Your Face Just Became the Password Criminals Can't Wait to Steal
Your Face Just Became the Password Criminals Can't Wait to Steal
This episode is based on our article:
Read the full article →Your Face Just Became the Password Criminals Can't Wait to Steal
Full Episode Transcript
A piece of malware can now copy your face — not your password, not your card number, your actual face — and use it to walk into your bank account. Security researchers at Zimperium found it running across five countries right now. It's called GoldPickaxe, and it doesn't want your login. It wants you.
Think about the fixes you already know
Think about the fixes you already know. Password stolen? You reset it in a minute. Phone hacked? You restore from a backup. But your face doesn't have a reset button. According to Zimperium, this malware tricks people into building a full facial profile and photographing their I.D. cards — then uses that to build a video fake of you. If you've ever scanned your face to unlock your banking app, this story is about the exact thing you trusted to keep you safe. So how does a copy of your face become the key to your money?
Start with how it gets in. Zimperium researchers say the attackers disguise GoldPickaxe as a government app. You think you're doing paperwork. Instead, the app asks you to record your face from every angle. Then it asks for a photo of your I.D. Then your banking details. Each step feels normal on its own. That's the trick — the criminals aren't just grabbing a photo, they're collecting everything they'd need to pretend to be you. And for you, it means the "official" app you downloaded to be responsible was the whole trap.
Now here's where the money comes in. Your bank added face scanning to stop password thieves. So the criminals skipped the password and went straight for the face. Most banking apps run what's called a liveness check — a quick scan to confirm a real, live person is in front of the camera. But researchers describe an attack called camera injection. The fraudsters feed a pre-recorded deepfake video directly into the camera feed. The system never sees a fake face on a screen. It just sees video, and it believes it. The check that's supposed to prove you're real can't tell your real face from a good copy.
And these copies are getting better fast. Industry trackers read the numbers like this — face-swap bypass attempts jumped sevenfold in a single year, then kept climbing. That's not a slow creep. That's a flood. For a fraud investigator, that rewrites what counts as proof someone showed up. For the rest of us, it means the video of your face might not need your face to be there at all.
The Bottom Line
There's one more shift worth hearing. The Identity Theft Resource Center reports that for adults in their late thirties through their early sixties, someone taking over your device has now passed scams as the top threat. Device break-ins rose nearly eighty percent in a year. That's twelve months. The Sumsub fraud report found most businesses expect biometric fraud to rise the most next year. The people building these systems are already bracing for it.
Here's the part that flips it. A liveness check was never designed to prove the face is real. It only proves a face is present. Present and authentic are two different things — and criminals just found the gap between them.
So let's bring it home. Bad software can now steal a copy of your face and use it to open doors meant only for you. Your bank's face scan checks that a face is there — not that it's really yours. And the fakes are improving faster than the checks can catch them. You can change a stolen password. You can't change your face — which is exactly why this one lands closer to home than any leak before it. The full breakdown's in the show notes if you want the deep dive.
Ready for forensic-grade facial comparison?
Full forensic reports with detailed similarity scoring. Results in seconds.
Run My First SearchMore Episodes
That Annoying "Verify Again" Text? It's Catching Fraudsters Using Real ID Numbers
Researchers at deepidv looked at four million fake identities. Nearly a quarter of them used a real government I.D. number — a legitimate number, pulled from a real record — paired with completely invented personal details. <break time="0.5s"
PodcastYour Face Is Forever. A Judge Just Ruled Companies Can't Hide What They Did With It.
A judge just ordered a company to hand over its deletion logs. Not its marketing. Not its emails. The quiet, boring records that show exactly when it erased people's faces from its systems. And that o
PodcastYour Selfie Gets Checked Once. It Could Train Their AI Forever.
Upload a selfie to verify your identity — just once. That single photo could quietly become fuel for an A.I. that keeps improving long after you've forgotten you ever sent it. And under Europe's new A.I. law, the company holding that photo ca
