In 2025, a single fraud syndicate sourced 100 facial identities — stolen, scraped, or purchased for as little as $5 each on darknet identity markets — and used them to generate 160,000 verification attack attempts across African fintech platforms in a single month. Some of those faces appeared more than 12,000 times. The platform catching them was Smile Identity, one of Africa’s largest identity verification providers. The report documenting what they found, published in March 2026, should be required reading for every Nigerian fintech currently building toward the CBN’s July 1 liveness compliance deadline.
The headline figure from Smile Identity’s 2026 Digital Identity Fraud in Africa Report is 69%: the share of confirmed biometric fraud cases in Africa last year that were AI-generated, including synthetic faces, deepfakes, and real-time face swaps. In Southern Africa, the figure reaches 87%. These are not fringe incidents. The CBN has just made liveness verification mandatory for all account openings and reactivations across Nigeria’s banking and payments system. The compliance story and the fraud story are now the same story — and the adversarial environment is ahead of the regulatory specification.
What the Attack Looks Like
Biometric fraud in Africa has evolved in distinct phases. The early playbook — 2021 through 2022 — involved physical deception: printed photographs, cardboard cutouts, basic face masks held up to smartphone cameras. Weak liveness detection systems, built to catch the most obvious replay attacks, could handle this class of attack with passive detection: checking whether the image showed the characteristic texture and light response of a live face.
That era is over. In 2023 and 2024, AI-assisted face swaps emerged as the dominant attack method — attackers overlaying a target’s facial features onto their own during live verification sessions, using consumer-grade deepfake tools. By 2025, the sophistication had scaled to real-time identity grafting: injection-style attacks that bypass the device camera entirely, feeding pre-recorded or AI-generated video streams directly into verification sessions through software-simulated phones and virtual camera inputs. Smile Identity logged over 100,000 injection-style attempts per month last year.
The economics are stark. Deepfake generation tools, synthetic facial composites, and even biometric datasets are available on darknet markets and increasingly on surface-level Telegram channels for as little as $5 per identity. The barrier to entry for running a synthetic identity fraud operation in African fintech is lower than the cost of a SIM card registration.
What the CBN Mandate Requires — and What It May Miss
The CBN’s March 12, 2026 circular mandating liveness verification specifies that all account opening and reactivation must include real-time biometric verification against the NIBSS BVN or NIMC NIN database. Financial institutions have until July 1 to comply. The circular also mandates device binding — one active device per banking application — and a ₦20,000 transaction cap on newly activated accounts in the first 24 hours. Together, these measures close the most obvious account-takeover and SIM-swap vectors.
What the circular does not specify in technical detail is the required robustness of the liveness check itself. The mandate says liveness verification must occur. It does not prescribe whether that verification must include active liveness testing (requiring the user to perform specific actions — blink, turn, speak — to confirm physical presence), passive liveness detection (analysing a single frame or short video for synthetic media artifacts), or injection attack prevention (validating that the camera feed has not been intercepted or replaced). These distinctions are not academic. A liveness check that passes the CBN audit requirement but uses only passive, single-frame detection is a liveness check that a 2025-grade injection attack will bypass routinely.
The NIBSS-certified identity vendors at the centre of the compliance market — Prembly, Seamfix, Smile Identity, VerifyMe, and Dojah — are each running their own fraud intelligence operations and updating their detection models continuously. The question for fintechs selecting among them is not just whether a vendor is NIBSS-certified, but whether their liveness detection architecture addresses the current attack generation. Injection prevention requires active signal validation at the API layer, not just front-end camera checks. Only some of the vendors in the market have published technical detail on their injection detection capabilities.
The Identity Farming Threat Beyond July 1
The 160,000 attacks from 100 faces is the spectacular version of the problem. The quieter version is identity farming: syndicates that create synthetic or real-but-stolen accounts, age them through small, legitimate transactions over weeks or months to establish credibility, then activate them for high-value fraud or money laundering. Smile Identity caught 126,000 duplicate fraud attempts in 2025 — up from 52,000 in 2024 and 21,000 in 2023. That sixfold increase over two years reflects not just rising attack volumes but a professionalisation of fraud infrastructure that mirrors the professionalisation of the compliance infrastructure being built to stop it.
The CBN’s device binding requirement partially addresses identity farming by making it harder to operate multiple synthetic accounts from a single device. But identity farming operations using distributed device networks — a common syndicate architecture — are not deterred by single-device limits. The effective counter to identity farming is cross-platform deduplication: checking a new account applicant’s biometric against a database of previously flagged fraudulent identities. That capability exists at the vendor layer, not in the CBN mandate itself. Fintechs that rely solely on the minimum compliance requirement without subscribing to shared fraud intelligence networks will be the ones absorbing the farming costs after July 1.
The Compliance-Security Gap
Gartner projects that by 2026, over 30% of identity verification attacks globally will involve AI-generated media. Africa is already past that threshold. The 69% figure in Smile Identity’s report is not a leading indicator of where African fintech fraud is heading — it is where it already is.
The CBN’s July 1 mandate is the right structural response to a fraud environment where unsecured account opening was the primary attack vector. It will materially reduce the class of attacks that relied on the absence of any biometric check. It will not, on its own, stop the next generation of attacks that target the biometric check itself.
The fintechs that will emerge from this compliance cycle in a strong security posture are those treating liveness verification as a continuously updated security surface rather than a compliance checkbox. That means vendor selection based on fraud intelligence capability — not just NIBSS certification — and active participation in cross-platform deduplication networks. The July 1 deadline is a floor. The fraud environment has already built past the ceiling.
— Technology Desk, BETAR.africa