When criminals use or imitate biometric features such as your face, voice or fingerprints, it can also involve biometric identity fraud.
Our face can unlock our phone. Our fingerprint can help us access our bank account. Some services can even recognise our voice. These features make everyday tasks easier, but scammers can also try to misuse biometric information to steal our identity.
Artificial intelligence (AI) has made it easier to create convincing copies of faces, voices and documents. Criminals can use these copies to impersonate someone, trick people into sharing sensitive information or attempt to pass identity checks. They can also combine stolen personal details with fake information to create an identity that looks genuine.
This is known as AI identity fraud. When criminals use or imitate biometric features such as your face, voice or fingerprints, it can also involve biometric identity fraud.
What is an AI biometric identity scam?
Biometrics are physical or behavioural characteristics that help identify a person. They include fingerprints, facial features, iris patterns and, in some systems, voice characteristics.
An AI biometric identity scam happens when someone creates a fake version of it, to impersonate another person.
For example, a scammer might use an AI-generated video of a company director to convince an employee to approve a payment. Another criminal might use a cloned voice to pretend to be a victim’s family member and ask for money.
Not every biometric scam involves AI. Criminals have copied fingerprints and used photographs to attempt identity fraud for years. AI adds new ways to imitate people and makes some impersonation attempts harder to recognise.
The US National Institute of Standards and Technology (NIST) warns that facial images can be collected without a person’s knowledge and that fake or altered images can threaten identity verification systems.
How do these scams work?
1. AI face and video impersonation
A scammer can use photographs or videos available online to create a fake video of another person. They may use it during a video call or include it in a message to make a false identity appear genuine.
Imagine receiving a video call from someone who looks like your manager. The person says there is an urgent payment to make and asks you to transfer money to a new account. The face and voice seem familiar, so you act quickly without checking the request. A criminal could use this kind of impersonation to steal money or confidential information.
2. Voice cloning scams
AI tools can generate a copy of someone’s voice from audio recordings. Criminals may collect recordings from social media videos and use them to create fake calls or voice messages.
A family member might appear to call you in distress, claiming they have met with an accident or been detained and urgently need money. The voice sounds familiar, but the person on the call may be a scammer.
A 50-year-old security guard in Bhopal allegedly lost Rs. 35,000 after a scammer used a suspected AI-cloned voice to impersonate his friend. Believing the urgent request was genuine, he made three payments by scanning a QR code. He discovered the fraud only after speaking to his actual friend.
In 2024, the US Federal Bureau of Investigation (FBI) warned that criminals were using AI-generated voice and video to impersonate family members, colleagues and business partners. These impersonations can be used to persuade victims to send money or reveal sensitive information.
3. Fake identities built from real information
AI identity fraud can go beyond impersonation. Criminals may combine a person’s real name, date of birth, address and other stolen details with invented information to create an identity that appears genuine. They may use AI to prepare convincing documents or complete applications more quickly.
Bloomberg reported one such case in May 2026. Journalist Jennah Haque received an admission package from a US college despite never applying there. Someone had used her personal information to submit applications to multiple colleges and seek student financial aid.
The case shows how stolen identity details can be used for financial gain, even when the victim has not lost money directly from a bank account.
The incident involved identity theft and suspected AI-assisted activity, not a confirmed biometric-cloning scam. It illustrates the wider risk of AI-enabled identity fraud.
4. Attempts to fool facial recognition
Some banks and digital services ask users to take a selfie or move their head in front of a camera to verify their identity. These checks can help confirm that a real person is present and that their face matches the submitted identity document.
Criminals may try to defeat these checks using manipulated images, deepfake videos or other techniques. Success depends on the system’s security measures. A convincing fake does not automatically bypass a well-designed verification system.
Signicat, a digital identity technology provider, reported in January 2025 that deepfakes accounted for nearly 6.5% of identity fraud attempts in its cited research. It also reported a 2,137% increase in deepfake fraud attempts over three years. These figures describe the research cited by Signicat and should not be treated as worldwide or India-specific rates.
4. Fingerprint and Aadhaar-related fraud
In India, biometric fraud can also involve fingerprints. Criminals may obtain biometric information or misuse identity details to attempt unauthorised transactions through Aadhaar-enabled Payment System (AePS) services.
In 2024, India’s Ministry of Home Affairs reported that around 29,000 incidents of AePS fraud had been reported on the National Cyber Crime Reporting Portal.
Not every fingerprint fraud involves AI, and not every AePS fraud involves cloned biometrics. Criminals can exploit weaknesses in identity verification or misuse personal information without creating any AI-generated material.

How can you protect yourself?
Be careful about what you share online. Public photos and videos can provide material for impersonation. You do not need to stop posting pictures, but think twice before sharing sensitive identity documents, detailed personal information or recordings that reveal private details.
Verify urgent requests. If someone asks you to transfer money, share an OTP or reveal account information, call them on a number you already know. Do not rely only on the face, voice or video you see on your screen. Ask a question that an impersonator is unlikely to answer correctly, but do not treat a correct answer as proof of identity.
Never share OTPs, PINs or banking passwords. A genuine bank employee or government official should not ask you to reveal these secrets over a call or message. Do not install an app or share your screen just because someone claims they need to verify your identity.
Use additional security wherever possible. Keep your phone and apps updated. Enable transaction alerts and use a PIN or another security factor alongside biometrics where available. Facial recognition and fingerprints are useful security features, but they should not be your only reason to trust a person or approve a payment.
Act quickly if you suspect fraud. If money has been stolen in India, contact your bank immediately and call the national cybercrime helpline at 1930. You can also report the incident at cybercrime.gov.in. If you suspect that someone has misused your Aadhaar details, contact UIDAI through its official website at uidai.gov.in for guidance.
Can you still trust biometric security?
Yes. Fingerprints and facial recognition can make accounts and devices safer when services use them properly. The risk arises when people assume that a familiar face, a recognisable voice or a successful identity check proves everything is genuine.
AI can help criminals imitate a person, but it cannot make every fake successful. Security systems can use checks that look for signs of a live person, and services can combine biometrics with other forms of verification.
Your best protection is to treat biometric checks as one part of security, not as a reason to trust every call or message. Before you send money or share sensitive information, verify who is asking and why.

