FB pixel

KYC bypass tools sold on Telegram to defeat biometric checks

Channels offer deepfakes, stolen biometrics and virtual camera tools to circumvent liveness detection and financial institution checks
KYC bypass tools sold on Telegram to defeat biometric checks
 

Illegal hacking services designed to bypass Know Your Customer (KYC) facial biometric scans are being sold on Telegram channels to scammers looking to launder money.

The channels offer stolen biometric data as well as a variety of software for bypassing KYCs, including virtual cameras (VCam) that can be used during liveness checks to insert a deepfake or an image of another person. Sellers promise that the tools can get around compliance checks of well-known financial institutions, including crypto exchange Binance, Spain’s second-largest bank BBVA and UK-based Revolut.​

The findings were published by MIT Technology Review, which examined 22 public Telegram channels and groups in Chinese, Vietnamese and English.​

Among the services on offer are jailbreaking physical phones, which allows scammers to use a virtual camera on the phone, and hacking a financial institution’s app with code known as the “hooking framework,” which triggers the VCam to open.

“Increasingly, hackers compromise both the phone itself and the code of the financial institutions’ apps before feeding the virtual camera a mix of stolen biometrics and deepfakes,” says Sergiy Yakymchuk, CEO of cybersecurity company Talsec.

Success rates, however, are hard to gauge, as organizations may remain unaware of KYC bypasses or fail to report them until later.​

Binance, BBVA, and Revolut say they are aware of KYC bypasses, while Telegram told MIT that it has removed the channels in question. Many more, however, are likely to go unnoticed.

The rise of hacking tools for sale is driven by the expansion of Asian scam syndicates across Africa and the Pacific. Many of the syndicates are based in Cambodia and Myanmar, where government oversight is limited and legal frameworks are underdeveloped.

Fraudsters often obtain money through “pig-butchering scams,” a sophisticated form of online investment fraud, and then pass it on to money-laundering networks, known as “water houses.” Money launderers then gain access to bank accounts by circumventing KYC controls, turning them into money mules and redistributing illicit proceeds. Finally, the money is channeled into digital assets, particularly the stablecoin Tether, where it can lose trace.

In 2025, around $17 billion was stolen in crypto scams and fraud, according to blockchain analysis firm Chainalysis.

In Vietnam and Thailand, government authorities have been attempting to stamp out mule accounts by introducing tougher identity verification and anti-fraud measures.

As of 2024, Vietnamese banks must use biometric authentication for money transfers exceeding 10 million Vietnamese dongs (US$380). Vietnam also recently introduced facial scans for mobile subscriptions and mobile device registrations.

Thailand has also imposed heightened KYC requirements for banks and mobile networks. The latter are intended to combat identity fraud, “ghost SIMs,” and SIM box systems, which are often exploited by fraud rings.

Related Posts

Article Topics

 |   |   |   |   | 

Latest Biometrics News

 

Face biometrics use cases outnumbered only by important considerations

With face biometrics now used regularly in many different sectors and areas of life, stakeholders are asking questions about a…

 

Biometric Update Podcast explores identification at scale using browser fingerprinting

“Browser fingerprinting is this idea that modern browsers are so complex.” So says Valentin Vasilyev, Chief Technology Officer of Fingerprint,…

 

Passkeys now pervasive but passwords persist in enterprise authentication

Passkeys are here; now about those passwords. Specifically, passkeys are now prevalent in the enterprise, the FIDO Alliance says, with…

 

Pornhub returns to UK, but only for iOS users who verify age with Apple

In the UK, “wanker” is not typically a term of endearment. However, the case may be different for Pornhub, which…

 

Europol operated ‘shadow’ IT systems without data safeguards: Report

Europol has operated secret data analysis platforms containing large amounts of personal information, such as identity documents, without the security…

 

EU pushes AI Act deadlines for high-risk systems, including biometrics

The EU has reached a provisional agreement on changes to the AI Act that postpone rules on high-risk AI systems,…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events