office@safebyte.io București, România ISO 27001:2023 · ISO 9001:2023
Offensive testing

eKYC and anti-deepfake resilience

Fraudsters open accounts with AI-generated faces, forged documents and cloned voices — increasingly injected directly into the application without any real camera involved. We test your onboarding flow against both attack classes, following ISO/IEC 30107-3.

Français: această pagină nu e încă tradusă. Textul de mai jos e în English.

eKYC and anti-deepfake resilience

Remote identity verification has shifted from “is this the right person?” to “is this even a real person?”. Fraudsters open accounts using AI-generated faces, forged documents with a swapped portrait and cloned voices — and the newest, least tested vector no longer goes through the camera at all: synthetic media is injected directly into the application flow, via a virtual camera or at the API level, bypassing the sensor entirely. We test exactly what your onboarding lets through, against both attack classes.

Presentation vs injection

The distinction is central and determines where the damage lies:

  • Presentation attacks — what you show the camera: a printed photo, screen replay, 3D masks, graded according to ISO/IEC 30107-3 levels (from L1 to high-fidelity custom masks)
  • Injection attacks — synthetic media fed directly into the flow, with no real camera: deepfake video, face-swap and face-reenactment, face morphing, API-level injection into the verification endpoint

What else we test

  • Document fraud — manipulated or forged documents, portrait substitution, print-and-recapture, MRZ and chip inconsistencies
  • Voice — cloned voice against any voice-verification or call-centre step
  • Liveness bypass — defeating active (challenge-response) and passive liveness, plus replay of earlier legitimate sessions

The compliance context matters: AML/KYC onboarding, the FATF guidance on digital identity, the eIDAS/European Digital Identity Wallet direction and payment obligations under DORA/PSD2.

What you get

  • An attack matrix (presentation vs injection × vector), showing what passed and the exact technique and media that succeeded
  • Grading aligned with ISO/IEC 30107-3 and gap analysis against certification levels
  • Remediation: injection-attack detection, stronger liveness, hardening the channel from capture to backend against manipulation, document and chip authenticity verification