TL;DR: Synthetic impersonation is shifting breaches toward login and verification abuse as Gartner found 62% of organisations experienced a deepfake attack in the past year, while iProov says it surpassed one million daily transactions in 2025; legacy identity controls are now being tested at the point of human authenticity, not at the network edge.
At a glance
What this is: This is iProov's analysis of how deepfakes and synthetic impersonation are shifting identity verification from a supporting control to a frontline security boundary.
Why it matters: It matters because IAM, workforce identity, and customer identity programmes now have to treat verification as a live trust decision, not a one-time onboarding check.
Context
Identity verification now sits in the security path where attackers can impersonate a person, not just intercept a session or exploit a system. In this article, iProov argues that deepfakes and synthetic media have moved the attack surface to the point where organisations must decide whether the human on screen is real before granting trust.
That shift matters for identity governance because the control problem is no longer limited to credential strength, MFA, or network perimeter controls. When synthetic impersonation can be generated at scale, verification becomes a resilience issue for customer identity, workforce identity, and any workflow that relies on a human being authenticated remotely.
The article also shows that the market is now reacting to this change rather than debating it in theory. The relevant question for practitioners is how to design identity controls that can withstand AI-generated deception without turning every interaction into a manual review.
Key questions
Q: What breaks when video verification is trusted without deepfake detection?
A: Without deepfake detection, video verification can become a false sense of assurance rather than a control. Fraudsters may use synthetic faces or voices to pass live interviews, leading to account takeover, fraudulent onboarding, or payment abuse. The control fails when organisations rely on appearance alone and do not validate the session with technical signals that can detect manipulation in real time.
Q: Why do synthetic impersonation attacks matter more for high-risk transactions than routine login?
A: Because the business impact is concentrated where a false identity can move money, reset access, or change ownership. Routine login is disruptive, but recovery and approval flows create much larger blast radius. Teams should prioritise the steps where one successful impersonation produces lasting account or financial damage.
Q: How can security teams tell whether identity verification is failing against AI-generated media?
A: The signs usually appear as mismatched capture behaviour, repeated challenge failures, unusual device or session patterns, and verified users whose actions do not fit prior context. Teams should also watch for attack paths that bypass normal user friction while still passing the formal verification step. That is often where the control boundary is weakest.
Q: Should organisations use the same verification standard for workforce access and customer identity?
A: No. The control objective is related, but the risk tolerance is different. Workforce access often depends on operational continuity, while customer identity covers onboarding, recovery, and regulated transactions. Organisations should set assurance levels by use case, not force one verification threshold across all identity journeys.
Technical breakdown
Why deepfakes break human identity assurance
Deepfakes undermine the assumption that a remote interaction can be trusted if the user presents the right factors at the right time. Traditional identity controls often verify possession of a device or knowledge of a secret, but synthetic media attacks target the human authenticity layer itself. In practice, that means a fraudster can satisfy an authentication flow while impersonating the real user with convincing video, audio, or image artefacts. The result is not a broken password policy. It is a broken trust model in which identity verification is asked to prove something the older control stack was never built to assess.
Practical implication: treat remote identity proofing and authentication as separate controls and test both against synthetic media.
Why liveness checks and legacy verification controls are not enough
Liveness checks were designed to distinguish a live present person from a static artifact, but that boundary is now easier to manipulate with modern generative tooling and OS-level injection techniques. Once attackers can feed altered video streams or face swaps into the verification path, the control no longer validates human presence with enough assurance for high-risk transactions. The real issue is not simply spoofing a camera. It is the collapse of confidence in the evidence source itself. That forces teams to think about how identity evidence is captured, tested, and continuously challenged rather than assuming a single biometric step settles the matter.
Practical implication: validate the integrity of the capture pipeline, not just the biometric matching step.
How AI-driven fraud shifts identity controls from edge protection to trust assurance
AI-driven impersonation changes the control objective from blocking unauthorised access at the perimeter to proving that the person initiating the interaction is genuinely present. That is why high-assurance verification is becoming central to customer onboarding, account recovery, workforce access, and regulated transactions. The article also points to a broader governance shift: identity resilience now has to be measured against adversarial media generation, not only against credential theft. The relevant architecture is one that can absorb deception, not merely one that can authenticate a session. This is where human identity governance starts to converge with anti-fraud and assurance controls.
Practical implication: align verification strength to transaction risk and raise assurance for recovery, onboarding, and high-value approval flows.
Breaches seen in the wild
- Arup deepfake fraud 2024: Deepfakes of Arup's CFO and colleagues on a video call led a Hong Kong employee to transfer HK$200 million (about US$25.6m) to fraudsters.
- Schneider Electric Jira breach 2024: Credentials linked to a Lumma infostealer infection gave Hellcat access to Schneider Electric's Jira; 40GB and 400,000 user rows claimed.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Deepfake defence is now an identity governance requirement, not an edge case fraud control. The article shows that identity verification has become the point where synthetic impersonation meets access decisioning. Once attackers can present convincing human likeness at scale, traditional identity programmes are no longer just checking who has a credential. They are deciding whether the subject behind the interaction is authentic enough to trust, which makes verification a core governance control for workforce and customer identity alike.
Human authenticity is the new assurance boundary. The most important shift here is not the rise of deepfakes on its own, but the fact that the trust decision has moved from network access to the person presenting themselves. That creates a named concept worth tracking: synthetic identity trust collapse. It means organisations can no longer assume that verified presentation equals verified person, and practitioners should treat that distinction as a first-class control problem.
Legacy identity stacks still overestimate the assurance value of single-step verification. Passwords, MFA, and basic liveness checks were built for a world where impersonation was costly and low scale. The article shows that generative AI has changed that economics, so the assurance gap now sits between successful login and actual human presence. The implication is that identity architecture has to move toward stronger evidence chains, not just more friction.
Workforce and customer identity are converging under the same deception risk. The article explicitly ties deepfakes to enterprise security, employee impersonation, and account takeover. That matters because many organisations still govern workforce IAM, fraud controls, and customer verification as separate programmes. Synthetic impersonation cuts across all three, so governance models that keep them isolated will miss the shared adversary behaviour.
Independent validation matters because the market is becoming crowded with unsupported claims. iProov's emphasis on external testing reflects a wider truth for the field: assurance controls lose value when the evaluation method is not as rigorous as the attack method. For practitioners, the real decision is whether the verification control has been tested against adversarial media generation and capture-path manipulation, not whether it markets itself as biometric.
From our research library:
- Gartner predicts that by 2026, 30% of enterprises will consider identity verification solutions unreliable in isolation because of AI-driven attacks.
What this signals
Synthetic impersonation is pushing identity programmes toward continuous assurance rather than one-time proofing. For practitioners, the practical takeaway is that remote verification now needs to be treated as a security boundary with explicit risk tiers, not a convenience feature attached to onboarding.
Synthetic identity trust collapse: once attackers can convincingly imitate a human at scale, the programme can no longer assume that a verified presentation equals a verified person. That is forcing identity teams to re-evaluate how much trust they place in biometrics, challenge flows, and remote recovery paths.
The strongest programmes will stop treating fraud and IAM as separate disciplines. Identity verification, account recovery, and transaction approval are becoming one control surface, and governance has to reflect that convergence.
For practitioners
- Separate onboarding, authentication, and recovery assurance levels Assign different verification strength to account creation, routine login, account recovery, and payment or approval events. High-risk steps should require stronger human authenticity evidence than standard access, because the attack surface changes by transaction type.
- Test the capture path for synthetic media injection Review whether camera feeds, browser sessions, mobile capture flows, and video streams can be altered before biometric evaluation. Verification controls fail when the evidence source is compromised, even if the match engine itself works correctly.
- Raise assurance for remote high-value transactions Require stronger identity evidence when the transaction can move money, alter credentials, or change account ownership. The risk is not everyday sign-in. It is the small number of actions where impersonation creates disproportionate loss.
- Reclassify deepfakes as an identity control threat Bring fraud, IAM, IAM operations, and security architecture teams into the same governance discussion so deepfake risk is managed as an identity assurance problem rather than a standalone fraud issue.
Key takeaways
- Deepfakes are turning identity verification into a live trust decision, especially when remote users can be convincingly impersonated at scale.
- The main exposure is no longer simple login abuse alone, but the ability to pass verification and then exploit recovery or approval flows.
- Practitioners need stronger assurance tiers, capture-path testing, and tighter governance over high-risk identity actions.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63, NIST CSF 2.0 and OWASP ASVS set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | SP 800-63A — Enrollment and Identity Proofing | The article focuses on proving that a human is genuine during remote verification and recovery. |
| SP 800-63B — Authentication | Deepfake-enabled impersonation directly affects how authentication evidence should be trusted. | |
| Recommendation — Strengthen identity proofing for high-risk journeys and align assurance depth to transaction sensitivity. Raise authentication assurance where synthetic media could satisfy the current login flow. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | Identity verification determines whether the right subject gets authorised at the point of access. |
| PR.DS-10 — Integrity | The article highlights capture-path and media integrity as prerequisites for trustworthy verification. | |
| Recommendation — Tie verification strength to authorisation risk so high-impact actions require stronger assurance. Test the integrity of the video and biometric evidence pipeline before trusting the result. | ||
| OWASP ASVS | V6 — Authentication | The article is about authentication controls that must resist deepfake and impersonation abuse. |
| Recommendation — Assess authentication flows for impersonation resistance and challenge strength under adversarial media. | ||
Key terms
- Deepfake: Synthetic or altered media created with AI or machine learning so that a person appears to say or do something they never did. In security terms, deepfakes are trust attacks that can distort identity verification, approval workflows, and fraud detection.
- Human Authenticity Assurance: Human authenticity assurance is the set of controls used to determine whether a remote subject is a real, present person rather than a synthetic or manipulated representation. It goes beyond basic authentication by testing the integrity of the person, the capture path, and the evidence used for trust decisions.
- Identity proofing: The process of verifying that a person is who they claim to be before granting or restoring access. In higher-risk recovery paths, proofing can include stronger evidence checks such as government ID validation or liveness-based facial verification so the assurance level matches the sensitivity of the request.
- Synthetic impersonation: The use of generated voice, video, text, or profile content to appear like a real person or trusted organisation. In practice, it weakens the reliability of familiar identity cues and forces teams to rely more on independent validation than on appearance alone.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org