Without those controls, a fraudster can present a printed deepfake, replay a synthetic image on another device, or inject previously generated media through a virtual camera. If the system only checks that an image was provided, rather than whether it came from a live capture, the attacker may pass as a legitimate user and bypass onboarding or account recovery controls.
Why the control gap matters
When capture integrity is missing, the verification step is no longer testing whether the person is physically present, only whether some image-like content can satisfy the checker. That weakens onboarding and recovery flows because attackers can reuse pre-made media, synthetic faces, or replayed captures to impersonate a real applicant without needing the live subject in front of the camera.
The practical failure is not just “bad photo accepted”, it is that the system confuses presentation of evidence with evidence of presence. A robust verifier has to distinguish live capture from stored, replayed, or injected media, otherwise fraud can be scaled with automation and reused artefacts.
How attacks typically succeed
Attackers usually exploit the gap by choosing the lowest-friction path that still satisfies the checks the platform actually performs. That may include showing a printed image to the camera, replaying a deepfake or synthetic face on a second device, or routing pre-recorded media through a virtual camera so the application sees a valid stream.
Once the workflow accepts “an image was provided” as sufficient proof, the attacker can often move past identity proofing, account recovery, or first-time enrolment. The control failure is especially dangerous when downstream decisions trust the result as if it came from a live, human-present session.
For teams designing fraud-resistant verification, the relevant comparison is not image quality alone but capture authenticity. The challenge is to ensure the session includes signals that are hard to fake at scale, then treat any missing or suspicious signal as a reason to step up verification rather than silently continue.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-63 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC — Access Control | Identity verification gates access decisions and recovery flows. |
| Recommendation — Enforce stronger access gates when capture integrity is weak. | ||
| NIST SP 800-63 | IAL — Identity Assurance Level | The question concerns assurance in identity proofing and verification. |
| Recommendation — Use higher assurance steps when live presence cannot be established. | ||
| CIS Controls v8 | 6 — Access Control Management | Verification failures can bypass account recovery and enrolment access decisions. |
| Recommendation — Require stronger control checks before granting recovery or onboarding access. | ||
Practitioner Guidance
What to verify: Confirm the verifier is checking for live capture signals, replay resistance, and injection resistance, not just face similarity or document readability. If the workflow cannot distinguish a camera feed from a virtual camera, assume it is vulnerable to media replay.
Decision rule: If the control only proves that an image or video frame was supplied, do not use it as a standalone gate for onboarding or account recovery. Route the case to a higher-assurance step when the session is high value, the user is high risk, or the captured signal looks artificially generated.
Common mistake: Teams often tune for lower false rejects and then remove the very checks that stop replay and injection abuse. That improves convenience for legitimate users, but it also makes the workflow easier to automate for fraudsters.
Practitioner takeaway: Treat live-capture assurance as a security control, not a cosmetic UX feature, because once that distinction is lost the verification flow becomes easy to spoof at scale.
Related resources from NHI Mgmt Group
- What happens when online identity verification relies on selfie capture without additional checks?
- How should organisations implement document-free identity verification without weakening fraud controls or compliance checks?
- What happens when businesses rely on identity verification without integrating it into broader authentication and transaction controls?
- How should security teams use selfie capture in online identity verification without weakening fraud controls?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 17, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org