CaraComp
CaraComp
Forensic-Grade AI Face Recognition for:
Get Started7-day refund guarantee**
biometrics

Identity Verification For Banking: Where Recovery Fails

Your Bank's Back Door Is a Selfie and a Sticky Note
A customer completes a selfie-based identity verification for banking step while updating account details on a phone.

Imagine this: you're switching to a new phone. You log into your banking app, hit a snag updating your email address, and customer support steps in to help. They ask you to take a selfie holding your ID and a handwritten note. You do it. Done. Problem solved.

Now imagine a fraudster doing the exact same thing, with a photo of your ID they bought on a dark web forum and a face that's close enough to yours to fool a tired support agent. That's not a hypothetical. That's the weakness Fincrime Central exposed in Qonto, a major European digital bank, and it's almost certainly how your own financial accounts work too.

TL;DR

Financial companies build strong security for sign-up, then quietly switch to much weaker checks the moment something goes wrong, and that "backup" process is exactly where attackers are breaking in.

The Front Door Is Fine: Selfie Verification Is the Risk

Here's the thing about modern banking security: companies have genuinely gotten better at the front door. When you first open an account, there are often sophisticated checks happening behind the scenes, video selfies, document scans, even checks that try to detect if you're a real living person rather than a photo being held up to a camera (this is sometimes called a "liveness check," which is exactly what it sounds like: it tries to confirm you're alive and present, not a static image).

CaraComp DailyEP.89
3 stories · 3:13
Starts at 01:08 — this story
3:13

Watch this story, in under a minute

Plays right here · jumps to 01:08
In this episode

A new briefing every weekday — three stories, three minutes.

Subscribe on YouTube

Qonto used a service called Fourthline to run those checks at sign-up. Fourthline is serious technology, the kind banks in Europe use to confirm you are who you say you are before they hand you access to financial services. Impressive, right?

Here's the kicker. When Fourthline's system ran into an error during routine account updates, say, a customer trying to change their email address, Qonto's support team didn't have a secure backup option. So they fell back to asking customers to submit a manual selfie alongside their ID document and a handwritten note.

Read that again. Enterprise-grade verification on the way in. A selfie with a handwritten note when things went sideways. This article is part of a series, start with Face Detection Before Identification How Facial Analysis Act.

$15.6B
lost to account takeover fraud in the U.S. in 2024, a 23% jump from $12.7 billion the year before
Source: Fincrime Central reporting

Why Recovery Is the Real Target

Let's talk about how attackers actually think, because this is where most security explanations lose people. Criminals aren't sitting there trying to guess your 15-character password. They're not trying to intercept your two-factor code (that's the six-digit text message that proves it's really you, the extra step beyond your password). Those things are genuinely hard to crack.

What's easy? Finding the path around all of that.

According to research published by AuthSignal, account recovery is the identity industry's most overlooked vulnerability, and the reason is almost embarrassingly simple: recovery processes are built for convenience, not security. When you're locked out of your account at 10pm, stressed and frustrated, the last thing anyone wants is a 45-minute verification process. So companies design recovery to be quick and human. And quick and human means it can be fooled.

As TechRadar reported in their analysis of recovery-based attacks: attackers have figured out that password resets and account recovery workflows are becoming a major entry point to bypass authentication entirely. Once they know the fallback process is weaker than the front door, they stop targeting the front door.

"When recovery is needed, organizations attempt to reconstruct trust using weaker signals than those used in the original proofing process." Analysis reported by AuthSignal

That's the trap in plain English: the moment your account is most vulnerable, when you've lost your phone, changed devices, triggered a security flag, is exactly when the verification drops to its weakest level. It's backwards. And the Qonto case is a textbook example of how it plays out in a real financial product.


Selfie ID Verification: The Account Recovery Vulnerability

Don't let this be a Qonto story in your head. It isn't. Qonto got named because they got scrutinized, but the manual selfie-with-ID fallback is everywhere. It's used by fintechs, credit unions, app-based lenders, and more traditional banks when their automated systems can't make a call. It looks official. It feels like security theater, because it is.

Here's why this matters so much right now, specifically: the tools to fake that process have gotten shockingly good. Deepfakes (AI-generated fake videos or photos that look real, think of it as a very sophisticated Photoshop that works on faces in real time) aren't just for politicians anymore. There are services, today, that can generate a convincing photo of your face holding an ID. A support agent who reviews 50 of these submissions a day isn't going to catch one that's been carefully constructed. Previously in this series: That 99 Accurate Badge Protecting Your Bank Account It Expir.

According to research from NHIMG, fallback authentication methods define the real attack surface of any security system, because an attacker only needs to find one weaker route to bypass everything stronger. It doesn't matter how good your front door is if the back window doesn't lock.

Why This Matters For You

  • The danger window is specificYou're most exposed when switching phones, updating contact info, or being asked to "re-verify" your identity after a login flag
  • 📊 The losses are already massiveAccount takeover fraud cost Americans $15.6 billion in 2024, up 23% in a single year, and that number is rising
  • 🔍 Your bank's sign-up security doesn't protect you hereThe same rigorous identity checks used when you opened the account are typically absent during recovery
  • 🚨 Fake media makes it worseAI-generated images are now sophisticated enough to fool human reviewers doing manual checks, which is exactly what fallback processes rely on
Trusted by Investigators Worldwide
Run Forensic-Grade Comparisons in Seconds
Detailed facial comparison reports. Results in seconds.
Get Started
7-day refund guarantee**

What You Can Actually Do, Before You're Locked Out

Most people only find out their bank's recovery process is weak when they're already in the middle of it, stressed, trying to regain access to their own money. That's the worst moment to discover a security gap. So let's get ahead of it.

First, and this is the most important thing, do this tonight, not someday: log into your most important financial accounts and look at what recovery options exist. Not your password. Not your two-factor setup. Specifically: what happens if someone says they're you and they've lost their phone? Is there a phone number to call? An email to contact? Does that process require anything that only you would actually know, or could it be faked with publicly available information about you?

If your financial provider's recovery process involves a customer support agent making a judgment call, especially one that relies on documents or photos, that's worth knowing now. Some providers let you set a PIN specifically for support calls. Some let you add a security phrase. Ask whether yours does.

As TechNewsWorld reported in their examination of identity breach patterns: the core problem is that identity assurance is treated as a one-time event, something you prove at sign-up, then never again. But the threat doesn't stop after you open the account. It just waits for the moment the guardrails are down.

If you've ever felt that quiet unease when a website asks you to "confirm your identity" with steps that feel weirdly easy, that instinct is correct. You're sensing the gap. The question this kind of situation forces us to ask is exactly the right one: is this check actually proving it's me, or just checking a box? Up next: Before Facial Recognition Names You It Has To Find You And T.

Key Takeaway

Your financial account's security is only as strong as its weakest path in, and for most people, that path isn't the login. It's the recovery process nobody thinks about until they're already locked out and desperate.


The Trust Inversion Nobody Talks About

There's something almost philosophically broken about the way this works. Companies spend serious money making sure the person who opens an account is real, because that's the regulated part, the part that auditors check, the part that shows up in compliance reports. Recovery? That's a customer service problem. Different team, different budget, different priority.

So we end up with this absurd inversion: the harder it is to sign up, the more trust you feel. And then, precisely when you need protection most, when you're locked out, when you've changed devices, when something unusual has triggered a re-verification, the system drops back to processes that haven't meaningfully evolved since online banking began.

A handwritten note. A selfie. A support agent making a call.

The Qonto case isn't a scandal about one company cutting corners. It's a mirror held up to an industry-wide assumption that security is something you achieve at the door, and then you're done. That assumption is wrong. And the people paying the price for it, to the tune of $15.6 billion last year, aren't the banks.

So here's the question worth sitting with tonight: if someone called your bank's support line right now, said they were you, and knew your address and the last four digits of your Social Security number, information that has leaked in roughly a dozen major data breaches over the past decade, what exactly would stop them?

Identity Verification During Account Opening vs. Recovery

Identity verification for banking usually gets its strongest treatment during account opening, when a bank runs document checks, liveness checks, and database matching before it will hand over access. That upfront process is where banks invest the most, because account opening is the regulated moment auditors actually review. The identity verification standard applied later, during recovery, rarely matches that same bar, which is exactly the gap this article has been describing.

Identity Proofing: What It's Supposed to Prove

Identity proofing is the formal term for confirming that a real person is who they claim to be, using a combination of documents, biometric checks, and database cross-referencing. Banks rely on identity proofing at sign-up to satisfy regulators and reduce fraud risk before an account even opens. The problem is that identity proofing is rarely repeated with the same rigor once an account exists, so a weaker process quietly takes over during recovery.

Identity Documents Are Easy to Copy, Hard to Verify Remotely

Identity documents like a driver's license or passport photo are simple for a fraudster to obtain, stolen scans circulate on dark web forums in bulk. A photo of an identity document alone proves very little, because anyone holding that same photo can present it. Real identity verification for banking needs a way to confirm the document belongs to the person in front of the camera, not just that the document exists.

Banking Onboarding Sets a High Bar That Recovery Doesn't Match

Banking onboarding is typically the most secure moment in a customer's entire relationship with a financial company, because it's built to satisfy strict compliance rules. Video selfies, liveness detection, and document scans are common during banking onboarding at reputable digital banks. Once that onboarding is complete, though, many banks never apply an equivalent identity verification process again, until something breaks and recovery kicks in.

Fraud Detection Gaps Show Up Most During Recovery

Fraud detection systems are usually tuned to watch for suspicious logins, unusual transactions, or mismatched device fingerprints. But fraud detection tools built for everyday activity often aren't built for the recovery workflow itself, where a human support agent, not an automated system, makes the final call. That's precisely the seam attackers have learned to target.

Document Verification Alone Isn't Identity Verification

Document verification checks whether an ID looks legitimate, correct fonts, security features, matching formats. But document verification by itself can't confirm the person submitting it is the document's rightful owner, especially when the submission is a photo rather than a live scan. Strong identity verification for banking pairs document verification with a liveness or biometric check, and recovery workflows often skip that pairing entirely.

Customer Identification Rules Were Built for Onboarding, Not Recovery

Customer identification requirements exist so banks can confirm who they're doing business with before opening an account. These customer identification rules were largely written with onboarding in mind, not the messier reality of a customer who has lost a phone or changed an email address. That's a real regulatory blind spot, and it's part of why recovery security lags so far behind sign-up security.

Biometric Verification Needs Liveness, Not Just a Photo

Biometric verification compares a face, fingerprint, or other physical trait against a stored reference to confirm identity. Biometric verification only works as intended when it's paired with liveness detection, otherwise a static photo or deepfake can pass the same check a real person would. A recovery process that accepts a plain selfie without liveness detection isn't really doing biometric verification at all; it's doing a visual guess.

IDV Is Only as Strong as Its Weakest Step

IDV, short for identity verification, is often described as a single event, but it's really a chain of separate checks, document, liveness, database match, human review. IDV breaks down the moment any one link in that chain gets swapped for something weaker, which is exactly what happens when a bank falls back to manual selfie review during recovery. A bank's overall IDV strength should be judged by its weakest step, not its strongest one.

Financial institutions that want to close this gap need to treat recovery as part of the same identity verification for banking framework they use at account opening, not a separate, lower-stakes process. That means applying the same document, liveness, and biometric verification standards to a password reset that they apply to a new signup. Until banks make that change, the recovery process, not the login page, will remain the easiest way into someone else's financial account.

Selfie Identity Verification Depends on What Happens After the Photo

Selfie identity verification is only as good as the checks that run after the photo gets taken. A single still image proves almost nothing on its own; the value comes from pairing that selfie with liveness detection and a document match, so the system confirms a real, present person rather than a picture of one. When a bank skips that pairing during recovery, selfie identity verification quietly becomes selfie collection instead.

Selfie verification exists to answer one question: is the person in front of the camera right now the same person the document belongs to? Selfie verification that relies purely on a support agent's eyeballing a photo, with no liveness detection or facial recognition behind it, is not selfie verification in any meaningful sense, it's a visual formality that a good deepfake can already defeat.

Facial Recognition Technology Is Not the Same as a Liveness Check

Facial recognition technology measures whether two faces match, the face in a photo against the face in an ID, or against a stored reference. That matching function is useful, but facial recognition technology alone can't tell the difference between a real face and a convincing photo of one; that job belongs to liveness detection running alongside it. Banks that market "facial recognition" as their recovery safeguard, without a liveness layer, are leaning on half the tool.

Facial Recognition Alone Can Be Fooled by a Static Image

Facial recognition compares facial geometry and features to decide if two images show the same person, but it doesn't inherently know if the image it's looking at is a live capture or a printed photo held up to a camera. That's why facial recognition is normally paired with liveness detection in strong identity systems, and why its absence in a recovery flow is such an easy target. A fraudster who has a clear photo of your face can sometimes get past facial recognition alone; getting past facial recognition plus liveness detection is much harder.

Selfie Video Requests Are Trying to Add Liveness After the Fact

A selfie video request, asking someone to turn their head, blink, or read a number out loud, is a low-tech way to add liveness detection when there's no automated system in place. It works reasonably well against a static photo, but a selfie video can still be spoofed with modern deepfake tools if the reviewer isn't trained to look for the tells. Some support teams now ask for a short video instead of a still photo specifically because a still image is the easiest thing of all to fake.

Video Selfie Checks Still Need a Human or System That Knows What to Look For

A video selfie adds motion, which rules out a simple printed photo, but it's not automatically secure just because it moves. If the person reviewing a video selfie isn't looking for lighting inconsistencies, unnatural blinking, or mismatched audio, a well-made deepfake can pass anyway. Real protection comes from combining a video selfie with liveness detection software built to catch exactly those signs, not from the video format alone.

Selfie Checks Are Only a Safeguard When Something Verifies the Selfie

Selfie checks are the visible part of identity verification, but the real security work happens in whatever compares that selfie against a document and confirms the person is physically present. Selfie checks that skip liveness detection and facial recognition scoring are really just asking, "does this person look like the ID?", a question a support agent under time pressure isn't well equipped to answer for a stranger. That's the exact gap the Qonto case exposed, and it's why selfie checks alone should never be the last line of defense for a financial account.

ID.me Shows What a Stronger Verification Model Looks Like

ID.me is one example of an identity verification provider built around combining document checks, facial recognition, and liveness detection into a single automated decision, rather than leaving the call to a support agent's judgment. Government agencies and some private companies use services like ID.me specifically because a manual review of a selfie and an ID photo doesn't hold up against modern fraud tools. Banks weighing how to fix their recovery process don't have to copy ID.me exactly, but the underlying idea, automate the hard verification instead of downgrading it, is the right one.

Some partner agencies may ask you to complete an additional identity verification for banking step if your first attempt fails, and that's normal rather than a red flag. You may be asked to verify your identity a second time using face-based biometrics or a fresh selfie video, especially if your original selfie failed a liveness detection check. Knowing that in advance means you won't panic and skip the step, or worse, simply record a rushed video that fails the same check again.

How Banks Confirm Someone's Identity Remotely Using Electronic Methods

Confirming someone's identity remotely using electronic methods means comparing a live capture of a person's face and document against trusted databases, instead of relying on a person's judgment alone. This approach is how account opening works at most digital banks today, and it's the standard identity verification for banking should be held to during recovery as well. Confirming someone is actually present, not just holding a photo, is the entire point of the electronic methods that replace manual review.

Online Banking Identity Verification Should Not Weaken After Sign-Up

Online banking identity verification tends to be strongest on day one, when a new customer opens an account, and weakest months or years later, when that same customer needs to recover access. That gap exists because online banking identity verification was designed around a single moment rather than the full lifetime of an account. Closing it means applying the same document and liveness standard to recovery that online banking identity verification already applies at signup.

Why Identity Verification Is Treated as a One-Time Event

Identity verification is often built as a gate you pass through once, at account opening, rather than a standard that applies for as long as the account exists. Identity verification is cheaper to run one time than to run continuously, which is exactly why banks invest heavily upfront and then quietly downgrade the process later. Until identity verification is treated as ongoing rather than a one-time event, recovery will keep being the weak link fraud goes looking for.

Financial institutions that handle customer data at this scale carry real compliance obligations, and those obligations don't disappear the moment an account moves from onboarding into everyday use. A bank's risk exposure during recovery is arguably higher than at signup, because the customer is already trusted and the account often already holds money. Digital-first platforms in particular need to apply the same data protection and identity verification for banking rigor across the entire customer lifecycle, not just the first login.

Compliance teams that only audit account opening are missing where fraud risk actually concentrates. KYC, know your customer, checks are typically run once, at signup, but the customers most at risk of account takeover are the ones who've been with a bank for years and have drifted out of active monitoring. A platform that revisits its identity verification for banking standards at recovery, not just at onboarding, closes the exact gap this article has described from the start.

Frequently asked questions

How does identity verification for banking actually work when I open a new account?

When you first open an account, banks typically run sophisticated checks behind the scenes, including video selfies, document scans, and liveness checks that try to confirm you are a real, present person rather than a photo held up to a camera. This front-door process tends to be genuinely strong, which is why attackers usually don't target it directly.

Why is account recovery a weak point in identity verification for banking?

Companies build strong checks for sign-up but quietly switch to much weaker checks once something goes wrong, such as updating an email after losing a phone. A support agent may simply ask for a selfie holding an ID and a handwritten note, and that backup process is where attackers are actually breaking in, since it's easier to fool than the original verification.

Can a fraudster get into my bank account using a fake ID and selfie?

Yes, a fraudster can use an ID photo bought on a dark web forum along with a face close enough to fool a tired support agent, submitting the same selfie-with-ID-and-note request a legitimate customer would during account recovery. This weakness was exposed at Qonto, a major European digital bank, and likely reflects how many other financial accounts handle recovery too.

Ready for forensic-grade facial comparison?

Full forensic reports with detailed similarity scoring. Results in seconds.

Run My First Search