What Makes ID Checks Fail

Some failures turn away real people. The expensive ones return a clean pass on a transaction that should never have completed.
Proof
October 5, 2026
What Makes ID Checks Fail

Two applicants reached the final round in a live demo during our recent webinar on candidate fraud, and both looked strong on paper. Both cleared a background check, and both cleared passive screening on the email and phone number they submitted. One of them, Kevin, was not who he said he was.

"Kevin isn't using a fake identity. He's using a real one," explained Eric Nelson, Senior Solutions Consultant at Proof. "A real person's harvested identity from LinkedIn, with a real history behind it. Passive signals won't trip because the data is real, but the person using it is not."

Nothing in that flow malfunctioned. The same arrangement clears a mortgage closing, a bank onboarding flow or a payout request, because it defeats the assumption underneath all of them, that a fraudulent person cannot present a genuine identity as their own.

Checks fail in two directions, and only one gets counted. A false rejection turns away a real person and shows up as drop-off, so every team watches it. A false acceptance reads green, and the only way to learn about it is a loss that arrives months later. 

Attackers work the half nobody measures. Group-IB researchers, reported by Biometric Update, documented 8,065 biometric injection attempts against one bank's onboarding flow between January and August 2025, roughly thirty-three a day.

Key takeaways

  • A harvested real identity defeats document authentication, face match and liveness at once, and no better model helps, because there is no artifact to detect.
  • Real document data in the wrong hands returns a clean response from the issuer, which says nothing about who holds the card.
  • A check that runs once says nothing about who finished the transaction.
  • Legitimate people fail for ordinary physical reasons, and a retry path recovers them without loosening the bar.

Why a genuine document clears the wrong person

Researchers at Silent Push found a job ad in a Discord server, ostensibly recruiting computer mouse reviewers. Turn on your camera during interviews, represent the skills confidently, and keep 35% of the salary. On Telegram the recruiter offered more: "I can remotely access your screen and complete coding tasks while you continue the conversation smoothly." 

Silent Push attributes the operation with high confidence to a North Korean IT worker recruiting Western and Latin American citizens as the 'face' and legal identity to bypass sanctions, KYC (identity verification) controls, and regional hiring restrictions.

Our research into face rentals traces what that does to a verification stack. The person on camera is real, the ID is theirs, and their face matches it because it is their face. Every check built to catch a fake returns a clean pass, and every one of those results is correct. The fraud sits behind the person holding the document, where a better model finds nothing. The countermeasures published alongside that alert still advise employers to watch for documents that appear forged or altered, which a genuine ID never does.

When the data is real and the holder is not

The same mechanic drives property fraud. Principal Product Manager at Proof Kurt Ernst walked through a case in a recent webinar on deepfake detection: a vacant lot worth $75,000 with an out-of-state owner. The fraudster pulled the owner's driver's license details from public sources and presented a card carrying genuine information. The DMV check came back clean, credential analysis passed, and the attacker joined the online closing running face-swap software.

A background check has the same blind spot. "It'll check data to make sure it's consistent," Nelson said of the applicant case. "Fraudsters can purchase that data, but it won't tell you that the person in front of you is the person they claim to be."

The check that stops watching

Most platforms analyze the document and the selfie at the start of a session and then go quiet. "Where it falls down is when you're doing the live session, doing an online notarization, an online closing," Ernst said. "There's not that injection attack detection there."

A legitimate person can clear verification and hand the session to someone else, or the feed can be swapped afterward. The log records a pass, accurately, for a moment that had ended by the time the money moved.

Why real people get turned away

The other half is quieter and far more common. Verification fails for physical reasons, and Our help desk webinar earlier this year named the everyday culprits: bad lighting, and a barcode that will not scan. A stack that accepts only a driver's license turns away people holding perfectly good evidence.

Loosening the bar trades a conversion problem for a fraud problem. A retry path avoids the trade: a second capture, an alternative document, or a trained reviewer who can tell a bad photograph from a bad actor.

What actually closes the gap

Count both failures first. Most teams know their drop-off rate to a decimal place and have no number for clean passes that turned out to be fraud.

Then match the evidence to the stakes: passive signals on everyone entering the flow, a document check at a defined stage, and a supervised session where certainty matters most. Proof Identify and Proof Defend evaluate 400+ fraud risk signals in real time during an identity check, and Proof Verify puts a trained human in the sessions where a clean pass is not enough.

See how Proof adds session evidence to the questions a document cannot answer >

graphic of envelop on a square

Subscribe to our newsletter

Related Articles