Deepfake Glitch Exposes Digital Certificate Fraud

Help Net Security · High sophistication
Last updated August 12, 2026

Spanish police arrested a man accused of using a deepfake face overlay and a forged national ID to pass a certificate provider’s live video identity checks. The goal was to obtain digital signatures that could be used for financial fraud, with police reporting 38 attempts affecting more than 30 people.

Key findings

  • Police allege the suspect attempted to defeat live video identity verification to obtain electronic certificates/digital signatures.
  • Investigators say the suspect used a forged national ID card while AI altered his face to match the ID photo during video calls.
  • A brief deepfake “glitch” during a live verification call exposed the suspect’s real face and helped uncover the scheme.
  • Police said the suspect used lighting tricks to mimic ID security features (e.g., holograms) and VPNs to anonymize connections.
  • Investigators linked the activity to extensive telecom usage: 320+ phone lines tied to 24 devices, many registered with stolen identities.

Who’s being targeted

  • Commonly targeted roles: Customer onboarding/KYC, Identity verification agents, Fraud & Risk teams, Compliance, Security awareness (all staff involved in account/certificate approval).
  • Affected industries: Digital identity & trust services (electronic certificate providers), Financial services (downstream fraud risk).
  • Attack channels: website.
  • Impersonated: A real citizen whose identity was stolen (applicant presenting their national ID).

Awareness takeaways

  • Treat live video identity checks as a fraud target: train verifiers to watch for face ‘masking’ artifacts, brief glitches, and unnatural motion around facial edges.
  • Add and enforce step-up verification when ID security features look ‘too perfect’ or are being deliberately staged with lighting tricks (e.g., require additional liveness actions or alternate verification paths).
  • Use fraud analytics to flag repeated verification attempts and suspicious patterns, then investigate quickly when a verification provider sees a ‘string of suspicious requests.’

Red flags to watch for

  • Face appears unnaturally ‘masked’ or briefly glitches during live video
  • Applicant overuses strong lighting/colored bulbs and repeatedly tilts the ID toward the camera to mimic holograms
  • Connection appears anonymized or inconsistent (e.g., VPN indicators), with unusual repeated attempts
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine you’re on a live video call: “Hi, I’m here for my video verification to obtain my electronic certificate.” Looks routine, right? In Spain, police say one man used AI to deepfake his face to match a forged national ID, trying to pass these video checks and grab digital signatures for financial fraud, until his digital mask glitched and his real face flashed on screen. Here’s what to watch for: a face that looks unnaturally masked or briefly glitches at the edges, over-the-top lighting and colored bulbs to make ID holograms look ‘perfect,’ and repeated verification attempts coming from VPN-like, anonymized connections. If you see even a tiny deepfake-style glitch or staged lighting on the ID, don’t approve it, pause the session and trigger your step-up verification path immediately.

MITRE ATT&CK techniques

Similar attacks

Deepfake Face-Swap Busted in Live Video ID Check

Deepfake Face-Swap Busted in Live Video ID Check

Spanish police arrested a suspect accused of using real-time face-swap deepfakes during live video identity checks to obtain fraudulent digital certificates for later misuse. The article describes how the attacker relied on lighting tricks and camera injection to spoof document and biometric…

August 13, 2026
Deepfake Glitch Exposes Digital ID Impostor

Deepfake Glitch Exposes Digital ID Impostor

Spanish police arrested a suspect accused of using deepfake face-swapping and forged documents to pass live video identity checks and obtain digital certificates in other people’s names. Investigators say he attempted impersonation 38 times against a certificate-issuing security company, succeeding…

August 11, 2026
Criminals Use AI Pretexts to Bypass Guardrails

Criminals Use AI Pretexts to Bypass Guardrails

Research from Cisco Talos and CrowdStrike says criminals are building AI into everyday operations, from writing malicious code to scaling fraud infrastructure. The reports describe real prompt logs where attackers use simple “authorized testing” claims to trick AI tools into helping them, plus…

August 6, 2026
Deepfake Video Call Drove $25M Wire Transfer Scam

Deepfake Video Call Drove $25M Wire Transfer Scam

The article discusses Google’s new selfie-video account recovery, but it also highlights a real deepfake-enabled fraud case. In that incident, a finance employee joined a video call showing deepfake versions of coworkers and was persuaded to send multiple wire transfers, illustrating how realistic…

July 23, 2026
Phishing Hits M365; Deepfake Vishing Targets Funds

Phishing Hits M365; Deepfake Vishing Targets Funds

The roundup describes real social-engineering incidents: a phishing email that led an employee to enter credentials on a fake Microsoft 365 login page, and a wave of voice-phishing attempts against major hedge funds using voice-mimicking technology. Both incidents show practical lures that can be…

August 7, 2026
Deepfake OnlyFans Catfish Scam Hits Fans

Deepfake OnlyFans Catfish Scam Hits Fans

Scammers are using AI deepfakes to impersonate real OnlyFans creators on social media and trick fans into paying for “live chats” or exclusive interactions. Victims are funneled from TikTok to private messages (e.g., Snapchat) and then pressured to send money via Cash App, after which the scam…

August 7, 2026