Level Five x Bloom AI in Korea

Image

Our CEO Frederick recently spoke at Bloom AI in Korea. Bloom is a Seoul-based AI community that builds offline spaces for people and tech to meet. Since April, they've run more than 30 events and welcomed over 7,200 people, bringing together builders, founders, and AI professionals for talks, panels, and hands-on sessions rather than pure networking mixers. They've hosted names like Nebius and NVIDIA on their stage. 

This community is exactly who Fred needed to talk to regarding this surge in AI enabled fraud.

Four seconds is all it takes

Voice cloning no longer needs a full audio profile. Four seconds of tone is enough, then a real person layers their own delivery on top. That's why deepfake calls sound so convincing. It isn't a machine talking. It's a person wearing someone else's voice.

Where does the audio come from? Mostly places you'd never think to lock down: TikTok, Facebook, X, Threads, YouTube, even TV appearances. Fraudsters also run robocalls just to capture someone saying "Hello, who is this?" then sell the clip on the dark web. Fred's advice, unless you're a public figure: keep your profile private, and think twice before posting your own voice online.

‍

Worried about how AI-enabled fraud is reaching your institution? Let's talk.

Contact us here

‍

99% is a lab number, not a bank number

Detection rates above 99% sound reassuring, until you learn that number only holds in a quiet room with clean audio. Drop it into a real network, especially the 4G and 3G connections still common across Southeast Asia, and detection falls to 50-60%. Fraudsters know this. They hide behind bad signal on purpose.

50-60% might sound workable, until you scale it to a full day of bank transactions. Everything below that threshold needs human review, and no bank can hire enough people to look at all of it. The room went quiet here too. It's not a technology gap. It's an operations gap. Banks don't need 99%. They need 99.999%, and that number doesn't exist yet.

‍

Watch the phone, not the face

If detection can't fully catch the voice, what's left? The device.

Is it an iPhone or Android? Does the screen resolution match the hardware? Is it jailbroken or rooted? Is developer mode on. Layer behavioral signals on top: a phone that doesn't move at all during a transaction is a red flag, especially if it's face-down on a desk charging.

The smaller signals are just as telling. Hesitation when typing a name, something almost nobody does with their own name. Copy-pasting a phone number, something people rarely do outside of an address field. Being on a call with someone else while completing a bank transaction, a weak signal for younger users, a strong one for older ones.

Even eKYC has a hole. Jailbreak the phone, play a deepfake video on a high-definition screen, point the camera at it. The app reads it as a live face. It's called camera injection, and it's simpler to pull off than most people assume.

The takeaway from the room wasn't that the fraud is getting smarter. It's that the fight has quietly shifted from proving who someone is, to proving what they're holding.

‍