Deepfake Glitch Exposes Digital ID Impostor

The Register Security · High sophistication
Last updated August 11, 2026

Spanish police arrested a suspect accused of using deepfake face-swapping and forged documents to pass live video identity checks and obtain digital certificates in other people’s names. Investigators say he attempted impersonation 38 times against a certificate-issuing security company, succeeding on multiple occasions until a brief deepfake processing delay exposed his real face on camera.

Key findings

  • Spain’s national police say a suspect made "38 attempts to impersonate 30 people" to obtain digital certificates in victims’ names, with certificates issued on "multiple" occasions.
  • The suspect allegedly targeted "a security company authorized to issue digital certificates" and bypassed identity checks with "forged documents, altered photographs, deepfake tools, and a carefully arranged lighting rig."
  • The verification process required a "live video check comparing the applicant's face with the photograph on the identity document," which the suspect attempted to defeat using real-time face alteration.
  • Police say the suspect used lighting tricks to mimic document holograms: "household spotlights with strategically placed colored bulbs" to simulate security features.
  • The operation was uncovered when the face-swap tool briefly failed: the disguise dropped for "barely a second," exposing the suspect’s real face to the camera.
  • Investigators say the suspect also used "VPNs to anonymize his connections" and allegedly used "more than 320 phone lines across 24 devices," many registered under stolen identities.

Who’s being targeted

  • Commonly targeted roles: Identity verification (KYC) teams, Fraud operations, Compliance / risk, Customer onboarding teams, Helpdesk teams supporting digital identity issuance.
  • Affected industries: Digital identity verification / certificate issuing, Government online services (downstream misuse risk), Financial services (downstream misuse risk via legally-binding e-signatures).
  • Attack channels: website.
  • Impersonated: A real person whose identity document is being used (stolen identity), A legitimate ID document holder (stolen identity).

Awareness takeaways

  • Treat live video identity checks as a high-risk target: train verifiers to look for deepfake ‘tells’ (brief glitches, timing delays, unnatural facial motion) and to stop/retry verification when anomalies appear.
  • Don’t rely on webcam ‘hologram demos’ alone, require additional verification steps when applicants use unusual lighting or carefully staged document movements.
  • Flag repeated attempts across multiple identities as fraud signals and strengthen monitoring for patterns of abuse (e.g., many attempts, many identities).
  • Assume fraudsters may hide behind anonymization and large numbers of phone lines/devices; build processes to detect and investigate these patterns.

Red flags to watch for

  • Video/face appearance inconsistencies (brief glitches, unnatural movement, mismatch with ID photo)
  • Applicant uses unusual lighting/positioning of ID to "recreate" holograms rather than simply showing the document normally
  • Multiple attempts for different identities and/or anonymized connections (e.g., VPN use) during verification
  • Overly choreographed document handling (precise tilting/angles) and non-standard lighting setup visible in reflections
  • Security features appear “too perfect” or behave oddly under light during webcam inspection
  • Signs of document manipulation or “apparent security features” rather than verifiable ones
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You’re on a video ID check, and for barely a second, the person’s face… changes. Spanish police say one guy tried this 38 times, deepfaking his face in real time to pass live video checks and grab digital certificates in other people’s names. He used forged IDs, deepfake tools, and even household spotlights with colored bulbs to fake holograms on camera. The only giveaway? A tiny processing delay where the disguise dropped for a blink. If you see a face or ID glitch, or weird lighting tricks, hit pause. Stop the session and restart verification through your official process, do not approve on a maybe.

MITRE ATT&CK techniques

Similar attacks

Criminals Use AI Pretexts to Bypass Guardrails

Criminals Use AI Pretexts to Bypass Guardrails

Research from Cisco Talos and CrowdStrike says criminals are building AI into everyday operations, from writing malicious code to scaling fraud infrastructure. The reports describe real prompt logs where attackers use simple “authorized testing” claims to trick AI tools into helping them, plus…

August 6, 2026
Phishing Hits M365; Deepfake Vishing Targets Funds

Phishing Hits M365; Deepfake Vishing Targets Funds

The roundup describes real social-engineering incidents: a phishing email that led an employee to enter credentials on a fake Microsoft 365 login page, and a wave of voice-phishing attempts against major hedge funds using voice-mimicking technology. Both incidents show practical lures that can be…

August 7, 2026
Deepfake Job Interviews and Vishing Hit Enterprises

Deepfake Job Interviews and Vishing Hit Enterprises

CrowdStrike warns that attackers are using AI to make social engineering faster and more convincing, including AI-generated resumes and deepfake job interviews to infiltrate companies. The report also describes vishing campaigns that quickly pivot from stealing accounts to stealing data from SaaS…

August 3, 2026
AI Chatbots Outperform Humans in Romance Scams

AI Chatbots Outperform Humans in Romance Scams

Researchers simulated “pig butchering” romance-style scams and found an AI chatbot built trust more effectively than a human scammer over a week of texting. In the test, victims were significantly more likely to comply with the AI’s request to install an app, showing how AI could automate the long…

July 30, 2026
Fake Zoom/Teams Calls Used to Steal Crypto Wallets

Fake Zoom/Teams Calls Used to Steal Crypto Wallets

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims into “updating” Zoom/Teams and running malicious commands. The phishing kit also fingerprints the victim’s browser to identify installed…

July 24, 2026
Deepfake FBI Videos Push Victims to Fake IC3 Sites

Deepfake FBI Videos Push Victims to Fake IC3 Sites

The FBI warned that scammers are impersonating IC3 leadership using AI-generated (deepfake) videos and spoofed IC3 websites to trick prior fraud victims into sharing more personal and financial information. In one example, victims are contacted on Facebook Messenger by someone posing as an FBI…

July 21, 2026