Join our Newsletter — 33% off our NHI Course

Deepfakes and identity verification: are legacy controls keeping up?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: Synthetic impersonation is shifting breaches toward login and verification abuse as Gartner found 62% of organisations experienced a deepfake attack in the past year, while iProov says it surpassed one million daily transactions in 2025; legacy identity controls are now being tested at the point of human authenticity, not at the network edge.

Editorial analysis by NHI Mgmt Group, based on content published by iProov: “iProov Scales to Over 1 Million Daily Transactions as Deepfakes Redefine the Enterprise Attack Surface”.

Key questions

Q: What breaks when video verification is trusted without deepfake detection?

A: Without deepfake detection, video verification can become a false sense of assurance rather than a control.

Q: Why do synthetic impersonation attacks matter more for high-risk transactions than routine login?

A: Because the business impact is concentrated where a false identity can move money, reset access, or change ownership.

Q: How can security teams tell whether identity verification is failing against AI-generated media?

A: The signs usually appear as mismatched capture behaviour, repeated challenge failures, unusual device or session patterns, and verified users whose actions do not fit prior context.

Practitioner guidance

  • Separate onboarding, authentication, and recovery assurance levels Assign different verification strength to account creation, routine login, account recovery, and payment or approval events.
  • Test the capture path for synthetic media injection Review whether camera feeds, browser sessions, mobile capture flows, and video streams can be altered before biometric evaluation.
  • Raise assurance for remote high-value transactions Require stronger identity evidence when the transaction can move money, alter credentials, or change account ownership.

Bottom line: Deepfakes are turning identity verification into a live trust decision, especially when remote users can be convincingly impersonated at scale.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 1 day ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Deepfake resilience is now an identity assurance requirement, not a fraud specialist add-on. When synthetic media can imitate a person convincingly enough to satisfy weak verification, human IAM inherits a new failure mode: authenticity can no longer be inferred from appearance alone. The practical implication is that identity programmes must evaluate proofing strength as a security control, not just a user experience feature.

A few things that frame the scale:

  • 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage, according to Ultimate Guide to NHIs.
  • 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures.

A question worth separating out:

Q: Who is accountable when a deepfake bypasses identity controls?

A: Accountability usually sits with the team that owns identity assurance, fraud controls, and recovery design together, because the failure spans multiple governance boundaries. If the programme allowed weak proofing, weak liveness, or weak recovery paths, the control owner must treat that as an identity governance gap, not an isolated incident.

👉 Read our full editorial: Identity verification must now absorb deepfakes and synthetic impersonation



   
ReplyQuote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Deepfake defence is now an identity governance requirement, not an edge case fraud control. The article shows that identity verification has become the point where synthetic impersonation meets access decisioning. Once attackers can present convincing human likeness at scale, traditional identity programmes are no longer just checking who has a credential. They are deciding whether the subject behind the interaction is authentic enough to trust, which makes verification a core governance control for workforce and customer identity alike.

A few things that frame the scale:

A question worth separating out:

Q: Should organisations use the same verification standard for workforce access and customer identity?

A: No. The control objective is related, but the risk tolerance is different. Workforce access often depends on operational continuity, while customer identity covers onboarding, recovery, and regulated transactions. Organisations should set assurance levels by use case, not force one verification threshold across all identity journeys.

👉 Read our full editorial: Identity verification must now absorb deepfakes and synthetic impersonation


This post was modified 1 day ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.