Case studies

What VerifAI catches, and how the evidence holds up.

Composite case studies drawn from pilot engagements and red-team exercises. Every scenario ends with signed, timestamped, independently verifiable evidence: exactly what a regulator, a court, or a board risk committee will ask for.

Video-KYC / OnboardingCASE 01

Pre-recorded synthetic passes 'wave-your-hand' liveness

Scenario

A tier-one private bank onboards a supposed HNW client remotely. The submitted 'live' video clip shows the correct challenge gesture and matches the passport photo to 96% face similarity.

Attack

Attacker used an open-source diffusion video model to generate a 22-second clip of the impersonated client performing the challenge, then streamed the file through a virtual camera into the vendor's video-KYC widget.

Signals that fired
  • rPPG cardiac liveness: no blood-flow oscillation in the 0.7-3 Hz band (score 0.04 vs 0.72 baseline).
  • Physics forensics: catchlights inconsistent across left/right eyes; shadow angles disagree with modelled lighting.
  • Compression forensics: double-encoding signature typical of re-render pipelines.
  • C2PA: absent - no signed capture provenance.
Outcome

VerifAI verdict SYNTHETIC at confidence 0.94. Case auto-escalated to the fraud desk with the six-signal breakdown; onboarding blocked. Perceptual hash pushed to the federated threat ledger, protecting every other subscriber from the same clip.

Ed25519-signed evidence PDFJWS receipt for regulatorAudit-chain entry anchored to OpenTimestamps
Wire authorisation / Video callCASE 02

Cloned CFO on a Teams call authorises a GBP 4.8M transfer

Scenario

A treasury operations analyst receives a scheduled video call from the group CFO instructing an urgent supplier payment. Face, voice, mannerisms - convincing enough that dual-control was bypassed.

Attack

Real-time face-swap plus voice-clone piped through OBS into the meeting client. The attacker also submitted a pre-recorded 'proof-of-authorisation' clip attached to the wire ticket.

Signals that fired
  • Frame classifier flags generative warping around the jawline and hairline.
  • Temporal coherence: identity embedding drifts 4.2 sigma across 8-second window.
  • Lip-sync: phoneme-viseme misalignment on plosives (/p/, /b/) at 180ms latency.
  • Audio forensics: prosody flat, spectral tilt matches known TTS vocoder family.
Outcome

The attached authorisation clip returned SYNTHETIC 0.97 in 6.4 seconds. The wire was held; treasury paged the CFO through an out-of-band channel and confirmed the call had never happened. Loss avoided: GBP 4.8M plus regulatory reporting.

Signed evidence PDF for the internal fraud casePublic verify-pdf URL for external counselTamper-evident audit trail across all four analyst touches
Private client / Voice channelCASE 03

'Proof of life' voice note authorising portfolio liquidation

Scenario

A relationship manager receives a WhatsApp voice note from a UHNW client asking to liquidate a GBP 30M discretionary portfolio, citing a family emergency. The voice is unmistakable.

Attack

3.2-second reference sample harvested from a public podcast appearance, cloned with an open-weights TTS model, delivered as a 41-second .ogg file.

Signals that fired
  • Audio forensics: neural-vocoder artefacts in 4-8 kHz band, characteristic phase discontinuities at concatenation points.
  • Prosody: pitch contour statistically flat versus the client's baseline (built from 12 prior recorded calls).
  • Federated ledger: perceptual audio hash matched an earlier flagged clip at a peer bank.
Outcome

VerifAI verdict SYNTHETIC 0.91. The RM initiated the mandatory callback protocol; the client confirmed no such request had been made. VerifAI's audit entry became the anchor exhibit in the subsequent SAR filed with the FCA.

Signed forensic PDFCross-bank threat intel citationRegulator-ready audit chain export
Disputes / EvidenceCASE 04

Cryptographic proof that a decision PDF is authentic

Scenario

Six months after a blocked onboarding, external counsel for the rejected applicant demands the bank's evidence and alleges the PDF has been altered post-hoc.

Attack

N/A - this is a post-decision integrity challenge, common in high-value disputes.

Signals that fired
  • Original evidence PDF re-verified through /api/public/v1/verify-pdf.
  • SHA-256 of the file matches the value inside the signed JWS trailer.
  • Ed25519 signature validates against VerifAI's published public JWK.
  • Audit chain head anchored to OpenTimestamps the night the decision was made.
Outcome

Byte-level, offline-verifiable proof the file left VerifAI unaltered. Combined with the OTS-anchored audit chain, the decision timeline is provably immutable. Counsel withdrew the tampering allegation the same week.

Public verify-pdf JSON responseOpenTimestamps proof fileFull audit chain verification transcript
Systemic / Federated intelligenceCASE 05

One catch protects sixteen banks in 47 minutes

Scenario

A subscriber bank flags a synthetic video used against its private-client desk. Verdict is confirmed and the perceptual hash of the clip is anonymously written to the federated threat ledger.

Attack

A commodity kit was distributing the same base clip across twenty target institutions during a coordinated wave.

Signals that fired
  • Perceptual (aHash) match on inbound submissions across other subscribers within tolerance 6.
  • Every subsequent submission of the same clip carries a THREAT_MATCH signal at ingestion time - before the ensemble even runs.
Outcome

Sixteen additional subscriber banks blocked the identical clip inside the same 47-minute window. Zero PII was shared - only the perceptual hash and verdict.

Anonymous threat ledger entryPer-bank signed match receiptsBench-published detection latency

Bring your worst case to our lab.

We run adversarial exercises with your fraud team against the exact attack vectors keeping you up at night.