Can AI Deepfakes Bypass Identity Verification?


A working face-swap attack takes fifteen minutes to set up on a laptop and costs thirty cents a minute.
"I'm not running a supercomputer. I'm running it on my MacBook Pro, so you don't need any special hardware," said Kurt Ernst, a principal product manager at Proof, who built one and ran it live during a recent webinar on deepfake detection. "Very little technical skill, so you can spin this up very easily."
Against a transaction worth six figures, that is not a constraint. Group-IB's Weaponized AI research, covered by Biometric Update, documented 8,065 biometric injection attempts against the onboarding flow of one financial institution between January and August 2025, roughly thirty-three a day.
Deloitte projects US generative AI fraud losses reaching $40 billion by 2027, up from $12.3 billion in 2023. And as Ernst pointed out: "I actually think that estimate is low. I think this is growing faster now than anybody thinks."
Key takeaways
- Injection attacks control what the camera sends rather than deceiving the camera, which most liveness checks were never built to catch.
- Face-swap software runs on consumer hardware for around thirty cents a minute.
- A clean check at the start of a session says nothing about who completed the transaction a minute later.
- Wire fraud insurance does not respond to seller impersonation, so that loss stays with you.
How an injection attack differs from a fake
Liveness detection asks whether the content arriving looks like a real, present human. Injection attacks leave that question alone and change what arrives, feeding synthetic media into the stream through virtual camera software or manipulation at the API layer.
The mechanics are mundane. A real person sits in front of a real camera while face-swap software alters the outgoing stream, and a virtual camera feeds it back in, so the system analyzes a manufactured image and concludes, correctly on its own terms, that it is real.
What an attack looks like against a real transaction
In the webinar, we walked through a real case involving a vacant lot valued at $75,000 with an out-of-state owner. Vacant land attracts this because nobody lives on it, so a sale can complete long before the owner checks the tax records.
The fraudster found the lot through public records, then obtained the owner's driver's license information, readily available online. The data on the card was genuine, so a DMV check returned clean and credential analysis passed. The attacker joined the closing running face-swap software, and the deed was signed and recorded. Each check did what it was built to do, and the sale went through anyway.
Most platforms stop watching after the check
Standard vendor behavior is to analyze the ID photo, the document and the selfie, then stop. "Where it falls down is when you're doing the live session, doing an online notarization, an online closing," Ernst said during the session. "There's not that injection attack detection there."
A legitimate signer can clear verification and hand the session to someone else, or the feed can be swapped for a synthetic one after the check completes. Either way the audit trail records a verification that was genuinely clean when it ran, and the transaction that mattered happened in a window nobody was watching. That is why the question to put to a vendor is blunt. "Do you do deepfake detection live in session? You'll hear, yeah, we do deepfake detection, but a lot of times it's not the live session."
The tells appear only when someone forces them
Current face-swap software still leaves artifacts. Glasses vanish as someone puts them on, and a hand passing across the face dissolves into it. Those artifacts surface only under deliberate prompting. "If you have the signer on the line and you're looking at it, you wouldn't be clued off to a deepfake at all, because it looks pretty good until you force them to do specific things."
A notary on a routine call has no reason to ask, so something has to tell them to look. Ernst borrowed a colleague's framing: the Swiss cheese approach, where every layer has holes and the stack catches what the slices miss. Defend runs video analysis, hardware checks and conventional risk signals against a model trained on a million hours of video.
The insurance gap worth raising with your risk team
"There are products out there that give wire fraud insurance, and you'll hear, we protect it," Ernst said. "That does not cover this type of seller impersonation, because that's just if the wire gets sent to the wrong location. It does not kick in if it's a synthetic identity where it's a stolen ID."
A policy written to cover misdirected funds will not pay out here, because the funds went exactly where the transaction said they should. The person behind the transaction was the fabrication.
Today's attacks still need a person in front of a camera, which caps the volume, and we that to lift: "Full AI agents where there's no human. It's a virtual human, and it looks like a real human. What's scary about that is now it can scale. Your systems can get attacked by thousands of bots an hour."
Thankfully, you’re not forced to detect deepfakes on your own. See how Proof runs deepfake detection throughout the live session >


















































.jpg)





























































.jpg)


















