Deepfake Face-Swap Busted in Live Video ID Check

Biometric Update · High sophistication
Last updated August 14, 2026

Spanish police arrested a suspect accused of using real-time face-swap deepfakes during live video identity checks to obtain fraudulent digital certificates for later misuse. The article describes how the attacker relied on lighting tricks and camera injection to spoof document and biometric checks, highlighting why organizations need stronger controls during identity “issuance,” not just basic liveness checks.

How the attack worked

A fraudster attempted to pass a live video identity verification process by using a real-time face-swap deepfake, appearing to be someone else in order to obtain a digital certificate or digital signature. The setup reportedly combined a special lighting arrangement designed to mimic the security features found on legitimate identity documents with camera injection, a method of feeding a manipulated video stream into the verification system rather than a live camera feed. The goal was not immediate financial theft but obtaining valid credentials that could be reused later in additional fraud attempts.

Why it nearly succeeded

The attack targeted the issuance stage of identity verification, the point where an organization grants a credential based on a successful check, rather than an ongoing authentication step. This is a high-value target because a single successful pass can produce a durable, reusable credential. The deepfake and camera injection combination was sophisticated enough to imitate both document security features and a live human presence, which is exactly what liveness checks and human reviewers are trained to look for.

What gave it away

The attack was only caught because of a technical glitch, a moment of lag in video processing that briefly exposed the fraudster's real face underneath the deepfake overlay. This points to the fragility of relying on visual inspection alone: without that lag, the attempt could plausibly have gone undetected. Reviewers should be trained to treat any of the following as reasons to pause and escalate:

  • Brief lag or glitches in a video feed that seem inconsistent with a normal camera stream
  • Lighting or reflections that look unnaturally perfect or mismatched with the stated environment
  • Any indication of a virtual camera or injected video source rather than a genuine physical camera

Building resistance

The core lesson is that liveness checks and human review, while useful, are not sufficient on their own against real-time deepfake tools. Organizations handling remote identity verification, certificate issuance, or SIM registration should:

  • Treat live video identification as a high-risk workflow requiring specific reviewer training on visual artifacts and video anomalies
  • Add injection attack detection (IAD) at the technical layer to catch manipulated video streams before they reach human reviewers
  • Build continuous adaptive trust into identity and authorization systems, so a credential's legitimacy is reassessed over time rather than assumed permanently valid after issuance
  • Recognize that a successfully issued certificate or signature can be reused later in unrelated fraud, making issuance-stage controls a priority alongside downstream monitoring

Awareness training vendors, including KnowBe4, are part of the broader industry response helping organizations prepare staff for these evolving identity fraud techniques.

Key findings

  • A suspect allegedly used real-time face-swap deepfakes during live video identity verification to obtain digital certificates/digital signatures for later fraud.
  • Spanish police allege the suspect posed as many different people and made repeated attempts to obtain false certificates.
  • The method described included a special lighting setup to mimic security features on real identity documents and “camera injection.”
  • Interpol reporting cited rapid growth in AI-enabled fraud, including synthetic identities and deepfakes used to bypass biometric checks.
  • The article argues defenses must include stronger issuance controls (e.g., injection attack detection and cryptographic protections), not only liveness checks.

Who’s being targeted

  • Commonly targeted roles: Customer onboarding / KYC, Fraud operations, Compliance, Identity & access management (IAM), Contact center / video verification agents.
  • Affected industries: Digital identity verification / certificate issuance, Financial services (banks), Telecommunications (SIM registration), Government / law enforcement.
  • Attack channels: website.
  • Impersonated: A legitimate applicant (identity holder) using a deepfake face-swap to appear as someone else.

Red flags to watch for

  • Video feed shows brief lag/glitches inconsistent with a normal camera stream
  • Lighting or reflections appear unnaturally “perfect” or inconsistent with the environment
  • Signs of camera injection/virtual camera use rather than a physical camera
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How was the deepfake face-swap detected during identity verification?

A moment of lag in video processing exposed the fraudster's real face, revealing that a real-time face-swap deepfake was being used during the live video identification process.

What was the attacker trying to obtain?

The individual was attempting to obtain digital signatures and certificates through fraudulent live video identity checks, intending to use them in future fraud attacks.

Are liveness checks enough to stop this kind of attack?

No. The article argues organizations need stronger defenses at issuance, including injection attack detection, rather than relying on human review or biometric liveness checks alone.

What technique was used to fool the video check?

The attacker reportedly used a special lighting setup to mimic security features on legitimate identity documents, combined with camera injection to insert the fake video feed.

Read the video transcript

Imagine doing a live video ID check, and for half a second, the applicant’s real face pops through the deepfake. Spanish police say someone used real-time face-swap deepfakes in these calls to pose as many different people and grab digital certificates for later fraud, using special lighting on IDs and even camera injection to fake the video feed. Here’s the tell: the video feed lags or briefly glitches, lighting on the face or ID looks too perfect for the room, or the app shows signs it’s using a virtual camera instead of a physical one. If anything feels off during remote ID issuance, don’t just pass the liveness check, pause the session and escalate for a secondary review before approving any digital certificate.

MITRE ATT&CK techniques

Similar attacks

Deepfake CFO Video Call Triggers $25M Fraud

Deepfake CFO Video Call Triggers $25M Fraud

The article describes real-world deepfake and identity-fraud incidents where attackers used believable human impersonation to manipulate employees. In one case, a staff member at Arup joined a video call with what appeared to be the CFO and was tricked into sending about $25M across multiple wire…

August 21, 2026
Deepfake Glitch Exposes Digital Certificate Fraud

Deepfake Glitch Exposes Digital Certificate Fraud

Spanish police arrested a man accused of using a deepfake face overlay and a forged national ID to pass a certificate provider’s live video identity checks. The goal was to obtain digital signatures that could be used for financial fraud, with police reporting 38 attempts affecting more than 30…

August 12, 2026
One-Click Copilot Link Triggers Data Exfil

One-Click Copilot Link Triggers Data Exfil

Researchers showed how an attacker could trick Microsoft Copilot into running a malicious prompt automatically just by getting a user to click a specially crafted link. The prompt can then make Copilot search connected accounts (like email and cloud storage) and send information to an external…

August 18, 2026
Deepfake OnlyFans Catfish Scam Hits Fans

Deepfake OnlyFans Catfish Scam Hits Fans

Scammers are using AI deepfakes to impersonate real OnlyFans creators on social media and trick fans into paying for “live chats” or exclusive interactions. Victims are funneled from TikTok to private messages (e.g., Snapchat) and then pressured to send money via Cash App, after which the scam…

August 7, 2026
Poisoned PRs Let One AI Agent Control Another

Poisoned PRs Let One AI Agent Control Another

Researchers found a real-world workflow flaw in Google’s Agent Development Kit (Python) repo where a low-privilege AI triage bot could be manipulated with prompt injection to trigger a higher-privilege maintainer agent. The attack uses “poisoned” pull requests to create a believable review/approval…

August 3, 2026
Fake CAPTCHA Tricks Users Into Running TerminalFix

Fake CAPTCHA Tricks Users Into Running TerminalFix

Attackers used a fake Cloudflare “verify you are human” overlay to copy a command to victims’ clipboards and trick them into pasting it into Windows Terminal/PowerShell. The command kicked off a multi-stage infection chain, including downloading payloads hidden inside PNG images, establishing…

August 31, 2026