11/08/2026
🔐 Your face might be “live”, but the camera never saw it.
Two of the fastest-growing threats to online identity checks are native virtual camera attacks and injection attacks.
Virtual camera attacks grew by 2,665% in 2024, using apps (sometimes from official app stores) to replace the real camera with pre‑recorded or synthetic video
Injection attacks bypass the camera entirely, feeding deepfakes directly into the verification software as if they came from a real device. Benchmarks show these attacks rising about 9× year over year from 2024 to 2026.
Why this matters:
Most remote onboarding, KYC, and account-recovery flows assume the camera feed is trustworthy. These techniques break that assumption, letting attackers slip deepfakes past basic liveness checks without ever showing a real person to a lens.
For anyone using or approving digital identity systems:
“Did the user move their head?” is no longer enough.
Strong defenses now need to validate the full session, media, device integrity, and behavior, not just the face on screen.