For a decade, remote identity verification followed one recipe. Photograph an ID document, take a selfie, perhaps turn your head, and let a model decide whether the face matches the document and whether the person looks alive.
The recipe scaled because cameras were trusted inputs. Generative video ended that. The question is no longer whether a face looks real, because synthetic faces look real. The question a fraud team now has to answer is where an image came from, and whether anyone could have swapped it on the way.
What changed: injection, not presentation
Older attacks were presentation attacks: a printed photo, a mask or a second screen held up to a real camera. Liveness checks were designed for that. They look for depth, texture, reflections and motion that a flat copy cannot fake well.
Injection attacks skip the camera altogether. A virtual camera driver, an emulator or a modified app feeds a synthetic video stream straight into the verification flow. Nothing is ever held up to a lens, so the artefacts liveness models were trained to spot are simply not there. The stream can be generated live, so it blinks, turns and smiles on request.
This is not a fringe technique. Group-IB reported 8,065 AI deepfake injection attempts against a single financial institution's KYC flow over eight months. That is one institution, and only the attempts that were identified.
Nor is it a distant problem for Israeli businesses. On 21 June 2026, Calcalist reported a deepfake fraud case in Israel with roughly 120 victims.
Why better detection alone does not close the gap
The instinctive response is a better detector. Detection has value as a signal, but as the only gate it has three structural weaknesses.
- It is an arms race on the attacker's terms. Every new detector is a training signal for the next generator, and the attacker only needs one model that passes.
- It is probabilistic. A score needs a threshold, and every threshold trades fraud losses against genuine customers rejected at sign-up.
- It inspects the content, not the channel. A perfectly rendered frame that arrived through a virtual camera looks the same as a real one, because at the pixel level it is the same.
The durable approach is to stop asking whether an image looks authentic, and to require proof that cannot be produced by rendering better pixels.
What still works: verify provenance
Provenance means verifying where and how a piece of evidence was created. In remote identity there are three places to establish it.
The document. Most passports issued today carry an NFC chip holding the holder's data and photo, digitally signed by the issuing state. Verifying that signature against the state's root certificate proves the data was issued by that state and has not been altered. A generator can draw a convincing passport. It cannot produce a valid state signature.
The capture. A mobile app can prove it is a genuine, unmodified build running on real hardware (on iOS, through Apple App Attest). It can also sign every frame it captures together with a single-use nonce issued by the server for that session. A frame injected from a virtual camera, replayed from an earlier session or swapped in transit carries no valid signature, so it does not verify. The check does not depend on how good the fake looks.
The match. With a trusted document and a trusted capture, the face match means something again. The live face is compared with the face the state signed on the chip, not with a photo of a card that could itself have been edited.
Do not ask whether the face looks real. Ask whether the evidence can prove where it came from.
Where attackers go next
Hardening onboarding shifts the pressure rather than ending it. Three patterns follow, and each needs its own answer.
- Account farming. One real person, or one stolen identity, opens many accounts. The answer is an identity that is unique per platform, so a second account for the same person is refused.
- Account takeover. When onboarding is expensive to fake, attackers buy access to accounts that already passed it. Verizon's Data Breach Investigations Report puts credential stuffing at a median of 19% of login attempts. Re-verifying the same person at sensitive moments is how a stolen password stops being enough.
- Harvesting the evidence itself. Every stored selfie and document scan is raw material for the next deepfake. A breach of a verification provider's image store exposes every face in it, and a face cannot be reset like a password.
That last point is often missed. Keeping biometrics to fight deepfakes creates the training data for the next generation of them.
A checklist for your next vendor review
If you are evaluating remote identity verification this year, these questions separate provenance from pixel inspection.
- Does the vendor verify the passport chip's signature to the issuing state's root, and what happens when the issuer is unknown?
- How does the vendor know a selfie came from the device's own camera in this session? Ask specifically about virtual cameras, emulators and replay.
- On which platforms is the capture attested, and what exactly is guaranteed on each?
- What is retained after the check: images, face templates, document scans, chip data? For how long, and where?
- Can two of the vendor's customers link the same person across their user bases?
- Does the decision rest on a score and a threshold, or on a cryptographic check that either verifies or does not?
How JERIX approaches it
JERIX is built on provenance. On passports, it reads the NFC chip and verifies the state's signature to a national root certificate, fully offline, against a trust store of 588 certificates from 112 countries. A chip whose issuer is not in the store is refused. The face is taken from the chip's signed data and matched against the live selfie.
On iOS, every capture is hashed and signed on the device with a single-use nonce and backed by Apple App Attest, so a frame that did not come from the device's own camera session fails. JERIX does not try to judge whether a face looks synthetic. A fake has no valid chip signature and no signed capture, so it does not verify.
After the check, no images or biometrics are retained. Each client receives its own token for a person, so one person cannot open a second account with the same client, and two clients cannot cross-reference their users.
If deepfake onboarding is on your risk register, we would be glad to walk your team through the flow with a real passport.