SpinDepth
    SpinDepth
    At Money20/20 Asia, a Fraud Executive Said the Quiet Part Out Loud
    Back to Insights
    APAC Intelligence

    At Money20/20 Asia, a Fraud Executive Said the Quiet Part Out Loud

    At Money20/20 Asia in Bangkok, VIDA founder Niki Luhur described fraud across Southeast Asia as having reached industrial scale, run by cross-border syndicates. His most important technical warning was not about deepfakes. It was about injection attacks.

    July 28, 2026·4 min read

    Fintech conferences usually deal in optimism. At Money20/20 Asia in Bangkok, one speaker did the opposite. Niki Luhur, founder and chief executive of Indonesian digital identity network VIDA, told the audience that fraud across Southeast Asia has reached an industrial scale, run by cross-border syndicates operating between Myanmar, Thailand and Indonesia, and he cited a 12 billion dollar Bitcoin seizure in Myanmar as a single illustrative data point.

    The context around the warning

    The room he said it in was full of executives discussing embedded finance, AI banking and cross-border payment innovation. According to the Money20/20 Future of Fintech in APAC 2026 report, based on surveys and interviews with more than 130 senior fintech leaders across Asia, Southeast Asia dominates fintech expansion plans with 22.9 percent of APAC respondents naming it their primary growth target, and digital payment transactions across the region are projected to exceed 1.5 trillion dollars in 2026.

    The same report found that 63.5 percent of fintech leaders identify fraud prevention as their top operational priority for the year, a figure that would have been unthinkable a few years ago. Growth and fraud are now the same conversation.

    Why injection attacks matter more than deepfakes

    Luhur's most useful technical point cut against the headlines. While deepfakes dominate media coverage of AI-enabled fraud, he argued the harder operational threat is injection attacks: fraudsters using virtual cameras on compromised devices to inject pre-recorded or AI-generated video directly into a liveness verification session, making a synthetic face appear to pass a real-time biometric check.

    The distinction is not academic. Most platforms have invested in facial liveness detection as their primary defence against deepfakes. If an attack injects video downstream of the camera rather than presenting a fake face to it, that defence may never engage. A platform can be fully invested in liveness detection and still be exposed.

    The numbers behind the warning

    Independent research supports the scale claim. The Sumsub APAC Fraud 2026 report, covered by Fintech News Singapore, documented a 142 percent rise in synthetic identity fraud across Asia Pacific, alongside a 1,500 percent surge in deepfake fraud cases in Singapore, a 1,900 percent jump in Hong Kong, and growth exceeding 400 percent in Malaysia.

    The macro figure came later. A United Nations Office on Drugs and Crime report released on July 21, 2026 estimated victims across East Asia, Southeast Asia, Australia and New Zealand lost between 88.3 billion and 114.1 billion US dollars to online scams in 2025, at least triple the 2023 estimate.

    A platform that has invested heavily in liveness detection can still be defeated if the fake video never passes through a camera at all.

    The proposed answer

    VIDA's response, launched at the event as ID FraudShield, combines biometric liveness detection, device intelligence, behavioural analytics and network detection into simultaneous multi-layer verification. The underlying logic is that no single defence layer holds against a coordinated multi-layer attack, and that legitimate platforms need verification architecture matching the coordination architecture of the networks attacking them.

    That principle, verifying person, identity and device at once rather than sequentially, is what Vietnam's mandatory biometric verification rules for new bank accounts began codifying from January 2026, and what other ASEAN regulators are watching.

    What this means for financial brands

    For any regulated brand operating in the region, the practical takeaway is that security investment has become a marketing asset. In a market where consumers know fraud is industrial in scale, being able to demonstrate genuinely robust verification is a differentiator that competitors relying on minimum-viable KYC cannot match. This is exactly where SpinDepth helps, turning real security and compliance into visible, credible trust.

    FAQs

    Q1: What did VIDA's CEO say at Money20/20 Asia?

    A1: That fraud across Southeast Asia has reached industrial scale, run by cross-border syndicates operating between Myanmar, Thailand and Indonesia.

    Q2: What is an injection attack?

    A2: Fraudsters use virtual cameras on compromised devices to inject pre-recorded or AI-generated video into a liveness check, so a synthetic face appears to pass real-time verification.

    Q3: How fast is synthetic identity fraud growing?

    A3: Sumsub documented a 142 percent rise across Asia Pacific, with deepfake cases up 1,500 percent in Singapore and 1,900 percent in Hong Kong.

    Q4: What is the proposed defence?

    A4: Simultaneous multi-layer verification covering biometrics, device intelligence, behavioural analytics and network signals, rather than sequential single-layer checks.

    For brands in Southeast Asia, demonstrable security is now demonstrable trust, and that is exactly where SpinDepth helps brands show up.

    Source:

    Source 1: Money20/20 Asia, Future of Fintech in APAC 2026 report

    Source 2: Fintech News Singapore, Sumsub APAC Fraud Trends 2026 Synthetic Identity Fraud

    Source 3: Hong Kong Free Press, Scam losses in Asian regions up to 114 bn in 2025 UN

    money2020 asiafraudvidabiometricssoutheast asia
    Share