MilikMilik

How Fraudsters Exploit Selfie Verification—and How Android Fights Back

How Fraudsters Exploit Selfie Verification—and How Android Fights Back
Interest|Mastering Your Phone

Selfie verification is not the fortress you have been sold

Selfie verification fraud is the abuse of face-based identity checks—such as taking a selfie to open an account—using fake images, masks, recordings, or injected video streams to trick systems into accepting the wrong person as the rightful owner.

The uncomfortable truth: selfie verification is far more fragile than its marketing suggests. Persona’s latest report found that simple presentation attacks are the dominant form of selfie fraud, and they are not rare outliers. Out of more than 27 million fraudulent selfies analyzed, 86.2 percent were presentation attacks. That is not a minor flaw; it is a structural weakness in how we are doing selfie fraud detection today. When a security measure fails in the most common attack scenario, calling it “high assurance” borders on misleading. Rather than obsessing over Hollywood-style deepfakes, we need to admit that selfie-based identity checks are being beaten by printer paper, plastic masks, and screens held up to cameras.

Fraud “slop”: paper, masks, and hijacked camera feeds

If you imagine selfie fraud as cutting-edge AI wizardry, you are giving criminals too much credit and your defenses too little. The vast majority of attempts are still low-tech presentation attacks, where someone wears a mask, holds up a printed photo, or replays a video from another screen to fool facial recognition. These basic tricks alone make up 66.2 percent of cases. That is how weak many current presentation attack security measures remain.

Of course, attackers also go beyond what the camera sees. Injection attacks use software or hardware to replace or bypass the camera stream altogether. That means the selfie app never sees the real scene—only a pre-recorded or synthetic feed. Even here, fraudsters prefer videos of real people over AI-generated selfies, and are 194 percent more likely to inject real-person videos. Fraud marketplaces now sell bundles of IDs, documents, and video selfies for as little as USD 12 (approx. RM55). With packages that cheap, treating selfie-based identity as “strong” security is wishful thinking.

When “Hey Mum” becomes a weapon: social engineering meets your face

Selfie fraud does not live in a vacuum; it feeds on social engineering. Many of those real-person videos that bypass facial recognition are harvested from people who are tricked into sharing a selfie or who are paid without understanding how their face will be used. That is where the now-infamous “your mum” scams merge with selfie fraud. Up until now, most of these scams have arrived by text or over messaging apps, but criminals are expanding to calls, too.

A phone call that sounds like your child—potentially powered by an AI-cloned voice—can pressure you into snapping a selfie, sending documents, or authorizing payments. Once captured, that imagery can be resold alongside other data and used to mount presentation attacks or even camera injection attempts. In other words, the facial recognition bypass begins with a con, not a line of code. If we ignore the human side of identity theft prevention, no amount of clever algorithms will save us.

Android’s new fake-call detection: your phone as scam filter

The good news is that mobile platforms are finally treating social-engineering scams as a first-class security problem, not a side issue. To help stop those “your mum” style calls before they lead to stolen selfies or IDs, Google is rolling out a new Android phone security feature that checks whether an incoming call is fake or real. Owners of recent Android phones, especially Pixel users, will see it first.

This system builds on Rich Communication Services. When someone calls, their phone app sends a signal that it is a genuine caller tied to a real contact; your phone can then verify that signal. When scammers spoof numbers or inject themselves into the chain, that initial signal is missing, and your phone can flag the call as suspicious. It is not perfect—if your contact is on a different platform that does not use Google’s phone app, verification may fail. Still, it is a meaningful shift: the network itself is being used as a front-line filter, not leaving users alone against increasingly polished cons.

Why awareness and updates matter more than blind trust in biometrics

The worst mistake you can make is to treat selfie verification as a magic shield. Persona’s data shows that GenAI content appears in 23.5 percent of fraudulent selfie attacks, with 20 percent in presentation attacks and 3.5 percent in injection attacks. That is a serious volume of AI-assisted abuse layered on top of already pervasive low-tech tricks. Meanwhile, attackers target high-value accounts with more elaborate methods and deploy bots or AI to launch hundreds of thousands of attacks.

On the defensive side, the tools are catching up. Persona recommends visual models that check for AI-generated content and presentation attacks, plus device intelligence, behavioral signals, and population-level analysis to spot bots and abnormal activity. Android’s fake-call detection is being released to Pixel devices first and will eventually reach all Android phones on version 12 and above. The takeaway is uncomfortable but clear: face-based logins and selfie checks are only as strong as the anti-fraud layers and call protections around them. Treat biometrics as one piece of identity theft prevention—not a reason to relax—and make sure your devices and services evolve as quickly as the attackers do.

Milik earns a commission when you shop through our links, at no extra cost to you. This article was generated with AI from published sources and product data.

You May Also Like

Comments
Say something...
No comments yet. Be the first to share your thoughts!