Not long ago, deepfakes were a novelty. Videos were passed around social media and between friends for their shock value alone. Today, these once “harmless” video tactics are being used as a tool for fraud. A highly effective one.
Fraudsters are using face morphs, synthetic AI-generated faces, altered facial attributes, fake identity documents, and video injection attacks to bypass traditional identity verification checks and pose as legitimate customers. Fraud rings are working together, creating a whole industry out of defrauding companies and individuals.
Liminal recently found that sophisticated attacks combining deepfakes, injection techniques, and physical manipulation now account for 23.3% of classified attacks, with an average loss of $280,000 per deepfake incident.
What makes the deepfake threat even harder to catch is the range of tools behind it. From low-effort consumer apps to fraud rings running dedicated infrastructure, companies are left scratching their heads.
Basic identity checks weren’t designed for this. So, what can you do? This infographic breaks down how deepfake fraud works, the tools attackers use, and how advanced liveness detection can stop it. Check it out below and read the full guide at jumio.com/deepfake-detection-guide.
[Text Version]
ESSENTIAL GUIDE
Advanced Deepfake Detection
What it is, why it matters and essential strategies to protect against sophisticated identity fraud tactics.
The Emerging Deepfake Threat
- 23.3% – Sophisticated attacks combining deepfakes, injection, and physical manipulation now account for 23.3% of classified attack
- $280,000 – average loss per deepfake incident
Source: Liminal Identity Fraud Intelligence: Trends & Insights, 2026
Deepfake Tactics Used to Trick KYC
- .Face morphs: Merging two or more faces
- Synthetic faces: Fake faces created with generative AI
- Face manipulations: Altering attributes of skin and/or facial features\
- Synthetic identity documents: AI tools are used to create fake ID documents
- Video injection: Bypassing physical cameras with fake or manipulated media
Tools Used to Create Deepfakes
- High-end, custom-built solutions: Fraudsters combine separate tools to generate or alter a face, clone a voice, synchronize lip movement, and refine the final video.
- Dedicated Infrastructure: Used for industrialized identity deception, where AI-generated faces, voices, documents, and behavioral signals are combined into coordinated fraud campaigns.
- Low-end consumer tools: Web-based face-swap tools, avatar generators, and video filters that require little technical skill can produce synthetic profile videos, altered selfies, or short clips that appear realistic.
What is Video Injection?
Video injection is a digital injection attack where fake data, such as AI-generated documents, photos, biometric images or pre-recorded video, is introduced into the data stream of an identity verification platform.
How Injection Attacks Impact Identity Verification
- Bypasses facial recognition, basic liveness and ID checks by mimicking a legitimate user
- Tricks less sophisticated systems that fail to distinguish between genuine and injected video
- Impersonates legitimate users to open accounts, pass onboarding checks, or authorize financial transactions
- Erodes trust, leading to customer dissatisfaction, fraud losses, and regulatory exposure
The Antidote: Liveness Detection
What is Liveness Detection?
Liveness detection is used by identity verification solution providers to ensure that the biometric sample being presented is from a live person rather than a static image, video, mask, manipulated selfie or injected stream.
How to Detect a Deepfake
1. Active liveness detection
User is prompted to perform a specific action, such as blinking, nodding, smiling or turning their head.
2. Passive and semi-passive liveness detection
Passive detection analyzes subtle characteristics of live biometrics without asking the user to perform a specific action. Semi-passive detection uses visual cues, camera behavior, or other signals to detect depth, motion, and physical presence.
3. Motion analysis
Motion analysis assesses the subject’s movements to determine whether it’s a live person, looking for natural motion and behavioral patterns.
How Jumio Can Help
- AI-driven technology
- ISO/IEC 30107-3 compliant
- Conforms to NIST/NVLAP testing standards
- Detects sophisticated fraud
Covering Industry Standard Checks
- ID image used as selfie
- Paper printouts
- Digital copy
- Face masks
And Going Beyond the Standard
Image Quality Checks
- Face not fully visible
- Multiple people
- No face present
- Black and white image
Deepfake Detection
- Synthetic images
- Face/head swaps
Injection and Replay Detection
- Fraudster
- Video injection attack
- Victim
Additional Fraud Checks
- Detects sleeping users & fake selfies
- Flags inactive & tampered images
Want to know more about deepfake fraud and how to stop it?
Read the Full Guide: jumio.com/deepfake-detection-guide
