Indonesia's blind spot: why 95% of synthetic identity fraud still goes undetected
In early 2025, a single deepfake fraud ring used 21 stolen IDs to file 44 account applications and walked away with USD 193 million. This piece explains why traditional document checks no longer stop synthetic identity fraud, and why the institutions that survive will treat it as an infrastructure problem, not a verification one.

In early 2025, Hong Kong police disrupted a deepfake fraud ring that had opened accounts at scale by merging fraudsters' faces with stolen IDs. Using just 21 stolen identity documents, the group filed 44 applications. Thirty succeeded. The total fraud value: USD 193 million.*
This is not an anomaly. It's a preview of what's coming to Indonesia's financial system if institutions don't fundamentally change how they approach identity verification.
The scale of the deepfake threat
Deepfake-related fraud losses exceeded USD 410 million in the first half of 2025 alone. Financial services have seen a 2,137% rise in deepfake fraud attempts since 2022. Deloitte projects that generative AI-enabled fraud losses will reach USD 40 billion annually by 2027.For Indonesia, where fintech adoption is high and identity verification infrastructure is still maturing, this represents an existential threat to institutions that haven't prepared for it.
Why synthetic identity fraud is uniquely dangerous
Synthetic identity fraud attacks the foundation of the customer relationship: the verification process itself. If a fraudster can convincingly impersonate a real person during onboarding, every control downstream assumes legitimacy.The account behaves normally for months, building a credit history. Then comes the bust-out event or large fraudulent transfer. By the time the institution detects the problem, the funds are gone.
What makes this particularly dangerous in Indonesia is that the vast majority of synthetic identities are not detected during onboarding. For institutions relying on manual review or basic document checks, this means most synthetic identities will pass.
The fraud landscape has fundamentally changed. It's no longer just sophisticated criminal networks. It's fraud-as-a-service: packaged toolkits available on dark web marketplaces that offer off-the-shelf solutions for:
- Synthetic identity creation
- Account takeover
- Phishing
- Business email compromise
What stops synthetic identity fraud
Traditional identity verification, checking a document and comparing a selfie to that document, was designed for a pre-deepfake world. It's no longer sufficient.What actually stops synthetic identity fraud is:
Behavioural analysis across the full customer lifecycle
Not just at onboarding, but continuously. Does the account behave normally for the first six months, then suddenly execute a massive transfer? That's a red flag that AI systems can catch in real-time.Omnichannel pattern detection
A fraudster who fails to open an account through your mobile app may try again through an agent or partner channel weeks later using slightly different information. Detecting this requires connecting dots across every interaction channel.Real-time model updates
As new deepfake techniques emerge, your fraud models need to learn from confirmed cases and adapt within days, not months. This requires infrastructure that feeds fraud intelligence back into detection systems continuously.According to HSBC's AI-powered Dynamic Risk Assessment system, which analyses over 1.35 billion transactions monthly, institutions using AI-based fraud detection can identify two to four times more financial crimes than their predecessors whilst reducing false positives by 60%.
The infrastructure requirement for defending at scale
Defending against synthetic identity fraud at scale requires:- An AI-powered core that processes transactions as events and exposes them through APIs in real time
- A governed data replica that gives your fraud team, analytics teams, and investigators full-fidelity access to complete account histories without creating production load
- Decision logic that can be updated through configuration (not vendor tickets) as new fraud patterns emerge
- Integration with your core banking system so that confirmed fraud cases feed directly back into detection models
George Chesakov, CEO of Salmon, articulated the competitive advantage clearly. "Oradian offers a vital combination of flexible, scalable, best-in-class technology and comprehensive in-market customer support and expertise that enables us to drive growth, scale rapidly, and boost our performance. This is an essential recipe for remaining competitive in an increasingly crowded fintech landscape."
Why now matters
Deepfake technology will only improve. The fraud techniques will only become more sophisticated. The institutions that will survive and thrive in Indonesia's market are those that treat synthetic identity fraud as an infrastructure problem, not a document verification problem.For a deeper dive into what this infrastructure looks like and a practical roadmap for implementation, download Oradian's AI fraud detection guide for digital-first financial institutions.
