Back to the listing

Identity fraud and deepfakes: Why identity verification is evolving

Deepfakes are increasingly being used in attempts to bypass remote identity verification systems. In response, companies are rethinking their strategies: verifying someone’s identity once is no longer always enough.

What is a deepfake?

Deepfakes are AI-generated or AI-manipulated content designed to realistically imitate a person’s face or voice. When used for fraudulent purposes, they can be used in attempts to bypass certain identity verification systems.

Identity fraud is becoming increasingly sophisticated

For a long time, identity verification systems primarily focused on detecting:

  • fake documents
  • printed photos
  • replayed videos
  • simple identity impersonation attempts

Biometric technologies and liveness detection have significantly strengthened the security of identity verification processes.

But the methods used by fraudsters are evolving rapidly.

AI-generated deepfakes are becoming more accessible, more realistic and easier to produce.

When deepfakes rely on real identities

Contrary to what one might expect, fraudsters are no longer only trying to create fake identities.

In many cases, they exploit real identities obtained through data breaches, compromised accounts or stolen identity documents. This information can include genuine documents, phone numbers, email addresses and other personal data that can make the fraud appear more credible.

Deepfakes can then be used to imitate the appearance of the legitimate identity holder during the identity verification process.

If this initial verification is successful, the fraudster may then be able to access certain services or use an account without immediately having to undergo another biometric check.

How deepfakes are used in identity fraud

Identity verification systems generally involve several stages:

  1. Data capture
  2. Biometric and document analysis
  3. Identity validation

Fraudsters look for potential weaknesses within this process.

Today, there are two main types of attacks.

Presentation attacks

In this scenario, the fraudster simply presents manipulated content to the camera, such as a photo, video or deepfake displayed in real time.

Modern liveness detection solutions are relatively effective at detecting this type of attack by identifying abnormal behaviour or visual inconsistencies.

Injection attacks

Injection attacks are much more sophisticated.

Here, the fraudster is no longer trying to deceive the camera directly. Instead, they attempt to manipulate or inject data into the stream transmitted to the identity verification system.

Rather than presenting a face in front of the camera, the fraudster intercepts or replaces the video feed sent to the verification system. The system then receives artificial content that it believes is coming directly from the camera.

Current limitations of deepfakes

Deepfakes still have certain limitations, including:

  • inconsistencies in movement
  • lighting issues
  • visual artefacts
  • difficulty reproducing certain facial details in real time

Active checks, such as asking someone to smile, turn their head or blink, can still detect many fraud attempts.

As AI models continue to evolve rapidly, companies are looking to complement liveness detection with additional verification mechanisms to strengthen the security of their identity verification processes.

Towards multi-layered identity verification

The objective is no longer simply to verify someone’s identity once, but to be able to reconfirm it in sensitive situations or at key stages of a process.

Rather than relying on a single verification mechanism, companies are combining several layers of verification. This approach helps reduce the risk of fraud even if one of the controls is bypassed.

This can include:

  • document verification
  • biometric verification with liveness detection
  • additional checks when sensitive actions are performed
  • reconfirming identity directly on site

By combining multiple layers of verification, companies can strengthen the reliability of their identity checks while maintaining a record of the controls performed.

Reconfirming identity on site

One person may complete the onboarding process and administrative checks, while another person subsequently arrives at the work site.

In this context, on-site identity verification makes it possible to confirm that the person who is physically present matches the identity verified during onboarding.

The verification can also be time-limited to ensure that the check corresponds to a real, recent and contextualised presence.

Securing the entire identity journey

As deepfakes and fraud techniques continue to evolve, companies need to approach identity verification as a comprehensive and evolving process.

Biometric technologies remain essential, but they need to be integrated into a broader approach that combines multiple layers of verification.

The challenge is no longer simply to verify an identity once.

It is to be able to confirm, at key stages of the journey, that the person present is indeed the person whose identity was initially verified.

Frequently asked questions

Can deepfakes bypass identity verification?

Deepfakes can be used in attempts to bypass certain remote identity verification systems. However, modern solutions combine multiple security mechanisms, such as document verification, biometrics, liveness detection and additional checks, to detect fraud attempts. As impersonation techniques evolve, many companies are also strengthening their controls by reconfirming identity at different stages of the process.

How can companies protect against deepfakes during identity verification?

There is no single solution for protecting against deepfakes. The most effective approach is to combine multiple layers of verification, including document verification, biometrics with liveness detection, risk signal analysis and, where relevant, identity reconfirmation during sensitive actions or directly on site. This multi-layered approach helps reduce the risk of fraud and strengthen the reliability of identity verification processes.

Looking to strengthen your identity verification processes?

Discover how CheckHub helps secure identity journeys through document verification, biometrics and on-site identity verification.

➡️ Request a demo.