If 2024 was the year generative fraud arrived, 2025 was the year it industrialised. Deepfake video calls moved from anecdote to standard enterprise threat briefing. Document forgery became a subscription service. Synthetic identities matured from credit-bureau curiosity to mainstream loss category. Fraud teams spent the year discovering which controls were real and which were theatre.
What broke
Everything that trusted pixels broke. Photo-of-document checks, selfie comparisons without certified liveness, voice recognition, "I saw them on the call": each fell to generation or injection attacks. Knowledge-based authentication completed its long death. SMS codes survived only where nothing better existed.
What held
Cryptography held. Passport NFC chips resisted a year of AI advances for a simple reason: generative models synthesise appearances, and chips are not appearances, they are government signatures. Certified liveness detection (ISO 30107-3) held against injection. Qualified signatures and seals kept court-grade evidentiary value precisely because their trust is mathematical, not perceptual.
The 2026 posture
The lesson writes its own strategy: move every high-stakes decision from perception to cryptography. WeVerify's stack, chip-level KYC, certified liveness, qualified signing, sealed video, held a no imposter accepts recorded to date through the worst year attackers ever offered. 2026 will be worse. Architecture beats vigilance.
