LAB · MIRROR TEST 204
Professor Phish
PROFESSOR PHISH

"Your face is a password. And passwords can be cracked."

OPERATION BRIEF — AI-ASSISTED MAJOR

The Mirror Test: KYC Bypass Simulator

Your mission: open 50 synthetic mule accounts at NeoVault neobank by bypassing their AI-powered Know Your Customer (KYC) verification. Synthetic identities, deepfake liveness bypass, automated account scaling. Total loadable value: $25,000.

300%
surge in doc fraud 2024
$3
avg. synthetic SSN cost
4 min
per account opened
STEP 1 OF 4 — FORGE THE IDENTITY

Build the Synthetic Identity

Assemble the four components of a synthetic identity by clicking each card. Watch your fake person materialize in the identity preview.

IDENTITY PREVIEW
NeoVault
KYC Verification Portal
Secure
SSN ●●●-●●-4721 — — —
Name James Caldwell — — —
DOB 03/14/1987 — — —
Address 847 NW 12th Ave, Miami FL 33136 — — —
Phone +1 (786) 555-0194 — — —
IDENTITY SCORE
Sufficient for account opening
/ 4 components assembled
STEP 2 OF 3 — BYPASS & SCALE

Bypass NeoVault's AI Verification

NeoVault requires a live face check: turn left, turn right, blink twice, smile. Choose your bypass method, then watch the detector fall.

NEOVAULT PORTAL — LIVE VIEW
NeoVault Identity Verification
Powered by AI · 256-bit encrypted
BYPASSED
Liveness check... PASSED ✓
Identity verified — proceeding to account creation
CHOOSE BYPASS METHOD
Most Effective
Deepfake Video Loop
Pre-recorded deepfake of the synthetic face performing the gestures, played through OBS Virtual Cam. Invisible to video KYC systems.
Adversarial Perturbation
Subtle pixel-level noise added to a real photo. Invisible to humans — but causes the AI liveness detector to classify the image as a live face with high confidence.
3D Printed Mask
Printed 3D face mask + IR lighting to spoof near-infrared camera sensors. Hardware required — but completely undetectable by video-based liveness models.
SCALE AND WASH

50 Accounts. 3.3 Hours.

The bypass method is automated. Now scale across all 50 synthetic identities. Each takes ~4 minutes. Then load and wash.

ACCOUNTS OPENED
/50
Elapsed:  ·  Avg: 4 min/account
AUTOMATION LOG
STEP 4 — THE WASH CYCLE
Loading $500 into each account... $25,000
Transferring $24,500 to mule account... → offshore
$0 Recoverable
$24,500 wired offshore via layered mule accounts · $500 per account left as "float"
Accounts closed within 72 hours · All KYC documents synthetic · No real person exists
DEFENDER REVEAL — WHAT NEOVAULT SHOULD HAVE CHECKED

Five Signals They Missed

Each synthetic identity left a detectable trail. A layered KYC system would have flagged the operation before account #3 was opened.

SCAM.AI PRODUCT
KYC Liveness Shield
Deepfake & adversarial attack detection for identity verification · <200ms latency

Every bypass method in this lab leaves a detectable signature. Scam.ai's liveness model runs frame-level analysis during KYC — catching synthetic face artifacts, adversarial pixel noise, and virtual camera injection in real time, before the account is approved.

Deepfake Frame Analysis

GAN texture artifacts and blink timing deviations detectable at 30fps — invisible to standard biometric matchers.

Adversarial Noise Detection

Detects CVPR-class pixel perturbations that fool cosine-similarity liveness models — invisible to humans, measurable to our classifier.

Virtual Camera Injection

OS-level device integrity probing detects OBS virtual cam, screen-capture APIs, and software rendering pipelines at submission.

Velocity & Graph Signals

Cross-session identity clustering flags shared device fingerprints, drop-address reuse, and open-timing clusters in real time.

KYC Liveness Shield → scam.ai
REAL-WORLD SCALE Synthetic identity fraud costs U.S. lenders $3.3B in H1 2025 alone — a 300% surge driven by $15 AI-generated IDs and commodity deepfake tools now defeating first-generation KYC systems in 78% of tested cases.

Change Alias

Choose your villain name, or roll the dice.

Share Feedback

Help us improve ScamAI University

Feedback received!

Thank you for helping us improve.