Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Physical biometrics and deepfake fraud: what should anti-fraud teams do?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19563
Topic starter  

TL;DR: Physical biometrics adoption in anti-fraud programs rose from 34% to 45% since 2022, making it the fastest-growing emerging technology tracked in the 2026 ACFE/SAS benchmark, but generative AI is already undermining the assumptions behind liveness checks and camera-based verification, according to Trusona. The real issue is not adoption speed, but whether identity verification controls can withstand synthetic media, injection attacks, and replay-driven impersonation.

NHIMG editorial — based on content published by Trusona: Physical biometrics are surging in anti-fraud programs. That's a problem

By the numbers:

Questions worth separating out

Q: How should security teams use biometrics without overtrusting them?

A: Security teams should treat biometrics as one authentication factor, not as proof of identity.

Q: Why do deepfake attacks change fraud verification risk?

A: Deepfakes change the risk because they attack the assumptions behind liveness detection.

Q: What do organisations get wrong about liveness detection?

A: Organisations often treat liveness detection as proof of identity when it only addresses one part of the problem.

Practitioner guidance

  • Rebuild verification flows around corroborated identity signals Use biometrics as one input alongside document authenticity, device reputation, phone risk, and session integrity checks so a single spoofed signal cannot carry the entire decision.
  • Test controls against injection and replay attacks Validate whether your verification stack can detect synthetic video streams, relayed sessions, and playback attacks, not just static photo spoofing or basic face swaps.
  • Separate low-risk liveness checks from high-risk decisions Allow biometrics to support routine verification, but require stronger assurance paths for account recovery, call center authentication, and money movement events.

What's in the full article

Trusona's full analysis covers the operational detail this post intentionally leaves for the source:

  • The ACFE/SAS benchmarking context behind the 34% to 45% biometrics adoption shift
  • The distinction between synthetic face attacks, voice cloning, and deepfake injection techniques
  • Why Identity Impersonation Detection is positioned as a complement to, not a replacement for, biometrics
  • The article's examples of session replay, man-in-the-middle, and help desk verification failure modes

👉 Read Trusona's analysis of why physical biometrics are rising while deepfake fraud advances →

Physical biometrics and deepfake fraud: what should anti-fraud teams do?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19154
 

Physical biometrics are becoming a governance trap when organisations treat them as proof of identity rather than one fraud signal. The problem is not that biometrics have no value, but that they are being deployed into verification journeys where synthetic media can now satisfy the control. That is a boundary problem, not a feature problem. Fraud teams should treat biometrics as a signal that must be corroborated, not as the decision point.

A question worth separating out:

Q: How can anti-fraud teams improve identity verification governance?

A: Set clear escalation rules for high-risk actions, require audit trails for biometric decisions, and measure false accepts separately from operational convenience. The goal is to know when biometric assurance is sufficient and when a stronger step-up path is needed, especially in recovery and support workflows.

👉 Read our full editorial: Physical biometrics are rising, but deepfake fraud is outpacing them



   
ReplyQuote
Share: