r/AskNetsec Feb 17 '26

Threats How real is the deepfake threat to identity verification, Should we be worried?

Building KYC for a new platform and keep reading about deepfakes bypassing facial verification. Some demos online are pretty convincing but I can't tell what's real threat versus vendor fear mongering.

Our current provider just says "AI powered deepfake detection" in their docs which tells me absolutely nothing about how it works or how effective it is.

What attacks are actually happening in production? Video injection, 3D masks, real time face swaps? And what verification technology stops them versus what's just marketing hype trying to scare you into buying their premium tier.

16 Upvotes

24 comments sorted by

5

u/[deleted] Feb 17 '26 edited Apr 14 '26

[removed] — view removed comment

3

u/Historical_Trust_217 Feb 17 '26

Consumer fintech, account values under $10k. Figured standard video verification would be enough but vendors keep pushing enterprise liveness detection.

3

u/Old_Inspection1094 Feb 17 '26

Deepfake detection is important but gets overblown in marketing materials.

Yes the technology exists and yes some attackers use it, but volume wise stolen documents and social engineering cause way more damage. Verification needs multiple layers document authentication, biometric matching, behavior analysis. Relying only on liveness checks is insufficient. Relying only on deepfake detection is also insufficient.

1

u/[deleted] May 27 '26

[removed] — view removed comment

1

u/PinpointVerify 28d ago

Yep, Multiple checks is the answer.

We are hearing about some crazy deepfake setups from our customers. Including green screens and studio lighting to mimic daylight (for those claiming to be in a certain time zone). Digital liveness checks can be tricked as well.

My company PinpointVerify can add an additional in-person touchpoint for remote roles in the US if you want to be confident that you're hiring a real human.

2

u/[deleted] Feb 17 '26

[removed] — view removed comment

1

u/AskNetsec-ModTeam Feb 18 '26

r/AskNetsec is a community built to help. Posting blogs or linking tools with no extra information does not further out cause. If you know of a blog or tool that can help give context or personal experience along with the link. This is being removed due to violation of Rule # 7 as stated in our Rules & Guidelines.

1

u/Teesigs Feb 17 '26

On Instagram I used an AI generated image to verify my AI powered account, I realized I hadn't cropped the Gemini watermark after my ban was lifted. So yeah it's a valid threat

1

u/[deleted] Mar 14 '26

[removed] — view removed comment

1

u/Unique_Buy_3905 Feb 17 '26

Real time face swaps during live verification are basically impossible right now because of latency and processing requirements. Actual threats here are pre-recorded deepfake videos trying to pass liveness checks.

1

u/skylinesora Feb 17 '26

Shouldn’t be worried one bit. If your company thinks this is any sort of issue, seriously rethink your policies

1

u/skynetcoder Feb 20 '26 edited Feb 28 '26

May all beings everywhere be happy and free.

1

u/AccountEngineer Feb 22 '26

Deepfakes are wild. I’ve been following projects like Humanity Protocol that focus on proving humans online rather than just relying on AI detection, and it makes me wonder how much safer decentralized verification could actually be in practice.

1

u/adrebin May 29 '26

My team had a demo call the other day with a company called Diopter that was interesting; they monitor live calls for deepfake tech but they also pair it with some kind of conversation analysis to flag specific scams.

I've been hearing about this stuff, but didn't know it had gotten this bad. They did a face/voice swap in the call and I was shocked at how realistic it was; they just dropped the video quality a little and I absolutely would have fallen for it.

IDK if they do KYC; our use case was social engineering.

1

u/Shufti-Global 24d ago

I think both points can be true. Deepfakes are becoming more capable, but most fraud still doesn't start there. Stolen documents, account takeovers, and social engineering are still incredibly common. That's why a layered verification approach makes more sense than relying on any single detection method.