Verihubs Logo
Home Blog Biometric Spoofing: How Fraudsters Fool Face Checks
11 min read • Face Recognition • Published on October 4, 2026

Biometric Spoofing: How Fraudsters Fool Face Checks

Biometric Spoofing: How Fraudsters Fool Face Checks

Biometric spoofing is any attempt to pass a face check with a fake instead of the real person. In eKYC, fraudsters use five main methods: printed photos, screen replays, 3D masks, morphed ID photos and injected video streams. Face matching alone accepts most of them, so each method needs its own detection layer.

Why Biometric Spoofing Works Against Face Matching

Face matching answers one question: do these two faces belong to the same person? First, it turns each face into a numeric template, and then it compares the templates. A good matcher is built to ignore lighting, angle, glasses and age, because real users vary on all of them.

Unfortunately, that tolerance is exactly what a spoof exploits. A clear photo of the victim produces almost the same template as the victim. So the matcher says “same person”, and it is right. The question it never asks is whether that person is actually present.

This is why face verification needs a partner check. Liveness detection asks whether the face belongs to a live human at the camera. Deepfake detection asks whether the face was generated or altered. Device checks ask whether the camera itself is real. Each method below defeats a different subset of those checks.

Five Biometric Spoofing Methods Seen in eKYC Onboarding

The methods range from a free print to a custom silicone build. In general, cost matters, because fraud rings pick the cheapest attack that still works against your flow.

1. Printed Photo Attack

The attacker prints a photo of the victim and holds it up to the camera. Also, photos are easy to find on social media, in leaked KYC files or on stolen ID scans. Some attackers cut out the eyes or mouth and place their own face behind the paper, so a “blink” prompt still passes.

2. Screen Replay Attack

Here, the attacker plays a video of the victim on a second phone or tablet. A replay adds natural motion, so it also beats checks that only look for movement. However, screens leave traces: moiré patterns, glare, bezels and a flat focus plane.

3. 3D Mask Attack

Masks range from paper cut-outs to resin and silicone builds, so quality varies widely. For example, a good mask has depth, so it defeats checks that only test for a flat surface. Still, masks cost more and take longer to make. Because of that cost, they tend to target high-value accounts rather than mass signups.

4. Morphed ID Photo

A morph blends two faces into one portrait. Then the attacker puts that portrait on a forged or fraudulently issued ID. Both the attacker and an accomplice can then match the document, because the morph sits between their faces. In other words, morphs target the ID side of the check, not the selfie. NIST treats the threat seriously enough to run a dedicated benchmark for it, called FATE MORPH.

5. Injected Video Stream

This time, the attacker skips the camera. Instead, software such as a virtual webcam driver or a tampered app pushes a prerecorded clip or a live deepfake straight into the verification flow. Because no physical object sits in front of a lens, checks built for prints and masks often have nothing to catch. Injection is now the method that most worries liveness vendors, since it scales cheaply.

Biometric Spoofing Beyond the Face: Fingerprint, Voice and Iris

Fingerprint, voice and iris spoofing - a latex fingerprint, a cloned voice waveform and a printed eye with a contact lens

Face checks get most of the attention in eKYC, but every biometric has its own spoofing playbook. The pattern repeats each time: capture a sample, rebuild it as an artefact or a file, then present or inject it.

ModalityTypical spoofMain defence
FingerprintLatent prints lifted from glass and rebuilt in latex, wood glue or siliconeSensor-level liveness, for example sweat pores, blood flow or multispectral imaging
VoiceReplayed recordings and AI voice clones built from short audio clipsSynthetic speech detection, plus a second factor for payments
IrisA high-resolution photo of the eye, sometimes with a contact lens for curvatureNear-infrared imaging and pupil response checks
FacePrints, replays, masks, morphs and injected deepfakesLiveness, deepfake detection and device integrity checks

Documented Biometric Spoofing Cases

  • Fingerprint, 2013. According to the Chaos Computer Club, its researchers beat Apple’s Touch ID shortly after launch with a fingerprint photographed from a glass surface and rebuilt as a latex copy.
  • Iris, 2017. According to the same group, a printed photo of the owner’s eye, topped with a contact lens, unlocked a Samsung Galaxy S8 iris scanner.
  • Voice, 2019. According to The Wall Street Journal, fraudsters used an AI clone of a chief executive’s voice to get a UK energy firm to wire about EUR 220,000.
  • Face, 2023. Hong Kong police broke up a ring that ran face swap software against online loan checks, the first such case the city had detected.

In fact, the lesson carries straight into eKYC. Each of these attacks beat a system that matched correctly. What failed was the check that a living person supplied the sample, in real time, through a trusted sensor.

Why Biometric Spoofing Is Harder to Recover From Than a Password Leak

A leaked password can be changed in a minute. A leaked face, however, cannot. Once a customer’s selfie or ID photo sits in a breach file, it stays usable for spoofing for years.

That, in turn, changes the design goal. Since you cannot keep faces secret, the system has to prove presence instead of secrecy, every time it relies on a face. So liveness is not only an onboarding control. It belongs at login, at device change and before high-value transfers too.

Detection Layers Mapped to Each Spoofing Method

Biometric spoofing defences mapped to each attack - liveness, deepfake detection, morph checks and device integrity

Still, no single model covers all five methods. The table maps each one to the layer that typically stops it, and to what face matching does on its own.

Spoof methodFace matching aloneLayer that stops itWhat the layer looks for
Printed photoUsually acceptsPassive or active livenessPaper texture, flat depth, edges, missing micro-movement
Screen replayUsually acceptsPassive or active livenessMoiré, glare, bezels, refresh artefacts, timing of response to prompts
3D maskOften acceptsLiveness with depth and texture analysisSkin texture, eye and mouth edges, rigid expression
Morphed ID photoAccepts by designDocument checks and morph detection on the ID portraitBlending artefacts, mismatch with authoritative records
Injected streamAcceptsDevice and SDK integrity, plus deepfake detectionVirtual cameras, emulators, hooking tools, generation artefacts

In short, two things stand out. First, liveness covers the three physical methods but not the last two. Second, morphs and injection need checks outside the selfie model, on the document and on the device. A stack that only buys “liveness” has therefore covered roughly the cheap half of the threat.

Active and passive approaches also behave differently here. Active checks ask the user to turn or blink, which hurts replays. Passive checks analyse one capture without prompts, which keeps drop-off low. Most teams now combine them, as our guide to the types of liveness detection explains.

Review Signals for Fraud Analysts Handling Spoofing Cases

Models flag the case, but analysts still make the final call on borderline ones. These are the signals worth training a review team on:

  • Edges and borders. Paper edges, a phone bezel or a hand holding a frame near the face.
  • Light that does not behave. Glare in a flat rectangle, or a face lit differently from the room behind it.
  • Too-perfect stillness. A face that never shifts while the background moves, which points to a mask or a still image.
  • Same face, many accounts. One face appearing behind several names usually means a farm, not a coincidence.
  • ID portrait oddities. A portrait that looks softer than the rest of the card, or that resembles two different selfies.
  • Device context. Emulator flags, a rooted phone or a virtual camera name in the session metadata.

However, the last two signals rarely show up in the selfie itself. So give analysts the device and document context in the same screen. Otherwise they judge an injected deepfake on image quality alone, and a good deepfake looks clean.

Biometric Anti-Spoofing Checklist for eKYC Teams

Use this list to audit a face verification flow against all five methods:

  1. Liveness at every face check. Run it at onboarding, login, device change and step-up, not just once.
  2. Deepfake detection on the same capture. Liveness alone does not judge whether a face was generated.
  3. Device and app integrity. Block or flag emulators, rooted phones, hooking tools and virtual cameras.
  4. ID portrait checks. Look for morph and generation artefacts on the document photo, and match against authoritative records where you can.
  5. Face deduplication. Search new faces against existing accounts to expose one face behind many names.
  6. Protected templates. Encrypt stored face templates and limit who can access raw images.
  7. Regular spoof testing. Rerun print, replay, mask and injection tests after every model or SDK update.

Finally, synthetic faces deserve their own note. A face swap or AI-generated selfie can pass liveness because it moves and responds like a person. Catching it is the job of a separate model, deepfake detection.

How Verihubs Layers Spoofing Defences in One Flow

Verihubs splits the problem the same way the table does. Its liveness detection runs active and passive checks that handle the three physical methods. For the attacks that skip the lens, the VeriSecure SDK runs device checks for emulators, root access, Frida hooking and injection or MITM tampering. It then runs deepfake detection on the same capture and returns one approve or reject decision.

For masks in particular, depth and texture cues carry most of the weight. Our explainer on 3D facial liveness detection covers how those cues work.

Frequently Asked Questions About Biometric Spoofing

What is biometric spoofing?

Biometric spoofing is an attempt to fool a biometric system with a fake, such as a photo, video, mask or injected deepfake, instead of the real person. In face verification, the goal is usually to open or take over an account in someone else’s name.

Can face recognition be fooled by a photo?

Face matching on its own can be, because a clear photo produces nearly the same template as the real face. That is why face checks used for onboarding or login need liveness detection alongside the match.

What is the difference between face spoofing and a deepfake?

Face spoofing usually means a physical fake shown to the lens, for example a print, a screen or a mask. A deepfake is synthetic or altered video, often fed into the app without a camera. Liveness detection targets the first, while deepfake detection and device checks target the second.

How do you detect a face morphing attack?

First, check the ID portrait, not just the selfie. Morph detection models look for blending artefacts in the document photo. Matching the portrait against an authoritative record also helps, because the record will not contain the morph.

Does liveness detection stop all spoofing?

No. Liveness detection stops most physical spoofs at the camera. However, morphed ID photos and injected streams need document checks, device integrity checks and deepfake detection as separate layers.

Can fingerprints be spoofed?

Yes. Researchers have repeatedly lifted latent prints from glass and rebuilt them in latex or silicone. Sensors with liveness checks, such as sweat pore or blood flow detection, make that much harder.

Biometric Spoofing Is a Portfolio of Attacks, Not One Threat

It is tempting to treat biometric spoofing as a single problem with a single fix. In practice, it is five problems with different costs, different scale and different blind spots. Prints and replays are cheap and common. Masks, by contrast, are rare but targeted. Morphs live on the document, and injection lives on the device.

So the useful question for a fraud team is not “do we have liveness?” It is “which of the five methods would get through our flow today, and who would see it?” Map your current controls against the table above, and the gaps usually show up within an hour.

Want to test your onboarding flow against all five methods? Book a spoofing assessment and see how VeriSecure handles each one.

Client Verihubs
Find out how accurate Verihubs Face Recognition
Get FREE Trial
View Blog