All posts
NewsSeptember 21, 2026·6 min read

He Wore 60 Stolen Faces. AI Agents Opened the Bank Accounts.

Think you found an AI video?

Paste the URL and let the Ledger community verify it. Free.

Check a video

Quick answer: Israeli police allege that Nikki Sokolov, 20, bought ID card photos leaked from hacked databases, used AI to animate them into selfies and video that satisfied banks' remote verification, then ran AI agents that opened accounts in more than 60 names. Roughly 120 people have filed complaints. The victims did not know.

Remote bank account opening asks you to prove you are a real person holding a real ID. You photograph the card, take a selfie, record a short video, and confirm the account is yours alone. Four checks, no branch visit.

Israeli police allege a 20-year-old defeated all four, at volume, without being in the room for any of it.

What Investigators Say Happened

Nikki Sokolov, 20, from Tzur Yitzhak, was arrested by the Lahav 433 cyber unit on suspicion of stealing more than 60 identities and fraudulently obtaining hundreds of thousands of shekels, Israel National News reported.

The source material was not stolen in person. Investigators say the ID card images came from hacked databases leaked online, purchased on the darknet or through Telegram channels. That data was already sitting there, cheap, from breaches that happened to other companies.

What changed is what a photo is now worth. Sergeant Major Raviv Neumann described the method plainly: the suspect "takes those images and details and brings them to life using AI." A flat ID portrait became a face that could blink, turn, and appear in a selfie and a video recording.

Then the automation layer. Investigators allege Sokolov built AI-powered digital agents that impersonated the identity holders when interacting with banking systems. The agents did the opening. Accounts were created, credit cards were issued against them, and funds moved out to the suspect.

Around 120 people have filed complaints. None of them knew an account existed in their name.

The investigation opened in January. By the end of March the suspect had left for Thailand, where Israeli police located him. Thai authorities detained him at Israel's request and deported him for staying without a valid visa. He was arrested on arrival at Ben Gurion Airport, and a Rishon LeZion Magistrate's Court judge extended his detention.

These are allegations. The case has not been tried.

60+ identities, ~120 complainants

The scale one person reached by buying leaked ID photos, animating them with AI, and letting software do the account opening. Losses run to hundreds of thousands of shekels.

Source: Israel National News and Calcalist

Why This One Is Different

Deepfake fraud stories usually feature one high-value target and a person doing the talking. A finance employee gets a video call and wires 25 million dollars. A scam compound puts a human on camera and uses AI to smooth the edges. Both need an operator working a mark in real time, which caps how many they can run.

This case removes the operator from the loop, and three things stack to make that possible.

The face was free. The attacker did not need to steal your identity documents. Someone else's breach already put your ID photo on a market. Every breach that leaks a scan of a government ID is now stocking a supply shelf for this.

Animation beat the liveness check. The verification asked for movement to prove a live human was present. AI supplied movement. The test measured the wrong thing: it asked whether the face moved, not whether the movement came from a person in front of a camera. Independent testing of identity-verification detectors finds the same mismatch one layer down: measured on what they actually catch rather than how they rank, nine of thirteen published detectors change position, which is research from Margen, a detector-evaluation company run by Ledger's founder.

Agents removed the volume ceiling. Identity fraud has always been bottlenecked by human effort. One person can only sit through so many onboarding flows. Software does not get bored, and 60 identities becomes a scheduling problem rather than a labor problem.

The judge in the case, Guy Maimon, put it as directly as anyone: "This case is undoubtedly an example of the future expected in cybercrime and of the ease and sophistication with which fraud offenses can be committed."

What This Means for You

Treat a leaked ID photo as a future face, not a past loss. When a breach notification says your driver's license or passport scan was exposed, the old advice was to watch your credit. The new exposure is that the photo is animation input. It does not expire and it cannot be reissued out of an attacker's hands.

Video verification is not proof you were there. If a service tells you an account was opened with a selfie and a live video, that no longer establishes a person was present. The same applies in reverse when you are on a call: the tells that give away a real-time face swap on a video call are behavioral, not visual.

Check for accounts you did not open. The victims here found out from investigators, not from their banks. A credit freeze is the standard advice and it is incomplete, because the report banks check before opening a checking account is a different one.

Report it through the official channel. In the United States that is IdentityTheft.gov, which generates the recovery plan and the affidavit banks ask for.

Think you found an AI video?

Paste the URL and let the Ledger community verify it. Free.

Check a video

The Pattern Underneath

The FBI's own numbers already showed AI-enabled fraud growing roughly six times faster than every other category it tracks. This case shows the mechanism behind that curve. The expensive part of fraud was never the deception. It was the labor.

AI removed the labor. A leaked photo, an animation tool, and a script now do what previously took a person willing to sit through 60 onboarding flows and keep a story straight each time. Understanding what a deepfake actually is matters less for spotting a viral video than for seeing why a verification step built around a moving face stopped proving anything.

The banks in this case asked for four things. All four could be manufactured from a photograph someone else lost.

Related Posts

Ledger App

Train your eye. Verify what you find.

Swipe real and AI-generated video clips to sharpen your detection instinct. Then paste any suspicious URL and see what the community has already flagged.

Train Your Eye
AI-generated video flagged in Ledger
AI Detected
Real video verified in Ledger
Not AI