Spanish police arrested a suspect accused of using deepfake face-swapping and forged documents to pass live video identity checks and obtain digital certificates in other people’s names. Investigators say he attempted impersonation 38 times against a certificate-issuing security company, succeeding on multiple occasions until a brief deepfake processing delay exposed his real face on camera.
Key findings
- Spain’s national police say a suspect made "38 attempts to impersonate 30 people" to obtain digital certificates in victims’ names, with certificates issued on "multiple" occasions.
- The suspect allegedly targeted "a security company authorized to issue digital certificates" and bypassed identity checks with "forged documents, altered photographs, deepfake tools, and a carefully arranged lighting rig."
- The verification process required a "live video check comparing the applicant's face with the photograph on the identity document," which the suspect attempted to defeat using real-time face alteration.
- Police say the suspect used lighting tricks to mimic document holograms: "household spotlights with strategically placed colored bulbs" to simulate security features.
- The operation was uncovered when the face-swap tool briefly failed: the disguise dropped for "barely a second," exposing the suspect’s real face to the camera.
- Investigators say the suspect also used "VPNs to anonymize his connections" and allegedly used "more than 320 phone lines across 24 devices," many registered under stolen identities.
Who’s being targeted
- Commonly targeted roles: Identity verification (KYC) teams, Fraud operations, Compliance / risk, Customer onboarding teams, Helpdesk teams supporting digital identity issuance.
- Affected industries: Digital identity verification / certificate issuing, Government online services (downstream misuse risk), Financial services (downstream misuse risk via legally-binding e-signatures).
- Attack channels: website.
- Impersonated: A real person whose identity document is being used (stolen identity), A legitimate ID document holder (stolen identity).
Awareness takeaways
- Treat live video identity checks as a high-risk target: train verifiers to look for deepfake ‘tells’ (brief glitches, timing delays, unnatural facial motion) and to stop/retry verification when anomalies appear.
- Don’t rely on webcam ‘hologram demos’ alone, require additional verification steps when applicants use unusual lighting or carefully staged document movements.
- Flag repeated attempts across multiple identities as fraud signals and strengthen monitoring for patterns of abuse (e.g., many attempts, many identities).
- Assume fraudsters may hide behind anonymization and large numbers of phone lines/devices; build processes to detect and investigate these patterns.
Red flags to watch for
- Video/face appearance inconsistencies (brief glitches, unnatural movement, mismatch with ID photo)
- Applicant uses unusual lighting/positioning of ID to "recreate" holograms rather than simply showing the document normally
- Multiple attempts for different identities and/or anonymized connections (e.g., VPN use) during verification
- Overly choreographed document handling (precise tilting/angles) and non-standard lighting setup visible in reflections
- Security features appear “too perfect” or behave oddly under light during webcam inspection
- Signs of document manipulation or “apparent security features” rather than verifiable ones
Read the video transcript
You’re on a video ID check, and for barely a second, the person’s face… changes. Spanish police say one guy tried this 38 times, deepfaking his face in real time to pass live video checks and grab digital certificates in other people’s names. He used forged IDs, deepfake tools, and even household spotlights with colored bulbs to fake holograms on camera. The only giveaway? A tiny processing delay where the disguise dropped for a blink. If you see a face or ID glitch, or weird lighting tricks, hit pause. Stop the session and restart verification through your official process, do not approve on a maybe.