Spanish police arrested a suspect accused of using real-time face-swap deepfakes during live video identity checks to obtain fraudulent digital certificates for later misuse. The article describes how the attacker relied on lighting tricks and camera injection to spoof document and biometric checks, highlighting why organizations need stronger controls during identity “issuance,” not just basic liveness checks.
How the attack worked
A fraudster attempted to pass a live video identity verification process by using a real-time face-swap deepfake, appearing to be someone else in order to obtain a digital certificate or digital signature. The setup reportedly combined a special lighting arrangement designed to mimic the security features found on legitimate identity documents with camera injection, a method of feeding a manipulated video stream into the verification system rather than a live camera feed. The goal was not immediate financial theft but obtaining valid credentials that could be reused later in additional fraud attempts.
Why it nearly succeeded
The attack targeted the issuance stage of identity verification, the point where an organization grants a credential based on a successful check, rather than an ongoing authentication step. This is a high-value target because a single successful pass can produce a durable, reusable credential. The deepfake and camera injection combination was sophisticated enough to imitate both document security features and a live human presence, which is exactly what liveness checks and human reviewers are trained to look for.
What gave it away
The attack was only caught because of a technical glitch, a moment of lag in video processing that briefly exposed the fraudster's real face underneath the deepfake overlay. This points to the fragility of relying on visual inspection alone: without that lag, the attempt could plausibly have gone undetected. Reviewers should be trained to treat any of the following as reasons to pause and escalate:
- Brief lag or glitches in a video feed that seem inconsistent with a normal camera stream
- Lighting or reflections that look unnaturally perfect or mismatched with the stated environment
- Any indication of a virtual camera or injected video source rather than a genuine physical camera
Building resistance
The core lesson is that liveness checks and human review, while useful, are not sufficient on their own against real-time deepfake tools. Organizations handling remote identity verification, certificate issuance, or SIM registration should:
- Treat live video identification as a high-risk workflow requiring specific reviewer training on visual artifacts and video anomalies
- Add injection attack detection (IAD) at the technical layer to catch manipulated video streams before they reach human reviewers
- Build continuous adaptive trust into identity and authorization systems, so a credential's legitimacy is reassessed over time rather than assumed permanently valid after issuance
- Recognize that a successfully issued certificate or signature can be reused later in unrelated fraud, making issuance-stage controls a priority alongside downstream monitoring
Awareness training vendors, including KnowBe4, are part of the broader industry response helping organizations prepare staff for these evolving identity fraud techniques.
Key findings
- A suspect allegedly used real-time face-swap deepfakes during live video identity verification to obtain digital certificates/digital signatures for later fraud.
- Spanish police allege the suspect posed as many different people and made repeated attempts to obtain false certificates.
- The method described included a special lighting setup to mimic security features on real identity documents and “camera injection.”
- Interpol reporting cited rapid growth in AI-enabled fraud, including synthetic identities and deepfakes used to bypass biometric checks.
- The article argues defenses must include stronger issuance controls (e.g., injection attack detection and cryptographic protections), not only liveness checks.
Who’s being targeted
- Commonly targeted roles: Customer onboarding / KYC, Fraud operations, Compliance, Identity & access management (IAM), Contact center / video verification agents.
- Affected industries: Digital identity verification / certificate issuance, Financial services (banks), Telecommunications (SIM registration), Government / law enforcement.
- Attack channels: website.
- Impersonated: A legitimate applicant (identity holder) using a deepfake face-swap to appear as someone else.
Red flags to watch for
- Video feed shows brief lag/glitches inconsistent with a normal camera stream
- Lighting or reflections appear unnaturally “perfect” or inconsistent with the environment
- Signs of camera injection/virtual camera use rather than a physical camera
Frequently asked questions
How was the deepfake face-swap detected during identity verification?
A moment of lag in video processing exposed the fraudster's real face, revealing that a real-time face-swap deepfake was being used during the live video identification process.
What was the attacker trying to obtain?
The individual was attempting to obtain digital signatures and certificates through fraudulent live video identity checks, intending to use them in future fraud attacks.
Are liveness checks enough to stop this kind of attack?
No. The article argues organizations need stronger defenses at issuance, including injection attack detection, rather than relying on human review or biometric liveness checks alone.
What technique was used to fool the video check?
The attacker reportedly used a special lighting setup to mimic security features on legitimate identity documents, combined with camera injection to insert the fake video feed.
Read the video transcript
Imagine doing a live video ID check, and for half a second, the applicant’s real face pops through the deepfake. Spanish police say someone used real-time face-swap deepfakes in these calls to pose as many different people and grab digital certificates for later fraud, using special lighting on IDs and even camera injection to fake the video feed. Here’s the tell: the video feed lags or briefly glitches, lighting on the face or ID looks too perfect for the room, or the app shows signs it’s using a virtual camera instead of a physical one. If anything feels off during remote ID issuance, don’t just pass the liveness check, pause the session and escalate for a secondary review before approving any digital certificate.