The Attack That Breaks the Identity Check You Just Deployed


A lot of hiring teams have spent the past year adding liveness detection to their identity verification process. A candidate who reaches the shortlist now has to blink, turn their head, or respond to a randomized prompt on camera rather than just submitting a photo. It is a real improvement. A pre-recorded video or a photo held up to a lens cannot respond to an unpredictable prompt in real time.
What it cannot stop is a biometric injection attack: an attack that routes synthetic video directly into the verification system without ever using a real camera.
Key takeaways
- Biometric injection attacks bypass liveness detection by routing synthetic video through virtual cameras directly into IDV systems, so the check never sees a real camera feed.
- Hiring pipelines are increasingly targeted because the fraud window is long and a more sophisticated attack has a higher payoff than consumer fraud.
- Automated liveness detection raises the floor but cannot account for attacks that defeat the camera feed assumption entirely.
How biometric injection attacks work
A liveness check is built on one assumption: that the video feed it receives comes from a real camera with a real person in front of it. Biometric injection attacks defeat that assumption before the check even runs.
Instead of holding a mask or a static photo up to a camera, a bad actor uses software to route a synthetic or pre-recorded video stream directly into the IDV system, making it appear as a legitimate camera input. The liveness check receives what looks like a live, responsive feed and, in many implementations, passes it. The attack does not require a sophisticated deepfake that can respond in real time to unpredictable prompts. Instead, it requires routing the right video through the right technical pathway, and the tooling to do this has become significantly more accessible.
Why hiring pipelines are increasingly targeted by injection attacks
IDV systems used in consumer finance, including bank account opening and benefits verification, have been hardening against injection attacks for longer than hiring-specific tools have. Regulatory scrutiny and fraud losses drove that investment earlier in financial services. Many hiring IDV tools are still catching up.
That lag matters because the stakes in hiring fraud are different. A fraudulent bank account has a short window before it is flagged and closed. A fraudulent hire has months of access to internal systems, customer data, and sometimes sensitive infrastructure before anyone realizes the identity was fabricated. For a bad actor who has already built a synthetic identity convincing enough to pass a background check, defeating an automated liveness check is often the last obstacle between them and a job offer.
It is worth the effort.
How layered identity verification defends against biometric injection attacks
Automated biometric checks do real work. They filter out unsophisticated fraud, create a documented verification record, and raise the baseline for what a fraudulent candidate has to accomplish. The problem arises when they are treated as the final answer rather than one part of a larger process.
What closes the gap is a combination of a triggered verification step and a silent intelligence layer that runs underneath it.
When a candidate reaches the shortlist, Proof Identify triggers an active verification: the candidate submits their government ID and a selfie, which are checked against each other and run through credential integrity checks. A Proof agent steps in if automated checks don't resolve. The result is a Proof identity report that travels through every subsequent stage.
Proof Defend runs silently throughout. While a candidate is completing an Identify verification, Defend is analyzing 150+ behavioral risk signals in the background: email age, device signals, location risk, identity database checks, and more. When a candidate is on camera, Defend's deepfake detection analyzes the video feed for face swaps and AI impersonations. The candidate doesn't see any of it.
That last capability is what makes injection attacks specifically tractable. Liveness detection is built on the assumption that the video feed comes from a real camera. Injection attacks defeat that assumption at the source. Defend's deepfake detection analyzes what is actually in the feed, so a synthetic video stream routed through a virtual camera to pass a liveness check is still generating the signals Defend is built to catch.
The result is a documented record of what ran at each stage, what was flagged, and what action was taken: the kind of audit trail that holds up when a decision needs to be defended.
The practical implication for hiring teams is this: knowing that a vendor passed a liveness certification at some point is not the same as knowing that their system accounts for attacks that defeat the camera feed assumption.
The attacks are evolving, and the teams best protected are the ones whose identity verification process does not rely on automated checks alone.







.jpg)




































































.jpg)




























































