Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Deepfakes and account takeover: are your identity checks ready?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Deepfakes now enable employee impersonation, account takeover, synthetic identity fraud, and real-time injection attacks that can defeat human judgment and some biometric checks, according to Yoti. The practical issue is not whether the media looks fake, but whether identity verification, MFA, and liveness controls can still establish trust under live fraud conditions.

NHIMG editorial — based on content published by Yoti: deepfakes, identity verification, and the business threat they create

Questions worth separating out

Q: How should security teams handle deepfake risk in identity workflows?

A: Security teams should treat deepfakes as a trust and verification problem inside identity workflows.

Q: Why do deepfakes create more risk than ordinary identity fraud?

A: Deepfakes compress the time needed to impersonate a real person and make the attack look legitimate at the exact moment trust is granted.

Q: What do organisations get wrong about biometric authentication and deepfakes?

A: They often assume a biometric match proves that a live human is present.

Practitioner guidance

  • Harden remote proofing workflows Require stronger verification for onboarding, account recovery, and payment approvals where synthetic media can influence the decision.
  • Add liveness and capture-path integrity checks Use liveness detection and injection attack detection together, because biometric matching alone does not stop a synthetic feed from entering the system.
  • Separate human judgement from final trust decisions Do not let employees rely on visual confidence, voice familiarity, or conversational fluency as the deciding factor in high-risk approvals.

What's in the full article

Yoti's full article covers the operational detail this post intentionally leaves for the source:

  • How Yoti positions liveness detection against deepfake-driven impersonation attempts in remote verification.
  • The practical differences between face match, biometric authentication, and capture-path protection.
  • Examples of injection attack detection across desktop and mobile verification flows.
  • Where Yoti suggests organisations should place identity checks in onboarding and recovery journeys.

👉 Read Yoti's analysis of deepfakes, identity verification, and business fraud risk →

Deepfakes and account takeover: are your identity checks ready?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Visual trust is no longer a defensible identity control. Deepfakes collapse the assumption that humans can reliably distinguish authentic people from synthetic media during a live interaction. That assumption was always fragile, but diffusion models and real-time generation have made it operationally unsafe. The implication is that identity programmes must stop treating human perception as a control and treat it as an advisory signal only.

A few things that frame the scale:

  • The average estimated time to remediate a leaked secret is 27 days, despite 75% of organisations expressing strong confidence in their secrets management capabilities, according to The State of Secrets in AppSec.
  • Only 44% of developers are reported to follow security best practices for secrets management, exposing a significant behaviour gap, according to The State of Secrets in AppSec.

A question worth separating out:

Q: Who is accountable when a deepfake bypasses identity controls?

A: Accountability usually sits with the team that owns identity assurance, fraud controls, and recovery design together, because the failure spans multiple governance boundaries. If the programme allowed weak proofing, weak liveness, or weak recovery paths, the control owner must treat that as an identity governance gap, not an isolated incident.

👉 Read our full editorial: Deepfakes are testing identity controls beyond visual trust



   
ReplyQuote
Share: