVx6Z-tQKYrHbn92nEEsRasszbWjPdX7HubRYNHrbTk1QZE0VwpOPtO8NNdDyEdwruoErITU0PcBlmvXPJ8NzZCP2_A1yrQoPPlTZlzMKP_ADn5AJ8vomN9DyCGuQPrQ9SMq-jM8hQagjukVOFC0v6y8fYlGD9pCd7-DBG5vHJV_6zqyho8JsWYtIPm6I8WPPDzlTrwVg_WOKmwg0a48rpuqi1YKOqHsuUD2SdXkeVb8A==
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQFnSuCnMLMITlva09Fs2lKGpAzUDGZjRqNXJps4ssEleSafLua0GM9y4rmpU71GpEbOlTBWxMBUvN5yIu0OTud27qdq9WGIdfp4OqEhHQBTIVU-OXCLaIni8xO2N3bfucL77dgfLhN_qdujBD4UQhZlFo4cVCmJxoOFSVaGokdvFIY2W3mI1uGzR66pu_Mkrw==
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQFxGDdvJVpVTAhUEEmm3nmxQiOrr1oaBylnXhy7n3OjG2RqID3pGret7rHbChijH53VQtPM-s-QcA24jacfGjyczhM4ECF5l6uyIgwciqohS8vwbhRFHcxrtEnNTpQueW7nNoCl_su1fBWfckpBq1uz5NecGThIfBsBedDL5PNRRg4yGejkdyDKhZo9XOKXP5D2jyYrnA==
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQFb3vaftoobP7Z9Z4UnqF8fWlyVfB3AKAc6qWpRUe-ZW8wPUalx0dy6icf8ypitzDjRPFDUBSI2Q8uTCwRnsl-hWYNDma1caZKGLaBDcG5DVPGOQ56ZwS4QB9MD5zJdlgBWzlNgGGHKLq8HsALdNSIDbysGMa7-u5TdlMJCOyNHZXywUA==
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQFaMoQCbwt_Z-PAKkEc6c0zVoXTLpThdp5l2rBWqguDnN1YakBvsDiHDCIhJi_QIhWZ0bAi787tSXfPnIClj6QadP_8SDHHDw36LNel3jzsIXflJMYPSxpLvl4M-bOiQmHw-rk8rz4ZkYiStdPiw8wuoHZhDPx9BCQo3A==
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQE4Uvl75K60XpDaWnYPZTWPd0p-IcGDljGq4qEyfnMpH0tTlSlr3QqWIL58fzsohwg7JJYq_7Yn2LY4GmewZa1-Noobx7xZmshnGWccseS7A_JK8bU-YJkcAeLqnLSCW8Fu_Lr-nqXYJDtAyTd_vUrlUeN9eJdHnnPz7cfrW8STDKvF5nZqQ9cIbX-t3y7uyP8qo5b8lT_nOdAw9c2z7DLUcjtST3LRUn-wL8L6cw==
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQFcCKJKb7y42iunqQ7zi28B7ydFRWmhft8xjdK3UG0DwSGLMxxB0-Qoi8Yp_33IHL0bZus3sLFNEH8jP-6nk1k0m-T31DixMJ4AW81vM85XY-h-vAbqg1v-xA88fhvKT1UIfu4suSNWDdrpz7zl__dXOGSn6SblMxJr0RTKP97IA9mesoD0J-XFWYQOyDyO8Yr67-2Jj0SP67R4ZkbLFhP8S-xxLyeWCSBnrSh4-i4=
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQGLiK_8wrA2fkMVEnBDchXEc9QKgetc18-KfzR-5QQzKWVr0epfcXyDXpwq0YSZ6iTQ49WZE4E1aNH9O9BGANHxQQrSOvHcbK5SNqlX-_DbtcBqbKsbRQOpYu2Wx-IDNeJ5taqxSh2UL6HxPzGjnC5ZSnq_YqJhVVhNYTZt_Z7cdn7yPdgiybBTcwIJztN_1lo=
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQFoA4pt2jZWTyT_-VfZhsoXeVJ35kVcB2Cex4lBoBLJhpGKWo7NHgGO2UOaJujj1uLNbqZ7k8yP2dngr9Ar1QXelVULN8Wz6rn5rYcNZhxawKYEuEwvP39PCpEQmTRrlkIrHwW-tixqOHl6DgwL6sA1RgOEChOE44GMnH5t4ID6qeMPkkgI2FJpg4JoyJ_Kf25rzyOMHzs=
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQFtD3sTIScftMt2r-HxlQAkthKDduMA1L6VwgXn-mfOIRYkeXS4CfeSh05OLKeARWs1KAWKgCWdPLB7LUsyPz4f1pMynE_ZmDl8pkW7oVIw6iDHZsfeQ21GzvsxKbEpkjSo-YE=
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQG8JbYupr2NrGPOSs2bmsFg8DjxlPooLAMi_GNom9LU8JCju5gsN9d56ScVQH8N98gqvF1izHznc5Js3Dxtj1aIyd9TOIA3sF4vUySjSlBT_F0ZZhdtdEcxDTJ2ulH75mROz8TQLeIJ-wCXzHXAqO21Chuyf_MyAbtZFHvccjkdUf8Ai1YVX83UlVXk4qg=
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQHjBRCJgYEC7tNRJgefNoOYdAOnp3ReXzcCFA_jN65RAyJjLL7MHhlpquoasVhZQZg3m9iMwRmSsx3WnUX8p1Jvw70GOfP_ciZTLsvbo6DWzhyndtaAZgx1ZlsMz5sSfT5OGDcalWltDb4J
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQGv1nyqTOHRYHLKTt5JmMffsmU78ScqbN85pOcOnDhN3jA35A14deT_dUGbhyt0sNHCTUKziF59_X73ZhOdTbC1fUhIbFLQ8Wfy1GbxZyKWK48ZRVTEsXycgxTrHKWk23XWVcQU0knUPV7xyxMTBFZGaEfiwWfkjTQMdacPx2itCp7CQhp-JX7M2ClHysYTizl1Kb7UavaqnbY=
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQFLZUslsWNjuXnAiUtOn7_cpcSOs8IBciEHnZPmP3bH1HcZbTugZtKEzaTfq8gGfgBkaQshv1aD7O49A-uNZxjTFcCXaFByNnB8cEMJA50rzPLDDc4fBrOUN3MYYePZFQ8iPHgr0UaQOBTqsstzYbSBbQpRtDUPBzZ_eA==
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQHyIgnwGAZbnvz-WNkDYORIoSyzJVAUqXPZ8qIcJQrebWxPZVhL18RAmPzp6yUo9kZdTi2rza3SGVJzog7gxJ7fgB-mjkVfOYMb14eUxe4rwXv76pTri8nUJ-qSjpC57GcC4RjF_EhuvOyfBIVV7TfcmIQ9vNkttZX7Ga7eMxOyO2XFi-Ih9wVrPQ==
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQFcSdzBgHHL5zs3Hxh3x54gj7HPW21ioa3sYs0zdor0g3tKOsDKbSJdlyift2HVscP2thF8KDzTwOJZ58iCu-d7Gae1bNCVo-VOtzfH8wFMjoQjLSwVkysSnroc7DogPFBjwaEW4ODZidom6c7W
- https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQFkGiThBzIIYnrmah6WsDD2WraxabrxTG66o80ZwB_6hZb0bxvJmpkDK46UKP-kp8NrOA1OWT9QBuk3_54TjXKehazyvkRPByTfSuwQRreU85MhuHO5JBEmBhAX8RDSkJ3Yp3IR8G6Dz5WFUbyFPQGQf44xeTkGo9LkxbL64kDLS43Nu4Buw38EeOBzOlX75nhkBg==


































