Deepfakes are evolving and are no limited to disinformation campaigns or viral media manipulation. Most security teams already understand the problem of deepfakes. However, the most urgent change is how synthetic media is made operational. This direction of fraud is being exploited within the identity moments that power the internet and the economy – such as customer registration with banks, driver registration for gig and delivery platforms, seller verification in marketplaces, account recovery, remote hiring, partner access, and privileged access workflows.
See also: Deepfake attacks and biometric spoofing

As more work and business is done remotely, identity has become a primary point of control – and a primary target. Malicious actors don’t just want to fool a selfie check. They want to impersonate a real person, establish persistent access, and reuse that fingerprint across consumer and enterprise environments. Cybersecurity and fraud teams now face a convergence of tactics that all aim for the same decision – the moment a system concludes “this is a real person”:
- High-fidelity synthetic faces and voices that can pass quick checks
- Reproducing real footage from stolen or collected sessions
- Automation that examines verification flows at scale
- Injection attacks that breach the capture line and replace the upstream input flow
This is why “deepfake detection” alone is no longer enough. Businesses need full session verification: including perceptions, device integrity, and behavioral signals… all in a single, real-time audit. That’s the model behind Incode Deepsight: an approach designed to verify identity sessions end-to-end, not just evaluate media in isolation.
The right question is not just “Does this person look real?” It’s “Can we trust this entire session end-to-end?” In enterprise systems, a successful bypass is not a reputation event. It’s an access event. When verification accepts a forged or compromised session as real, attackers can:
- Create fake accounts using synthetic identities
- Take over existing user accounts
- Bypass HR verification in remote hiring
- Gain unauthorized access to sensitive internal systems
See also: United Kingdom: Law criminalizing Grok's deepfakes

Unlike social media spoofing, these attacks can allow persistent access within trusted environments.
The downside is ongoing: account retention, privilege escalation paths, and lateral movement opportunities that start with a single incorrect verification decision. An independent study from Purdue University evaluated leading biometric vendors under advanced deepfake and impersonation attack scenarios. Most identity verifications rely on two signals: facial similarity and “liveness.”.
Both are useful, and both can be undermined if the system assumes the input stream is authentic. Attackers break this assumption in two complementary ways. First, they mimic real media. Deepfakes and voice clones improve under real-world operating conditions—short clips, mobile capture, compression, and imperfect lighting. A workflow that relies on a narrow visual surface is increasingly vulnerable to false acceptance. Second, they bypass the sensor altogether.
Injection attacks replace the input stream before it reaches the analysis. Instead of presenting a face to a camera, attackers can:
- Use virtual camera software to feed synthetic or pre-recorded video
- Run verification sessions within emulators designed to mimic legitimate mobile devices
- They operate from rooted or jailbroken devices that bypass integrity checks
- Replace live capture with manipulated upstream flows
See also: Deepfakes: How impersonation attacks are fueling financial fraud

In these scenarios, the means can seem perfect because they have never had to survive an actual capture run.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
