AI-driven identity fraud is emerging as a growing cyberthreat as attackers increasingly exploit synthetic identities, deepfakes and autonomous artificial intelligence agents to target digital systems, according to Ping Identity.

Jasie Fon, regional vice-president for Asia at Ping Identity, an identity management provider, told the Bangkok Post that Thailand is not immune, as the rapid digitisation of financial services, e-commerce and public platforms makes identity a primary attack surface.

"Across Southeast Asia, attackers are using AI to create synthetic identities, deepfake personas and automated agents capable of interacting with digital systems at scale," she said.

Citing an analysis by the UN Office on Drugs and Crime, Ms Fon said organised crime groups are already using AI for voice cloning, deepfakes and identity fraud.

Synthetic identity fraud has increased globally by as much as 300% in recent times, as attackers combine genuine and fabricated information to bypass identity verification systems.

Deepfake impersonation is among the most concerning threats. Fraudsters can use AI-generated video or voice to imitate executives, authorise fraudulent transactions or persuade employees to disclose sensitive information.

Such attacks exploit organisations' growing reliance on remote and digital workflows, making verification more difficult and increasing the risk of costly errors.

AI-powered phishing and scams are also becoming more sophisticated.

"Automated bots can generate highly personalised messages in Thai and other regional languages at a scale that traditional anti-phishing systems struggle to detect," she said.

Attackers are also combining stolen data with AI-generated personas to create identities capable of opening bank accounts, e-wallets and digital service accounts. These accounts can then be used to launder money, bypass know-your-customer controls or conduct other fraudulent activities.

Another emerging threat is AI-enabled mule account creation, in which automated bots bypass verification processes to establish accounts for moving illicit funds.

Ms Fon said these attacks are becoming increasingly scalable, adaptive and automated, creating significant challenges for enterprises as digital adoption accelerates.

Fragmented systems create additional blind spots as AI expands the attack surface. She said 69% of Southeast Asian organisations reported that AI had contributed to recent cybersecurity incidents.

A shortage of expertise in managing non-human identities and autonomous systems adds to the risk, leaving many security teams unprepared to govern AI agents or respond to related incidents.

AI can help defenders detect anomalies, reduce manual workloads and automate threat containment. However, attackers use the same capabilities to launch targeted attacks at scale and adapt rapidly.

This is creating an "AI speed gap", contributing to longer recovery times and higher breach costs across Southeast Asia.

To address the risks, Ping Identity advocates treating every AI agent as a first-class identity. Under its "Identity for AI" framework, organisations can discover, govern and monitor AI agents through a unified control system, reducing the risk of unapproved "shadow agents".

The framework applies authentication, authorisation and least-privilege access by default.

AI agents can be managed alongside human and machine identities, with access decisions made in real time based on context rather than static permissions.

Sensitive actions can also be monitored, reviewed and linked to accountable owners, improving transparency across autonomous workflows.

Ms Fon said organisations should assign every AI agent a clearly defined identity, owner and lifecycle, while enforcing least-privilege access and continuous authorisation.

She said regulators and enterprises across Southeast Asia are increasingly strengthening electronic know-your-customer and identity assurance frameworks, reflecting wider recognition that identity security is fundamental to the safe deployment of AI.

Cyber-enabled fraud in Southeast Asia has reached billions of dollars annually, while some studies suggest breaches involving AI-related attacks can cost more than twice as much because of their complexity and scale.

Organisations also face reputational damage and declining trust in digital services, particularly in finance and e-commerce.

Ms Fon says Thailand is not immune to AI-driven identity fraud.