Publications
The benchmarks, studies, and field notes we publish.
Featured
BenchmarksFourteen open-source deepfake detectors, evaluated on about 26,500 face crops across 12 demographic cells. The two that scored a perfect AUC of 1.000 fell to 0.243 and 0.340 once real and synthetic images shared one encoder, and a control isolated the file format itself as the cause.
Methodology notesThirteen published synthetic-ID detectors, measured on 6,948 passport-style images. Nine change rank the moment you measure what they actually catch rather than how they rank, and that gap is visible before a document has been through a single scanner.
All articles
- Fraud stories6 min read
When a 15-dollar AI ID passed a live exchange KYC check.
The OnlyFake case is the cleanest documented example of an automated control being beaten by generative AI: a synthetic passport image cleared a crypto exchange's document verification.
- Fraud stories6 min read
A cloned voice that said the password, and the bank let it in.
Reporters cloned their own voices and passed bank voiceprint authentication. Researchers defeated it with up to 99 percent success in six tries. The industry now concedes the control is beaten.
- Fraud stories7 min read
The engineer a security firm hired was a North Korean operative.
A North Korean operative cleared a security firm's background check, reference checks, and four video interviews using a stolen identity and an AI-augmented photo. The verification that failed was remote identity screening, and it fails at industrial scale.
- Fraud stories6 min read
Two deepfake CEOs, two executives who did not fall for it.
A cloned voice of Ferrari's CEO and a deepfake of WPP's CEO both failed, and neither was stopped by a detector. Each was stopped by a person verifying something the impostor could not supply.
- Explainers6 min read
Meta's Muse watermark, and what it does not do for deepfake detection.
Meta's Content Seal watermark labels the content Meta itself generates. That is useful, and it is not the same as detecting the deepfakes an attacker actually makes.
- Fraud stories7 min read
The deepfake that opened real bank accounts, and the call that did not.
A Hong Kong ring used face-swap deepfakes to pass remote bank onboarding and open real accounts. Contrast it with the famous 25-million-dollar video call, which bypassed a person, not a control.
- Fraud stories5 min read
The AI-edited claim photos insurers are already catching.
Admiral's own fraud examples are photoshopped damage and swapped number plates, and a Verisk study puts the gap in one line: a third of consumers would alter a claim image, and only a third of insurers are confident they could catch a deepfake.
- Fraud stories5 min read
The refund photos that do not fray right.
Named retailers from Boll and Branch to Bogg are catching AI-generated damage photos in refund claims. The tell is physical, not pixel-level, and the EU labeling deadline that could have helped passed in August 2026.
- Explainers6 min read
The people building image editing and the people getting defrauded by it never talk.
We read 2,400 posts from the two largest open image-editing communities looking for fraud talk and found none. The capability is published as neutral craft; the abuse appears only in fraud teams' incident data. No feedback loop runs between them, and nothing in the market creates one.
- Methodology notes5 min read
A detector score is meaningless until you name the condition.
The same two detectors score 1.000, about 0.70, and 0.243 on the same images, depending only on how the files were prepared. A score without its condition is not a weak claim, it is an incomplete one, and the condition that broke these models was not the one anybody expected.
- Fraud stories6 min read
A face swap cleared 38 video ID checks, and nobody can say which control failed.
Spanish police describe 38 attempts against remote video identity verification, a face altered in the call to match a forged ID, and coloured spotlights faking the document's security features. A one-second glitch ended it. What the coverage cannot say is whether the camera was bypassed, and that is the distinction that decides which control was on the hook.
- Explainers5 min read
What is AUC?
AUC is the probability that a detector scores a randomly chosen fake above a randomly chosen real image. It runs 0 to 1, where 0.5 is a coin flip and anything below it means the model is systematically wrong rather than merely weak.
- Explainers5 min read
What is an operating point?
An operating point is the threshold that turns a detector's score into a decision. The default of 0.5 is arbitrary, because a detector's output is not a calibrated probability, so the threshold has to be set from the error you cannot tolerate.
Field notes
Quarterly changes in attacker tooling, in your inbox.
A short briefing on shifts in attacker tooling, four times a year.