CaraComp
CaraComp
Forensic-Grade AI Face Recognition for:
Get Started7-day refund guarantee**
Podcast

Your Real ID Can Still Be Used to Steal $47 Billion — Here's the Check Almost Everyone Skips

Your Real ID Can Still Be Used to Steal $47 Billion — Here's the Check Almost Everyone Skips

Your Real ID Can Still Be Used to Steal $47 Billion — Here's the Check Almost Everyone Skips

0:00-0:00

This episode is based on our article:

Read the full article →

Your Real ID Can Still Be Used to Steal $47 Billion — Here's the Check Almost Everyone Skips

Full Episode Transcript


Last year, Americans lost forty-seven billion dollars to identity fraud and scams. And according to Mitek Systems, roughly ninety percent of the fraud in digital sign-ups involves a fake or doctored document — not a stolen password, not a hacked server. A real human face, holding a fake ID.


If you've ever opened a bank account on your phone,

If you've ever opened a bank account on your phone, you've done this dance. Snap a photo of your driver's license. Then hold your face up to the camera and blink. It feels airtight. It feels like the system just proved you're you. And that feeling — that quiet confidence that the selfie step covers everything — is exactly the gap fraudsters are walking through. So how does a scammer beat a system that just watched them blink in real time?

Identity verification is really two separate questions. Question one — is this document real? Question two — is the person holding it the person it belongs to? Those are independent facts. Answering one tells you nothing about the other.

The airport version makes it obvious. Your passport proves you have travel authorization. That's "something you have." Then the border agent looks up, looks at your face, looks back down at the photo. That second look is the part that stops someone else from boarding with your credentials. Security people call that biometric binding — tying the live human to the credential in their hand.

Now picture the fraudster. His face is completely genuine. He's a real person, standing in real light, blinking on cue. He'll pass a liveness check every single time. The document in his hand is the forgery. And according to fraud researchers at Sumsub, forged or altered documents — fake IDs, passports, phony proof of address — made up about half of all identity fraud attempts.


Trusted by Investigators Worldwide
Run Forensic-Grade Comparisons in Seconds
Detailed facial comparison reports. Results in seconds.
Get Started
7-day refund guarantee**

Why does everyone get this backwards

Why does everyone get this backwards? Because liveness detection markets beautifully. It sounds complete. It captures a live person, matches their face to a photo — of course that feels like the whole job. But liveness only confirms one thing. A real human is in front of the camera. It says nothing about the plastic card they're holding up.

So documents need their own liveness test. And this is where it gets genuinely clever. When a fraudster holds a phone screen up to a camera instead of a real card, the image picks up moiré patterns — those rippling wavy lines you see when you photograph a screen. Photocopies leave a different fingerprint. Consumer printers can only reproduce a narrower band of colors than a real government-issued card. The software measures that gap. And a physically tampered ID — where someone lifted a laminate and swapped a photo — reflects light in ways that don't match an untouched surface.

Each fraud technique leaves its own signature. The forensics look for the signature, not the face.

There's one more layer worth knowing about, and it's the one that keeps security engineers up at night. It's called an injection attack. Instead of holding a fake face up to your camera, the attacker skips the camera entirely. They feed a manufactured video straight into the app, pretending it came from the lens. No blinking required — the system never actually saw a room. That's why serious platforms use capture integrity controls, which is a technical way of saying the system proves the image really came off the device's sensor, in real time. For a fraud analyst, that's an architecture problem. For you and me, it means the little camera icon on your screen isn't proof that a camera was ever involved.


The Bottom Line

A liveness check doesn't verify your identity. It verifies that a human being exists. Everything else — whether that human is you, whether that card is real — comes from a completely different set of checks. One layer catches fake people. The other catches fake paper. Skip either one, and you've left a door open.

So, three sentences. An ID proves the card is real. A face scan proves a person is real. Only doing both, together, proves the real person owns the real card. If you've ever felt uneasy about handing your face to an app, that instinct was pointing at something true — you just now know the specific name for it. And the next time a company asks you to blink at your phone, you'll know the right question to ask about what they're checking on the other side. The written version goes deeper — link's below.

Ready for forensic-grade facial comparison?

Full forensic reports with detailed similarity scoring. Results in seconds.

Run My First Search