Deepfake Identity Fraud: Why Selfie and Liveness Checks May Not Be Enough


Deepfake Identity Fraud: Why Selfie and Liveness Checks May Not Be Enough

How many generated faces are reaching your selfie checks? Entrust’s 2026 Identity Fraud Report found that deepfakes account for about one in five biometric fraud attempts in its identity verification data. Deepfake selfie attempts also increased 58% in 2025.

That does not mean one in five biometric checks is fraudulent. Entrust analyzed more than 1 billion identity verification events across 195 countries and more than 30 industries. Its report covers September 2024 through September 2025 and reflects Entrust’s own verification data, so the findings should not be treated as a universal market rate.

For KYC teams, lenders, insurers, and HR screening teams, the takeaway is simple: a successful face match or liveness check should be one identity signal, not proof that every applicant detail belongs to the same person.

Why Deepfake Identity Fraud Is a Growing Onboarding Concern

Remote onboarding often asks an applicant to submit an identity document and capture a selfie or short video. Face matching can compare that image with the portrait on the document.

Fraud methods are changing alongside those controls. Entrust reported a 40% year-over-year increase in injection attacks. These attacks can feed manipulated images or video directly into a verification process. Its report also identifies AI-generated faces, face swaps, and animated selfies among techniques seen in biometric fraud attempts.

Teams handling synthetic identity verification should also consider how injection attacks and generated media may be used in an attempted liveness detection bypass.

NIST’s Digital Identity Guidelines, published in July 2025, also address forged media and injection attacks. NIST explains that presentation attack detection can provide protection against injection and forged-media attacks, but these controls cannot address every possible case.

For onboarding teams, that creates two separate questions:
  1. Does the biometric capture appear genuine?
  2. Do the identity details submitted with it align with credible records?

What Biometric Verification Can and Cannot Tell You

A face match can help determine whether a captured face resembles the comparison image. Liveness detection can help identify certain spoofing attempts.

Neither result automatically tells you whether the applicant’s name matches the submitted SSN, whether the address fits the rest of the record, or who controls the phone number on the application.

The FBI’s 2025 IC3 Annual Report, released in April 2026, provides a broader context on complaints containing AI-related information. IC3 received 22,364 such complaints during 2025, with $893,346,472 in adjusted losses associated with them.

IC3 tracks “AI Related” information alongside reported crime types rather than treating it as a standalone crime category.

For onboarding teams, the question should not stop at, “Did the selfie pass?” Other identity signals still need to make sense together.

How Deepfake Risk Can Appear in Business Workflows

Lending and fintech onboarding

A lender receives an application with a selfie, identity document, SSN, phone number, and address. The biometric check passes, but a separate review finds that the name does not align with the SSN.

That mismatch does not prove fraud. It may justify checking for an error or requesting another verification step.

Insurance applications

An applicant completes remote onboarding and provides a phone number. The face and document checks appear normal, but the phone later appears disconnected or shows unexpected characteristics.

The team may request updated information or contact the applicant through another established channel.

Remote hiring

A candidate completes a video interview and submits identity information for screening. A convincing video appearance does not establish that every identity field belongs to that candidate.

HR teams may still compare submitted data with independent records. The same principle applies to automated data validation for fraud prevention. Automated checks can flag inconsistent information, but they do not prove that a person or business is genuine.

5 Checks to Add Around Biometric Verification

Here are five checks teams can add around biometric verification to review identity data more closely.

1. Separate face matching from identity-data matching

Treat the biometric result as one part of the record. Review the name, SSN, address, phone number, and other relevant fields separately when they affect the decision.

2. Check whether the name aligns with the SSN

A valid SSN does not automatically mean the rest of the application belongs to the same person. A mismatch may justify correcting an error or requesting more information.

A match can support the review. It does not establish that the person completing the biometric check is the SSN holder.

3. Compare several identity fields

Names, addresses, phone numbers, emails, and dates of birth can provide more context when reviewed together.

Conflicting information may point to outdated records, a data-entry error, or information associated with another person. It should not automatically be treated as fraud.

4. Review the phone number separately

Teams may check whether a number appears active and review its line type, carrier, porting status, and caller ID information.

Unexpected characteristics may warrant another check. Normal phone data does not prove who controls the number.

5. Define the next step for conflicting results

Possible actions include correcting an error, requesting another document, contacting the applicant through an established channel, running another verification step, or sending the case for manual review.

One mismatch should not automatically lead to rejection.

How Searchbug Can Add Identity Data to a KYC Review

Searchbug does not detect deepfakes or replace biometric verification. Its tools can add independent identity and contact-data signals to an existing onboarding process.

Check whether a submitted name matches the SSN

Searchbug SSN and Name Match can help determine whether the name entered matches the supplied SSN.

A mismatch may lead to another verification step. A match can support the review, but it does not prove that the applicant is the SSN holder.
Note: Account with SSN Verification Access Add On is required for this search.
 

Compare applicant information with available records

The Enhanced People Search API can return available names and aliases, addresses, phone numbers, emails, date-of-birth information, and other records.

SSN and driver’s license information require eligible business access and the appropriate Restricted Access Add-On. Results depend on available records and account access, and returned data does not establish ownership of every record.

Check phone characteristics independently

Searchbug Phone Validator can return information such as line type, carrier details, porting status, reachability, and CNAM depending on the service and available data.

An unexpected phone result may justify another review. A reachable number with normal carrier information still does not confirm identity or phone ownership.

TL;DR

Entrust found that deepfakes accounted for about one in five biometric fraud attempts, while deepfaked selfie attempts rose 58% in 2025. Those figures apply to Entrust’s dataset, not all biometric checks.

KYC and onboarding teams can pair biometrics with SSN and Name Match, Enhanced People Search, and Phone Validator to review other identity and contact data. No single result proves fraud or confirms identity.

Create a free Searchbug API Test Account with $10 in credits to test these checks with your workflow. Teams reviewing larger files or working without an API can also use Bulk Processing.

Data Verification

Deepfake Identity Fraud: Why Selfie and Liveness Checks May Not Be Enough