Spanish police arrested a man accused of using a deepfake face overlay and a forged national ID to pass a certificate provider’s live video identity checks. The goal was to obtain digital signatures that could be used for financial fraud, with police reporting 38 attempts affecting more than 30 people.
Key findings
- Police allege the suspect attempted to defeat live video identity verification to obtain electronic certificates/digital signatures.
- Investigators say the suspect used a forged national ID card while AI altered his face to match the ID photo during video calls.
- A brief deepfake “glitch” during a live verification call exposed the suspect’s real face and helped uncover the scheme.
- Police said the suspect used lighting tricks to mimic ID security features (e.g., holograms) and VPNs to anonymize connections.
- Investigators linked the activity to extensive telecom usage: 320+ phone lines tied to 24 devices, many registered with stolen identities.
Who’s being targeted
- Commonly targeted roles: Customer onboarding/KYC, Identity verification agents, Fraud & Risk teams, Compliance, Security awareness (all staff involved in account/certificate approval).
- Affected industries: Digital identity & trust services (electronic certificate providers), Financial services (downstream fraud risk).
- Attack channels: website.
- Impersonated: A real citizen whose identity was stolen (applicant presenting their national ID).
Awareness takeaways
- Treat live video identity checks as a fraud target: train verifiers to watch for face ‘masking’ artifacts, brief glitches, and unnatural motion around facial edges.
- Add and enforce step-up verification when ID security features look ‘too perfect’ or are being deliberately staged with lighting tricks (e.g., require additional liveness actions or alternate verification paths).
- Use fraud analytics to flag repeated verification attempts and suspicious patterns, then investigate quickly when a verification provider sees a ‘string of suspicious requests.’
Red flags to watch for
- Face appears unnaturally ‘masked’ or briefly glitches during live video
- Applicant overuses strong lighting/colored bulbs and repeatedly tilts the ID toward the camera to mimic holograms
- Connection appears anonymized or inconsistent (e.g., VPN indicators), with unusual repeated attempts
Read the video transcript
Imagine you’re on a live video call: “Hi, I’m here for my video verification to obtain my electronic certificate.” Looks routine, right? In Spain, police say one man used AI to deepfake his face to match a forged national ID, trying to pass these video checks and grab digital signatures for financial fraud, until his digital mask glitched and his real face flashed on screen. Here’s what to watch for: a face that looks unnaturally masked or briefly glitches at the edges, over-the-top lighting and colored bulbs to make ID holograms look ‘perfect,’ and repeated verification attempts coming from VPN-like, anonymized connections. If you see even a tiny deepfake-style glitch or staged lighting on the ID, don’t approve it, pause the session and trigger your step-up verification path immediately.