CEO of Moveris discusses the fraud you can’t see
Why is fraud getting harder to spot just as AI gets better at pretending to be human? In this episode of The Lending Link, host Nathan George sits down with Justin Keene, Ph.D., CEO and Co-Founder of Moveris, to explore one of the fastest-growing threats in digital onboarding and account access: deepfakes and AI impersonation.
They talk about why old ways of spotting fraud, like checking device information, how people act, and even video checks to see if someone is real, are not enough anymore. As AI-powered attacks become smarter and easier to deploy widely, scammers can now bypass many of the checks that banks and lenders have relied on for a long time. Justin shares how Moveris tackles the problem in a new way by looking for real signs that a person is actually there, not just signs of trickery, using body and mind signals picked up by a regular camera.
They also talk about how AI is changing the way fraud works, making smaller banks, credit unions, and lenders who work with people with lower credit scores more likely to be targeted. They explain why tricks like using stolen usernames and passwords, reusing old identities, and using fake videos to fool people are happening more often. They end by looking to a future where showing you are a real person and the same person each time could become the main way to prove who you are online, instead of using passwords, CAPTCHA, and other steps that slow things down.
Episode Transcript
Nathan George: Hi, everyone on the phone. We'll be starting in just a moment. I think we're a minute after. Let's get things started. Welcome, everyone. Thank you for joining us today. I'm Nathan George from GDS Link, and we're going to be talking today about deep fakes and AI impersonation with an expert. Before we get started, though, I did want to let you know the session is live. It's interactive. If you have questions as we're chatting today, please drop them in. We'll try to answer those either in the session or towards the end. We'll also put up our contact info. You can touch base with us that way. Anyway, looking forward to the discussion. I'm joined today by Justin Keene, CEO and co founder of Moveris. Justin, let's jump right in. You've got over a decade of experience as a researcher and a professor. What brought you here? What made you decide to hit the sciences? And then I'm going to ask you the definition of the weird area of science that you specialize in.
Justin Keene: Yeah. So like Nathan said, my name is Justin. I'm the founder and CEO of Moveris, and my background is as a research professor. So I have a dual PhD in cognitive science and mass communication, so spent 12 years in higher ed running research labs. And so what drew me to that kind of field is kind of the same thing that drew me into what I do now really was I had questions that I thought that I could answer better than other people, and I thought that the answers would make me enjoy, you know, walking through life a little bit better. And so in college, I worked at an ad agency and I kept getting in trouble because I wanted to know, why are we making ads the way that we make them? Shouldn't we be able to, like, you know, use some kind of experimental approach or something that would help us test ads and all of that. I kept on being told, shut up and do your job. So I left that job and I went to grad school and I ended up getting, like I said, a dual PhD and ended up kind of pursuing into sciences. Along the way, the pandemic hit and I couldn't do my work anymore. And so my co founder, Eric, he was also a professor with me, we decided to try and figure out a way to do our research but do it in a scalable way. And so the type of science that we do is called psychophysiology. And so, Nathan, you said you were going to ask you about the fancy word. So that's the fancy word. All it really means is that we want to measure what happens in the brain by what the body does. And so Eric and I spent some time, because we had nothing better to do during the pandemic, trying to figure out how we were going to measure those things. And so we figured out how to measure it just with the basic webcam, just any basic webcam signal. And that kind of evolved over time into what Moveris is now. Moveris is a simple webcam based API tech that allows you to detect humans really well, to reject deepfakes really quickly, so that you don't have to deal with user fraud either in your onboarding flows or in re verification or in zoom calls or any other kind of interaction.
Nathan George: Cool. Really fascinating the approach you guys have taken. I want to dig into the science a little bit more. Can you give us an idea of like, what is it that you're looking for? What are the signals that you're getting about what's going on in the brain from what's happening on the camera? How are you connecting those dots and how accurate is it?
Justin Keene: Yeah, so at its core, we're kind of measuring. Think of it as kind of two buckets of things. So we want to look at human cognition and human emotion. And the reason why we want to look at those is that there's. There's a lot of bodily actions that happen in contexts, but they don't happen generally. And emotion and cognition happen across contexts all the time. So you're always displaying some form of emotion, even if it's boredom. Boredom is an emotion. I was gonna ask about that.
Nathan George: Can you tell when somebody's bored or not paying attention?
Justin Keene: Yeah, I mean, yeah, it's low attention and low positivity and you know, like it's that kind of thing. And so, you know, your cognition, you're constantly processing information, whether it's paying attention to something external, whether it's ruminating on something in your own head. And so those two things are going to span across any kind of context that someone's in. So we want to look at measures of those. The way we look at those. Again, we measure what's happening in the brain by what the body does. We look at correlates like heart rate and facial muscle movements and certain other behavioral outcomes, as well as more physiological or biometric outcomes. And that allows us to over time track how someone is paying attention to something, how they're emoting or responding to something. And ultimately for, from our perspective, as a fraud fighting tool and company, it allows you to detect whether or not Someone is who they say they are, are they human? And what is their intent behind the thing that they're doing on your platform at that time? Yeah.
Nathan George: So I'm curious, when you're detecting these signals, you're looking at facial expressions, you're looking at all the components that you're measuring. How hard is that for AI to reverse engineer what you're looking for? Right. Like, how challenging are those signals to think?
Justin Keene: So think of it in kind of two scales. So there's the kind of macro things. Does it look close enough that it's really convincing? And then there's the micro things of when you start to pick it apart, does it still, like, is it scientifically or at a data level, is it still convincing? And if you think of the macro level, we've all seen deepfakes that are really, really scary and really convincing. Right. Like the last couple weeks, there's been a series of videos that were fairly viral on LinkedIn and Twitter and Reddit of people using face swap technology from Kling AI to be able to map. Basically they sat there and prerecorded themselves doing some actions and then they face swapped in the characters from Stranger Things and it looks terrifying, right? Like almost every post that, that has that video is like, oh man, we're, we're screwed as a society, you know, and on the macro level, more convincing
Nathan George: than just adding a sombrero on somebody's.
Justin Keene: Yeah, yeah, at the macro level, they're right. You know, like, it is really convincing at just kind of the gut check level. You watch it and you go, man, they have the right number of fingers. Their fingers don't look like hot dogs like they used to whenever OpenAI video stuff would do that, you know, like it, it looks pretty convincing on its face. Underneath all of that, though, are a series of small micro emotions, small, you know, little physiology things that happen that are not necessarily even perceptible to the human eye, but computer vision can detect them. At the same time, AI has no reason to recreate them because they don't ultimately match the broad model. If you think of what generative AI is doing, it takes a whole bunch of example videos and it's trying to generate a video that matches the broad terms and the broad scope of those videos it's been trained on. It has no reason to look to the micro stuff at all, because that's not how LLMs work. And so from our perspective as a company, what allows us to be different is that we're not looking for signs of AI manipulation or AI Generation we're looking for signs of humanity, those micro things that aren't ever going to change day to day and what is or is not a human. And also with that the macro things can change all at once and those are still not going to affect the micro things that make a human a human. Right. And so yeah, AI advances rapidly obviously and we see it in front of us because particularly deepfakes and these face swap techs and things like that, you see it all the time because it is really kind of terrifying to watch. However, it's also very detectable if you know what to look for.
Nathan George: It's been interesting because obviously in the context of lending where we operate GDS operates in particular, the instances of deep fakes are on the rise big time. I mean we're seeing it across the, across the board. Sometimes it's not even third party fraud, typical fraud. Sometimes it's first party fraud, people trying to do things illegitimately. I'm wondering as you think about the current methods for detecting this kind of thing. I was still kind of sticking with the science topic and things, the normal methods today that we see. If you look at the fraud prevention options that are out there for you, you typically fall into a few buckets. You know, you're looking at data signals from the IP address geolocation, is it on a vpn, things like that. You might look at phone signals if they're on a mobile phone. Something that says this device has been involved with fraud in the past or maybe the area it's coming from or the type of network it's on is a little hinky. Then you've got maybe a little more sophisticated version like with I think, you know, neuro IDs an example of one or behaviosec where it's looking at how fast you input the information on a loan application or things like that. Those have been pretty successful at detecting fraud. Can you talk maybe a little bit about how yours is different and advantages to adding that to the fraud stack and how that might help identify things in a different way that maybe those are missing.
Justin Keene: Yeah. So I'll start off by saying we, we have a lot of friends and partners that do other things within IDV and fraud fighting. So I'll start by saying that I'll, I'll follow up by saying the way in which we've had to protect accounts and fight against bots over the last 20 years has been relatively standard. Right. Passwords using MFA or 2fa in some way. Because we say hey, if this person's if this is their cell phone and they're trying to log in, then it must be them, right? Like we're using these corollaries of identity to mean them. And we've taken that same kind of process and applied that to bot detection or fraud detection or human detection. Hey, if they click in a way that makes sense for humans, must be human. If it has certain signals within the device, it must be legitimate. Like, oh, we look at the Mac address for this specific thing or we look at, we get some data out of iOS and we're able to tell what camera they're actually using, or is it a virtual camera? All that makes a lot of sense, but ultimately it's all corollary data, right? Like you're hoping that enough of those data points point to something else. And that makes a lot of sense in the past. The problem now is that synthetic fraud and agentic AI have made it where those agents can click on your screen in a way that looks human to, you know, the processes that are looking for that. There are ways to simulate the camera outputs in a way that it doesn't present to the browser as if it is a virtual cam. So that goes away. These fraudsters are getting more sophisticated in the identities that they do steal. And so in the past it was things like the age of the email. Well, if this email has been created in the last three weeks, we're going to reject it because it could be fraudulent. Well, now they're able to get into emails that are decades old, you know, because Gmail has been around for so long and they get in, and because they're able to intercept in the smtp, you know, profiling approach, they're able to intercept that email before you ever see it come into your inbox. They receive it, they see the contents, they delete it. So you never even know that your email is being used for this. And so there's, there's all these signals that we've used over time and each one of them now is either no longer, as, you know, confidence inspiring as it used to be, or they're just straight up fakeable. And so where we land as a company and kind of what makes us different is that we're instead of looking for corollaries of humanity like, oh, in the gyroscopes on the phone, are they tilting in a way that a human would, or are they clicking in a way that a human one? Instead of looking for those, we just say open up your camera, right? Like if you're there, we'll see you and our technology is able to tell whether or not you're a human or not. And so, you know, like, rather than looking for all of these other, you know, kind of outcomes and evidence and all that, let's just go to the source. If we start there then then all of that other stuff, it matters in some way, right. Like you still have to know whether or not that person is who they say they are. Are they presenting you with deep faked deep, you know, ID documents in something or are they presenting some kind of work profile in their past that's, that's not legitimate? You know, like there still are other fraud risks to it. But if you start off by knowing whether or not this thing that's presenting itself to your system is a human, you don't have to do all this weird jockeying to figure out all these other signals. You, you just say, oh, up or down and now we can move on.
Nathan George: Right. And so it's, it's like a step beyond. Can you recognize a fire hydrant, a bicycle or a crosswalk in the picture?
Justin Keene: Yeah. Look, the reality is, yeah, No1 likes Captcha1 2. It's very fakeable. There's several agents out there now that are publicly available that can successfully navigate captcha without being detected. And ultimately that friction only is there for your sense of feeling like it's safe. Right. Like there's several things that we do in identity and cybersecurity that are really more about making people feel safe than they are about actually securing the thing at this point.
Nathan George: Security theater basically.
Justin Keene: Right, yeah, exactly. And so we actually, we have a sub products at Moveris called Cognitocheck that it in less than 350 milliseconds it can detect whether or not you're a human. And it's a captcha killer basically. Because our joke is that no one likes clicking on fire hydrants. Like everybody's tired of doing it. It doesn't help. All it does is cause friction. And if you're a provider or you're a financial institution or you're a creditor, any level of friction at all could be the thing that makes people go to your competitor. And so when we're adding friction for theater or when we're adding friction because we just simply don't know how else to it. It's just a bad approach that's not going to last long term. It's not a successful way to manage your fraud risk.
Nathan George: I think when actually I met one of your partner guys at Lynn360 last year when we first ran into you guys, one of the things that was interesting when he first started describing the technology to me was I was trying to scratch my head thinking, where does this come in? And then as you've described, your fraud strategy has to be a layered approach because there's so many tactics and those tactics change on a regular basis and they try to come at you from all angles. So the best strategy is a comprehensive one that's got layers as they get closer and closer to a lending decision. And I think one of the things that interested me the most is whether you're on a laptop filling an application out today or you're on a mobile phone, there's a camera right there. And that camera doesn't, isn't really used in loan applications very much unless you're doing like verifying a driver's license or something like that, which those can be expensive calls because as those layers of security as you go through them, it's also got cost associated with each step. So I think the thing that really fascinated me was the opportunity to watch the person on a camera through the whole process just to verify, hey, is this a real human being? I think you and I had chatted as we were preparing for this about how AI has enabled fraud at scale, but not targeting the big guys, but actually targeting the little guys who have the least amount of defenses in place today and maybe who have historically never been targets. Yeah, because it costs too much to hit them one at a time. But now you can buy an AI attack strategy in a box and just go out and hit every credit union website that's out there.
Justin Keene: Yeah, fraud as a service is a real thing. There's a really well known fraud ring based out of Southeast Asia that is so legitimate that they have a building with their name on the sign on the top, they have an HR department. You can go on their website for their open positions. They by the way, they offer unlimited time off and family medical, in case you're wondering. Like, I mean these are legitimate businesses and legitimate operations from a perspective of like they operate just like our businesses do. Just the outcome is that, you know, they're trying to defraud people of their money. And so the problem is that agentic AI and these deployable networks have made it where, you know, community banks and some of these smaller maybe you know, lenders that weren't necessarily like deep prime subprime, but they were, you know, kind of non traditional lending mechanisms, they're seeing a massive rise in fraud and it's because they didn't have the money historically to buy into like you were talking about, to buy into the really expensive set of API calls. They, they couldn't afford 15 to $20 in verification API calls. That's just not profitable for them. So instead they went with three or four dollars. And you know, and the fraudsters know this, right? And so it, you know, it's not the Wells Fargo's and the bank of America's, although they still do get hit. It's the small local bank, it's the community bank, you know, these kind of situations that are now able to be a main target because it's not linear anymore where the person has to sit there and do one attempt and then they go do another attempt and they go to, they can just deploy a bot network and, and all of a sudden they've made 10,000 attempts that day. And if four of them work, they just made $20,000. Right? It's a completely different.
Nathan George: And you know, we've been talking mainly about loan applications, but also when you think about account takeover or somebody calling to get authorization to disperse funds or something like that, small business lending and you know, where the, your loan amounts are higher, you know, you can fake business owners conversations and things like that,
Justin Keene: even job applicants, right? Like we had one of our friends last week sent us a text while he was interviewing someone for his company. He said, hey, I think I'm on a call with a fake person. And he was texting our CTO Magnus. And Magnus was like, well, send me a video of it. And so he sent him a video. We passed it through our system and sure enough, yeah, the guy was using a face swap technology on this interview, right? So one of the things that I asked it of the CEOs at Lend360, I said, hey, how many people are in your organization that have access to really primary information? So engineers, back end folks, how many of them do you have in your org that you've never met face to face? And a couple hours later, One of the CEOs came up to me, he just said 13. And I was like, that's a random number. And he was like, I have 13 people working for me in my org that I've never met face to face that have access to mission critical information, right? And so like we tend to think of it from the consumer coming in as a mechanism of fraud, but it's expanding to where it's all sides now. It's almost like the, you can't really trust what your eyes see in Your ears hear. And so you have to have some layer of trust that girds up all of these systems because we've built ourselves on the social trust idea as a, you know, set of corporations and if we don't have that, all of it melts.
Nathan George: That makes me think about, you know, we talked a little bit about what the future, you know, future fraud vectors, but also future technology that's going to be making things easier. I live in Georgia and we've got the driver's license on in the Apple, in my Apple wallet. So you know, as I'm looking at that and I'm thinking, man, all the, the cost and infrastructure that goes into trying to do ID verification. Well, now I've got this tokenized identity on my phone that when I'm filling out an application one and I just use the driver's license id, it's verified against the government database. It's real quick. But the interesting thing about that, and I've seen a few articles where they wrote about it, I think one of the fintech takes guys or fintech Weekly, one of those just wrote about this, that all of that digital token, that identity token, it all depends on the facial recognition, just like that on the mobile phone. So how good is that photo capture, that face capture of actually verifying that it's a real person? I'm not sure if you guys have been looking into that piece or not, but it certainly seems to be an up and coming tech that it's where
Justin Keene: we're going as a company long term. Right. Like no one likes passwords, no one likes captcha and so, and no one likes fraud, so we should stop that too. But like long term, what we're really good at is detecting humans. And so if we can detect that you're a human and you're the same human and that you're the human that you say you are, man, that solves a lot of problems for us as a cyber security kind of infrastructure. Yeah, face ID on your phone is, it does work. It does some things. It's not just theater. It's not just twirling the little face thing to be cute, but it's looking again at really macro things. I have friends that have twins. One is a boy and one is a girl and they can both open up each other's iPhones. That doesn't make any sense. It's one thing if they're identical twins, but these are fraternal, you know, and so like it's, it's not as precise as it needs to be. If we're going to have it be the gatekeeper for really sensitive pii. Right. Like, putting your driver's license on there is crazy convenient until it's easily accessible with a picture that somebody holds up to the phone. And, you know, it's like the, you know, the way that people would fake, you know, the, the thumbprints and stuff in spy movies, you know, like it's, it's just more fakeable than you would think.
Nathan George: Well, it's always the movies, you know, they, they shoot the gun and hold the, hold the phone up to their face and are they alive or not? It needs to be a real liveness check as well as a spot check. Interesting.
Justin Keene: Yeah, yeah,
Nathan George: it's interesting. I mean, are there any other kind of potential areas of exposure that you guys are seeing either now or kind of around the corner as AI continues to advance? Any other trends that would be helpful to chat about or keep people keep an eye out on?
Justin Keene: Yeah, there's really two that I think are scary because to go back to the traditional signals idea, they meet every single traditional signal and one of them is kind of just general credential stuffing is easier now than it ever has been because think of all the different times you've gotten an email from somebody that you bought something from online and it's, oops, our system got hacked. Oops, our system got hacked again. If that lines up enough time, suddenly those hackers can now call through all of this data at rapid scale. And now they're able to say, hey, I not only know Justin's name, I know his Social Security number, I know his birth date, I know the last four addresses he's lived at. I know his bank account number, I know his checking routing number, I know who he banks with, I know who his banker is. You know, like, they've got this full profile of you. It's not just that they have your credit card number and they tried to defraud you at a. You know, I had a fraudulent charge attempt the other day at a ski resort in New Hampshire. I've never been to New Hampshire and I haven't been skiing in the last, like, decade. Right. And so, like, thankfully my, you know, Chase caught it and they're like, this doesn't seem real, but like, it's not just that now it's this far more sophisticated where they're, they're literally taking your entire identity and able to do things with it. And because of deepfakes, they can now they have your picture and they have your real id, so they can create a deep fake of you for any kind of video liveness, the traditional video liveness that you think of, where it's, you know, turn your head or whatever, they can fake all of that now. And so if you don't have real liveness built into that, if you don't have some kind of real identity check built into that, it passes all of the flags that we put in traditional onboarding. The second one with that is a particular flavor of it that I think is particularly interesting because if you steal my identity, I'll likely notice it, right? Like I check my credit, I, you know, like those kinds of things. But we've seen this really interesting uptick in Centerlink. Naftali at Centerlink and I have talked about this a few times at different things. We've seen an uptick where people take former international graduate students identities. So these are people that came over to the US to go to grad school. When they're here, they're given an ssn, they have, you know, a bank, they have credit history, they paid rent, they have a real address, they have a real id, all of these things. And then those students graduated and they repatriated back. Right. And so when they left, they didn't close down all of that stuff because
Nathan George: there's no credit file here. They've got all kinds.
Justin Keene: Yeah, there's no real reason for them to. And frankly, as someone that graduated from grad school, you know, a long time ago, but I remember graduating from grad school, I did not have money to deal with it, and I didn't have time to deal with it. All I wanted to do was, you know, like, just go on to my next stage. And I'm sure that they're the same. But what happens is these fraudsters wait a little while and, and then they take these identities that are fully intact. Right. They know everything about this person and they're not around anymore to check on, on FICO or whatever, to see what their score is doing or to see what this fraud is has happened. And they'll take these, these identities and they'll go to a deeper, a subprime lender and they'll take out $5,000 and then they'll pay it back a couple of weeks later. And then the next month they'll take out $7,000 and they'll pay it back a couple weeks later. And they're building up a credit profile for this fake person. They've got all the deepfakes built onto it. They've built, you know, if they were to call a phone. It's a real person answering the phone, all of that. And then eventually they go and they take out, you know, 30 to 40,000 for something and then they bail and then they drop the identity, they ghost it. And so that is a particular flavor of credential stuffing that deepfakes are ripe for. And it's where they're getting used. Not the most, but it's where they're getting used often that it's a problem for our traditional approaches to fraud detection because it passes every check we have.
Nathan George: We, we saw, we saw a similar case with a client where they're. They were doing the same thing they had experienced in fraud from the same thing. But the, instead of it being, you know, people would come over for college or whatever and then. And then left to go back to their home country. This was actually with prisoners who were like, I think it was a prison in Louisiana if I remember right. I can't recall the exact detail, but basically the same type of thing was, was happening because, you know, they're not monitoring their credit from, from prison and death row. You know, typically a loan application, you're not checking their credit, you know, you're not checking their, their criminal history. But. Well, we've got it. We've only got about one minute left. This has been a good call. Every time we talk, it's like more interesting topics come up. I wanted to give everyone online a quick chance to ask quick questions. If you want to pop on over, please do so. Otherwise I'm going to turn on Sarah. If you could, let's turn on our contact information. Any questions that we don't make it to today, you see our email addresses here. Happy to respond to any questions that you might have. If you're interested in hearing more about GDS link or Movera's capabilities and how we might be able to help you with fraud, please reach out and let us know. Love to hear your feedback, your questions or talk about any way we might be able to help with that. Thanks everyone. Great way to start out the year talking about some interesting ways to fight fraud, particularly the harder to reach stuff. So, Justin, thank you very much. Really appreciate the time and enjoyed getting to know you and your team and looking forward to a good year with you.
Justin Keene: Yeah. Hey, thanks for the time and thanks for the opportunity to chat. If anybody has any questions or wants to get a demo or anything like that of what we do over at Moveris, please do reach out. Love to chat with you.
Nathan George: Excellent. There will be also I forgot to mention. There will be a recorded version of this that everybody can watch through again. Or use AI to fake us saying things we didn't say.
Justin Keene: Yeah, there you go.
Nathan George: But Justin will know. But anyway, thank you guys again all. I hope you have a great day and good rest of your week.
Justin Keene: Thanks.
About Moveris
Moveris brings together science, technology, and trust. Their team of researchers and innovators specializes in psychophysiology and human-liveness detection, helping organizations distinguish real human presence from AI-generated signals. They are committed to building solutions that are rigorous, ethical, and frictionless for our clients. Learn more here.
About GDS Link
GDS Link makes modern lending simple. Our real-time decisioning platform integrates over 200 data sources with advanced analytics, enabling lenders to make fast, data-driven credit decisions while mitigating risk. From loan origination to collections, GDS Link provides seamless automation, policy monitoring, and AI-powered insights to help financial institutions optimize lending strategies, stay agile in a competitive market, and drive better outcomes. GDS Link was recognized as the Leading SaaS Decisioning Platform 2025 and Real-Time Policy Monitoring Innovators of the Year 2025. Follow GDS Link on LinkedIn here.